Client Restrictions (Access Control & Audit Trail)
Require team members who aren't on a client's Care Team to enter a reason before viewing that client's sensitive information. Every access reason is logged and available in a report, giving admins a clear audit trail for compliance. Care Team members can access the client's record as usual, with no extra step.
Built by Core Engineering
The problem it solves
Organizations working with sensitive client populations need a way to monitor and deter unauthorized access to specific client records, and to prove they did so for compliance purposes, without walling off legitimate Care Team members from doing their jobs. Client Restrictions solves this by gating access behind a logged reason only for users outside the Care Team, while leaving Care Team access unchanged.
What's included
- Per-client restriction toggle, surfaced as a lock icon in the client list
- Access-reason modal shown to any non-Care-Team user attempting to view a restricted client
- Access reason logging, with a report showing who accessed a restricted client and why
- Configurable reason expiration window, after which access must be re-justified
- Action-specific rules: reasons required for chat, scheduling, and Care Plan actions; not required for sharing documents or requesting form completion
How it works
A user with the appropriate permission restricts a client from their Personal Information page under Actions; a lock icon then appears next to that client's name in the client list. When a user who is not on the client's Care Team attempts to access the client's data, chat with them, schedule an appointment, or take a Care Plan action, a modal appears prompting them to enter a reason for access; submitting the reason refreshes the page and grants access. That reason is logged and available in a report showing which team members accessed a restricted client and why, supporting internal compliance and audit needs. If an expiration window is configured via the client_restriction_expiration_hours setting, users must re-enter a reason after that period elapses. To remove a restriction, an admin toggles the setting off and saves.
Client Restrictions require any team member who isn't on a client's Care Team to enter a reason before viewing that client's information, creating a documented audit trail for compliance and internal privacy policies. It's built for organizations, particularly in behavioral health and multi-specialty group settings, that need tighter access control over sensitive client records without adding friction for the providers who are already authorized to see them. Once a client is restricted, a lock icon appears next to their name in the client list, and non-Care-Team users are prompted with a modal to enter an access reason (up to 500 characters) before the record loads. If an expiration window is configured, users are prompted to re-enter a reason after that time period elapses.