Everyone is given “see all” because the organisation is small and trust is high. Then a second branch opens, or a receptionist is hired, or management asks for a report. Trust, it turns out, is not an access policy. The file that was “visible to the team” becomes visible to people who never took part in the visit.
Clinic system access is not a list of buttons hidden in settings. It is a set of daily answers: who orders arrival? who reads the examination? who issues the invoice? who sees another branch’s totals? If the answer remains “everyone”, the boundary collapses at the first change in the team.

Why “everyone can see it” fails
It works for weeks in a clinic with one clinician and a stable receptionist. It fails when someone is away, when a temporary hire is used, or when a copy of a report is sent to an external accountant. The record does not judge intent. It is seen by whoever was granted sight.
- Reception needs to order arrival and may record a payment. It does not need the examination text.
- The clinician needs the visit of their specialty. They do not need files in a branch where they do not work.
- Finance needs the movement. It does not need the clinical note.
Role and branch before the screen
Access is built on the role, then on the place of work. A multi-branch organisation needs one policy and local permission. A central report must not break the clinical isolation of one branch from another. That is the subject of multi-branch clinic operations and the security page.
Management reads indicators from authorised activity, not by opening files one by one. If a director needs clinical detail, that is a documented exception, not permanent open access.
An activity record is not a punishment
The log helps when someone asks: who changed the appointment? who issued the invoice? An answer from the system is clearer than memory. This is not an accusation. It keeps the path reviewable months later, when two people disagree about a discount or a cancellation.
Without a log, the clinic returns to questions in the corridor. With a log and no access limits, the log itself becomes a way to browse every file. Both are needed: a limit on sight, and a trace of the action.
What we show, and what we do not
We write about role and branch access because that is what runs every day. We do not publish unverified compliance certificates, and we do not claim a default setup fits every branch network on the first day. Setup is work with the organisation, not a tick in a proposal.
Common mistakes in clinic access
- Copying a clinician’s account for a new hire “until the role is set”, then forgetting to set it.
- Giving an accountant full access because reports were late.
- Leaving accounts open after people leave the team.
- Measuring security by password rules, not by how many people see a file without needing to.
Frequently asked questions
Is a strong password enough?
It protects the account from outside sign-in if it is actually used. It does not stop a colleague who was given “see all” from reading what does not concern them. A password is not a role policy.
What changes when a new receptionist is hired?
They receive the reception role only: arrival, waiting, and perhaps payment. A clinician account is not copied. If questions about the examination keep returning, the path is reviewed; access is not widened. See also CRM vs the medical record.