Watson
Skip to clinic content

CLINIC ACCESS & PATIENT DATA

Give access a clear purpose.

Patient information should be available to the people who need it for their work. Watson uses assigned roles, location scope and separate clinical permissions to control access within the clinic workflow.

ACCESS HAS THREE PARTS
  1. 01

    Who

    The member and their assigned role

  2. 02

    Where

    The business or location they can access

  3. 03

    What

    The areas and actions they are permitted to use

ACCESS IN THE CLINIC WORKFLOW

Start with the person, location and task.

A job title alone should not decide what someone can see or change. Set the location assignment and permitted actions for the work that person performs.

01

Assigned business and location

Access is resolved from the user's current assignments. Group views limit operational records to the locations the person can access, and clinical requests check the relevant business scope.

  • Current role and location assignments
  • Viewing and management levels by area
  • Access can be changed when responsibilities change
02

Separate clinical permissions

Reading clinical records and editing diagnosis, prescription and lab sections are controlled separately. The saved clinical entry identifies its author and last update.

  • Permission to read clinical records
  • Separate writes for each clinical section
  • Checks against the current record before saving

DIFFERENT VIEWS FOR DIFFERENT PURPOSES

Keep patient-facing and staff views distinct.

Reception, the consultation room, pharmacy and group oversight use different information. Review what each workspace exposes as part of the clinic setup.

A public queue display for the waiting room

The configured patient-facing display communicates queue ticket and room information. It is separate from the clinical notes and staff workspace used to manage the visit.

HQ summaries with a defined scope

Group operational views use selected record summaries and assigned locations. They do not automatically expose the full clinical chart across a group.

Staff control of patient conversations

Authorised team members can take over a conversation and pause Watson in that thread. Clinical questions and decisions should follow the clinic's care process, with the right person handling the response.

REVIEW BEFORE ONBOARDING

Make the data-handling details concrete.

Review the clinic's requirements with the processing terms and the actual setup, including the clinical records it will hold.

Clinical data scopeAgree for your clinic
Confirm the processing terms for consultation notes, prescriptions, lab entries, attachments and visit history, as well as the connected communication and payment records.
Hosting and connected providersReview the data path
The published DPA identifies the engine and database hosting in AWS Kuala Lumpur and names providers involved in processing outside Malaysia. Confirm which connections and data flows apply to the clinic's setup.
Retention, export and recoveryConfirm the operating details
Review the applicable retention and deletion terms, available export formats, backup coverage and recovery process for each clinic data type. Agree how the clinic retrieves historical records during a transition.
Access and incident contactsAssign responsibility
Name the people who manage staff access and data requests. Review the contact and escalation process for an access issue, data concern or service incident.

BEFORE YOUR DEMO

Your questions, answered.

Can all clinic staff read and edit clinical records?

No. Reading clinical records and editing diagnosis, prescriptions or lab sections require the relevant permissions within the assigned business or location. Review each role during setup and when staff responsibilities change.

Does an HQ view expose all patient notes?

The HQ records view uses selected operational summaries. Clinical access is separate and remains subject to business or location scope and the relevant permissions.

Where can we review Watson's published data-processing information?

The Privacy Policy explains personal-data handling, and the Data Processing Agreement sets out the published processing terms and sub-processor information. For this clinic offering, confirm the specific clinical-record data scope and operating details before onboarding.

Does Malaysian hosting mean all processing stays in Malaysia?

No. The published DPA identifies engine and database hosting in AWS Kuala Lumpur and also lists connected providers that process data outside Malaysia. The clinic should review the services and transfers that apply to its configured channels and workflows.

Can we review backup and export requirements before onboarding?

Yes. Bring the clinic's required data types, retention needs, export formats and recovery expectations to the review. These need to be confirmed against the specific setup and processing terms rather than inferred from a general security statement.

How should we handle patient information during the initial demo?

Use illustrative examples or a representative sample with identifying patient details removed. Agree the data scope, authorised access and secure transfer process before sharing real clinic records.

SEE IT IN YOUR CLINIC

Review the setup with the people responsible for your data.

Bring your clinic's access, data-handling and recovery requirements. We will map them to the current workflow and the details that need to be agreed.