Skip to main content

Understand SAR Data, auditing and reporting

Learn what information is included in a Subject Access Request report, how SAR activity is audited, and which workflow events can be triggered during processing.

Written by Connor Baeza

Overview

SAR (Subject Access Request) reports compile information from across a patient’s Rio EPR (Electronic Patient Record) record into a single report. Understanding what data is included and how SAR activity is audited can help support information governance processes.


What data is included in a SAR

SAR reports return information from all configured SAR datasets. Even when no information exists for a section, the section remains visible within the report.

Included data covers:

  • Demographics

  • Referrals

  • Appointments

  • Assessments

  • Progress Notes

  • Care Plans

  • Documents

  • Audit Trail information

  • Alerts

  • Risks

  • Results


Important data inclusion rules

Progress Notes

All versions of Progress Notes are included, regardless of locking status.

Sensitive Services

Data is included regardless of whether the referral relates to a sensitive service.

Unsaved Information

Information that has not been saved within Rio is not included.

Client Search Audits

Audit records are only included where a Client ID is available.


SAR auditing

Every SAR generation is audited within Rio.

Audit records include:

  • Generation date and time.

  • Included document names.

  • Document copy dates.


Workflow events

The SAR module supports workflow triggers that can be used for automation and notifications.

Available events include:

SAR Requested

This event triggers when a SAR form is submitted.

SAR Successful

This event triggers when a SAR report is successfully generated.

SAR Failed

This event triggers if SAR generation fails.

Use these events to notify Information Governance teams or trigger internal workflows.

Did this answer your question?