Confidential Patient Access

Some patients should not
appear in every staff search.

Mark a patient as confidential and they become invisible to your team. No search result. No patient list. No before and after. Only the staff you authorise can see them at all.

VIP, celebrity and high-profile patients : invisible to most staff
Staff treated at their own clinic : hidden from colleagues
No locked file warning : the patient simply does not exist for others
Access controlled per staff member, not by role
Supports compliance for
HIPAA GDPR PHIPA Australia Privacy Act
Patient Search
Logged in as: Front Desk Staff
Confidential: ON
Search patients...
A
Anna B.
Last visit: 14 Aug 2026
R
Robert M.
Last visit: 09 Aug 2026
S
Sarah K.
Last visit: 02 Aug 2026
Confidential patients not shown for this account
3 patients visible · per staff permission Audit trail active
Admin view
4 patients incl. confidential
Not locked
Simply not there

Mark a patient as confidential and they become invisible to your team

Patient search puts privacy at risk in ways access control alone can’t stop. A staff member with normal access can type a well-known name into the search box and see if that person is your patient, even without opening the file. CureCast lets you make a patient invisible to everyone except the staff you choose.

Admin-Granted Access
Invisible, Not Locked
Staff Marks Patient
VIP & Celebrity Privacy
Per Staff Member
Still Logged in Audit Trail

Why Patient Search Puts VIP Privacy at Risk

Access control decides what staff may open. It does not stop curiosity.

A staff member with normal patient access can search your patient list. That’s the job. It also means they can type a well-known name into the search box and see whether that person is your patient.

They may never open the file. Seeing the name in a search result is already the disclosure you were trying to prevent.

This is the most common way high-profile patient privacy fails in a clinic. Not a hacker. Not a lost laptop. Someone on the team who was curious, and who had legitimate access to the patient list.

For a practice treating public figures, this is the risk that keeps an owner awake. One screenshot of a search result, and a patient who trusted you with their face is on social media.

How to restrict patient access to specific staff

Two layers, so only a handful of people ever see the patient.

 

1

The administrator grants confidential patient access

Only an administrator can give a staff member permission to work with confidential patients. This is a separate permission from ordinary patient access. Most of your team never receives it.

2

An authorised staff member marks the patient

Anyone holding that permission can open a patient file and mark that patient as confidential.

From that moment, the patient is visible only to staff who hold confidential patient access. For everyone else in the clinic, the patient does not appear in search, does not appear in patient lists, and does not appear in before-and-after galleries. The record isn't locked with a warning message. It's simply not there.

That distinction matters. A locked file tells a curious employee that something worth seeing exists. An invisible one tells them nothing.

What a confidential patient record looks like

Invisible, not just restricted. For staff without confidential patient access:

  • The patient does not appear in patient search
  • The patient does not appear in the patient list
  • The patient's photos do not appear in before-and-after collections
  • The patient's photos do not appear in procedure or condition galleries

For staff with confidential patient access, the patient works exactly as any other patient does. They search, open, compare, and manage the file normally.

There is no partial state. A staff member either sees the patient completely or does not see them at all.

VIP, celebrity, and staff patient privacy protection

Not only celebrities.

Public figures and celebrities

Actors, athletes, politicians, broadcasters, and anyone whose treatment would be newsworthy.

Your own staff as patients

When a team member is treated at the clinic where they work, their colleagues should not be able to browse their record. This is one of the most common privacy complaints inside healthcare organisations, and one of the easiest to prevent.

Patients known to your team

Family members of staff, local figures, and anyone whose privacy is at risk simply because your clinic is small and your town is smaller.

Patients who ask for privacy

Some patients request that their care be kept from all but a few people, for reasons they don't have to explain. Under HIPAA, individuals may request restrictions on the use and disclosure of their information. Confidential patient access gives you a way to honour that request in the system rather than only in a policy document.

Sensitive procedures

Any treatment a patient would not want discovered by someone who happens to work at your practice.

Who can mark a patient as confidential

Marking a patient confidential is itself a permission.

Not everyone can hide a patient. Only staff holding confidential patient access can mark or unmark one, and only an administrator can grant that permission in the first place. This permission is set per staff member, not attached to a broader role.

This keeps the decision with the people who should be making it. A clinic owner treating a public figure decides who in the practice needs to know. The receptionist does not get to decide, and neither does anyone else who was not given the permission.

See how staff permissions work →

Prior access after a patient is marked confidential

If a staff member viewed, downloaded, or shared a patient’s information before that patient was marked confidential, that activity remains in the audit trail exactly as recorded. Marking a patient confidential doesn’t rewrite history.

What changes is what happens next. Once the patient is marked confidential, a staff member without confidential patient access can no longer find or open that patient anywhere in CureCast, regardless of what they may have viewed before.

Confidential patient access is still logged

Confidential patients are recorded in the audit trail like any other patient. Views, downloads, and shares are logged against the staff account that performed them, the same way they are for any patient.

The difference is who can perform them at all. With ordinary access control, you review the log afterwards and discover someone looked. With confidential patient access, the people who shouldn’t look never had the patient in front of them to look at.

See how audit trails work →

HIPAA minimum necessary standard for a single patient

HIPAA’s minimum necessary standard expects staff access to patient information to be limited to what their role requires. UK and EU GDPR, and the Australian Privacy Principles all carry equivalent expectations of data minimization.

Most systems apply that idea at the level of a role. Confidential patient access applies it to an individual patient, which is where a high-profile privacy risk actually lives.
See how security compliance work →

What confidential patient access does not do

Confidential patient access controls what staff can see inside CureCast.

It does not prevent someone who is authorised from talking about a patient outside the clinic, and it does not control what happens to a photo after an authorised person downloads it. Restrict download and share permissions alongside it for the strongest protection.

It also does not replace your practice’s own confidentiality policies, staff training, or employment agreements. Treat it as the technical half of a wider approach.

Frequently asked Questions

What is a confidential patient in CureCast?

A patient marked as confidential is visible only to staff who hold confidential patient access. For every other staff member, the patient does not appear in search, in patient lists, or in before-and-after galleries.

Who can mark a patient as confidential?

Only a staff member who has been granted confidential patient access by an administrator. Ordinary patient access is not enough.

Can a patient be unmarked later?

Yes. Any staff member with confidential patient access can add or remove the confidential flag at the patient level.

Can other staff see that a confidential patient exists?

No. The patient does not appear in their search results or patient lists at all. There is no locked record or warning message that would reveal that a hidden patient exists.

Is this useful for celebrity or VIP patients?

Yes. It’s the reason most practices ask for it. A clinic treating a public figure can restrict that patient to the handful of people involved in their care, so the patient’s name never appears in anyone else’s search.

Can I use it for a staff member who is also a patient?

Yes. When someone on your team is treated at your clinic, marking them confidential keeps their record out of their colleagues’ view.

Do confidential patients appear in before-and-after galleries?

Not for staff without confidential patient access. Their photos are excluded from before-and-after collections and procedure galleries for those users.

Is confidential patient activity still recorded in the audit trail?

Yes. Access to confidential patients, including views, downloads, and shares, is logged in the same way as any other patient activity, attributed to the staff account that performed it.

Is the confidential patient permission set per staff member or by role?

Per staff member. An administrator grants it individually rather than assigning it to a broader role.

Plastic surgeon using CureCast photo management app during patient consultation

See How CureCast Fits Your Practice

Discuss how CureCast fits into your clinical photo workflow, from capturing and organizing patient photos to securely managing them across your practice.

 

Prefer email? [email protected]