Records request handling

Guides identity verification, lawful basis, timescales, and routing for records access requests.

49|11|Updated Jul 31, 2026
One-click install
npx skills add https://github.com/vstorm-co/agenticos --skill records-request-handling-vstorm-co
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: Records request handling
Source: https://github.com/vstorm-co/agenticos/tree/main/backend/app/core/catalog/skill_gallery/healthcare/records-request-handling
Command: npx skills add https://github.com/vstorm-co/agenticos --skill records-request-handling-vstorm-co

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Handling a request to access records is a legal process with a statutory clock, and mistakes like confirming a registration before identity is verified or making redaction decisions ad hoc create compliance risk. This Skill gives an agent a disciplined procedure for responding to records requests correctly. ## Core Features & Use Cases - Identity-first triage: Establishes who is asking, what they are entitled to, and requires proof of identity before confirming anything about a person. - Statutory timescale communication: States the applicable response period unprompted and clarifies that the clock starts when the request is complete, not when it arrived. - Escalation routing: Routes requests involving third-party information, deceased patients, children, or court orders to the records team instead of deciding them locally. - Use Case: A patient emails asking for their records. The agent verifies identity first, states the statutory response period, and routes the request without ever confirming registration details over the unverified email thread. ## Quick Start Use the records request handling skill to respond to this patient's request for access to their medical records.

Frequently Asked Questions about Records request handling

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I handle a patient records access request?▼

Establish three things first: who is asking, what they are entitled to, and proof of identity. Do not confirm that a person is even registered until identity is verified, then state the statutory response period that applies in your jurisdiction.

When does the response clock start for a records request?▼

The statutory response period starts from the date the request is complete, meaning when identity is verified, not when the email or letter first arrived. State this timescale to the requester unprompted.

Which records requests should be escalated to a records team?▼

Escalate any request involving third-party information, a deceased patient, a child, or a court order, with the reason attached. Redaction decisions are never made by the agent handling the initial request.

Can I confirm a patient's registration by email?▼

No. Never send a record, confirm a registration, or discuss content over an unverified channel, including replying inside an email thread whose sender has not been checked. Identity must be established before anything is confirmed.

What are the limitations of automated records request handling?▼

The procedure routes rather than decides: it cannot make redaction decisions or rule on complex cases involving third parties, children, or court orders. Those always go to the records team with the reason attached.