Around the care

Healthcare administration

The administration around care rather than the care itself: who referred someone, who is paying, what was arranged and when they are due back. Not a clinical system, and this page is careful about the difference.

First

The line this page will not cross

Consonas is not a clinical records system. It holds no structured clinical data, it is not registered as a medical device with the Medicines and Healthcare products Regulatory Agency, and it is not built to the standards a clinical system is held to. Nothing on this page should be read as suggesting you put clinical notes in it.

The reason to say that at the top rather than in a footnote is that this is the sector where a vague marketing page does actual harm. A practice that puts clinical information into an administrative system because a website was ambiguous has a problem that is expensive, and in some cases reportable, and the supplier who was ambiguous will not be the one explaining it.

The useful test is whether a clinician would rely on the information to make a decision about treatment. If yes, it belongs in your clinical system. What follows is everything else, and in most practices everything else is in a shared inbox, a diary and two spreadsheets.

Referrers, roles, consent

What generic software has no concept of in this trade

The referrer is the business

In a great deal of private healthcare the patient did not choose you, somebody sent them. A general practitioner, a consultant, a physiotherapist, an employer, an insurer, a case manager. That relationship is the reason the practice has work, and it is almost never recorded as anything at all.

The consequence is that a practice cannot answer basic questions about its own income. Which referrers send the most. Which have stopped. Whether the drop in January was a market change or one consultant retiring. Everyone has an impression and no one has a number.

A referrer as a relationship, connected to every person they referred, turns that into arithmetic. It also makes a drop visible: a referrer who sent you six people a quarter and has sent none for two is a telephone call worth making, and it is a telephone call nobody makes because no one notices.

The permission model has to be two decisions

Reception books appointments, takes payment and answers the telephone. They need the system. They frequently should not be reading clinical correspondence. In a product with one permission level per person, those two facts are in direct conflict, and the resolution is either that reception sees everything or that reception cannot work.

Splitting it into two decisions is what resolves it. The role says what somebody can do: book, reschedule, take payment, raise an invoice. Sensitivity is a separate grant that says which restricted records they may open. Somebody can have full ability to run the front desk and no access to a restricted record, and the restricted record does not appear in their search as a locked row confirming it exists, because in this trade the existence of the record can itself be the sensitive fact.

Consent is not one thing

An appointment reminder is not marketing. A recall is not a newsletter. A practice that treats consent as a single switch ends up with two bad outcomes at once: people who asked not to receive marketing stop receiving reminders, and people who wanted reminders receive a newsletter and complain.

Consent per channel, held as a fact with a date and a source and checked again at the moment of sending, is what separates them properly. It also produces the evidence you will want if anyone ever asks what someone had agreed to at the time, which a single current value field cannot answer.

Six ordinary weeks

Six things a practice deals with in a week

Ordinary weeks in an ordinary practice.

The situation What usually happens What Consonas does
A referrer who sends you patientsNowhere, or a name in someone's contacts. When they stop referring, no one notices for six months.A relationship connected to every person they referred, so referral volume is a number and a drop is visible.
Reception must book but not read correspondenceOne permission level, so either reception sees everything or cannot do their job.A role that permits booking, and sensitivity as a separate grant for clinical records. Two decisions instead of one.
An enquiry that did not become a patientLost, so nobody knows how many enquiries the practice gets or what proportion convert.A relationship with what they asked about and what happened, and consent recorded for any later contact.
Someone due a six month reviewA spreadsheet, a diary entry, or the practitioner remembering.A task against the person with a date, appearing in a daily view of what is due and what has slipped.
An insurer paying for treatmentThe policy number typed into a notes field on the patient, and the insurer is not a record at all.The insurer is an organisation, connected to the people whose treatment they fund, with the policy details on the connection.
A subject access requestTwo or three systems searched by hand against a statutory deadline.One organisation, one search, and tooling built for it. What is clinical stays in the clinical system and is answered from there.

Referrals

Making the source of the work visible

Every referrer is a relationship, connected to the people they referred, with the history of what happened to each. That is enough to answer the questions a practice cannot currently answer: who sends the most, who has stopped, and what a referral is worth on average.

It also changes what business development means. Instead of taking eleven people to lunch because they are the ones you know, you take the four who have gone quiet and the three who are growing, which is a completely different afternoon.

Consent is per person and per channel here too. A consultant who wants your quarterly summary and a consultant who does not are two positions on one record rather than a judgement someone makes each time.

How relationships work

The front desk

Booking without reading

Appointments live in the same calendar as everything else, attached to the person they concern. Clashes are reported rather than prevented, because whoever is booking usually knows something the calendar does not, and a system that refuses teaches people to keep a paper diary as well.

Recalls are tasks with dates against the person rather than entries in somebody's diary. A six month review appears in the daily view before it is due, and it is visible to whoever is covering rather than to the one person who set the reminder.

All of it works under a role that does not carry access to restricted records. The front desk can run the front desk without the practice having to choose between capability and confidentiality.

How permissions work

Obligations

Erasure, subject access, and evidence that cannot be edited

A subject access request has a statutory deadline. So does a report of a personal data breach to the Information Commissioner's Office. Neither cares how many systems you keep information in, and both are considerably easier when the administrative side is one searchable place instead of an inbox and two spreadsheets.

Erasure removes a person from every place they appear instead of the one you were looking at: record, connections, notes, audiences, message history, consent records and files. What survives is the trail's statement that an erasure happened and who performed it, without the content.

The audit trail cannot be edited by anyone, including us, and it is on every plan including the free one. No one here can open your organisation without a stated reason, a second approver and an entry in that trail which you can read yourself.

How security works

Before the import

The sensitivity decision, and five smaller ones

In this trade the sensitivity configuration comes first, before the import rather than after it.

Relationship types
Patient or client, referrer, practitioner, insurer, employer, next of kin, care home, commissioner. Most private practices need six of these and are offered one called Contact.
The referrer is a relationship
In most of this trade the referrer is the reason the business exists, and is almost never recorded as anything. A general practitioner, a consultant, an employer, an insurer, a physiotherapist who sends you work. Connected to every person they referred.
Sensitivity by default
This is the trade where the posture inverts. Assume restricted, grant deliberately. Sensitivity is held separately from the role, so reception can book appointments without seeing clinical correspondence.
Consent, per channel, with a date
Appointment reminders are not marketing. A recall is not a newsletter. Holding consent per channel with a date and a source is what lets you send the first two to someone who has refused the third.
Appointments and recalls
The calendar with clashes reported rather than prevented, and tasks for recall dates against the person rather than in a diary. A six month review is a task with a date, not somebody's memory.
Custom fields
Insurer and policy number, referral source, funding route, accessibility requirement. Few. Anything clinical belongs in your clinical system rather than here.

Reception needs the system and frequently should not be reading clinical correspondence. With one permission level per person those two facts are in direct conflict, and one of them always loses.

Which is why sensitivity is a grant held separately from the role, and why we would tell a practice to set that up on the first afternoon.

Plain limits

What we will not claim

We will not tell you it is compliant

Compliance is a property of your practice rather than of a piece of software, and any supplier telling a healthcare provider otherwise should be treated with suspicion. What we will do is describe accurately what the product does, where data is held, who can see it and what evidence exists, so that your data protection officer can reach their own conclusion.

Data is not held in the UK

The European Union or the United States, chosen at creation and fixed from then on. UK practices should choose the European Union. If your requirement is specifically UK residency, we do not meet it today, and that is a better thing to learn from this page than from a procurement questionnaire.

What we do not have

No SOC 2 and no ISO 27001. No published penetration test. No integration with any clinical system today. No SMS sending. The security page carries the full list, including two protections that are built and not yet enabled in production, because a sector doing diligence deserves the unflattering half of the picture as well.

What to check before you commit

Run an export on the first afternoon, before there is anything in it that matters. It is free on every plan and produces everything you hold in a format that opens without our software. Knowing it works is worth more than any assurance on a page like this one, and the rest of the questions worth putting to any supplier are written down rather than left for you to think of under time pressure.

The first hour

Where a practice should start, and in what order

About an hour, and the first paragraph is the one that matters most.

Understand what this is not, first

This is not a clinical records system and clinical records belong in one. Consonas holds the administrative relationship: the referrer, the enquiry, the appointment, the recall, the invoice, the person who has not become a patient yet.

A team that is clear about that boundary gets an hour of setup and a system that helps. A team that is not gets a duplicate of a clinical system and a governance problem.

Model referrers as their own type

A referring practice, a consultant, a self referral, an insurer. Most administrative teams cannot say which referrers produce which volume, and that number decides where the relationships are worth investing in.

Separate the payer from the patient

An insurer, an employer, a parent, the patient themselves. They are different records with different needs, and a system that records only one of them cannot answer the other's question.

Put the recalls in as dated tasks

The six month review, the annual check, the follow up after a procedure. This is where the recurring value is, and in most administrative teams it lives on a spreadsheet someone maintains.

Set sensitivity deliberately, and keep the clinical detail out

The safest arrangement is that this system holds who and when, and the clinical system holds what. Free text fields will hold whatever somebody types, which is true of every system of this kind, so the boundary has to be a habit as well as a setting.

The backdrop

Recognition, retention, and the questionnaire that arrives before the first invoice

The rules a private practice actually runs into are mostly not data protection rules, and almost none of them are about software.

The practitioner is registered, the practice usually is not

In most of private healthcare the permission to work sits with the individual rather than with the business. A registration with a professional regulator such as the General Medical Council, an indemnity arrangement, and in several disciplines a continuing education requirement that has to be evidenced when someone asks. The practice is the setting. The person is the one who can be suspended, and the practice is the one that discovers what that means for next week's clinic list.

All of that is dated, none of it is clinical, and in most practices of this size it lives in a folder and a memory. A dated task against the practitioner is not a compliance system and we would not describe it as one. It is a reminder that arrives while there is still time to act, which is the difference between a renewal and an incident.

Recognition by an insurer is a contract, and it has an end

Insurers recognise practitioners rather than practices, usually per discipline, sometimes with a fee schedule attached and sometimes with conditions about the setting. Recognition is reviewed, changed and withdrawn. Fee schedules move without either side having a conversation about it.

Administratively that means the pair of practitioner and insurer is itself a thing with a period instead of a fact about either one. A practice that cannot list which of its clinicians is recognised by which insurer finds the gap at the point of billing, which is after the treatment, which is the expensive end. Hold it as a connection between the practitioner and the insurer with a start date, and put the schedule reference on the connection rather than in the head of whoever has been there longest.

Retention and erasure pull in opposite directions

Health records carry retention periods set by professional and national guidance, measured in years and in some cases decades, and longer again for children. The administrative record is not automatically governed by the same rule. Appointment history, correspondence about an invoice, a note that somebody rang to complain about parking: these are business records rather than health records, and the question of what may be deleted has a different answer for each.

We deliberately do not answer that question for you. What Consonas does is described further up this page: erasure removes a person from everywhere they appear, and the trail keeps the statement that it happened without the content. Whether to use it, and what your clinical system must keep regardless, is a decision for your data protection officer working from facts rather than from a supplier's reassurance.

The questionnaire that arrives before the first invoice

Corporate clients, insurers and occupational health contracts send an information governance questionnaire, and it arrives before the work does. Where is the data held. Who can see it. What happens when somebody leaves. Does sign in carry a second factor. Is there an audit trail and can it be altered. How would a breach be notified. What certifications do you hold.

Most of it we can answer plainly, because the answers are on this page, on the security page, and in the note on why every customer organisation gets its own database: a region fixed when the organisation is created, the European Union or the United States, an audit trail nobody including us can edit, two factor sign in, sensitivity as a grant held separately from the role, and export on every plan. One line we fail. There is no SOC 2, no ISO 27001 and no published penetration test. Where that line is scored as a gate rather than as a risk to be weighed, you will not get through it with us, and a form is a much cheaper place to learn that than a migration.

Consent to treatment is not the consent this system holds

Two different things wearing the same word, and the confusion is common enough to be worth a paragraph. Consent to treatment belongs to the episode of care, is a clinical act, and lives in the clinical record. Consent to be contacted is administrative, held per channel, with a date and a source.

A practice that runs the two together ends up asking somebody to agree to a newsletter in the same breath as a procedure, which is poor practice and produces a consent record that no one sensible would want to rely on afterwards. Keep the words apart and the systems stay apart on their own.

The other parties

The insurer, the case manager, and the daughter who rings on a Thursday

Very little in this trade is a transaction between two parties, and the third party is usually the one holding the money or the authority.

The insurer, who is paying and is never the patient

The insurer is an organisation, connected to the people whose treatment it funds, with the policy details on the connection. What that arrangement makes possible is the ordinary awkward moment at the desk. A course of treatment is authorised for a set number of sessions, the patient arrives for one more than that, and whoever is on reception has to know whether it is covered before the appointment rather than six weeks later when the invoice comes back.

An authorisation reference and the number of sessions it covers, held where reception can see them without seeing anything clinical, turns an invoice dispute into a conversation at the desk. It is a small piece of information in an unglamorous place and it is one of the few administrative facts in this trade with a direct price on it.

The employer, who is entitled to an outcome and not to a record

In occupational health and in employer funded treatment the payer is a company, and the company is entitled to considerably less than it usually expects. Somebody in human resources will ring and ask how their employee got on, and the correct answer is attendance, an outcome, and whatever report they are contracted to receive. Nothing else.

This is the relationship where the permission model earns its keep most obviously. The employer sits on the record as the payer, connected to the person whose treatment it funds. If the clinical correspondence is one click from that connection and visible to whoever picks up the telephone, the wrong answer is the easy answer, and the wrong answer here is a disclosure instead of a mistake.

The solicitor and the case manager, where the patient is not the client

Medicolegal and rehabilitation work invert the usual arrangement. The instruction comes from a solicitor or a case manager, the report goes to them, the deadline is theirs, and the person being examined is the subject rather than the customer. A practice that models this the ordinary way, with the patient at the centre and the solicitor as a note, loses track of the only relationship that produces more work.

Model the instructing firm as the organisation, the individual solicitor or case manager as the person you actually deal with, and the person examined connected to both. Then the question nobody in this kind of practice can currently answer, which instructing firms send work and which have quietly stopped, becomes exactly the same arithmetic as the referrer question at the top of this page.

The care home, the school and the household, where whoever rings keeps changing

Some patients are booked by someone else every single time, and that someone else changes. A care home has staff turnover and a deputy manager who rings for six months and then does not. A school has a designated member of staff for this year. A household has one adult who books for four people.

The durable thing is the home, the school or the household. The person who rings is a connection with a period on it. Holding it the other way round, as a contact record with the home's telephone number typed into it, loses the history the first time a manager leaves and leaves the practice ringing a number that reaches someone who has never heard of the patient.

Next of kin, and the gap between authority and concern

Two different roles arrive in the same telephone call and they are not the same record. A parent of a child, an attorney, a court appointed deputy: these hold authority. A worried son holds concern. Both are worth recording. Only one of them can be guessed at the desk without consequence, and it is not authority.

Record the relationship as what it actually is, and put any contact restriction where whoever answers the telephone sees it before they say anything. Do not leave a message on this number. Do not write to the home address. Do not discuss the appointment with the person who books it. In this trade those are safety instructions rather than preferences, and they belong at the top of a record rather than in the fourth note down where someone in a hurry will not reach them.

The interpreter, and the room on the ground floor

Language and accessibility requirements are administrative facts with booking consequences. An interpreter has to be arranged in advance and a ground floor room may have to be held. Reception needs both at the moment of booking, neither is clinical, and a practice that discovers them on the day loses the appointment and the goodwill in one go. These belong in the small set of custom fields rather than in free text where they are found by accident.

Several of those parties keep records of their own at the other end of the same relationship: solicitors and law firms, who instruct the medicolegal work, professional services firms, who count referrals the same way, and training providers and schools, where one member of staff books on behalf of everyone else. How a role and the separate sensitivity grant are actually set is on administration and permissions.

Person and episode

The patient lasts, the episode does not, and everything expensive hangs off the episode

The one modelling decision in this trade that is hard to change later, and the reason it is not the obvious one.

The durable record is a person here, which is less helpful than it sounds

Several trades on the sectors index discover that the record which lasts is a building, a site or a case rather than a person. Healthcare administration is one of the few where the durable record genuinely is the person, and the temptation is to conclude that the modelling is therefore easy.

It is not, because the thing that repeats is not the person. The same individual can be a self funding physiotherapy client in March, an insured patient under a new employer's scheme in November, and the subject of a medicolegal examination two years later at the request of a solicitor they have never met. One person, three funding routes, three referrers, three separate arguments about money. A record with one insurer field and one referrer field describes whichever of the three happened most recently and quietly loses the other two.

The episode is what repeats, and it needs a beginning and an end

The thing worth naming is the episode: a referral, a reason, a funding route, a practitioner, a run of appointments and an ending. Most practices can carry it as a connection between the person and the referrer with a start date, with the dated tasks for recalls and reviews hanging off it. That is enough to answer the three questions that actually get asked. Who sent this one. Who is paying for it. What is still due and when.

Practices whose episodes carry a great deal of their own detail can make the episode a record in its own right on the plan that carries custom record types. We would still start with the simpler arrangement and let the second year make the case, because the cost of starting simple is an afternoon of restructuring later, and the cost of an elaborate model that nobody maintains is a year of data that describes the model rather than the practice.

Five connections that are wrong without periods on them

The person and the treating practitioner, because clinicians leave and a departing clinician's list has to move somewhere identifiable rather than becoming everyone's. The person and the insurer policy, because policies renew annually, employers change scheme, and the policy number changes with them. The practitioner and the insurer, because recognition is a contract with an end as described above.

The person and the care home or household, because residency ends. And the individual referrer and the referring practice, because a general practitioner who moves either takes your referrals with them or does not, and which of those happened is the single most useful piece of business development information a practice of this size can have. In every one of the five, the fact and the period are both the information. A connection without dates answers today's question correctly and destroys last year's.

The three custom fields worth having

Funding route, as a short fixed list: self funding, insured, employer, legal, contracted. It changes who is chased for money, what is said at the desk and which report the practice manager wants at the end of the quarter, and it is one field.

Authorisation reference with the number of sessions it covers, for the reason in the section above: reception needs it before the appointment rather than after. And accessibility or language requirement, because it has to be acted on at the moment of booking. Everything beyond those three can wait until its absence has annoyed someone twice, which is the general rule on this site and is unusually true in a trade where every extra field is an invitation to type something clinical.

The fields to refuse, and who will ask for them

Diagnosis. Medication. A risk flag with clinical meaning. A free text box called notes about the condition. Each of these begins as a reasonable convenience requested by a sensible person with a good reason, and ends as a clinical record kept in the wrong place, incompletely, by whoever happened to be typing.

The boundary set out at the top of this page is only real if it survives the first request for a convenient field, and that request always comes from someone trying to do their job properly. The answer that works is not a rule about typing, it is having somewhere better to put it: if the clinical system is where that fact lives, the field is not needed here, and if the clinical system cannot hold it, that is a conversation about the clinical system rather than about this one.

Reasons not to

Six kinds of practice we would rather send somewhere else

The section further up says what we will not claim. This one says who should stop reading, by the shape of their practice rather than by the shape of our conscience.

The practice whose management suite already holds the administration

Several disciplines have a practice management product that carries the clinical record, the diary, the invoices and a serviceable contact list in one place. If you have one and you are broadly content with it, adding a second system means every patient exists twice, and the second copy is wrong within a month unless somebody is paid to keep the two level.

The case for a separate administrative system is strongest when the referrer question and the enquiry question cannot be answered at all. It is weakest when they are already answered adequately, and adequate is a perfectly good place to leave something.

The practice that wants patients booking themselves

There is no patient record, and no portal that shows one. A patient can book a slot on a published booking page and can fill in a web form, and on the plans carrying the portal somebody outside can sign in to see the enquiries they raised. What none of them can do is reschedule, read a letter, or see anything clinical. If self service around a clinical record is the thing you are buying, a patient system is the thing to buy, and bolting one alongside a CRM produces two records that disagree.

The practice whose whole problem is the text message

Consonas does not send SMS today. That is in the questions below and it is repeated here because it is the most common single reason a practice in this trade should buy something else. If missed appointments are the thing keeping the owner awake and reminders by text message are the intervention, buy the reminder product. It will cost less than this and it will solve the actual problem, which is a better outcome than a general system that solves an adjacent one.

The practice that needs it to talk to the clinical system this year

There is no integration with any clinical system today. A patient created in one is not created in the other, so somebody types twice or imports periodically. In a practice of three people that is an irritation. In a busier one it is a job, and a job that needs an owner and a habit rather than good intentions. If double entry is unacceptable to you, that is a reason to wait or to buy elsewhere, and it is much better learned now than in the third week.

The practice with UK residency written into a contract

The European Union or the United States, chosen when the organisation is created and fixed from then on. UK practices with no specific residency clause should choose the European Union. Practices whose commissioner, insurer or corporate client has written UK residency into the contract should stop at this paragraph, because nothing further down the page changes it.

The practice where a certificate is the gate rather than the evidence

Some buyers, particularly where a public body or a large insurer sits behind the contract, treat certification as a threshold to be met rather than as one piece of evidence among several. There is no SOC 2, no ISO 27001 and no published penetration test. Where the certificate is the gate, we do not get through it, and describing the audit trail in more detail does not change the answer.

Who that leaves

A practice of a handful of people where no one can say which referrers produce the work, where the recall list is a spreadsheet one person maintains, where the enquiry that did not convert left no trace, and where the front desk can either see everything or do very little. That practice is the one this page was written for. Everyone in the six paragraphs above is better served by something else, and we would rather write that down than find out during a trial.

From practices

Asked by practices

Is this a clinical system? Can we put patient notes in it?

No, and please do not. Consonas is not a clinical records system, holds no structured clinical data, is not registered as a medical device, and is not built to the standards a clinical system is held to. It is for the administrative relationship around care: enquiries, referrers, appointments, billing relationships and communication. Clinical records belong in a clinical system.

Then where is the line?

A useful test is whether a clinician would rely on it to make a decision about treatment. If yes, it belongs in your clinical system. Appointment history, who referred somebody, which insurer is paying, whether a recall is due and what was discussed about an invoice are administrative. What was found on examination is not.

Is it suitable for special category data?

It is capable of holding it, with sensitivity as a separate grant, an audit trail nobody can tidy up, consent recorded per channel with a date, erasure that removes a person from everywhere they appear and blanks the values in the entries about them, and a region you fix at creation. Whether your particular processing is lawful and appropriate is a decision for your data protection officer, and we would rather they made it with the facts than took a claim from a marketing page.

Do you hold data in the UK?

No. The European Union or the United States, chosen when the organisation is created and fixed from then on. UK organisations should choose the European Union: it is the closest region available and carries the data protection posture UK law expects. If your requirement is specifically UK residency, we do not currently meet it and would rather say so.

Can reception be prevented from seeing certain records?

Yes, and this is the configuration to get right before importing anything. A role gives someone the ability to do their job. Sensitivity is a separate grant on specific records. Reception can book, reschedule and take payment without ever being able to open a restricted record, and the restricted record does not appear in their search results as a locked row confirming it exists.

Does it send appointment reminders?

On the plans carrying the communication and sequences modules it can send messages against a schedule, and consent is checked per channel at the moment of sending. It is not a specialist reminder product, does not send SMS today, and does not integrate with a clinical system's appointment book. If reminders are the main thing you need, a specialist tool may serve you better.

We are a single practitioner. Is this overkill?

Possibly. If your practice is a diary and forty patients, a diary may genuinely be enough. Where this starts paying is when there is a referrer relationship worth understanding, when someone else answers the telephone, or when you cannot answer how many enquiries you had last quarter.

What happens to our data if we stop paying?

You drop to the free plan rather than out. Nothing is deleted, everything stays readable and searchable, and export continues to work on any plan free of charge. For a practice holding sensitive information, knowing you can get it all out and knowing exactly what happens if you stop paying are both worth checking before you start rather than after.

Our referrers are one practice with several partners. Is the referrer the practice or the person?

Both, connected to each other. The practice is durable and the partners move, so record the individual who referred and connect them to the practice with a period. Volume by practice and volume by individual are then two views of the same records rather than a choice made on the first afternoon that you cannot undo in the second year.

We do medicolegal work alongside treatment. Does that fit?

It fits the same shape as a referral, with the parties in different places. The instructing firm is the organisation, the solicitor or case manager is the person you deal with, the person examined is connected to both, and the deadline is a dated task rather than a note. Files attach to records like any other file. Nothing in the product understands what a report is, and it should not: the report itself is clinical work product and belongs where your clinical work lives.

A patient asks us to delete everything. What actually happens?

In Consonas, erasure removes them from every place they appear instead of the one you were looking at, and the trail keeps the statement that an erasure happened and who performed it without the content. That answers the administrative half only. Whether your clinical retention obligation permits or requires the clinical record to survive is a question for your clinical system and your data protection officer, and answering the administrative half is not answering it.

Can each clinician be limited to their own patients?

The model is a role for what someone can do plus sensitivity as a separate grant on specific records. That covers the case this trade runs into most, which is a front desk that must book without reading. If your requirement is that every clinician sees a strictly separate list from every other clinician, set it up on a free organisation and check it before you commit rather than taking a sentence on a marketing page for it.

Is it lawful for us to hold enquiries from people who never became patients?

That is a question for your data protection officer rather than for us, and any supplier answering it confidently for your practice is guessing. What the product does is hold the enquiry, what was asked about, what happened to it, and consent per channel with a date and a source, so that whichever answer your practice reaches, the evidence for it exists instead of being reconstructed later.

Who inside a practice should own this?

Usually the practice manager or whoever owns the front desk process, rather than a clinician. The one decision worth an owner and an afternoon is sensitivity, and it should be made before anything is imported rather than after someone notices reception can read a consultant letter.

Start with the referrers

Import the referrers and the enquiries rather than anything clinical, and see whether the numbers agree with what everybody believes.

Three people, a thousand relationships, no card and no time limit.