Who should see what as a clinic grows

The point at which everybody seeing everything stops being fine, why job titles make bad permissions, and the two events that matter more than the settings.

In a clinic of three, everybody sees everything and it is fine. Not because access control does not matter, but because three people who trust each other are a functioning control by themselves.

At some point that stops being true, and it does not announce itself. It is usually the first person hired who was not there at the beginning — a weekend receptionist, a locum, somebody's cousin covering August.

The question is not trust

This is where the conversation usually goes wrong, because restricting access sounds like an accusation. It is not, and framing it that way is what stops clinics doing it.

Access control answers a different question: if something goes wrong, how many people have to be investigated? A receptionist who cannot open clinical notes cannot be accused of reading them. Narrow access protects the person more than it protects the record.

Note

It is also the version of the argument that survives a staff meeting. "I do not trust you" is unanswerable; "if a record is ever queried, I want the list of people who could have opened it to be short" is a sentence people agree with.

Job titles make bad permissions

The instinct is to grant access by role — receptionist, nurse, dentist, manager. It falls apart on contact with a real clinic, because a small practice runs on people doing several jobs.

Your practice manager also does the books. One of your clinicians handles the rota. The Saturday receptionist is a nursing student who does clinical work on Tuesdays. Every one of them fits two titles, and a system that grants by title forces you to pick the more generous one.

What works instead is granting by area of the system and composing a person from the areas they need. The question stops being "what is Ayşe" and becomes "does Ayşe need to open clinical notes", which has an answer.

AreaWho genuinely needs it
The diaryEverybody who books or is booked
Patient contact detailsEverybody who contacts patients
Clinical recordsPeople who write or read notes clinically
Everyday financeWhoever takes payment
Sensitive financeFewer people than everyday finance — this is a separate question
Reports and analyticsWhoever is accountable for the numbers
Staff and permissionsOne or two people, and one of them is you

The fifth row is the one clinics collapse into the fourth. Taking a card payment and seeing what every patient owes across the practice are different levels of exposure, and the second is rarely needed by the person doing the first.

Clinical notes are their own category

If you do one thing, do this: make reading clinical records a separate permission from using the calendar.

The front desk needs to know who is coming, for how long, and with whom. It does not need to know why. Those two facts live in the same record and they are not the same disclosure — and in a small town, the second one is the one that ends up repeated somewhere it should not be.

The two events that matter more than the settings

Most clinics eventually configure permissions sensibly and then lose the benefit to one of these.

  • Somebody leaves and their access does not. This is the single most common real-world failure, and it is not a technical one. Revocation has to be part of the last day, in the same checklist as the keys.
  • Somebody needs access "just for today". Granted in a hurry, never removed, and six months later the temporary permission is the permanent one nobody can account for.
Important

Put a date in your calendar twice a year to read the list of who has access to what. It takes ten minutes and it is the only thing that catches both failures above. Most clinics that do it find at least one surprise the first time.

The log is for the ordinary case

An audit log — who opened, changed or exported what — sounds like an instrument for catching wrongdoing, and that is the rarest thing it does.

What it actually does is answer ordinary questions without a search: who changed this appointment, when did this note get edited, did that export ever happen. Those questions come up monthly. The serious use arrives once, if at all, and by then it is far too late to start recording.

Exports deserve particular attention, because an export is the moment data leaves the controls you set. Everything above governs who can see something inside the system; a spreadsheet on a laptop is governed by nothing.

Where to start

  1. Separate clinical records from the calendar. This alone covers most of the exposure.
  2. Separate sensitive finance from taking payment.
  3. List everybody with access and cut anything nobody has used this year.
  4. Add revocation to whatever you do on somebody's last day.
  5. Put a twice-yearly review in the calendar, with a name against it.

None of this is a project. It is an afternoon, then twenty minutes a year — and the reason to do it before you need it is that the moment you need it is the moment it cannot be done retrospectively.

Which areas are separable and which sit behind higher plans is set out in what the product actually does; the practical detail is in roles and permissions.

Common questions

Should reception staff see clinical notes?
Generally no. The front desk needs to know who is coming, when and with whom; it does not need to know why. Those facts sit in the same record and are not the same disclosure, and separating them is the single highest-value permission change most clinics can make.
Is it insulting to restrict a colleague's access?
It is if framed as trust, so do not frame it that way. Narrow access protects the person: somebody who cannot open a record cannot be asked to account for having opened it. That version of the argument survives a staff meeting; the trust version does not.
Why not just grant permissions by job title?
Because small clinics run on people doing several jobs. The manager does the books, a clinician handles the rota, the weekend receptionist does clinical work midweek. Granting by title forces you to pick the more generous of two, every time. Granting by area of the system and composing a person from what they need has an answer for each case.
What is the most common access mistake in a clinic?
Not the configuration — it is somebody leaving and their access staying. Revocation belongs on the last-day checklist next to the keys, and a twice-yearly read of who can see what catches the ones that slipped through, along with every "just for today" that became permanent.
What is an audit log actually for?
Mostly for ordinary questions — who moved this appointment, when was this note edited, did that export happen. Those come up monthly. Catching misconduct is the rare use, and by the time you want it, it is far too late to start recording.

Read next

Composed from areas, not from job titles.

Clinical records are their own permission, separate from the diary, and sensitive finance is separate from taking payment — so a person is built from what they actually do. Roles you define yourself are on Suite; the audit log is on Network.

See what each plan includes