Skip to content

Concept explainer

The patient lens

Describes how the patient lens narrows a record to the people with a current reason to see it, and how that reason is established.

The patient lens narrows every read of a record to the people with a current reason to see it. That reason is a care relationship, established by an admission at a site and the patient's consent for that site.

What the lens is

The patient lens is a narrowing applied at the record read path. It carries one authorisation decision forward into the reads that follow, so a query resolves to the entries the reader is entitled to see and returns those.

Because the narrowing sits at the boundary of the read itself, a reader receives the entries their reason reaches. The lens is a property of the read path, held in one place, rather than a step each screen remembers to apply.

Figure 1.Diagram showing a clinician opening a record, one access decision combining role and care relationship, and the read returning only the entries the reader may see.

Establishing the reason

The reason a reader may see a record is a current care relationship.

That relationship is established by an active admission at a site, together with the patient's consent for that site. A role settles the actions a reader may take; the care relationship settles the patients those actions reach. Deciding from both keeps a record within the reach of the people caring for the patient now.

When the admission closes, the relationship lapses after a short defined period, and the lens narrows the record back. A reader who once held a reason sees the record while the reason lasts, and basic information after it lapses.

One decision, carried forward

The decision is made once, at the point a request enters, and the lens carries it into every read in the same request.

Carrying one decision forward keeps a single answer consistent across the reads that follow it. It holds the read path and the decision in step, so the entries a reader receives match the access they were granted.

The patient's own record

A patient reading their own record is always within the lens.

Patient access to one's own record is a floor: a patient, and a valid proxy acting for them, reaches their own record, including their own sensitive categories. Consent governs who else may read a record; a patient's reach into their own record rests below that governance and stays open.

Attribution rides with the read

Every read the lens permits is attributed to the person who made it, at the moment they made it. On a shared workstation each member of staff signs in as themselves, so a record read stays truthful about who saw it.

Sites without a reason

A site with a care relationship yet to open sees basic information only: the public reference, a display name, a photograph, and coarse demographics such as age band and sex. That is enough to admit a patient.

Clinical detail stays behind the lens until an admission opens a care relationship at the site. The record is one per patient and held once outside the tenancy structure, so once the relationship opens, a clinician draws on the same history wherever the patient is treated.

Can a reader query around the lens?

The narrowing sits at the read path itself, so a query resolves to the entries the reader is entitled to and returns those. The reason a reader holds settles what the query reaches.

Does the lens apply to a patient reading their own record?

Yes, and it resolves in the patient's favour. A patient, and a valid proxy, reaches their own record as a floor that consent governance sits above.

What does a site see before admission?

Basic information: the public reference, a display name, a photograph, and coarse demographics. Clinical detail follows once an admission opens a care relationship at the site.

Read how consent and directives set the reason the lens depends on.