Skip to content
All articles
Health

Patients · registry, sensitive data and consent

The Patients screen is the administrative registry of the people your practice serves, with the Patient 360 view. Here you add identifiers without exposing the number, record and revoke consent by purpose and channel, store the document and legal guardian encrypted, and run the document checklist. Every read of sensitive data is logged.

Open Health, then Patients. If the Health menu is not there, the vertical has not been turned on yet: ask an administrator to enable it in Settings, under Verticals.

Registering a patient

  1. Click New patient.
  2. Fill in Name. It is the only mandatory field.
  3. Fill in Birth date and Sex if you already have those details.
  4. Click Save. The patient now appears in the list with their Status.
  5. Click Open 360 on the patient row to see and complete everything else.

Identifiers without exposing the number

Inside Patient 360 there is an Identifiers section. You enter the system, for example a national ID or the name of the insurance card, and the Value. On saving, the system stores a blind form of the value: it can search by exact equality, but it does not keep the number readable. That is why the identifier list shows the system and never shows the value back, not even to the person who entered it.

Sensitive data and the Reveal button

The Sensitive data section holds Document and Legal guardian. Both fields are encrypted and do not appear by default: the screen only shows that something is on file. To see it, click Reveal. The system asks for the purpose of the read, decrypts and returns the value, and at the same time writes an access record with who read it, which patient, the stated purpose and whether it was an emergency access.

That record cannot be changed or deleted. It exists precisely to answer the question that comes up in an audit or in a data subject request: who saw my data, when and what for.

💡 If you only need to confirm that the document is on file, do not click Reveal. Every reveal becomes a permanent row in the access trail.

The Consent section records the patient's authorization per pair of Purpose and Channel. The available purposes are care coordination, transactional appointment communication, billing and finance, care program, preventive outreach, marketing, research, telehealth and sharing with a third party. The channels are email, SMS, WhatsApp, voice, push and postal mail.

  1. Choose the Purpose.
  2. Choose the Channel.
  3. Click Grant to record consent, or Revoke to record an opt-out.
  4. The list now shows the pair with its current status.

The distinction that matters most: transactional purposes, tied to care or to a service already contracted, do not depend on explicit consent to work. Marketing, research and sharing with a third party do. An opt-out, on the other hand, applies to everything. If the patient revoked that purpose and channel pair, the send is blocked even when it is transactional, and even when the message is urgent.

Consent is not a notice in the interface. It is checked at the moment of sending, which means a campaign, a reminder or a recall simply does not go out to somebody who revoked.

Example: Ann Ribeiro grants consent for appointment reminders by SMS and for preventive outreach by email, but revokes marketing by WhatsApp. She keeps getting the reminder for Thursday's appointment and can be included in a preventive recall by email. The year end WhatsApp campaign never reaches her, and the recall preview counts her as not contactable on that channel.

Document checklist

Still inside Patient 360, the Document checklist tracks what the practice requires from each patient, for example an ID or an insurance card. You add the item, mark it received when it arrives and then approve or reject it. The states are Pending, Received, Approved, Rejected and Expired, and the summary tells you how many required items are still missing.

The file itself is not stored in this checklist. It references the attachment already uploaded to the CRM, which avoids two copies of the same document sitting in different places.

Common questions

  • Can I see the identifier number later? No. The value is stored blind precisely so that it cannot be read back. If you need the number, it lives on the physical document or in the attachment.
  • Does revoking consent erase the history? No. The revocation is recorded as a new state of that purpose and channel pair, and it takes effect on sending immediately.
  • Why does the screen not show a diagnosis or clinical notes? Because the vertical is administrative by design. Clinical information stays in the institution's clinical system.
  • Who can reveal sensitive data? Anyone with access to the patient screen. The real protection is not hiding the button: it is that every reveal is logged with a name and a purpose.

Open this article inside the system

Read it and want to see it working?

The account is free and the whole manual is available inside the system, with an assistant that answers from this very content.

Create free account
Patients · registry, sensitive data and consent · Sellio