Professional access

Secure access to patient information for external professionals.

External professionals get their own secure, permissioned login, case by case, so a social worker, a commissioner or a visiting clinician sees what they should see, and can add to the record rather than asking someone else to do so.

How it works

Case by case, not caseload by caseload.

This is what multi-agency care records look like in practice: access granted to a professional for the people they are actually involved with, and nobody else.

1They get their own login

With two-factor authentication, like a family login.

No a shared account and no emailed PDFs. See the records for people they already work with

2Scoped to what they need

Every tab and function is permission-controlled.

Care plans but not family records, if that is right.

3They can add, not just read

Notes written where the care is recorded.

So the record stays joined up between organisations.

A staff-record setting can restrict a professional’s view to only the people they are key worker for. The same restriction is available for internal staff.

A doctor at a desk reviewing a record on a laptop
The alternative

What other services do instead, and what it costs.

The default in a lot of organisations is still email, and it is worth naming what that means.

  • Emailed notes are a data breach waiting for a wrong address. Once a set of notes leaves in an attachment there is no permission model, no audit trail and no way to withdraw it. Giving a scoped login instead means access can be granted, narrowed and removed.
  • And it makes care disjointed. A physiotherapist who cannot write into the record writes somewhere else, and the next person reading the care record never sees it.
  • The security behind the login. Ameryst has been ISO 27001 certified since 2021 and is penetration-tested annually by an external firm. Two-factor authentication is standard for every family member and professional, and staff in Office 365 organisations can use Azure single sign-on instead.
In the module

What professional access to care records covers

Their own secure login

With two-factor authentication

Case by case

Not accessing your whole caseload

They can add notes

So care stays joined up across organisations

Full audit

Who opened a record, not only who changed it

Key worker scoping

Restrict a view to their own people only

The directory fills itself

Assigning a professional adds them to the address book automatically

Organisation search

See how many of a trust’s patients you support

Revocable

Access granted can be narrowed or removed

Why it matters

What scoped external access is worth

Compliance & governance

Emailing notes is the risk you have not priced

An attachment sent to the wrong address is a reportable breach, and even the ones that go to the right address leave no audit trail and cannot be withdrawn. A scoped login replaces all of that with something you can grant, narrow, revoke and evidence, and it answers the question an information governance review will ask.

Patient safety

One record, not several

A visiting professional who can write into the care record means the next person to read it sees what happened, rather than hearing about it later.

Reputation

Multi-agency working that works

Being the organisation that gives partners proper access rather than PDFs is noticed by the people who refer to you.

Cost & financial control

Less chasing on both sides

A social worker who can look for themselves does not ring your team to ask, and your team does not spend the afternoon compiling a report.

Granting access

Four steps, and every one of them reversible.

01

Add the professional

They join your address book automatically

02

Scope the permissions

Down to individual sections of a record

03

They log in

With two-factor authentication, as themselves

04

Everything is logged

Views as well as changes

Have a clear answer ready for the coroner and legal-access question before you need one. It is worth agreeing your policy at implementation rather than under pressure.

Questions services ask about professional access

Can we control exactly what an external professional sees?
Yes, down to a fine grain. Every tab and function is permission-controlled, including individual sections of the patient detail, so a social worker might see care plans and be able to add notes without seeing family members' own records. The same controls decide whether they see assessments, notes or bookings, and they are set per professional rather than once for everyone.
Do they get access to our whole caseload?
No. Access is granted case by case for the people they are actually involved with, and a setting can restrict a professional to only the people they are key worker for. A visiting clinician who works with three of your patients sees three records, and the rest of your caseload is not part of their world at all.
Can they write into the record, or only read it?
They can add to it, where you permit that. It matters: a visiting physiotherapist who cannot write into the record writes somewhere else, and then the care record is no longer the whole picture. What they add sits alongside everything else, attributed to them and timestamped, so the next person reading it can see exactly where it came from.
How is this more secure than emailing notes?
An email attachment has no permission model, no audit trail and no way back once it is sent. A scoped login can be granted, narrowed and revoked, and every access is logged — including who opened a record rather than only who changed one.
How do they log in?
With their own account and two-factor authentication. Family and professional logins both use 2FA, and Azure single sign-on is available for staff in Office 365 organisations. Because the login belongs to the professional rather than to a shared mailbox, access can be narrowed or withdrawn for that one person without affecting anybody else.
Do we have to maintain a directory of professionals?
Less than you would expect. Assigning a new professional to a patient automatically adds them to your organisation's address book, so the directory fills itself as you work rather than through a separate admin task. Search then works across organisations and professionals as well as patients, so finding the right person months later does not depend on anyone having tidied the list.
What about a coroner or a legal request?
Worth agreeing your policy at implementation rather than in the moment. The audit trail records views as well as changes, so you can show who opened a record and when, not only who edited it. The subject access extraction tool produces one person's data in a single action, which makes answering a request a task rather than an exercise.

See it working with your own service in mind.

Half an hour or an hour, whichever suits. We’ll spend it on the parts that matter to your service.