Skip to content

Review a Records Request

Every records request — whether a patient raised it from the portal or a records officer logged it for a third party — passes through a review before anything is released. Reviewing is where a records officer confirms the requester is who they say they are, checks the authorization where one applies, and decides per record category what may be disclosed.

Who / when: the Records Officer, on any request sitting in Submitted or Under Review. (Only a Records Officer and an Administrator can review — it is a least-privilege capability, not a clinician or reception default.)

We continue with Tunde Okafor, reviewing the law-firm request for Amina Bello.

  1. Records Officer — open Records → Request Queue and click the request’s row. Its full detail opens in a drawer (there is no separate “request detail” menu item).
  2. Records Officer — read the request: patient, requester name and requester type, contact, channel, the requested record categories, the date scope, and the purpose.
  3. Records Officer — if this is a third-party request, press “View Authorization” to open the uploaded proof. Satisfy yourself it is genuine, in date, and covers what is being asked. (Opening the authorization is itself audited.)
  4. Records Officer — assigning a request to yourself or a colleague moves a Submitted request to Under Review, signalling it is being worked.
  5. Records Officer — in the Review Decision panel, the requested categories appear as ticked boxes. Decide:
    • Approve everything — leave all requested categories ticked and press “Approve Selected”. The request becomes Approved.
    • Partially approve — untick the categories you will not release, then press “Approve Selected”. The request becomes Partially Approved, and only the still-ticked categories will be compiled later.
    • Deny — enter a reason (required) and press “Deny”. The request becomes Denied (a terminal state).
  6. Records Officer — if the facility charges for copies and this is a third-party or expedited request, tick “Expedited” where applicable; the optional configured fee is captured automatically on approval. (A patient’s own request is free by default.)

When the decision is recorded, the patient (if they have a portal identity) receives a content-free notice that their request was approved or denied — a heads-up with a link to the portal, never the records themselves.

An Approved or Partially Approved request is ready to fulfil — the records officer runs the longitudinal compiler over the approved categories to build the encrypted pack. See Fulfil a Request — Compile the Records Pack. A Denied request stops here, with its reason on the record.