Family & Resident Portal
Privacy-filtered updates that keep families and residents informed — without exposing the clinical record.
The Family & Resident Portal is the privacy-filtered window for authorized family members and residents. It is built on hard rules rather than configuration: safe, purpose-built projections only, a denylist scope can never override, and existence-only updates — so families get reassurance without ever touching the clinical record. Portal viewers never see the staff app, and staff data never reaches the portal.
What's in the module
Invite-based authorized access
Each viewer's access is one attested authorization: the administrator attests to the authorization on file, and the flow mints a one-time invite link shown once and never stored in plain form. Every authorization records its legal basis — resident self-access, POA (Power of Attorney), Guardian, or court order — and revoking one requires a documented reason.
Scoped, tab-limited views
Each authorization carries a scope: which tabs are visible — Overview, Medications, Care Plan, Updates, Requests — and how much medication detail shows. Scope can only narrow what a viewer sees; it can never unlock anything on the privacy denylist. Defaults are conservative — purpose categories on, doses off, update details off.
Non-stigmatizing purpose categories
Families see a non-stigmatizing purpose label — Sleep support, Mood support, Anxiety support, Pain management — never the raw drug name or the clinical diagnosis. The mapping runs server-side from the indication text, and the indication itself never crosses into the portal.
Care-conference and help requests
Families and residents can ask for help, a question, a call, or a care conference, routed to staff without exposing any internal workflow. The Updates tab reports only that something changed — a medication updated, a provider review completed — never what changed, and never a score.
A full access audit
Every authorization has a per-resident audit trail — created, scope changes, revocations, and sign-ins. A hard denylist that scope can never override keeps behavior logs, AI insights, compliance tasks, survey risk, F-tags, diagnoses, and staff notes out of the portal entirely.
Regulatory context
The portal is a direct expression of the HIPAA (Health Insurance Portability and Accountability Act) minimum-necessary principle: family and resident viewers receive only reassurance-level information under a documented legal basis, and every access is authorized at the function level and written to an audit log.