A letter arrives asking for everything
A former client emails asking for a copy of all the information you hold about them. You know there is a time limit, and you know the request is legitimate. You also know their information is in your practice system, your email, a notebook, some texts on your phone, invoices in Xero and possibly a letter you wrote to their GP.
You start searching. Two evenings later you think you have it all, but you are not certain, and you still need to decide what can be released and what needs advice. The request sits heavily all week.
Why it is harder than it should be
The difficulty is rarely the request. It is that a therapy practice's records about one person are spread across tools that were never designed to be searched together.
- Clinical notes in one place, admin records in another.
- Emails with the client scattered across folders, and sometimes across personal and practice accounts.
- Invoices and payments in your accounting package.
- Texts and voicemails on a phone.
- In a group practice, information held by more than one associate.
Then there is the review: some content may involve third parties, and what should be released is a decision for you and whoever advises you. That judgement needs time, and the search eats it.
The cost of a scramble
| Problem | Risk |
|---|---|
| Deadline tracked in your head | Missing the response window |
| Search across many places | Missing something that should have been included |
| No record of what was sent | No answer if the client later says something was left out |
| Review squeezed into evenings | Less care over third-party information than it deserves |
| No process | Every request is handled from scratch |
How we make requests manageable
- A request log. Each request is recorded with the date received, identity check status and the due date worked out from the rules your adviser gives you, with reminders as it approaches.
- A client search across your connected systems: practice system, practice email, document storage and accounting. It gathers matching records into one private review folder for that request.
- A checklist of places the search cannot reach, such as paper notes or a work phone, so you confirm each one by hand.
- Review tools: you mark each item to include, withhold or redact, with a note of why. The system does not make these calls.
- A disclosure pack is produced from the items you approved, with a record of exactly what was sent, when and how.
- A closed-request record kept for as long as your policy says, so there is an answer if questions come later.
This works best alongside tidy records in the first place, so we often pair it with bringing scattered notes and documents into one system.
When the next request arrives
You log it, the due date appears, and the search runs. You spend your time on the review, where judgement is needed, rather than on hunting through folders. When you send the pack, the record of what went out is created as you do it.
It stops being a week-long worry and becomes a process with a start, a middle and an end.
Is your practice ready for a request?
- You have received a records request and found it hard to gather everything.
- Client information sits across several systems and devices.
- You would struggle to show what you sent in response to a past request.
- There is no written process for handling requests in your practice.
- You track the response deadline from memory.