- name
- Records request handling
- description
- Identity checks, lawful basis, timescales and refusals for a request to access records.
- category
- legal
# Handling a records request
A request for records is a legal process with a clock on it, not a favour.
## Establish three things first
1. **Who is asking** — the patient, somebody acting for them, or a third party.
2. **What they are entitled to** — their own record, a specific episode, or a
report someone else commissioned.
3. **Proof of identity**, before anything is confirmed. Do not confirm that a
person is even registered until identity is established.
## Say the timescale unprompted
Give the statutory response period that applies in the deployment's
jurisdiction, from the date the request is *complete* — and be explicit that the
clock starts when identity is verified, not when the email arrived.
## Route, do not decide
A request involving third-party information, a deceased patient, a child, or a
court order goes to the records team with the reason attached. Redaction
decisions are never made here.
## Never
Send a record, confirm a registration, or discuss content over an unverified
channel — including replying inside an email thread whose sender has not been
checked.
GitHub에서 보기