Concept explainer
Emergency access
Explains the emergency access route that lets a clinician reach a record in urgent care, with the extra logging it records.
Emergency access is the route that lets a clinician reach a record in urgent care, over a patient's cross-site partition and a site's sensitivity markings. Emergency access is recorded with the clinician, the time, the site and the stated reason for the hospital's own reviewer. The patient's access log shows only the fact of the override, with the hospital, the time, the purpose and the outcome. The individual clinician and the written justification are withheld from the patient and stay with the hospital.
What emergency access is
Emergency access is a defined route, held open for urgent care. A clinician with an active admission at the site invokes it to reach a record that a patient's partition or a site's markings would otherwise hold closed.
The route is bounded in time. It opens under an emergency purpose for a window that a new site sets to four hours, and it ends on its own when that window lapses. A review clock runs alongside it, set to 72 hours at a new site, and a reviewer works the entry within it.
| Setting | Default | What it governs |
|---|---|---|
| Emergency-access window | Four hours | How long an emergency-access session stays open. |
| Emergency-access review clock | 72 hours | The period a reviewer works the entry within. |
An administrator sets both per site in the access settings, hosted in Nexus Manager, within the floor and the ceiling the platform holds. The reference on sessions and timeouts lists them alongside the other session defaults.
What it reaches, and what still holds
Emergency access reaches past a patient's cross-site partition and a site's sensitivity markings for the window. Other controls stay in force, so the route widens a read rather than opening everything.
| Control | Under emergency access |
|---|---|
| A patient's cross-site partition | Reached past for the bounded window. |
| A site's sensitivity markings | Reached past for the bounded window. |
| An explicit block against the clinician | Still holds. |
| The patient's access to their own record | Unaffected. |
An active admission at the site is the precondition. Emergency access widens the read inside that admission, so a clinician already caring for the patient reaches the detail the moment care needs it. Where the patient has no active admission at the site, the record stays at basic identification, and admitting the patient in Gate is what opens it. Emergency access widens a read an admission has already opened rather than standing in for the admission.
What it records
Every emergency access carries a structured justification, a reason the clinician states at the moment of access. The platform records that reason alongside the clinician, the time and the site.
Every emergency access is logged and shown to the patient
An emergency access is recorded in full for the hospital's reviewer, and the patient sees that an override happened in their own access log, with the hospital, the time, the purpose and the outcome. A reviewer works a queue of these accesses, and an administrator can end an open window before it lapses. The extra logging is what lets an urgent read stay accountable after the fact.
Who invokes it
The reading clinician invokes emergency access for a patient they are caring for, with an active admission at the site. The route sits with the person reaching the record, so the account of who acted stays truthful.
The window ends on its own when its four hours lapse. An administrator holds a control to revoke an open window, which closes the route the moment a review calls for it.
Common questions
Who sees an emergency access?
The patient sees it in their own access log, and a reviewer sees it in a queue. The reviewer's view carries the clinician and the stated reason. The patient's view does not. It shows the fact of the override, the hospital, the time, the purpose and the outcome, without naming the individual clinician or the written justification, both of which stay with the hospital.
How long does the window last?
Four hours at a new site, and an administrator tunes it per site within the platform's floor and ceiling. The window ends on its own when it lapses, and an administrator can end it sooner by revoking it. The review that follows runs on its own clock, set to 72 hours at a new site.
Does emergency access reach a blocked record?
It reaches past a patient's partition and a site's markings. An explicit block placed against the clinician stays in force, and the patient's own access to their record is unaffected.
Read the fields the access log keeps for each event.