Release of Information — Request to Disclosure
Who / when: a Patient asking for their own record from the portal, or a Records Officer logging a third party’s request (a lawyer, insurer, employer, court or other facility) at the front desk — then a Records Officer reviewing, fulfilling and disclosing it through one controlled, audited workflow.
Release of Information (ROI) = giving out a copy of a patient’s health record under control. Requester type = who is asking (Patient = the data subject; everyone else is a third party). Records category = the kind of record requested (encounters, notes, diagnoses, problems, labs, imaging, prescriptions, vitals, documents). Longitudinal compiler = the engine that assembles the approved categories across a date window into one branded Medical Records Pack PDF. Records officer = the staff role that runs ROI end to end. Disclosure = one release; the accounting of disclosures is the immutable log of them.
- Request in — patient door. A Patient opens Records in the portal, ticks the record categories and date range they want, chooses portal download or printed pickup, and sends the request. The requester is forced to Patient and the channel to Portal; the request enters the queue as Submitted (and is free).
- Request in — third-party door. Alternatively a Records Officer opens Records → Request Queue → “Log A Request”, selects the patient, sets the requester type (Lawyer / Insurer / Employer / Court / Other Facility / Authorized Representative), the channel (Front Desk / Email / Phone / Mail), attaches the authorization file (required for any third party), and sets the categories and scope. The request enters the queue as Submitted.
- Review. A Records Officer opens the request from Records → Request Queue, verifies the requester and (for a third party) opens “View Authorization”. Assigning moves it to Under Review. The officer then Approves all categories, Partially Approves a subset, or Denies with a reason. On approval, any optional third-party/expedited copying fee is captured through the Bill seam.
- Fulfil. On an Approved / Partially Approved request, the Records Officer presses “Compile Records Pack”. The longitudinal compiler gathers only the approved categories within the scope window into one branded PDF (cover + contents index + a chronological section per category) and stores it encrypted at rest. The request becomes Fulfilled.
- Disclose and deliver. The Records Officer presses “Deliver To Portal” (shares the encrypted pack into the patient’s portal + a content-free notice) or “Printed Pickup” (in-person collection). Either way Veona writes the immutable disclosure row and moves the request to Delivered.
- Patient receives. A portal-delivered pack appears in the patient’s My requests list with a Download button; the file downloads inside their authenticated session — never by email.
What happens next: the disclosure is now part of the accounting of disclosures in Records → Disclosure Log — an append-only record of who received what, over which scope, by which method, and when. Every action (view, authorization open, decision, compile, deliver, download) is also written to the tamper-evident audit trail. Denied and Delivered are terminal — a new need means a fresh request.