Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

Network · Patient Management

Secure exchange is a transaction. A patient relationship is not.

Your EHR holds the clinical story. The administrative one — who this patient is to your office, what has passed between you, what is still outstanding — usually holds together only in somebody's head.

HIPAA mapping

Where this fits in the HIPAA rules.

4 provisions this capability contributes to, each with the specific Patient Management behavior behind it. The obligation stays with your practice — the mapping shows which part of the work the platform carries.

§164.312(b)

Audit controls

Requires mechanisms that record and examine activity in systems containing ePHI. Activity in a patient's workspace is recorded like any other access, and appears in the ePHI Audit against the workforce member who did it.

§164.312(a)(1)

Access control

Requires technical policies allowing access only to those authorized. Patient workspaces are reached through the same roles and the same ePHI flag that govern everything else here, rather than through a second permissions model invented for patients.

§164.524

Access of individuals to PHI

Gives individuals a right of access to their designated record set, generally within thirty days. Your designated record set lives largely in your clinical systems; what is held here is one part of the picture and a practice fulfilling an access request should not assume this is all of it.

§164.502(b)

Minimum necessary

Applies to most uses and disclosures, though not to disclosures to a provider for treatment. Which staff need to see a given patient's correspondence is a determination your practice makes; roles are how the determination gets enforced once made.

What it does

There are two records of every patient, and practices only keep one.

On Basic, a practice can invite a patient into Secure Messaging and exchange messages and files with them. That is a complete capability and it is genuinely useful. What it is not is a place where the patient exists as a subject: each exchange is its own event, and the relationship is whatever a member of staff remembers about the last one.

Patient Management is the Pro layer that gives those relationships somewhere to live. Patients are records in a directory rather than addresses on a message. They are counted, they are brought in through a tracked invitation lifecycle, and they carry an alternate identifier so a patient your practice knows by one number elsewhere can be matched to the same person here — the unglamorous problem that decides whether any patient-facing tooling is ever trusted.

What changes operationally is who has to remember. Opening a patient is an audited action attributed to a named person, so the relationship has a history that survives staff turnover. The question that exposes the difference is the ordinary one: somebody rings about a document from four months ago, and the office either opens the patient or starts asking colleagues who dealt with them.

The boundary is firm and worth repeating rather than burying. Patient Management is not an electronic health record and not a replacement for your practice-management system. There is no charting, no clinical documentation, no diagnosis or treatment record, no scheduling, no billing and no consent engine. What it is is the administrative relationship with a patient, held in one place, inside a system that already governs who may see it.

How it works

5 mechanisms keep Patient Management working.

01

Patients are records, not addresses.

A patient exists as a subject with a place of their own, rather than as a recipient on a series of separate exchanges. That is the difference between Basic and Pro on the patient side, and it is the difference between a practice that can answer a question about a patient and one that can only answer a question about a message.

02

A persistent home for the relationship.

The patient's workspace is where their side of the relationship with your office lives, rather than being reassembled from three mailboxes when something comes up. The test is a call about something four months old: with a workspace it is a matter of opening the patient, and without one it is a matter of who still works here.

03

Invitations with a lifecycle, and an Alt ID.

Patients are brought in through Office Invitations, tracked through states rather than sent and forgotten. Each carries an alternate identifier for cross-system matching, because the patient your practice knows by one number in one system has to be the same person here. Identity reconciliation is the boring problem that decides whether the rest is trustworthy.

04

The same access model as everything else.

Reaching a patient workspace runs through the roles on the workforce record and the per-person ePHI flag, not a separate permissions system for patients. One model to reason about, and one place to change when someone's job changes.

05

Opening a patient is an audited act.

Patient-management actions appear in the Personnel ePHI Audit against a named workforce member with a time on them. This is why the directory matters beyond convenience — attribution needs a subject to attribute to, and a message thread is a weaker subject than a patient.

Who this is for

Built for the practices that need it most.

Practices whose patient correspondence lives in email.

The most common arrangement and the hardest to answer questions about. The problem is not usually that the messages are insecure; it is that they are in twelve places and one of those people left in June.

Practices that exchange documents with patients regularly.

Intake paperwork, records requests, forms going back and forth. Where that traffic is routine, having it collected per patient stops being administrative tidiness and starts being how you answer things.

Practices that already run a good EHR.

This is the audience the page is actually for. If your clinical record is in decent shape, the gap is everything around it, and a second clinical system would be a step backwards.

What you get

5 outcomes you’ll feel in week one.

Patients as subjects.

Records in a directory, not addresses on a message.

One workspace per patient.

Exchanges and files together instead of across mailboxes.

Invitation lifecycle and Alt ID.

Tracked onboarding, and identity that matches your other systems.

One access model.

The same roles and ePHI flag as everywhere else.

Attributable.

Opening a workspace appears in the ePHI Audit by name.

FAQ

What people ask first.

6 questions cover most first-time evaluations. See all FAQs →

Is this an EHR?
No, and it is not trying to become one. There is no charting, no clinical fields, no scheduling and no billing. It holds the correspondence-and-documents side of the patient relationship and expects your clinical record to live where it already lives.
Which plan includes it?
Pro. A Basic office can invite a patient into Secure Messaging and exchange messages and files with them — that is Secure Messaging doing its own job, not a limited Patient Management. Pro adds the per-patient workspace around those exchanges.
Does this answer a patient's §164.524 access request?
Only partly, and it is important not to over-promise here. The right of access covers the designated record set, which for most practices is mainly in clinical systems. What is held here is one part of it. Treat this as a source to include rather than as the answer, and check what your designated record set actually comprises before responding.
Can we keep substance use disorder records here?
42 CFR Part 2 imposes consent and redisclosure requirements substantially stricter than HIPAA's, and this product does not implement a Part 2 workflow. There is no Part 2 mode. If your practice is a Part 2 program, that is a question for counsel about your systems generally, and nothing here should be read as addressing it.
Does it produce a §164.528 accounting of disclosures?
No. The provision gives an individual the right to an accounting of certain disclosures, with its own required content and its own exclusions, and an internal activity record is not that accounting merely by existing. Access records here are a source you might draw on; producing the accounting is your practice's work.
Can patients see their own workspace?
Patients participate in the exchanges — that is what being invited into the channel means. Treat what a patient can see as a question to confirm against your account rather than from a marketing page, because it is exactly the kind of detail that changes and that we should not be describing from memory.

What it does not do.

  • Pro only. The Basic depth it used to claim was Secure Messaging, counted twice.
  • Distinct from Compliance Evidence & Records, which holds program artifacts rather than patients
  • Not an EHR: no charting, clinical fields, scheduling or billing, and no 42 CFR Part 2 workflow

The clinical record is handled. This is the other one.

Most practices discover they need it the first time someone asks what was sent to a patient in March, and the answer depends on who still works there.