Provider Manual · Part VII

The patient chart — Chart Sharing

Records out of the practice without a fax machine: choose exactly what to disclose, send a password-protected link that expires, and keep an automatic accounting of every open, view and download.

9 sections~17 min read13 screenshots
VII
Part VII · continued

The patient chart — Chart Sharing

Records out of the practice without a fax machine: choose exactly what to disclose, send a password-protected link that expires, and keep an automatic accounting of every open, view and download.

7.18Chart Sharing

Send part of a chart to someone outside the practice

A cardiologist wants the last two visit notes. A lawyer has a signed authorization for a date range. A patient asks you to send their records to a new doctor. Chart Sharing does that without a fax machine and without attaching records to an email: you pick exactly what to send, the practice prepares each item as its own PDF, and the recipient opens them on a web page protected by an access code and an expiry date.

It lives in Patient Information under Care workflow, as the Chart Sharing tab. The tab opens on the shares already sent for this patient, newest first, with New share at the top right.

The Chart Sharing tab in Hero EMR Patient Information for Maria Garcia, with the sub-line Send selected parts of this chart to an outside recipient through a password-protected link that expires, a New share button at the top right, and five share rows each showing the recipient name, email, organization, a contents summary such as Clinical summary and 2 progress notes and 24 documents, who created it and when, and a status chip reading Sent, not yet opened, or Revoked, or Opened, last viewed 34m ago
Every share ever created for this patient, with its contents, its status, and when the link stops working.

Use Chart Sharing when

  • The records are going to a person or organization outside the practice — a specialist, an attorney, an insurer, a school, another clinic.
  • You want to send a defined set of items, not the whole chart.
  • You need a record of who opened what, and when.
  • The material is bigger than a fax cover sheet and a few pages.

Use something else when

  • The recipient is the patient. Their own records already live in the patient portal, permanently and for free.
  • The receiving office only accepts fax, or wants a one-page form. Send a fax instead.
  • You are making a referral. Order the referral — it carries its own letter and packet.
  • You are sending a letter or a completed form you are about to write. That is Forms & Letters.
Nothing leaves until everything is ready. The recipient is emailed only after every selected item has been turned into a PDF. They never land on a half-built page, and you never have to tell them to check back later.
7.19Who can share

The tab, the permission, and what each person may include

Sharing a chart is a disclosure of protected health information, so it is deliberately narrower than reading a chart. Two things are checked: whether you can open the tab at all, and — separately — which categories you are allowed to put in a share.

  1. Physicians and organization admins have it already. The Chart Sharing tab appears in Patient Information without anything being switched on.
  2. Staff need one permission. An admin grants Share chart records (records.share) from staff & assistants. It is marked sensitive, and it is part of the office-manager and owner presets — front desk, medical assistant and biller presets do not include it. Without it the tab is not in the list.
  3. You can only share what you can already see. A staff member gets a category only if they hold that category’s own read permission. Someone who cannot open lab results in the chart sees Lab results greyed out with a padlock and a line saying they do not have permission to share it. Physicians and admins get all nine categories.
  4. Every share names its author. The list row and the detail dialog both read Created by and your name. Revoking, extending and resetting the code are recorded under the name of whoever did them.
The permission is not a review step. Anyone holding it can send any part of a chart they can read, to any email address, without a second approval. Grant it the way you would grant a key to the records room.
7.20Create a share

Three steps: what, to whom, and confirm

New share opens a three-step dialog. You can move back and forth freely; nothing is created and nothing is sent until the last button on the third step.

Step 1 — What to share

  1. Entire chart is the top card, and it tells you the size. It reads like Everything you are able to share — 145 files across 9 categories. Consider whether the recipient needs all of it. It is there for the rare request that genuinely covers everything; the sentence under it is the hint that most requests do not.
  2. Otherwise work down the nine categories. Clinical summary, Progress notes, Documents & scans, Lab results, Imaging, Questionnaires, Prescriptions, Billing, Forms & letters. Each row carries a one-line description and a count. Ticking the row takes the whole category.
  3. Open a category to pick individual items. The chevron on the right expands the list. Each item shows what it is and a detail line — a note reads Progress Note with Apr 20, 2026 · Dr. Romero · Final · v5. Categories with more than a handful of items get a search box, and Select all / none works within the open category. A part-selected category shows a dash instead of a tick.
  4. Unsigned notes cannot be shared, and say so. A draft is listed greyed out with Not signed on its detail line and its checkbox disabled. A share is a legal disclosure of the record, and a draft is not the record yet — sign the visit first and it becomes selectable.
  5. The footer counts as you go. 17 files will be prepared updates on every tick, and Next stays disabled until you have chosen something.
Step 1 of 3, What to share, in the Hero EMR New share dialog: an Entire chart card reading Everything you are able to share, 145 files across 9 categories, a ticked Clinical summary row, and an expanded Progress notes category showing a search box, Select all slash none, a greyed-out Progress Note dated Jul 30, 2026, Dr. Johnson, Draft, v7, Not signed with its checkbox disabled, two ticked signed notes from April 2026, and a footer reading 3 files will be prepared
A part-selected category shows a dash. The greyed row is a draft — Not signed, so it cannot go out.

Step 2 — Recipient & access

  1. Name and email are the address. Organization is optional and appears on the share row later, which makes a list of shares much easier to read.
  2. Relationship and Purpose of disclosure are what the record will say you did. Relationship is Treating provider, Patient, Legal representative, Attorney, Insurer or Other. Purpose is Treatment, Payment, Health care operations, Patient request, Legal or Other, and the hint under it — Recorded in the patient’s disclosure log. — is literal. Choosing Other asks you to write the reason.
  3. The message is optional and travels in the link email. Plain text, up to a thousand characters. It is the place for “these are the two visits we discussed on the phone”. Never put the access code in it.
  4. Set how long the link lives. One, three, seven, fourteen, thirty, sixty or ninety days — seven by default. The line underneath resolves it to a date, The link stops working on Sep 6, 2026., in your practice’s time zone. Shorter is safer; you can always extend it later.
  5. Decide how the access code reaches them. Email the access code to the recipient in a separate message (recommended) sends it as its own email, so the link and the code never sit in one message. Show it to me once — I’ll give it to the recipient by phone or in person puts it on screen when the share is created and never again.
Step 2 of 3, Recipient and access, in the Hero EMR New share dialog, filled in with recipient name Dr. Marcus Webb, an email address, Organization Bay Area Cardiology, Relationship Treating provider, Purpose of disclosure Treatment with the hint Recorded in the patient's disclosure log, a message to the recipient, Link expires set to 7 days with the line The link stops working on Sep 6, 2026, and two access code delivery choices with Show it to me once selected
Relationship and purpose are not paperwork for its own sake — they are what the disclosure log will say.

Step 3 — Review & confirm

  1. Three cards restate the whole share. Contents lists each category with its count and the total files; Recipient repeats the name, email, relationship, organization and purpose; Access shows the expiry date and how the code is being delivered. Read the recipient’s email address here, out loud if it helps. It is the one mistake that cannot be taken back quietly.
  2. The confirmation is a real attestation. The yellow box states that the disclosure is permitted — for treatment, payment or health care operations, at the patient’s request, or under a signed authorization on file — and that you have limited it to the minimum necessary. Create secure share stays disabled until you tick I confirm this disclosure is permitted and limited to the minimum necessary.
Step 3 of 3, Review and confirm, in the Hero EMR New share dialog: a Contents card listing Clinical summary 1, Progress notes 2, Documents and scans 24, Lab results 26, Imaging 6, Questionnaires 4, Forms and letters 3 and the total 66 files will be prepared, a Recipient card, an Access card reading Link expires Sep 6, 2026, 7 days, a yellow HIPAA disclosure confirmation box with its ticked checkbox, and the Create secure share button
Last look before anything is created. The tick is required, and it is recorded with your name.
7.21Preparing & emails

What happens in the minutes after you press create

Creating the share does not send anything. It queues the work, and the dialog swaps to a Share created pane that tells you so: Preparing 66 files, and Dr. Marcus Webb will get the link by email as soon as everything is ready.

  1. Each selected item becomes its own PDF. A note renders as the note; a scanned document keeps its pages; a lab order, an imaging study, a prescription record or a visit’s billing becomes a clean printed page. Every page is stamped with the patient’s name and date of birth, the practice, and a confidentiality footer naming the recipient and the date.
  2. If you chose to be shown the code, this is the only time you will see it. It sits in a large block with a Copy button and the warning This is the only time the code is shown. Give it to the recipient by phone or in person — never in the same email as the link. Nobody can look it up afterwards, including you and including support. If you lose it, reset it (§ 7.22).
  3. Copy link works immediately. Useful when you are on the phone with the receiving office and want to read them the address while the files build.
  4. The recipient gets one email, or two. The link email — subject … has shared medical records with you — goes out when the last file is finished, and carries your message and the expiry date. With emailed delivery a second, separate email carries only the access code. Neither email ever contains both.
The Share created pane in Hero EMR, showing a green Preparing 66 files panel with the line the recipient will get the link by email as soon as everything is ready, a yellow Access code panel with the code in large monospace type, a Copy button and the warning that this is the only time the code is shown, the share link in a read-only field, and Copy link and Done buttons
The one-time code. Read it down the phone now, or reset it later — there is no third option.
Do not email the code yourself. Putting the link and the code in one message removes the entire point of the second factor: one forwarded email, or one mistyped address, and the records are open. If the recipient cannot take a phone call, choose emailed delivery and let the practice send the two messages separately.
7.22Manage a share

Statuses, and everything you can still do after sending

The tab list is the status board. While files are still building the row polls and updates on its own; the rest of the time the chip tells you where the share stands.

ChipWhat it meansWhat to do
Preparing 3 / 17Files are still being built. Nothing has been emailed.Wait. The row updates itself.
Sent · not yet openedThe emails went out; nobody has opened the link.If it has been a while, resend the link email or call.
Opened · last viewed 2h agoThe recipient unlocked it and has been reading.Nothing. The activity log has the detail.
FailedNothing could be prepared.Open the share and use Retry failed files.
ExpiredThe expiry date has passed; the link no longer opens.Extend it, or create a new share.
RevokedSomeone shut it off deliberately.Nothing — this is permanent.

Clicking a row opens the share detail, which is three stacked sections.

Access

  1. Copy next to the link gives you the address again at any time.
  2. Extend pushes the expiry out by 7, 14, 30 or 90 days from now — ninety days is the ceiling, always measured from today rather than added to the old date.
  3. Resend link email sends the link again to the same address. It does not resend the code, because the code is never stored anywhere it could be read back.
  4. Reset access code issues a new one and lets you choose delivery again. The previous code stops working immediately, and so does any session the recipient already had open.
  5. Revoke kills the link on the spot. It asks first, because it cannot be undone: the recipient sees the “no longer available” page from that second, and the prepared files are deleted seven days later. The share and its log stay in the chart for ever.
The Hero EMR Share detail dialog: an Access section with a green chip reading Opened, last viewed just now, the relationship, organization and purpose, the share link in a read-only field with a Copy button, the expiry date with an Extend by dropdown set to 7 days from now and an Extend button, the line Access code delivered manually by Nicholas Romero, and Resend link email, Reset access code and Revoke buttons, above a Contents section reading 47 of 66 files ready with Retry failed files and Download all buttons
Everything you can still change about a share you have already sent.

Contents

  1. Each file shows its state. Ready · 34 KB · 1 page, or a red line explaining exactly why one failed.
  2. Preview opens the finished PDF as the recipient will see it, stamps and all. Use it to check you sent what you meant to send.
  3. Retry failed files queues just the failed ones again, once the underlying problem is fixed.
  4. Download all (ZIP) gives you the same bundle the recipient can download, for your own records.
The Contents section of the Hero EMR Share detail dialog showing a Documents and scans group where three rows carry a green Ready chip with size and page count and a Preview link, and several rows carry a red message reading Failed, the original file is in archived storage, restore it from cold storage, then retry
A failed file names its own cause. Everything else still went out.
One bad file does not sink the share. If some items are ready and some failed, the recipient is emailed anyway and sees the ready ones; the failures show on their page as Not available. Fix them and retry, and they appear without you having to send a second link.
7.23Activity log

The accounting of disclosures, written for you

HIPAA gives a patient the right to ask who their records went to. The Activity section at the foot of the share detail is that answer, kept automatically: Every open, unlock, view and download, for accounting of disclosures.

  1. It starts at creation and never stops. Created by you, then the files finishing, then each email going out, then everything the recipient does — Link opened with the IP address it came from, Wrong access code (1 of 5), Access code accepted, Viewed Progress Note, Downloaded all files.
  2. Your own later actions are in it too. Extending the expiry, resetting the code, retrying files and revoking the share are each logged with the name of the person who did it.
  3. Every line is stamped in your practice’s time zone, so the log reads the same for everyone in the office regardless of where they are sitting.
  4. The log outlives the files. Revoking a share or letting it expire removes the prepared PDFs a week later. The share, its contents list and this log stay in the patient’s chart permanently.
The Activity section of the Hero EMR Share detail dialog, sub-titled Every open, unlock, view and download, for accounting of disclosures, listing newest first: Viewed Progress Note, Access code accepted, Wrong access code 1 of 5, Link opened with an IP address, Link email sent to the recipient, Files prepared, and Created by Nicholas Romero, each with a date and time
Newest first. A wrong-code attempt is logged as carefully as a successful one.
This is the page to open when a patient asks. It answers “who did you send my records to, what was in it, and did they look at it” without anyone having to reconstruct it from memory or a fax confirmation sheet.
7.24What the recipient sees

Two emails, a code, and a page of files

Knowing the recipient’s side is most of what you need to answer their phone call. They never sign in, never create an account, and never install anything.

  1. The link opens a locked page. Your practice’s name and logo, Secure medical records from …, who shared them, one field, and Open records. The hint reads Enter the 12-character code the practice sent you separately. and the foot of the page carries your phone number under Didn’t get a code?
  2. The code is forgiving about format, strict about tries. It formats itself as they type and case does not matter. A wrong one says That code isn’t right. 4 attempts left. Five wrong tries locks the page for fifteen minutes; the lockout clears itself, and a Reset access code from your side clears it at once.
  3. Unlocked, they get a list, not a download dump. The patient’s name and date of birth, who shared it and when, a chip with the expiry date, your message, and the files grouped under the same category headings you picked them from. Each row has View and Download, and Download all (ZIP) sits above the list with its size and file count.
  4. View opens the file beside the list. On a wide screen the PDF fills a pane on the right and they can keep clicking down the list; on a phone or tablet it opens full screen or in a new tab.
  5. The page tells them the rules. A confidentiality notice at the foot states that the records are for the named recipient and the stated purpose, that re-disclosure is prohibited, and what to do if they received it in error — with your phone number beside it.
The locked Hero EMR chart-share page as an outside recipient sees it: a padlock icon, the heading Secure medical records from Dr. Romero's Practice, the line Shared by Nicholas Romero, an Access code field hinting Enter the 12-character code the practice sent you separately with an XXXX-XXXX-XXXX placeholder, an Open records button, and a footer reading Didn't get a code? Contact the practice at its phone number
The link alone opens nothing. This is what the second email — or your phone call — is for.
The same locked Hero EMR chart-share page after a wrong code, showing the entered code in the field and a red message reading That code isn't right. 4 attempts left.
The count down is deliberate. After five, the page stops accepting tries for fifteen minutes.
The unlocked Hero EMR chart-share page showing Maria Garcia with her date of birth, the line Shared by Nicholas Romero, MD, Dr. Romero's Practice, a chip reading Link expires Sep 6, 2026, the sender's message in a green quote box, a Download all ZIP button with size and file count, and files grouped under Clinical summary, Progress notes and Documents and scans with View and Download buttons, and two rows marked Not available with the note This file couldn't be prepared
The same category headings you chose from, in the same order. Failed items are visible and labelled, not hidden.
The unlocked Hero EMR chart-share page with a progress note open in a PDF pane on the right, titled Progress Note with a close button, showing the rendered note stamped with the practice name and the patient header, while the file list stays usable on the left with the opened row highlighted
View keeps the list in reach, so the recipient can read straight down a visit.
The Hero EMR chart-share page for a revoked link, showing the heading This link is no longer available and the line If you still need these records, contact Dr. Romero's Practice
Expired, revoked, or simply wrong — the page never says which, and never names the patient.
7.25HIPAA guidance

Four habits that keep a share defensible

  1. Send the minimum necessary. “Entire chart” is almost never what a cardiologist needs, and it is the hardest choice to defend later. Ask what the request is actually for, then pick the categories — or the individual items — that answer it. The one exception the rule itself carves out is a disclosure to another provider for treatment; even then, a targeted share is easier for them to read.
  2. Choose the purpose honestly. The purpose you pick is written into the disclosure log, and the log is what the practice would produce if the patient or a regulator asked. Records for an attorney are Legal, not Treatment, even when a clinician is the one sending them.
  3. Never let the link and the code travel together. Two channels is the whole design. Emailed delivery keeps them in two messages; manual delivery keeps the code off email entirely. Pasting the code into the message field, or into a follow-up email, collapses it back into one.
  4. Revoke the moment something looks wrong. A mistyped address, a request that turns out not to be authorized, a recipient who says they never asked — revoke first and sort it out afterwards. Revoking is instant, it kills any session the recipient has open, and the log records who did it and when.
An access code is not consent. Chart Sharing makes a disclosure safe to transmit; it does not make it permitted. Treatment, payment, health care operations, the patient’s own request, or a signed authorization on file — if the request does not fit one of those, the answer is to get the authorization, not to shorten the expiry.
7.26Troubleshooting

The four calls you will actually get

What you see or hearWhat it meansWhat to do
Failed: The original file is in archived storage. An older scan or photo has been moved to cold storage and cannot be read straight away. Restore the original from the Media tab, then Retry failed files on the share. Everything else has already gone out.
“It says the link is no longer available.” The share has expired or been revoked — the page deliberately does not say which. Check the chip on the row. If it expired, Extend and resend the link email. If it was revoked, that is permanent: create a new share.
“It stopped letting me try the code.” Five wrong attempts locked the page for fifteen minutes. Wait it out, or use Reset access code — it clears the lockout and issues a new code at the same time.
“I never got the email.” Filtered, mistyped, or the files were not finished yet. Check the address in the detail dialog, look at the activity log for Link email sent, then Resend link email. If the address is wrong, revoke and start again — the address cannot be edited.
A draft that ought to be shareable. If a note you expected to pick is greyed out as Not signed, it is still a draft, or a newer unsigned version has replaced the one you remember. Sign it, reopen New share, and it will be in the list. Notes signed after a share was created are not added to it retroactively — that needs a new share.

Need help? Email support@heroemr.com.