Network · Patient Management
Secure exchange is a transaction. A patient relationship is not.
Your EHR holds the clinical story. The administrative one — who this patient is to your office, what has passed between you, what is still outstanding — usually holds together only in somebody's head.
HIPAA mapping
Where this fits in the HIPAA rules.
4 provisions this capability contributes to, each with the specific Patient Management behavior behind it. The obligation stays with your practice — the mapping shows which part of the work the platform carries.
§164.312(b)Audit controls
Requires mechanisms that record and examine activity in systems containing ePHI. Activity in a patient's workspace is recorded like any other access, and appears in the ePHI Audit against the workforce member who did it.
§164.312(a)(1)Access control
Requires technical policies allowing access only to those authorized. Patient workspaces are reached through the same roles and the same ePHI flag that govern everything else here, rather than through a second permissions model invented for patients.
§164.524Access of individuals to PHI
Gives individuals a right of access to their designated record set, generally within thirty days. Your designated record set lives largely in your clinical systems; what is held here is one part of the picture and a practice fulfilling an access request should not assume this is all of it.
§164.502(b)Minimum necessary
Applies to most uses and disclosures, though not to disclosures to a provider for treatment. Which staff need to see a given patient's correspondence is a determination your practice makes; roles are how the determination gets enforced once made.
What it does
There are two records of every patient, and practices only keep one.
On Basic, a practice can invite a patient into Secure Messaging and exchange messages and files with them. That is a complete capability and it is genuinely useful. What it is not is a place where the patient exists as a subject: each exchange is its own event, and the relationship is whatever a member of staff remembers about the last one.
Patient Management is the Pro layer that gives those relationships somewhere to live. Patients are records in a directory rather than addresses on a message. They are counted, they are brought in through a tracked invitation lifecycle, and they carry an alternate identifier so a patient your practice knows by one number elsewhere can be matched to the same person here — the unglamorous problem that decides whether any patient-facing tooling is ever trusted.
What changes operationally is who has to remember. Opening a patient is an audited action attributed to a named person, so the relationship has a history that survives staff turnover. The question that exposes the difference is the ordinary one: somebody rings about a document from four months ago, and the office either opens the patient or starts asking colleagues who dealt with them.
The boundary is firm and worth repeating rather than burying. Patient Management is not an electronic health record and not a replacement for your practice-management system. There is no charting, no clinical documentation, no diagnosis or treatment record, no scheduling, no billing and no consent engine. What it is is the administrative relationship with a patient, held in one place, inside a system that already governs who may see it.
How it works
5 mechanisms keep Patient Management working.
Patients are records, not addresses.
A patient exists as a subject with a place of their own, rather than as a recipient on a series of separate exchanges. That is the difference between Basic and Pro on the patient side, and it is the difference between a practice that can answer a question about a patient and one that can only answer a question about a message.
A persistent home for the relationship.
The patient's workspace is where their side of the relationship with your office lives, rather than being reassembled from three mailboxes when something comes up. The test is a call about something four months old: with a workspace it is a matter of opening the patient, and without one it is a matter of who still works here.
Invitations with a lifecycle, and an Alt ID.
Patients are brought in through Office Invitations, tracked through states rather than sent and forgotten. Each carries an alternate identifier for cross-system matching, because the patient your practice knows by one number in one system has to be the same person here. Identity reconciliation is the boring problem that decides whether the rest is trustworthy.
The same access model as everything else.
Reaching a patient workspace runs through the roles on the workforce record and the per-person ePHI flag, not a separate permissions system for patients. One model to reason about, and one place to change when someone's job changes.
Opening a patient is an audited act.
Patient-management actions appear in the Personnel ePHI Audit against a named workforce member with a time on them. This is why the directory matters beyond convenience — attribution needs a subject to attribute to, and a message thread is a weaker subject than a patient.
Who this is for
Built for the practices that need it most.
Practices whose patient correspondence lives in email.
The most common arrangement and the hardest to answer questions about. The problem is not usually that the messages are insecure; it is that they are in twelve places and one of those people left in June.
Practices that exchange documents with patients regularly.
Intake paperwork, records requests, forms going back and forth. Where that traffic is routine, having it collected per patient stops being administrative tidiness and starts being how you answer things.
Practices that already run a good EHR.
This is the audience the page is actually for. If your clinical record is in decent shape, the gap is everything around it, and a second clinical system would be a step backwards.
What you get
5 outcomes you’ll feel in week one.
Patients as subjects.
Records in a directory, not addresses on a message.
One workspace per patient.
Exchanges and files together instead of across mailboxes.
Invitation lifecycle and Alt ID.
Tracked onboarding, and identity that matches your other systems.
One access model.
The same roles and ePHI flag as everywhere else.
Attributable.
Opening a workspace appears in the ePHI Audit by name.
Is this an EHR?
Which plan includes it?
Does this answer a patient's §164.524 access request?
Can we keep substance use disorder records here?
Does it produce a §164.528 accounting of disclosures?
Can patients see their own workspace?
What it does not do.
- Pro only. The Basic depth it used to claim was Secure Messaging, counted twice.
- Distinct from Compliance Evidence & Records, which holds program artifacts rather than patients
- Not an EHR: no charting, clinical fields, scheduling or billing, and no 42 CFR Part 2 workflow
Continue exploring
Related features in the platform.
Network
Secure Messaging
Encrypting a message is the part everyone gets right. Knowing whether the person receiving it is covered by an agreement, and refusing to send when they are not, is a different job — and it is the one this channel does.
Learn moreOperations
Workforce & Access Governance
A workforce record carries the roles a person holds, whether they may reach ePHI, and the specific systems they can touch. One place, one answer, dated.
Learn moreDefense
ePHI Audit
The question after an incident is never abstract. It is whether one named person opened one named record on one particular afternoon, and whether you can show it.
Learn moreThe clinical record is handled. This is the other one.
Most practices discover they need it the first time someone asks what was sent to a patient in March, and the answer depends on who still works there.
