Overview
SAR (Subject Access Request) reports compile information from across a patient’s Rio EPR (Electronic Patient Record) record into a single report. Understanding what data is included and how SAR activity is audited can help support information governance processes.
What data is included in a SAR
SAR reports return information from all configured SAR datasets. Even when no information exists for a section, the section remains visible within the report.
Included data covers:
Demographics
Referrals
Appointments
Assessments
Progress Notes
Care Plans
Documents
Audit Trail information
Alerts
Risks
Results
Important data inclusion rules
Progress Notes
All versions of Progress Notes are included, regardless of locking status.
Sensitive Services
Data is included regardless of whether the referral relates to a sensitive service.
Unsaved Information
Information that has not been saved within Rio is not included.
Client Search Audits
Audit records are only included where a Client ID is available.
SAR auditing
Every SAR generation is audited within Rio.
Audit records include:
Generation date and time.
Included document names.
Document copy dates.
Workflow events
The SAR module supports workflow triggers that can be used for automation and notifications.
Available events include:
SAR Requested
This event triggers when a SAR form is submitted.
SAR Successful
This event triggers when a SAR report is successfully generated.
SAR Failed
This event triggers if SAR generation fails.
Use these events to notify Information Governance teams or trigger internal workflows.
