Skip to content
  • There are no suggestions because the search field is empty.

Patient Access Log Overview

The Access Log records which Team Members have viewed each Patient's record in the Staff Portal, and for how long. It gives your Organisation's privacy and compliance functions a session-level picture of access to patient data โ€” useful for audits, access reviews, investigations, and collation of data for billing where appropriate.


๐Ÿ”’ Availability and Permissions

The Access Log is a paid platform extension, enabled per Organisation. If you can't see it in your Staff Portal, it isn't part of your Organisation's current plan โ€” contact Wellifiy support or your account manager to discuss activation.

Once enabled, access is controlled by Role. Team Members need both the Reporting and Patient Access Log permissions to view the Access Log and run exports. Holding only one of the two isn't enough. An administrator can review which Roles have them enabled under Administration โ†’ Roles & Permissions.


๐Ÿ“ Where to Find It

For the Organisation-wide view, go to:
Reporting โ†’ Access Log

Each patient's record also has its own Access Log tab, covering just that patient.


โฑ How Access Is Measured

The Access Log measures active viewing time, grouped into sessions, so durations reflect how long a record was actually being worked with rather than how long a tab happened to be open.

  • A session begins when a Team Member opens a patient's record.
  • It stays open while they keep interacting โ€” moving between the patient's screens and tabs counts as continued activity.
  • When activity stops, the session closes automatically after an inactivity window, with a short buffer added to the end to account for time spent reading after the last click.
  • If a Team Member steps away and returns later, beyond the inactivity window, the return is recorded as a new, separate session โ€” long pauses don't inflate the reported duration.

Each patient is tracked independently. A Team Member with several patient records open in different browser tabs generates a separate session for each patient.

A few things worth knowing:

  • Only Team Member activity in the Staff Portal is logged. The Access Log doesn't cover patients' own activity in the Patient App or Patient Web Portal.
  • Only successfully loaded patient screens are counted โ€” failed or blocked requests aren't recorded as access.
  • Logging runs in the background and has no impact on how the Staff Portal performs.

โš™๏ธ Timing Settings

Two settings shape how sessions are measured:

  • Inactivity window โ€” how long a Team Member can be idle before their session is considered ended. The default is 5 minutes.
  • Reading time buffer โ€” the extra time added to the end of each session to account for final reading. The default is 30 seconds.

These are configured by Wellifiy for your Organisation. Contact Wellifiy support if you'd like them adjusted.


๐Ÿ‘ค The Access Log on a Patient's Record

Open a patient's record and go to the Access Log tab to see every access session recorded for that patient, in one table. This is the quickest way to answer a question about a single patient โ€” for example, responding to a patient who asks who has viewed their record.

The per-patient tab is view-only. To export access data, use the Organisation-wide Access Log under Reporting.


๐Ÿงพ The Organisation-Wide Report and Export

The Access Log under Reporting gives you an Organisation-wide view of patient record access, with one row per session. Each row includes:

  • Patient name
  • Patient Identifier
  • Clinician name
  • Session start timestamp
  • Session end timestamp
  • Session duration

Exports are prepared in the background, so you can keep working while the file is generated. You'll receive an email notification once it's ready, and the file is then downloaded from Reporting โ†’ Export History. The email is a notification only โ€” no export data is sent by email. See Downloading Exports from Export History for the full walkthrough.


๐Ÿ’ก Best Practices

  • Use the Access Log to respond to privacy and access audits with precise access durations for each Team Member
  • Review it periodically for unusual patterns โ€” for example, a Team Member viewing an unusually high volume of records, or holding records open for unusually long durations
  • Start from a patient's Access Log tab when the question is about one patient, and the Organisation-wide report when you need to compare across Team Members or pull data out
  • Treat durations as a measure of active engagement rather than exact wall-clock time โ€” the inactivity window and reading buffer are designed to reflect real usage

Next step:
โžก๏ธ Review which Roles hold the Reporting and Patient Access Log permissions โ€” see Create Roles and Permissions.