प्रतिबंधित रिकॉर्ड सवाल-जवाब
जब कोई sensitive patient या clinical document छिपा दिखे, not found की तरह खुले, या owner approval माँगे, तो यह पेज इस्तेमाल करें।
कौन कर सकता है: patient.readRestricted और patient.update वाले owners; अपने restricted patients के लिए assigned practitioners; restricted documents के लिए document authors या clinical.document.readRestricted वाले users।
कहाँ: patient details, clinical documents, और owner/admin access workflows।
किसी मरीज़ के लिए “not found” क्यों दिखता है?
Restricted record उन users से छिप सकता है जिनके पास access नहीं है। कुछ patient-linked modules जानबूझकर forbidden के बजाय not found लौटाते हैं, ताकि system यह reveal न करे कि sensitive record मौजूद है।
- Check करें कि आप सही workspace में हैं।
- Policy allow करे तभी UHID या patient phone से search करें।
- Owner से confirm करने को कहें कि record restricted है या नहीं।
- Treatment के लिए access चाहिए तो clinic policy के हिसाब से assignment या permission request करें।
Patient-linked modules PATIENT_NOT_FOUND, Patient not found, Report not found या Document not found लौटा सकते हैं।
कौन-से records restricted हो सकते हैं?
Patients इन categories में restricted हो सकते हैं:
VIPPSYCHIATRYHIVEMPLOYEE_HEALTHOTHER
Psychiatry या psychology templates जैसे कुछ templates by default restricted clinical documents बना सकते हैं।
Restricted patient कौन खोल सकता है?
patient.readRestrictedवाला Owner या Super Admin।- Assigned practitioner, जब उनका user id
assignedTherapist,assignedPractitionerId,assignedDoctorIdयाassignedPractitionerIdsमें हो। - Other staff patient को lists या direct reads में नहीं देख सकते।
हर allowed या denied access audit होता है, केवल ids के साथ, PHI के बिना।
Restriction status कौन बदल सकता है?
Restriction बदलने के लिए patient.update और patient.readRestricted दोनों चाहिए। Backend route PUT /patients/:id/restriction है।
Required fields हैं:
restricted:trueयाfalse।category: restricted होने परVIP,PSYCHIATRY,HIV,EMPLOYEE_HEALTHयाOTHERमें से एक।reason: 3 से 500 characters।
Audit restricted flag, category, किसने बदला और reason length record करता है। Free-text reason log नहीं होता।
Owner किसी patient को restricted कैसे mark करे?
Reviewed files में इस route के लिए visible frontend button मौजूद नहीं था। अगर आपकी deployment में owner workflow है, तो वहाँ दिखा label इस्तेमाल करें; वरना support/admin के जरिए change raise करें।
- UHID और phone से patient identity confirm करें।
- Clinic policy के अनुसार category और reason confirm करें।
- Approved owner/admin workflow से restriction apply करें।
- Patient list फिर खोलें और पक्का करें कि allowed users को लाल प्रतिबंधित रिकॉर्ड (Restricted) badge दिख रहा है।
- Staff को बताएं कि non-authorised users अब Patient not found देख सकते हैं।
Owner restriction कैसे हटाए?
सिर्फ search आसान करने के लिए restrictions न हटाएँ।
- Access और restriction audit trail review करें।
- Confirm करें कि policy removal allow करती है।
- Approved owner/admin workflow से
restrictedकोfalseset करें। - 3 से 500 characters का reason रखें।
- Normal staff visibility केवल तब confirm करें जब role और branch rules allow करते हों।
Patient दिख रहा है, लेकिन document क्यों नहीं दिख रहा?
Clinical documents पर document-level restriction भी हो सकता है। Restricted documents author और clinical.document.readRestricted holders को छोड़कर सभी के लिए 404-style behaviour से invisible रहते हैं।
- Document author से confirm करें कि document itself restricted है या नहीं।
- Owner से पूछें कि आपकी role में
clinical.document.readRestrictedहै या नहीं। - अगर आपको केवल patient-level access चाहिए, तो यह न मानें कि उससे document-level access भी मिल जाएगा।
Generated role matrix standard role bundles को जानबूझकर clinical.document.readRestricted नहीं देता।
Access safely कैसे request करूँ?
- Clinic का internal approval path या Help & Support (
/app/support) इस्तेमाल करें। - Policy allow करे तो केवल UHID या document number भेजें।
- लिखें कि care या administration के लिए access क्यों चाहिए।
- Owner के assign करने या सही permission grant करने का इंतज़ार करें।
- किसी दूसरे staff member से record का screenshot न माँगें।
Restricted records के लिए क्या audit होता है?
System audit करता है:
- Restricted list exposure को
PATIENT_RESTRICTED_LIST_ACCESSके रूप में। - Allowed direct access को
PATIENT_RESTRICTED_ACCESSके रूप में। - Denied access को
PATIENT_RESTRICTED_ACCESS_DENIEDके रूप में। - Restriction changes को
PATIENT_RESTRICTION_CHANGEDके रूप में। - Restricted patients पर care-team changes को
PATIENT_CARE_TEAM_CHANGEDके रूप में।
Audit metadata ids और counts इस्तेमाल करता है। यह free-text restriction reason store नहीं करता।
फिर भी समस्या है?
Help & Support (/app/support) खोलें और clinic policy allow करे तो केवल UHID या document number, time, screen और exact message भेजें। Chat में diagnoses, patient names, PHI वाले screenshots या restricted-record details न share करें।