Concept explainer
Data subject requests
Describes how Pensieve handles a request from a patient about their data, what can be produced, and how the hospital records the response.
A data subject request is a patient exercising a right over their own record. Pensieve splits these into two kinds. Access, refusal, restriction of a reader and delegation are things the patient does directly, through the patient application, with no request to make. Correction and erasure are decisions the hospital makes as the Data Fiduciary, and Pensieve never actions an erasure received straight from a patient.
What the patient does directly
A patient reaches their own record through the patient application, in full and unredacted, across every hospital that has treated them. Their own view is never redacted, age-banded or summarised, because a restriction a patient authors subtracts only from third parties, never from the patient. The controls below take effect the moment the patient sets them, so they are not requests the hospital has to process.
| Control | What it does |
|---|---|
| Read | Reads the whole record directly, in full and unredacted, with no hospital in the question at all. |
| Permit or refuse a hospital | Permits or refuses a named hospital. Refusal dominates and removes that hospital's ability to read. It deletes nothing the hospital already wrote. |
| Restrict a sensitive category | Confines a category to chosen stated reasons at a named hospital. The categories are substance use, mental health, HIV and reproductive health. |
| Block a named clinician | Blocks one named individual for a chosen period. The block survives an emergency override. |
| Delegate to a family member | Adds a person to the care circle, always time-bounded, with a guardian's view of a child that narrows as the child matures. |
Read these controls in full in access directives and consent and directives.
Correcting a record
A patient cannot overwrite a clinical entry, and neither can the hospital. A correction is handled by amendment. The correction is appended alongside the prior value, and the prior value stays recognisable rather than being replaced, so the record shows both what was recorded and what it was corrected to. The amendment, including the prior value, is written into the audit trail in the same transaction as the change. A correction request goes to the hospital, which records it and answers the patient.
Amendment, not overwrite
Keeping the prior value alongside the correction is a legal requirement in several markets, and it is what lets the record defend itself later. An entry that could be silently overwritten would carry no evidence of what it once said.
Erasure is the hospital's decision
Pensieve does not decide whether a patient's record may be erased, and it will not action an erasure request received directly from a patient. It refers the individual to the hospital's grievance officer. The hospital, as the Data Fiduciary, decides, because deleting a clinical record the hospital is statutorily obliged to keep would expose the hospital.
An erasure request is never answered as a single yes or no. Pensieve produces an inventory that decomposes the request by data category, and the hospital assigns each category one of three states together with the named legal ground for that choice.
| State | What it means | When it applies |
|---|---|---|
| Active | Held and usable for care, billing, analytics and every other configured purpose. | No ground requires it to change. |
| Restricted | Held, but processing beyond storage is confined to enumerated purposes. Not shown in clinical workflow, not available to analytics, not exportable, and surfaced to the patient as restricted. | An unexpired statutory floor, a hold, or a live legal claim blocks erasure. |
| Erased | The content is gone, and what remains cannot reconstruct it. | The retention floor has expired or never applied to the category. |
What survives a full erasure
A hospital that honours an erasure request to the fullest extent the law permits still holds a body of records from which the person can be identified. This is not a gap in the platform. It is the consequence of financial, statutory and evidentiary retention duties that fall on the hospital.
The residual is enumerated, not hidden
A full erasure leaves a justified residual, and each part of it can name the instrument that requires it. The financial chain, the charges, invoices, payments and the ledger, is retained under tax and companies law and carries the patient reference. The audit trail is retained because it is the evidence of who did what to the record. Statutory registers, such as the narcotic and pre-natal diagnostic registers, are retained for the term their own statute sets. The patient receives this list, with the reason for each entry, rather than a bare refusal.
Who does what
| Step | Owner |
|---|---|
| Intake and identity verification | Hospital |
| Decomposition into a category inventory | Pensieve produces it, the hospital decides |
| Legal ground and state per category | Hospital, as Data Fiduciary |
| Execution across every store | Pensieve |
| Notice to downstream recipients of the record | Pensieve produces the register, the hospital notifies |
| Response to the patient, with reasons for any refusal | Hospital |
Can a patient send an erasure request to Pensieve?
No. Pensieve does not decide erasure and will not action a request received directly from a patient. It refers the person to the hospital's grievance officer, then provides the workflow and records the decision the hospital makes.
Does a correction erase what was there before?
No. A correction is an amendment. The prior value is kept alongside the correction, and both are written into the audit trail, so nothing is silently overwritten.
If a record is erased, is every trace of the patient gone?
No. Statutory retention floors leave a justified residual, such as the financial chain, the audit trail and statutory registers. The patient receives that enumerated list with the reason for each part.
Read how a disclosed record is tracked and released in disclosure and release, and how long each record class is held in retention.