Concept explainer
The record across sites
Explains how one patient record stays consistent across the sites of an organisation, so care at any site draws on the same history.
One patient record belongs to the patient. It exists once and follows the patient across every hospital that runs Pensieve, so any site that is treating the patient draws on the same history. The organisation is the custodian and Data Fiduciary for the care it delivers, not the owner of the record. This page explains how the record stays one thing across every site and hospital that treats the patient, what stays local to a site, and how access holds at each site.
One record, many sites
An organisation is the legal entity that runs the hospital, and a site is one of its physical locations. A patient holds one record, read by every site that is treating them. A visit happens at a site, and its diagnoses, orders and charges attach to the visit, while the record that carries them across time belongs to the patient and has no owning site or hospital.
What sits where
Most operational things belong to the site where the work happens. The patient record belongs to the patient, with no owning hospital, and sits outside the tenancy structure. The catalogue and tariffs a site works from are operational data it authors for itself. Reading the split makes the boundary clear.
| Thing | Belongs to | Why it sits there |
|---|---|---|
| Patient record | The patient | It exists once with no owning hospital, so any site treating the patient reads the same history. |
| Visit | Site | A visit happens at one physical site. |
| Charges and invoices | Site | Money is raised and settled where the care is given. |
| Permissions | Site | Access is decided from the admission at the site in front of you. |
| Catalogues and tariffs | Site | Each site authors its own orderable catalogue and charge items. |
Reading at another site
The record is one, and access is decided at each site. A clinician at another site reads the shared history once they hold a current care relationship with the patient, built from an admission at that site and the patient's consent. Role and relationship decide the read at every site, so the same record shows each reader what their present reason to see it allows.
The boundary holds at the read
A patient lens sits on the record read path. A reader draws exactly the history their role, their relationship and the patient's consent entitle them to, and a query beyond that entitlement resolves to an empty result at the boundary. The record spans sites and hospitals; the entitlement to read it is decided site by site.
Emergency access
Where a clinician needs a record urgently ahead of a standing relationship, emergency access is a defined path. It opens the record for the moment of need and records the clinician, the time and the stated reason, so the read is accounted for afterwards. Read the full path at emergency access.
Coding standards are shared, catalogues are not
Each site authors its own catalogue of what can be ordered and its own tariffs, so a site works from its own lists rather than a central one. What is shared is the layer beneath: the clinical terminology baseline the record is coded against, shipped with the platform and the same at every site. That shared coding is what lets a patient's record read consistently wherever it is opened, even though each site runs its own catalogue. The section on organisations and sites sets out how the two nest.
Common questions
Does each site keep its own copy of the record?
The patient holds one record. It exists once across every hospital that runs Pensieve, and care at a second site reads the same history rather than a copy. The organisation is the custodian, not the owner.
Does one record mean anyone at any site can read it?
Access is decided at each site from role, relationship and consent. A reader at another site opens the record once they hold a current reason to, such as an admission there.
What stays local to a site?
Visits, charges and permissions are scoped to the site where the work happens. The patient record belongs to the patient and has no owning site or hospital. Only the operational reference data, such as the catalogue, is held by the hospital.
Read how a permission is decided from role, relationship and consent at each site.