Quick Start for Healthcare & Clinics
Getting Started for Healthcare Providers
Healthcare organisations handle “special category” data under GDPR — health information requires extra care. This guide helps medical practices, dental clinics, physiotherapists, and other healthcare providers set up SAR Portal correctly.
Before You Start: Healthcare Considerations
Special Category Data
Health data is classified as “special category” under GDPR Article 9. This means:
- Higher sensitivity requirements
- Stricter identity verification needed
- More careful redaction required
- Greater regulatory scrutiny
SAR Portal’s features address these needs, but healthcare staff should understand the stakes.
Professional Guidance
For complex medical DSARs (ongoing treatment, litigation, mental health records), consider consulting with:
- Your medical defence organisation
- A healthcare privacy specialist
- Your professional body
Step 1: Map Your Patient Data (10 minutes)
Healthcare data is often spread across multiple systems:
| System | Data Types |
|---|---|
| Practice Management Software | Appointments, demographics, billing |
| Electronic Health Records | Clinical notes, diagnoses, treatment plans |
| Imaging Systems | X-rays, scans (often with patient ID) |
| Lab Systems | Test results |
| Correspondence with patients | |
| Referral Letters | Communications with other providers |
| Staff HR Systems | Employee records (for staff DSARs) |
Action: Document where each data type lives and who can export it.
Step 2: Configure SAR Portal for Healthcare (15 minutes)
Organisation Settings
- Settings > Organization (Settings is Admin-only)
- Use your registered practice name
- Include your registration number if applicable
Identity Verification (Critical)
For healthcare DSARs, identity verification is essential:
- SAR Portal includes OTP (email code) verification. To confirm identity on a case, use the one-click Mark Verified button — the method is recorded automatically (Manual review when an admin clicks it; Portal token for portal submissions). There is no method dropdown or verification-notes field
- For highly sensitive requests, you may also want to:
- Confirm date of birth
- Verify against patient records
- Request photo ID for access to mental health records
Tip: Document your verification policy and apply it consistently.
Team Configuration
Assign appropriate access:
- Clinicians: May need to review clinical notes before release
- Practice Manager: Typically handles DSAR coordination
- Reception: Should NOT have access to DSAR responses
Step 3: Understand Healthcare-Specific Exemptions
Not everything needs to be disclosed. Healthcare providers can sometimes withhold:
| Situation | Example | Action |
|---|---|---|
| Harm to patient | Disclosing self-harm risk to patient who is currently unstable | Seek clinical guidance |
| Harm to others | Notes revealing safeguarding concerns | Consult with appropriate body |
| Third party data | Other patients mentioned in records | Redact (SAR Portal AI handles this) |
| Confidential source | Referrer who asked not to be identified | May be exempt |
When in doubt: Seek guidance from your medical defence organisation.
Step 4: Set Up Your Response Workflow
Recommended Healthcare Workflow
- Request received → Practice Manager notified
- Identity verified → OTP + date of birth check
- Data gathered → Export from all relevant systems
- Clinical review → Clinician reviews notes before release (optional but recommended)
- AI processing → Attach exports via a case action (Request Info, Submit Info, or Close Case); redactable files are scanned automatically on the Review Detected PII screen, where you redact third-party data before attaching
- Final review → Practice Manager confirms completeness
- Delivery → Secure portal or encrypted email
Record Healthcare-Specific Details
SAR Portal captures the request type and a free-text Notes field on each case. Use the Notes field to record healthcare-specific reference details you need for the request, for example:
- Patient ID number (from your practice management system)
- Date of birth used for verification
- GP registration (if applicable)
Select the correct request type when creating the case so the workflow and deadlines are set correctly.
Step 5: Handle Common Healthcare DSARs
Full Medical Records Request
Most common request from patients.
Process:
- Export complete patient record from EHR
- Include all correspondence, referrals, test results
- Attach the exports to the case via a case action (Request Info, Submit Info, or Close Case) using the file picker
- The files are scanned automatically — on the Review Detected PII screen, redact other patients/third parties before attaching
- Clinician reviews if needed
- Deliver to patient
What to include:
- All clinical notes
- Test results
- Referral letters (both sent and received)
- Appointment history
- Any images (X-rays, photos)
Request from Solicitors
Patients often have solicitors request records on their behalf.
Additional verification:
- Request letter of authority from patient
- Verify solicitor is legitimate
- Patient should confirm consent
Employee DSAR (from Staff)
Former staff may request their data.
Include:
- HR file
- Payroll records
- Performance reviews
- Training records
- Any communications about them
Exclude (if separate system):
- Patient records they created (that’s patient data)
Family Member Requests
A relative requesting records of a deceased patient or incapacitated family member.
Requires:
- Proof of authority (next of kin, power of attorney)
- May require legal advice for complex cases
Healthcare Redaction Checklist
When reviewing AI redaction, verify:
- Other patients’ names removed from appointment lists
- Other patients’ details removed from clinical notes
- Healthcare provider names retained (usually not redacted)
- Family members’ health information removed (if disclosed in confidence)
- Staff names handled appropriately (context-dependent)
Example: Dental Practice DSAR
Scenario: Patient requests all data after leaving the practice.
Step 1: Gather Data
- Export from practice management: appointments, treatments, billing
- Export clinical notes
- Export any X-rays
- Check email for correspondence
Step 2: Create the Case and Attach Exports
- Create a new case with patient details (Cases > Create New Case)
- Attach all exports via a case action (Request Info, Submit Info, or Close Case) using the file picker
Step 3: AI Processing
- Redactable files are scanned automatically — you land on the Review Detected PII screen
- Select the entities and Redact Selected; the AI flags other patients mentioned (e.g., family members who are also patients), then Confirm & Attach to Case
Step 4: Clinical Review
- Dentist reviews notes for any sensitive content
- No exemptions apply in this case
Step 5: Deliver
- Patient downloads via secure portal
- Case marked complete with full audit trail
Compliance Documentation
Healthcare providers face more regulatory scrutiny. SAR Portal helps by:
- Automatic audit logs: Every action timestamped
- Verification records: OTP confirmations logged
- Redaction evidence: What was redacted and why
- Response timing: Proof you met the one-month deadline
If the DPC or a patient complains, you can export the complete case record as evidence.
Getting Help
Healthcare-specific questions?
- Contact support@sarportal.com
- Reference this guide for faster assistance
Complex medical-legal issues?
- Consult your medical defence organisation
- Seek specialist privacy legal advice
Ready to get started? Open SAR Portal and follow the steps above.
New to SAR Portal? Start your free trial — your first DSAR could arrive tomorrow.