Sharing patient records and referrals securely

Clinical documents move constantly between practices, specialists, insurers, and patients. The recipients are rarely on the same system, and patients in particular will not create an account to read one result.

Controls that fit clinical workflow

The requirement is narrow access for a specific purpose, with a record of who saw what.

  • Email verification so a record reaches only the intended recipient.
  • Short expiry windows matched to the episode of care.
  • A complete access log for each document.
  • Instant revocation if a document is sent in error.
  • No account required, which matters most for patients.

On compliance claims

Be careful with any vendor that markets compliance as a property of their software. Regulations like HIPAA govern how an organization operates, not merely which tools it buys — controls, agreements, and processes all sit on your side of the line.

What a tool can honestly provide is the mechanism: encryption in transit and at rest, access limits, verified recipients, revocation, and an audit trail you can produce. Capsule provides those. Whether your overall handling meets a given regulation depends on your practices, and you should confirm that with your own counsel or compliance officer.

Optional end-to-end encryption

For particularly sensitive records, end-to-end encryption can be enabled per share: the document is encrypted in the browser and the key never reaches our servers. The trade is that no preview, search, or recovery is possible for that share — which for some records is exactly the point.

Common questions

Can patients open a secure document without an account?
Yes. A patient clicks the link and, for sensitive records, verifies their email address with a one-time code. No account or app is required.
Is Capsule HIPAA compliant?
Compliance is a property of how an organization operates, not of software alone. Capsule provides encryption in transit and at rest, access controls, verified recipients, revocation, and a full audit trail. Whether your use meets HIPAA depends on your own policies and agreements, which you should confirm with your compliance advisor.
What happens if a record is sent to the wrong person?
Revoke the link immediately; access is refused from that point, including for someone who has already opened it. The access log shows whether it was opened before revocation.

Related