# How patient privacy works

> Velarya splits a patient's record into separate permissions: contact details, clinical records, comments, wallet, cards and files each have their own. Names can be shortened by role, medical history, visit notes and chart answers are encrypted, and every recorded access to a patient's record, including refused attempts, appears in their Access history.

- Source: https://velarya.com/help/how-patient-privacy-works
- Who can do this: Roles are changed in Roles & Permissions (Roles & permission builder at manage). Access history and the Audit Log need HIPAA audit trail viewer (Admins by default)
- Plans: Basic, Scale, Branded, Connected
- Time: 4 minute read
- Last verified: 2026-09-29

## What is patient privacy in Velarya?

Patient privacy in Velarya is the set of controls that decide which of your staff see which parts of a patient's record, and the record kept each time they look. It rests on five things:

- **Separate permissions.** Contact details, clinical records, comments, wallet, cards on file and files each have their own permission, so a role gets the parts its work needs.
- **Name visibility.** A role can show patients' full names, the first name and the initial of the surname, or the first name alone.
- **Charts for the treating team.** Providers open the charts, forms, visit notes and clinical photos from their own appointments with a patient.
- **Encryption.** Medical history, visit notes, chart and form answers and chart review comments are encrypted field by field.
- **A record of each access.** Each time someone opens or changes a patient's information, or is refused, Velarya records who, what and when, and shows it in the patient's **Access history**.

## Who can see what?

Velarya gives each role a level on each patient permission in **Roles & Permissions**, most of them in the **Clients** and **Clinical & Charting** groups. The four system roles come with these levels, written as the grid shows them; None means the role does not hold that permission.

| Permission | What it opens | Admin | Location Manager | Front Desk | Service Provider |
|---|---|---|---|---|---|
| **Client personal info** | Profiles, contact details, tags, the Client Note and the scheduling alert; **edit** changes them | edit | edit | edit | view |
| **Client name visibility** | How much of each name shows | full | full | full | full |
| **Client notes** | History comments; **edit** writes them | edit | edit | view | edit |
| **Wallet, points & credits** | Wallet and points balances; **adjust** changes them | adjust | adjust | view | None |
| **Cards on file** | Saved cards; **add** and **remove** | remove | add | add | None |
| **Client documents & photos** | The **Files** tab; **add** and **remove** | remove | add | view | view |
| **Clinical details (sex at birth, meds, allergies)** | Medical history and the medical alerts list; **edit** adds and changes medical alerts | edit | view | None | view |
| **Clinical charts & forms** | Charts, forms, visit notes and clinical photos | edit | view | None | edit |
| **Export client lists** | **Export** on the Clients list | On | Off | Off | Off |
| **Merge duplicate clients** | **Merge** on the Clients list | On | Off | Off | Off |
| **HIPAA audit trail viewer** | **Access history** and the **Audit Log** | view | None | None | None |

![Front Desk role permissions, Clients group: Client personal info edit, name visibility full, Client notes view outlined](https://velarya.com/assets/help/how-patient-privacy-works/roles-front-desk-clients-a4d25e11.webp)

A few rules sit on top of the levels:

- **Service Providers open every patient's profile.** That includes contact details, the Client Note, comments, the medical history and medical alerts on the **Clinical** tab, and the **Files** tab. The appointments they see on a profile are the ones booked with them.
- **Charts follow the treating team.** Charts, forms, visit notes and clinical photos open for a Service Provider when they come from the provider's own appointments with the patient or belong to no visit, and for staff limited to some locations when the patient has a visit at one of those locations. For anyone else they show as restricted. Medical history, medical alerts and files follow **Clinical details (sex at birth, meds, allergies)** and **Client documents & photos** alone.
- **Medical alerts are for the whole team.** They show on the **Alerts** banner at the top of the profile to everyone who opens it, so the whole team sees a safety flag.
- **A permission a role lacks is left out.** Without **Client notes**, a staff member sees no comments; without **Wallet, points & credits**, no balances, on the profile or the Clients list.

What those clinical records are, and how sign-off works, is in [How forms and charts work](https://velarya.com/help/how-forms-and-charts-work). What each clinical permission lets staff do is in [Chart a visit: notes, charts and photos](https://velarya.com/help/chart-a-visit) and [Record a patient's medical history and files](https://velarya.com/help/record-medical-history-and-files).

System roles are locked. To change what a role can do, duplicate it and edit the copy, as [Loyalty roles and permissions](https://velarya.com/help/loyalty-roles-and-permissions) shows step by step.

## How does name visibility work?

**Client name visibility** in Velarya sets how much of a patient's name a role sees, for limited roles such as a trainee or a temporary helper at the front desk. It has three levels, and the system roles and every new role start at **full**.

| Level | A patient named Avery Lin shows as |
|---|---|
| **full** | Avery Lin |
| **first initial** | Avery L. |
| **first only** | Avery |

![Role permission grid row for Client name visibility with first only, first initial and full, first initial selected](https://velarya.com/assets/help/how-patient-privacy-works/name-visibility-tiers-f8f31757.webp)

The level applies wherever the dashboard names a patient, including the Clients list, profiles and their dialogs, the **Calendar**, **Front Desk**, **Transactions** and its export, the waitlist and the loyalty logs. Email addresses and phone numbers follow **Client personal info**, whatever the name level.

## How do I see who opened a patient's record?

**Access history** in Velarya lists every recorded access to one patient's record, newest first, including refused attempts. It covers their profile, contact details, comments, wallet, charts and forms, visit notes, photos, files and medical alerts, and the patient's own form submissions and signatures.

1. Select **Clients** in the left sidebar and select the patient.
2. Select **More actions** > **Access history**. The item shows to roles with **HIPAA audit trail viewer**, which Admins hold by default.

![More actions menu on a patient's profile with Access history outlined, below Edit client details and Set scheduling alert](https://velarya.com/assets/help/how-patient-privacy-works/access-history-menu-af41a8a7.webp)

3. Read each row: who, when and what they did. A refused attempt is marked as denied.
4. Select **Load more** at the bottom for older entries.

![Access history dialog listing who opened Avery Lin's record and when, with the action labels blurred](https://velarya.com/assets/help/how-patient-privacy-works/access-history-dialog-2bfd28f6.webp)

A Velarya support person working in your account shows with their first name followed by "Velarya Support". Opening **Access history** is recorded too, so the list also shows who checked it.

## Where is the practice-wide audit log?

The **Audit Log** in Velarya lists every recorded event in your practice, not just one patient's: sign-ins, refused permissions, patient views and changes, appointment and order changes, refunds and settings changes. Open **Organization settings** > **Audit Log**, under **Compliance & Billing**. Choose an action in the filter, such as **Client View**, **Client Update** or **Permission Denied**, to narrow it, and select **Load More** for older events. The **Audit Log** needs **HIPAA audit trail viewer** too.

## What do patients see?

In the patient app, patients see their own record and nobody else's. Comments, the Client Note, tags, alerts and the audit trail never appear there. Push notifications and texts name what happened on the patient's account, never the treatment or an amount, because anyone near the phone can read them. Each patient chooses their own channels, as [Manage patients' text consent and opt-outs](https://velarya.com/help/manage-text-consent-and-opt-outs) explains.

## What you can change

| Setting | Where | Default | What it does |
|---|---|---|---|
| A role's permission levels | **Organization settings** > **Roles & Permissions** | The system roles above, locked | A copy or a custom role takes any level up to your own |
| **Client name visibility** | The role's permission grid | **full** on the system roles and new roles | Shortens patient names for that role |
| **HIPAA audit trail viewer** | The role's permission grid | Admins | Opens **Access history** and the **Audit Log** |
| **Export client lists** | The role's permission grid | Admins | Shows **Export** on the Clients list |
| A staff member's role | **Organization settings** > **Staff Directory** | Chosen for each staff member | Gives them that role's permissions at every location they work at |

## Where to find patient privacy settings

Roles live in **Organization settings** > **Roles & Permissions**, under **Staff**. One patient's **Access history** is in **More actions** on their profile, and the practice-wide log is **Organization settings** > **Audit Log**. For where each kind of note lives and who sees it, see [Add notes, tags and alerts to a patient](https://velarya.com/help/add-notes-tags-and-alerts).

## Frequently asked questions

### Does Velarya sign a Business Associate Agreement?

Yes. Velarya signs a Business Associate Agreement with every practice, on every plan. In the product, medical history, visit notes, chart and form answers and chart review comments are encrypted field by field, each kind of patient information sits behind its own permission, and the HIPAA audit trail viewer permission opens the record of each recorded access to a patient's information.

### Can the Front Desk role see a patient's medical history?

Not with the system Front Desk role, which holds no Clinical details or charts permission. Front Desk staff see contact details, appointments, tags, the Client Note, comments, wallet balances, saved cards, the Files tab and the Alerts banner, which includes medical alerts so the whole team knows about a safety flag. To let a front desk lead read medical history, duplicate the role and set Clinical details (sex at birth, meds, allergies) to view on the copy.

### Can a Service Provider see every patient?

Yes, every patient's profile, since patients move between providers: contact details, the Client Note, comments, the medical history on the Clinical tab and the Files tab. The appointment list shows the appointments booked with them. Charts, forms, visit notes and clinical photos open from that provider's own appointments with the patient, and those linked to no visit. Each profile a provider opens, and each clinical record they are refused, appears in that patient's Access history.

### Are exports of the patient list recorded?

Yes. Export on the Clients list shows to Admins and to roles with Export client lists turned on, and each export is recorded in Organization settings > Audit Log with who ran it and when. Merging duplicate patients sits behind its own permission, Merge duplicate clients, which Admins hold by default and other roles receive when an Admin turns it on.

### Can Velarya support staff see my patients?

Yes, when a Velarya support person works in your account. Everything they open is recorded under their own first name followed by Velarya Support, in the patient's Access history and in your Audit Log, so your records never show it as one of your staff. A support session ends by itself after 30 minutes.
