| The patient can ask for a copy of their record164.524 |
✓ |
A tracked request with a deadline the system works out for itself, and a decision at the
end. Complete with the five parts that generate most of the federal enforcement:
one extension of up to thirty days, which records both the reason and the
date the patient was actually told; an itemised fee limited to the four
things the rule permits, with a warning when it goes over your configured cap;
the format they asked for; sending a copy to somebody they
nominate, linked to their written instruction; and review of a
refusal by a named professional who was not part of the original decision. |
| They can ask for something to be corrected164.526 |
✓ |
A correction is filed as a new version — the original is never overwritten. Complete
through what happens when a correction is refused: the patient's
statement of disagreement in their own words, the clinic's
written reply, and the rule that both must travel with any future sharing
of that record. The system attaches them automatically, so it does not depend on anyone
remembering. |
| They can ask you to restrict something164.522(a) |
✓ |
A restriction seals the documents it covers and records the reason and the decision.
Lifting it puts the document back to the sensitivity it had before, not to "ordinary". It
includes the self-pay restriction: where the patient paid in full
themselves, the software refuses to let staff turn the request down at all, because HITECH
does not give them that choice. |
| They can ask to be contacted differently164.522(b) |
✓ |
"Do not call my home. Write to this address." In a mental-health service this is not
administration — it is the mechanism by which a service avoids revealing to an abusive
partner or relative that somebody is in therapy. The request, the decision and the binding
of that decision to every outgoing message are all built. |
| They can ask who their information went to164.528 |
✓ |
A register of what left the service, to whom, on what basis and when — reportable for six
years, produced on demand rather than assembled by hand. It gathers from
every register in the system, which matters: there is more than one, and an
answer drawn from only one of them would hand a patient six disclosures out of eight with
nothing to suggest anything was missing. |
| Family and friends can be told — unless the patient objects164.510 |
✓ |
The rule gives four different bases for telling somebody involved in a patient's care, and
they stay four rather than collapsing into a "family may be told" tick box — because the
question afterwards is never whether somebody was told, it is on what basis. An objection is
enforced, not displayed: the software refuses to record a disclosure to a
person the patient objected to. |
| You must give them a privacy notice164.520 |
✓ |
The notice is a versioned document with an effective date. Receipt is acknowledged and
recorded — and where the patient will not sign, the good-faith effort and the reason
it failed are recorded too, which is what the rule actually requires. A material change
creates a new version rather than editing the old one. |
| They can complain, and you must record it164.530(d) |
✓ |
A complaint cannot be closed without both an outcome and the reasoning behind it. "No
action" is a permitted outcome — the rule says the disposition may be nothing, not that it
may be unrecorded. Complaints cannot be deleted. |
| Written authorisation where it is needed164.508 |
✓ |
Signed authorisations are held in the e-signature module, and a disclosure that claims to
rest on one is refused unless it names the authorisation it relies on. That turns "we had
consent" from somebody's memory into a link. |
| Only what is needed for the job164.502(b) |
◐ |
Built: staff reach the records of the people on their own caseload rather
than the clinic's, because access follows the care relationship and not the job title. On
the sharing path, the purposes the rule exempts and the judgement that was made are both
recorded.
What remains: that judgement is recorded rather than
applied automatically at every route. A person still decides how much to send; the system
captures the decision instead of making it. Closing this would mean the software deciding
"minimum necessary" on your behalf, and any product claiming to do that is overstating what
software can do — so expect to show a policy and a record here, not an algorithm. |
| Fix the damage when something goes wrong164.530(f) |
✓ |
A mitigation record: what harm was done, what was done about it, by whom and when. Separate
from the breach record, because most things that need mitigating are not breaches. |
| Deciding data is no longer identifiable164.514 |
✓ |
The system records the determination; it does not make it. The eighteen identifiers
are eighteen separate answers, because the claim fails on the one nobody thought about, and
the "do you actually know it could be re-identified" test is a separate question again.
Software that claimed to de-identify data automatically would be the most dangerous thing
here: get it wrong and a record leaves with no protection and no way to call it back. |
| Contracts with your suppliers164.308(b) · 164.314 |
✓ |
A register of business associates with the dates of their agreements — and a disclosure to
one of them is checked against whether a current agreement exists. An expired
contract stops being paperwork and starts being a refusal. |
| How much you may charge for a copy164.524(c)(4) |
⚙ |
Built: the fee is itemised into the four components the rule permits and
nothing else, and the request warns when the total goes over your cap.
You set: the cap itself. The regulation names no figure —
it says "reasonable, cost-based", and the federal guidance and the case law on what that
means have moved and will move again. So the cap is a setting on your company rather than a
number written into the software that somebody would have to find and edit. Agree it with
your counsel and enter it once. |
| Six years of documentation164.316(b)(2) |
✓ |
Shipped as retention rules, including the one for minors that runs to adulthood plus six
years. Every period counts from a stored date — last contact, date of birth, date of death —
rather than from when a file happened to be created. |