Skip to main content

Understanding Clinical Note Access Permissions

How Roles, Data Access, confidential notes, Share Notes, Clinical Administrators and System Administrators combine to control who can see a clinical note

Clinical note access in PracSuite is controlled by several settings working together, rather than a single permission. This article walks through each layer, from most restrictive to least, so you can understand exactly who can see a given note and why.

In short, there are five layers to be aware of:

  1. The user's Role, which decides whether they can access clinical notes at all.

  2. The user's Data Access Permissions, which narrow that access down to specific businesses, professions or practitioners.

  3. The Confidential flag on individual notes, which restricts a note further, even from users who would otherwise see it.

  4. The Share Notes feature, which is the one exception that can grant access outside the normal scope.

  5. The Clinical Note Administrator and System Administrator permissions, which override the above.


1. Role permissions

A user's Role, configured under Settings > Users & Security > Roles, determines whether they can access clinical notes at all, and what they can do with them generally. The relevant Role permissions are:

  • Clinical Notes Access, to view clinical notes. Only applies when Full Clinical Administrator Permissions is off.

  • Create Notes, to create new clinical notes.

  • Draft Notes, to save clinical notes as drafts.

  • Create Confidential Notes, to mark a clinical note as confidential.

  • Copy Note, to copy an existing clinical note.

  • Edit Notes Written by Other Practitioners, to edit clinical notes authored by another practitioner.

  • Edit Notes After Revision Period, to edit a clinical note after its revision window has closed.

  • Edit Author of Note, to change which practitioner a note is attributed to.

  • Edit Note Date, to change the date recorded on a clinical note.

  • Delete Note, to delete a clinical note.

  • Download, Print, Email, to download, print or email a clinical note.

  • Share Notes, to share a clinical note with another user or party.

If a user's Role doesn't grant Clinical Notes Access, they won't be able to view clinical notes at all, regardless of any other setting described below.


2. Data Access Permissions

Data Access Permissions are set on the individual user's own profile, not on their Role. Go to Settings > Users & Security > Users, open the user, and go to their Security tab.

Data Access Permissions are made up of several separate categories, including General & Appointment Book, Reports, and Clinical Notes. Each is configured independently, so a user can be fully open in one area and tightly restricted in another. For clinical note access, only the Clinical Notes Data Access category is relevant, the others (such as Reports or the Appointment Book) don't affect who can see a note.

Where the Role decides whether a user can access clinical notes generally, the Clinical Notes Data Access category decides whose notes they can see across patient files. It's set to one of four options:

  • Full Access, covering all businesses and practitioners.

  • Businesses, limited to one or more selected businesses.

  • Professions, limited to one or more selected professions.

  • Practitioners, limited to one or more selected practitioners.

By default, a new user is set to Full Access in every category until an admin deliberately narrows it. A common setup is to restrict a practitioner's Clinical Notes data access to just themselves, so they only see their own notes across all patient files.


3. The confidential flag

Any user with the Create Confidential Notes Role permission can mark a clinical note as Confidential when writing it. A confidential note is hidden from other users, even if those users would otherwise have Data Access to that practitioner, business or profession.

In effect, marking a note confidential adds a further, tighter restriction on top of Data Access. It's commonly used for sensitive entries that the author wants to restrict beyond their team's usual visibility, such as notes about a colleague, a workplace incident, or another sensitive matter unrelated to standard treatment.

Confidential notes can only be accessed by the author, or by a user with Clinical Note Administrator or System Administrator permissions (see below), or a user the note has been explicitly shared with using Share Notes.


4. The Share Notes exception

Share Notes is the one feature that can grant a user access to notes that fall outside their normal Data Access scope, including confidential notes, on a per-patient basis.

A practitioner can select the Share Notes button on a patient's Clinical Notes tab to share their own notes, files and form responses for that patient with other practitioners, either with everyone or with specific businesses, professions or practitioners. They can also choose whether confidential notes, files and forms are included in what's shared.

A user must have their user profile linked to their practitioner file before they can share their notes with others. See Using the Share Notes feature for the full walkthrough.


5. Clinical Note Administrator

Full Clinical Administrator Permissions is a special Role toggle that grants full access to clinical notes, going beyond the standard permissions above. In addition to all the usual note actions, a Clinical Administrator can:

  • Access notes marked Confidential by other users.

  • Manage the Share Notes setting on behalf of other practitioners, including sharing their notes with users who aren't Clinical or System Administrators.

Because these are administrator-level functions, the Full Clinical Administrator Permissions toggle can only be turned on or off by a System Administrator.

Importantly, a Clinical Administrator's Data Access Permissions still apply. A role can be given full Clinical Administrator privileges but still be restricted, via Data Access, to specific businesses, professions or practitioners. In that case, the user gets administrator-level access, including confidential notes and sharing control, but only within their allowed scope.

Because this permission bypasses the confidentiality and sharing choices made by individual practitioners, it should be assigned with care. See Clinical Note Administrators for more detail.


6. System Administrator

System Administrator is a special, built-in role that can't be edited. Users flagged as System Administrators always have full, unrestricted access to everything in PracSuite, including all clinical notes, confidential or otherwise, and their Data Access Permissions are always set to Full Access and cannot be changed.


Putting it all together

To work out whether a user can see a particular clinical note, it helps to ask the questions in this order:

  1. Does their Role allow Clinical Notes Access at all?

  2. Does their Clinical Notes Data Access Permission cover the business, profession or practitioner the note belongs to?

  3. Is the note marked Confidential? If so, only the author, an admin, or someone it's been shared with can see it.

  4. Has the note's author used Share Notes to extend access to this user specifically, even outside their normal scope?

  5. Does the user have Clinical Note Administrator or System Administrator permissions, which override the above (within any Data Access scope that still applies)?

For the full list of every Clinical Notes Role permission and how Data Access Permissions work across all areas of PracSuite, see the Role & Data Access Permissions Guide.

Did this answer your question?