Skip to content

Procedure

Disclosure and release

Steps for releasing records to a third party under a lawful request, the checks applied, and how each disclosure is logged in the record.

Releasing a patient's record to a party outside the hospital is a governed action. It proceeds on a lawful basis or the patient's consent, every release is written to a disclosure register the patient can read, and a medico-legal record is released only through its own approval chain.

The disclosure register

Pensieve keeps a disclosure register against each record. Every release adds an entry, so who received a copy, when, and what they received stays queryable. This is what lets the hospital tell a patient exactly who their data went to, which is the recipient limb of the patient's right to know how their record has been processed.

recipientparty

The outside party the record went to, such as an insurer, a registry, a national exchange or a referring institution.

scopecategories

Exactly what was released, decided per data category rather than as the whole record by default.

released attimestamp

When the release was made.

basislawful basis

The lawful basis relied on, or a reference to the patient's recorded consent and the notice version it was given against.

responserecord

What each recipient said when later notified of an erasure, restriction or correction. See below.

Making a release

A release is deliberate and evidenced. It is a different act from the treatment access that Cirith Manager resolves for a clinician inside the hospital, and it is recorded in its own register.

  1. 1

    Establish the basis

    A release proceeds only on a lawful basis or the patient's consent. Where consent is the basis, it is recorded against a notice version, with what was consented to, when, and by whom.

  2. 2

    Fix the scope

    Decide exactly what is released, per data category. A sensitive category the patient has restricted, such as substance use, mental health, HIV or reproductive health, is released only where its own basis is satisfied.

  3. 3

    Send to the named recipient

    The record leaves the hospital to the named party. Where the release travels to an external system, it goes on the hospital's own authority using the hospital's own credentials.

  4. 4

    Record the entry

    The release is written to the disclosure register, naming the recipient, the scope, the time and the basis, so the patient can later be told who received their data.

Medico-legal release is separate

A medico-legal record is not released through ordinary access. It carries an indefinite retention hold that no scheduled destruction clears, and it is released only through a disclosure workflow with its own approval chain, distinct from the treatment gate that opens a record for care.

When a disclosed record later changes

A record that has already been released may afterwards be erased, restricted or corrected at the hospital. Because a copy has left the hospital, that change reaches the recipient as a notification, not as a reach-in deletion. Pensieve produces the register of recipients, the hospital notifies each one, and each recipient's response is recorded against the register.

Notification is not deletion

A recipient such as an insurer, a registry or a national exchange holds the released data as an independent controller with its own retention grounds and its own statutory periods. Notifying it of an erasure or a correction does not delete its copy, and no party can reach into that controller's systems to delete on its behalf.

What Pensieve can guarantee

Because downstream deletion cannot be guaranteed by anybody, Pensieve is precise about what it commits to. It states these three things and does not promise a downstream deletion it cannot effect or verify.

Pensieve commits toWhat it means
Authoritative erasure at the system of recordWhere the law permits erasure, the record is erased or restricted at the hospital's own system of record, to the limit the law allows.
Provable revocation of discoverabilityThe record stops being discoverable, and that revocation is evidenced rather than asserted.
An auditable record of who received a copy and whenThe disclosure register names every recipient, the scope, the time and each recipient's response to a later change.
Can Pensieve force a recipient to delete a released record?

No. A recipient holds its copy as an independent controller with its own retention grounds. Pensieve notifies each recipient of an erasure, restriction or correction, records the response, and tells the patient who received their data, but it does not promise a deletion it cannot effect.

Is releasing a record the same as a clinician reading it?

No. A clinician reads a record under the treatment gate for the care they are giving. A release sends a copy to a party outside the hospital, on a lawful basis or the patient's consent, and it is written to the disclosure register.

How does the hospital answer a patient asking who received their data?

From the disclosure register, which holds every recipient, the scope and the time. The patient is told exactly who received their data and what each recipient said when notified of a change.

Read how a patient's erasure or access request is handled in data subject requests, how the hospital answers who read a record in answering who saw this record, and how consent is captured and versioned in consent documents.