Integrations & data · Practice guide

Review who can see information when reports are combined

Illustrative situation

Two individually limited reports become more revealing when an integration joins their data into one export. Joining information can reveal more than either source showed on its own. Review the finished report and download with the people responsible for information access, rather than inheriting assumptions from the original tools.

Healthcare booking calendars on two connected screens with blue and orange appointment cards.
Make the handover between tools clear for the team using them.

What this means for your practice

Review the combined output and its audience through the organisation's information-governance process. Permissions on source systems do not automatically define suitable access to every derived report.

An example to discuss with your team

Open the combined fictional report as a staff role with limited access, then check its detailed views and download options.

Healthcare data integration connecting two applications through a field-mapping board.
Agree what each field means and which system owns it.
Healthcare data validation separating matched records from an exception tray.
Make rejected or uncertain records visible for review.

Questions to take to your supplier

Open a fictional combined report as a limited role and inspect the export. Is every field needed for that audience's purpose? Agree an owner and review access whenever the report's scope changes. The practical question is what the reader can actually see and use.

Agree the working process

Review the complete set of combined fields and the purpose of the report with the organisation's responsible information owners. A reader may learn more from the combination than from either original screen, so source access alone should not settle the decision. Define who needs the summary, who may open detailed records and who may export information. Ask the supplier to demonstrate those different views with fictional data and test roles. Include filters, downloads and saved links, not just the first page.

Keep a named owner for the report and a review trigger when new fields, sources or audiences are added. A report that was appropriate for one management purpose may need reassessment when reused elsewhere. Make the intended use understandable to recipients so they do not treat a convenient export as a general-purpose information list. During access reviews, include derived reports in the inventory rather than checking only the systems from which their information originally came.

How to check the result

Count derived reports without a documented audience and owner.

Turn reading into a next step

Your action checklist

Work through these checks with your team or supplier. Tick the ones you have resolved and leave unknowns open.

Checks to discuss

Record what you know, what is still missing and the answer you need from your team or supplier.

Use project decisions only, without personal, patient or confidential details. Entries stay in this page and are not submitted to Kay & Co. Copy or download before leaving; this page does not save your notes.

Further reading

These sources provide background for the topic. The practice examples and checklist are illustrative planning suggestions from Kay & Co.

Related guides

Need help with this?

Tell us what is getting in the way. Kay & Co. can help you understand the options and turn the next step into something that works for your practice.

Explore integrations & data services or discuss your project.

Try the free Healthcare Digital Planner to find your starting priority.