Case Notes Services
Authentication Service
Case Notes’ Authentication Service provides the user identity, role, team membership and passwords to the Case Notes base system and modules.
Initially, the Authorisation Service is used to log the user onto Case Notes by checking login details against the recorded ID and password and to confirm additional levels of authorisation, such as SmartCards or Biometrics.
During system use, it provides information to the Access Control Framework (ACF) and the Resource Permissions Manager (RPM) within Case Notes. These control access to data, resources and modules, controlling and tracking user and system access. This includes the access control of administrative and clinical user roles to organisational data, patient details, episodes and events within an individual health record.
Authorisation can originate from an internal or external service. External services will usually be regional or national and will cross multiple organisations. The request to the internal or external service is managed by the Enterprise Services module (ESM). With the advanced version of the ESM, Case Notes also provides the ability to switch between external and internal Authentication as required.
Through system administration options, the Authentication Service allows users to be added or their details edited. The service identifies de-synchronisation of a patient’s internal and external demographic details and supports correction of the user record.
- Features
- Provides authentication information to Case Notes
- Supports Relationship Management
- Works with internal or external authentication sources
- Generic interface with external configurable adaptors for specific requirements or portals
- Connected external or disconnected internal operation, with the ability to switch between the two a required
- Real-time caching of external user data
- Proven in the UK NHS Care Records Service (NCRS) or 'Spine' and in many other implementations in the NHS
- Benefits
- Secure - supports full access control to appropriate functions and patient data
- Protects patient confidentiality
- Maintains correct user details
- Supports local security or external security services if required
- Supports common policy across multiple organisations
- Provides on-line access using caching during periods of off-line operation

