Workflow pattern
A record that satisfies an outsider
Shows the shape where a record has to satisfy an external party such as an auditor or insurer, and how Pensieve assembles what they need.
A record often has to satisfy someone beyond the hospital: an auditor, an insurer, a regulator, or the patient. This pattern sets out the shape that request takes, and how Pensieve assembles the record, its provenance and its access history into what the outside party needs.
The shape
An outsider is a party beyond the hospital who the record must satisfy: an auditor, an insurer, a regulator, or a patient exercising a right over their data. A disclosure is the assembled set of records that answers their request.
The shape has one entry and one settled exit. It begins with the outside request and ends with a logged disclosure delivered to the party.
Atlas provides the clinical facts, Vault provides the charges and assembles an insurance claim, Falcon shows the lineage of each figure, and Cirith Manager answers who accessed the record and checks each release.
Where it starts
The shape starts with a request. An outside party names the patient, the period, and what it needs to be satisfied.
The record answers because each fact already carries its author, its time, and its lineage. A posted charge stands fixed and a completed form locks the moment it is finished, so the assembled evidence reads as it stood at the time.
The path
- 1
The request arrives
An outside party's request names the patient, the period, and what it needs.
- 2
The basis is established
The lawful basis for release and the checks that govern it are confirmed before any record is gathered.
- 3
The record is assembled
The clinical facts, the audit entries, and the financial entries are gathered, each carrying its author and time.
- 4
The provenance is attached
Each figure carries its lineage, and each completed form is the locked version exactly as it was filled.
- 5
The release is checked and logged
Access is checked against the confirmed basis, and each disclosure is logged in the patient's record.
- 6
The set reaches the outside party
The assembled set leaves as a claim submission or a produced export, matching what the party needs.
What is recorded
| Recorded item | What it captures |
|---|---|
| The request | Who asked, for which patient and period, and what they need. |
| The basis | The lawful basis and the checks that governed release. |
| The assembled set | The clinical, audit and financial entries gathered. |
| The provenance | The author, time and lineage carried by each entry. |
| The disclosure | The moment of release, logged in the patient's record. |
Tools in the shape
| Tool | Its part in the shape |
|---|---|
| Atlas | Provides the clinical facts, each carrying its author and time. |
| Vault | Provides the charges as they stood and assembles an insurance claim. |
| Falcon | Shows the lineage of each figure so a reviewer traces it to source. |
| Cirith Manager | Answers who accessed the record and checks each release. |
What holds throughout
The evidence reads as it stood
A posted charge stands fixed and a completed form locks the moment it is finished. The assembled evidence reads as it stood, so an outside party sees the record of the time alongside its provenance.
Where the shape varies
The shape holds whether the outside party is an auditor, an insurer, a regulator, or a patient exercising a right over their data. What changes is the basis for release and the form the assembled set takes. The provenance travels with the evidence in every case.
Common questions
How does the record satisfy an auditor asking who saw it?
The access log answers who viewed the record, when, and the reason recorded for each access.
How is an insurer's claim substantiated?
The claim assembles from the charges and the clinical facts that support them, each carrying its source.
Does assembling a disclosure change the record?
Assembly reads the record and logs the release. The underlying entries stand as they were, and the disclosure itself becomes a new logged entry.
Read how an access history is produced for one record in answering who saw this record.