A portal for the employers and HMOs you work with
Many clinics see patients on behalf of a company — an employer running annual physicals, or an HMO covering its members. The Employer & HMO Portal gives those companies their own secure window into the records of the people they cover, without ever mixing one clinic's data with another's.
What it does
- Lets a clinic record the companies it works with and link patients to them right from the patient file.
- Gives each company its own web address and its own users — a company administrator who manages their team, and HR users who can view the records of associated patients.
- Lets HR see a linked patient's appointments, diagnoses and treatment, prescriptions and financial history — read-only, and only for the patients that clinic has associated with them.
- Lets HR download the employee's Annual Physical Exam report (a 2-page PDF) for any visit where the clinic completed one.
- Lets companies record health entries on a patient — a medical note, reported medication, a medical undertaking, or other health information — and upload a copy of the employee's company ID, with each entry marked as visible to the company, the clinic, or both.
- Lets a company span several clinics — the same employee can be covered across every clinic they visit, all under one company.
- Keeps company profile details — address, contact number and website — that clinics can also surface on documents such as certificates.
Who manages what
- The clinic creates the companies it works with and links patients to them. Clinic administrators can keep a company's address, contact number and website up to date.
- The platform activates a company's portal — assigning its web address and first administrator — and can reconcile duplicate company entries.
- The company manages its own HR users and records health entries and IDs for the patients it covers.
Why it helps
For the clinic
Corporate and HMO work is organized in one place, and the company handles its own users and record-keeping instead of phoning the front desk.
For employers & HMOs
HR gets a clear, self-service view of the care their people received, across every clinic involved, without paperwork going back and forth.
For patients
Their workplace coverage is handled smoothly, and only the company they are actually linked to can see their information.
Access is strictly limited: a company only ever sees patients a clinic has associated with it, sensitive free-text medical fields are never exposed, and every clinic's data stays fully separate. Companies are created by clinics but their portals are switched on by the platform administrator.
Health entries
An HR user can write down what the company knows about an employee's health: a medical note, medication the employee has reported taking, a medical undertaking the company holds, or other health information. Each entry is typed, so the clinic can tell at a glance what kind of thing it is looking at.
Each entry carries a visibility — the company only, the clinic only, or both — and the ones shared with the clinic appear on the patient's page there. Authors edit and delete only their own entries. Everything is stored encrypted with the clinic's own key, the same protection the rest of the record gets.
An entry is context, not a clinical record. It does not prescribe anything, order anything or instruct the clinic; a clinician who thinks it belongs in the medical record writes it there themselves. That separation is deliberate — an employer's account of what an employee said is a different thing from a doctor's finding, and the record should never blur the two.
On what authority you share
Linking a patient to a company opens a real door: that company's HR staff can read that patient. So the patient's own page asks why that is lawful — their consent, with the date they gave it; an obligation under employment law; treatment or insurance administration; a legal claim; or protecting life and health. You can note where the signed form is kept.
Links made before this existed show as no basis recorded, in red, with a count. That is deliberate — nobody was asked at the time, and saying so is more useful than quietly relabelling them as consent. It does not block anything; it tells you what to catch up on.
If a patient withdraws consent, record it and the sharing stops. Not a flag someone has to remember to act on: the portal itself refuses to read that patient from that moment. The link stays on file, so you keep the history of what happened and when.
A template for the data sharing agreement itself — the document between your clinic and the company — ships with the platform documentation. It has not been reviewed by a lawyer; have yours look at it before you sign anything.
Requesting deletion of a patient's records
A company can ask a clinic to delete the records of a patient it is linked to — for example when an employee leaves and asks for their check-up records to be removed.
The company can only ask. The clinic holds the medical record and makes the decision: the request lands in that clinic's own Deletion Requests queue, and the clinic can approve it or decline it with a reason the company can read.
Three limits are worth knowing:
- A request covers that patient's record at that one clinic. The same person at another clinic is a separate record and needs its own request.
- A company can only raise a request for a patient it is actually linked to.
- If the link ends before the clinic decides, the request is withdrawn rather than carried out.
Deleting a company's own portal does not delete any clinical records. Those belong to the clinics that created them; what goes is the company's own data — its users, its notes and its uploaded documents. The links between the company and each patient stay, because they are part of each clinic's own history of who a patient's employer was at the time of care.
Bulk booking campaigns
Company Administrators can ask one linked clinic to arrange appointments for a group. Open Bulk booking, select the clinic, choose a date window and preferred time, then add people from the company-linked patients or enter the details for a person who is not yet registered at that clinic. You can also request a doctor when that is appropriate.
Submitting takes two steps. Preview campaign checks the entries and reports how many people were accepted, split between company-linked patients and new people; nothing is sent yet. The form comes back with everything still filled in, so you can correct a row and preview again. When the counts look right, Submit campaign sends the request to the clinic.
A campaign is a request, not a confirmed appointment. The clinic reviews every person in its booking inbox. A Tenant Administrator, Doctor, or Receptionist can match or create the patient, choose the final doctor, date and time, and confirm the appointment. The clinic may decline or leave a request pending when it cannot accommodate it.
When you paste a CSV, each line needs at least first name, last name, email and phone; date of birth, middle name and notes are optional and may be left empty between commas. A line with fewer than four or more than seven columns is reported by line number so you can correct it and preview again.
For an existing patient, the portal accepts the request only while the company-patient association permits sharing. If consent was the recorded basis and the patient withdraws it, the company cannot submit another request for that person. For a new person, provide only the details the clinic needs to contact and register them, and make sure the company is authorized to share them.
The campaign page shows totals for pending, confirmed, declined and cancelled requests. It does not expose the clinic's private clinical record or turn a campaign into an appointment without the clinic's decision.