Provider Manual · Part XIV

The patient portal

The patient's side of Hero EMR — and what staff need to support it: the portal tour, getting patients registered, sign-in help, booking, messaging, payments, records, letting family and caregivers help, and choosing what parents and guardians of teens see.

9 sections~31 min read7 screenshots
XIV
Part XIV

The patient portal

The patient's side of Hero EMR — and what staff need to support it: the portal tour, getting patients registered, sign-in help, booking, messaging, payments, records, letting family and caregivers help, and choosing what parents and guardians of teens see.

14.1Portal tour

Tour the portal: what your patients see

The patient portal is the patient-facing companion to Hero EMR — a separate site where your patients book and manage visits, message the care team, pay bills, complete pre-visit paperwork, and read their records. It carries your practice’s logo, colors, and name (set under Portal branding), so to patients it looks like your portal. The desktop navigation runs across the top, with a Schedule Visit button on the right and an avatar menu holding Sign Out, Notifications, Payments & Billing, and Profile.

Home Health Record Messages Appointments Letters & Forms Payments & Billing Profile
  1. Home greets and orients. The patient lands on Welcome back, their first name, with two calls to action: Schedule appointment and Message care team. Once a visit is booked, a Next visit card shows the date and time in your practice’s time zone (with the patient’s local time labelled when it differs), the provider, and either the office location or Virtual visit · join from this portal.
  2. Tasks surface themselves. Below the hero sit a pre-visit checklist for the next appointment’s questionnaires and paperwork, a forms-to-sign card for practice-sent agreements (2 forms from your care team to sign), a questionnaires-to-complete card beside it for questionnaires sent without an appointment (1 questionnaire from your care team to complete), Follow-ups to schedule with per-item Schedule now buttons, and Quick actions (Schedule Appointment, Manage Prescriptions, Health History, Letters & Forms). While pre-visit work is pending, an amber banner counts the remaining tasks with a View All link.
  3. Profile holds the patient’s own record-keeping. The Profile page is tabbed: Personal Info, Allergies, Medications, Health History, Pharmacy, Guarantor, Insurance, and Settings. Three of those come and go: Health History shows only when your practice collects a history category this patient is allowed to answer, Insurance only when insurance self-service is enabled, and an extra Complete Setup tab sits just before Settings while any orientation step is unfinished. Billing is no longer a Profile tab — it has its own page (see Portal payments), and old ?tab=billing links redirect there. Personal Info autosaves as the patient types; the address ZIP code is validated on the spot — both here and during registration, only a 5-digit ZIP or 9-digit ZIP+4 is accepted (typos like a 4-digit ZIP are flagged immediately), which keeps the chart address clean enough to bill from. On first sign-in an orientation wizard walks up to seven setup steps — allergies, medications, health history, pharmacy, guarantor, insurance, billing — with health history, insurance, and billing dropping out when your practice hasn’t enabled them; if the patient skips it, Home shows a Complete your patient profile reminder with a Go to profile button — handy when you ask a patient to finish intake before a visit.
  4. One login can manage a family. A single account can hold multiple patient profiles; a patient selector appears in the header when there’s more than one. Under Profile Settings, a Family section offers Add Myself and Add Child (which creates a minor profile). When a parent acts for a child, Home is labelled Proxied by the account name. Adults can also let family or a caregiver help with their own portal — see Family & caregiver access.
Patient portal home page at mobile width showing the welcome header for a signed-in patient and the main dashboard cards
The portal home page — welcome header, next-visit snapshot, and task cards. Empty sections hide themselves, so two patients can see quite different home pages.
About those badges: the amber count on Messages tallies follow-ups awaiting scheduling, not unread mail — which is why it can persist after a patient has read everything. The Appointments badge counts pending pre-visit tasks. Payments & Billing carries a red ! rather than a count — it means the patient has a past-due balance. The pre-visit checklist itself is driven by your questionnaire assignments — see the patient experience of paperwork.
Your practice can switch whole portal sections off. Ten organization-level portal features — messaging, self-scheduling, billing & payments, insurance self-service, health records, letters & forms, medication refills, document upload, caregiver sharing, and family access requests — ship switched on, but any of them can be turned off for the whole organization. Turning one off removes everything attached to it at once: the top navigation tab (desktop and mobile), the matching Quick actions shortcut on Home, the matching Profile tab, and the matching orientation step — and switching off self-scheduling also hides the Schedule Visit button. Check what your practice actually has enabled before telling a patient to “go to the Messages tab”; on some practices it isn’t there.
14.2Invitations & registration

How a patient gets registered

Patients can’t self-enroll in the portal — access starts with an invitation your practice sends from the admin-only Patient Registration workspace. The staff-side mechanics (status pills, the invite dialog, delivery channels, teen account modes) are documented in Patient registration; this section follows what the patient experiences from the moment the link arrives.

  1. The link arrives. The patient receives the signup link by email, by text, or directly from your staff — the invite dialog can generate a Portal signup link with a Copy button for handing over in person. Invitations expire in 30 days; after that, staff use Resend invite.
  2. They verify identity on Complete Signup. The link opens the portal’s signup page with the patient’s name shown read-only. They confirm their Date of Birth, then create credentials — an email and password, or Continue with Google / Continue with Apple.
  3. They walk the registration steps. Registration collects insurance and personal details (teen flows add a parent step), then a review, and lands on a success screen showing their Medical Record Number and a What’s Next? list. From there the orientation wizard in the portal tour takes over.
  4. Abandoned signups can resume. A patient who created a login but stopped partway is routed to a resume-registration screen on their next sign-in — or staff can simply resend the invite.
The admin Patient Registration workspace listing patients with their portal access status, where invitations are sent and resent
The staff side of the story: invitations are sent, resent, and tracked from Admin → Patient Registration.
Two prerequisites and one gotcha: invite delivery channels stay greyed out until email and SMS providers are configured under External providers (see also SMS setup). And the signup link is bound to the email address typed in the invite dialog — which may differ from the chart email — so confirm it with the patient before sending.
Registration can hand the patient their intake packet: a questionnaire rule set to At patient registration and a paperwork template with Assign and send reminder at patient registration both fire the moment the portal account is attached to the chart — no appointment required. About fifteen seconds later the patient gets one message naming your practice and listing everything waiting, and the items sit on the portal home under the forms-to-sign and questionnaires-to-complete cards. Set them up in questionnaire rules and paperwork scoping.
Teen patients: for patients in your practice’s configured teen age band, who signs in — and who signs forms — depends on the account mode chosen at invitation: in Parent-managed mode the parent does both; in Teen private mode the teen signs in and a parent or guardian email is collected separately for consent paperwork. Choosing or switching the mode is part of patient registration. What parents and guardians see of a minor’s visits that a clinician hid from them is a separate practice setting — see Teens & guardians.
14.3Sign-in & security

Passwords, passkeys, and verification codes

Portal sign-in is Email Address + Password + Sign In, with Continue with Google and Continue with Apple as alternatives. Depending on how your practice’s portal is configured, patients may also see passkey sign-in and a second-step verification code. Knowing the patient’s-eye view here is what lets your front desk troubleshoot “I can’t log in” calls quickly.

  1. Password recovery is self-service. The Forgot your password? link on the login page emails the patient a reset link. That emailed link is the only reset path — there is no staff-side button that sets or resets a patient’s password.
  2. Passkeys, where enabled. On practices with passkeys enabled, returning patients get an automatic prompt (Checking for your passkey… or start typing to sign in another way.) plus a manual Sign in with passkey button. Patients add or remove passkeys under Profile Settings → Passkeys (“Sign in faster with your face, fingerprint, or device PIN”), and a dismissible banner after sign-in offers Set up now. Browsers without passkey support show a “not supported” notice — don’t promise passkeys on every device.
  3. Verification codes, where required. Practices can require a second step at sign-in: the patient sees Check Your Email or Check Your Phone, enters a 6-digit Verification Code, and taps Verify and Continue. Helpers include Resend Code, Text me a code instead / Email me a code instead, and Use a Different Account. Where trusted devices are enabled, a checkbox offers: Trust this browser on this portal so you do not need an email code on every sign-in.
  4. Text-message codes are the patient’s choice. Under Profile Settings → Cell phone verification, the patient taps Add phone, verifies it with Send code → Verify, and controls the toggle Text me a code when I sign in (you can turn this off anytime). SMS verification is patient opt-in — never forced by the practice. Verified numbers list masked, with a Remove number action.
Patient says…What to do
“I forgot my password”Point them to Forgot your password? on the login page — the reset link arrives by email. Staff cannot reset it for them.
“My signup link doesn’t work”The invitation likely expired (30 days) or was never completed — use Resend invite in Patient Registration.
“It says an account already exists”They originally signed up with Google or Apple. Tell them to use the matching Continue with… button instead of a password.
“The code never arrives”Confirm the email on file matches what they’re typing, and have them try Resend Code or switch channels with Text me a code instead.
“I belong to two practices”That’s expected — after authenticating they pick a practice and tap Open Portal.
These are deployment settings, not Admin toggles. Passkey availability, the email-code requirement, and trusted devices are configured per practice as part of portal deployment — there is no switch for them in the Admin screens. If your practice wants to change sign-in behavior, raise it with Hero EMR support rather than hunting for a setting.
14.4Booking & visits

How patients book, change, and join appointments

Portal booking is self-service direct booking — when a patient confirms a slot, the visit is created on the physician’s calendar immediately, marked as coming from the patient portal. There is no approval step and no request queue to work. Confirmation email and your reminder policies fire automatically (see Notifications).

  1. Pick the visit, provider, and time. From Schedule Visit (or Home’s Schedule appointment), the patient toggles In-office visit or Remote visit, picks a Physician — grouped Seen before vs Other physicians — a Location for office visits, and a slot under Available Times on a month calendar. Only physicians and visit types you’ve enabled for online booking appear; a physician with no virtual offerings shows “This physician does not currently offer virtual visits.” A booking link your staff sent with Ask the patient to book opens this page with the provider and visit type already chosen and, when staff gave a date, the calendar on that date with the note “Your care team asked you to book on or after …”.
  2. See the cost up front. When visit billing policies apply, the confirm dialog states the money terms plainly — an amount required to hold the appointment, due before the visit, due at check-in, or billed afterward — or Your care team will confirm pricing before the appointment. If pricing changes mid-flow the patient must review and confirm again.
  3. Confirm. Confirm appointment (or Confirm reschedule) books the slot; on success the patient can Add appointment to Calendar (an .ics download) and Get Directions. A slot grabbed by someone else fails safely: This time slot is no longer available. Please select a different time.
  4. Manage everything from Appointments. An Action Needed panel lists pending questionnaires, the next appointment is featured with its pre-visit task list, later visits sit under Coming Up, and history under Past Visits. Cancelling shows a Cancel appointment? dialog with a refund/fee preview before Confirm cancellation; rescheduling reuses the scheduling screen.
  5. Join telehealth from the portal. Virtual visits show a Join video visit button that activates 15 minutes before the start time and stays open for about an hour after. If required pre-visit tasks are incomplete, the button reads Complete previsit to join instead. The clinician side of the video visit is covered in Run telehealth visits.
  6. Check in on arrival. For an in-office visit, the Your next visit card on Appointments shows Check-in opens at 9:30 AM ahead of time and a Check in button inside your check-in window; afterwards it reads Checked in ✓ with the time, and your front desk sees the patient arrive. Unfinished pre-visit tasks, or a required payment, come first. See Online check-in.
The patient portal schedule-a-visit flow where the patient picks a physician and an available time slot
Booking is direct: pick a provider, pick a slot, confirm — the visit lands straight on the calendar.
The patient portal Appointments list showing an upcoming visit
The Appointments tab manages what’s booked — pre-visit tasks, cancellations with a fee preview, and reschedules.
Two request-style flows do exist. Follow-up requests created at encounter completion appear to patients as Follow-ups to schedule cards with Schedule now links (see Schedule the follow-up), and waitlist offers appear on the Appointments tab under Active Waitlist with Claim this time / No thanks (see Waitlist).
Want gatekeeping? Shape the menu, not a queue. Since portal bookings confirm instantly, the way to control them is upstream: restrict which visit types are bookable online, set booking windows, and attach visit billing policies. Note that times display in the practice time zone with the patient’s local time as a secondary label — relevant for out-of-state telehealth patients.
14.5Portal messaging

Message the care team — and where it lands

Patients read and write secure messages under the portal’s Messages tab — Your Message Inbox, with a Search messages… box and a New Message button. Every message a patient sends arrives in your clinician Inbox, routed by category, so nothing depends on someone remembering to check a separate system.

  1. The patient composes with structure. New messages require a category — Clinical or Billing support — and a priority — Routine or Urgent / safety — plus a recipient chosen via the Select Physician picker. They enter a subject and message, can Add attachment, and hit Send.
  2. It lands in your Inbox by category. Clinical messages arrive in the Inbox’s Patient folder; billing questions arrive in Billing. Opening a thread shows the full Message History with linked-encounter context and a Your Response to Patient reply box with Send to Patient. Triage, forwarding, and reply mechanics live in Inbox threads; AI-drafted replies in AI responses.
  3. Patients tune their own alerts. Under the avatar’s Notifications page, patients control email, text, and push alerts (Messages from your care team, reminders, Quiet hours). Notification emails are alerts only — the portal reminds them “Full message details stay in your secure portal inbox.” — a privacy point patients often ask about.
Patient portal Messages page showing a secure message thread between the patient and the practice
The patient’s side: a secure thread with the practice, searchable and attachable.
The clinician Inbox in Patient view with a portal message thread open, showing the Message History, linked encounter context, and the Your Response to Patient reply box with an AI response chip and Send to Patient button
Your side: the same conversation in the Inbox Patient folder, with thread history and the Send to Patient reply box.
Urgent / safety is a triage flag, not an emergency channel. The portal is not monitored in real time — make sure your patient-facing materials say emergencies go to 911 or urgent care, not a portal message.
Two more nuances: follow-up scheduling reminders are injected at the top of the patient’s Messages screen — they’re scheduling tasks, not chat threads (and they’re what the nav badge counts). And if your practice runs membership-gated messaging, new clinical messages can be blocked by the membership policy — with the explanation shown inline — while billing-support messages still go through.
14.6Portal payments

How patients pay their bills

Patients reach billing three ways — the Payments & Billing tab in the top navigation, the Bills & payments row in Home’s Account → Billing & Insurance panel, or Payments & Billing in the avatar menu — and all three open the same page. It leads with the Account balance and a Pay balance button, a snapshot rail (past due, due soon, Open charges, “Secured by Stripe”), and a Transactions view split across Open / Pending / Paid tabs, with an Insurance tab alongside. This section covers the patient-side checkout only — staff-side balances, statements, and collections live in Patient AR.

  1. Pay a charge. Pay charge shows the Amount due and a Pay with choice between Saved card and Link or new card, plus an Express checkout row (Apple Pay, Google Pay, Link, or card) — all powered by Stripe. Charge details itemizes the Original charge, Paid so far, status, and provider so the patient can see exactly what they owe. A charge still with insurance reads With insurance · Nothing due yet rather than a $0.00 amount, and a bill reads Amount due until the patient has paid part of it. A share the primary insurer assigned to the patient while the visit’s secondary claim is still pending isn’t due yet and can’t be paid online while that claim is pending: its invoice reads Pending other insurance · $10.00 with no due date (the detail says Pending other insurance), and its charge card reads Waiting on {payer}. When that is all the patient has, the page reads “Nothing is due now. $10.00 is waiting on your other insurance.” and the action card Waiting on your other insurance — “$10.00 may be due after it processes your visit. Nothing to pay now.” A page left open from before is refused before any card is charged (“Nothing is due on this charge yet — it’s waiting on {payer}.”), and Print current statement / Save PDF lists the share as Pending other insurance, outside the total due. For a minor, what a parent or guardian sees on a billing line can also depend on the practice’s teen settings (Teens & guardians).
  2. Store a card for pre-visit billing. Add a card saves and authorizes a default card — this is the card your visit billing policies charge against for holds and pre-visit payments. The patient sees “Securely stored for next time.”
  3. Review history and statements. Lower on the page, Payment history collects payments, refunds, and in-progress billing updates automatically, and Statements keeps anything the practice has sent available for reference.
  4. Manage a membership, if your practice offers one. Practices with recurring plans get a Membership section with enrollment, Billing history, Invoices, payment-recovery prompts, and a Cancel membership flow that asks for a reason. The office can also text or email the patient an enrollment or payment link that opens this page (the patient signs in first). Plan setup and the staff-side view are owned by Memberships.
Stripe Connect is the prerequisite. Portal payments work once your practice completes Stripe setup; until then patients see Online payments are unavailable. The charges patients pay here are the ones produced by encounter charges and your billing policies. Trust messaging shown at checkout — “Encrypted · PCI-compliant via Stripe — This practice does not retain saved cards.” — is a useful line for your front desk to echo.
Refund expectations live in the cancel dialog. When a patient cancels a visit, the refund or fee preview appears in the Cancel appointment? dialog (see Booking & visits), not on the billing page — point patients there if they ask what cancelling will cost.
14.7Records & documents

Records, letters, and documents patients can access

The Health Record tab is the patient’s window into the chart. Everything here is downstream of clinician work: signed notes, patient instructions, and orders published by Sign & close, plus lab and imaging results released to the chart (see Results in the portal) and documents from the Media tab. The page organizes it all under pill tabs:

Past Appointments Lab Results Imaging Letters Media
  1. Browse the visit history. Past Appointments is a searchable Visit history. Opening a visit shows Patient instructions (“Care guidance from this visit”), the Visit note, the message exchange, Diagnoses, medications from the visit, and lab/imaging orders that deep-link to their own tabs. The instructions are the ones you drafted at encounter completion.
  2. Medications, as your team sees them. Profile > Medications lists Current medications and Past medications. Each medication shows its full product name, including the release type, for example “Bupropion XL 150 mg tablet” rather than just “Bupropion”. Current is everything in your Current, Scheduled and On hold groups plus everything in Needs review, because the patient may still be taking it. A prescription that ran out carries a Refill needed note. Anything else your team is reviewing carries Your care team is reviewing. The new-patient medication step and the pre-visit Review your medications check use the same grouping, labelled Current, Current · refill needed and Current · your care team is reviewing. How rows land in each group is explained in What counts as current. When your practice allows online refill requests, eligible rows carry a Request refill button, and a Refill requests section below the list shows each request’s status, your care team’s message, a Book a visit button when a visit is needed, and Cancel request while it is still pending — see What patients see.
  3. Pull in outside records. An Import Records button opens Import Medical Records, where the patient searches for their outside health system and connects via Epic to bring external records into the chart. Availability depends on the outside system supporting Epic patient access, so set expectations accordingly.
  4. Request letters and forms. Letters & Forms is the patient-initiated document desk. Request New Medical Form / Letter walks Visit → Type → (Dates) → Review, with types including Work Excuse Letter, School Excuse Letter, FMLA Form, Paid Leave Certification, Disability Form, Travel Medical Clearance, Accommodation Request, and Custom Form Upload (the patient uploads their own PDF). My Request History tracks submissions, and a How it works panel explains the flow.
  5. You approve; they download. Requests arrive in your clinician Inbox under Forms/Letters (see Inbox queues), where the physician reviews the generated PDF, can quick-edit corrections, and approves with their saved signature embedded — or rejects with a reason. Completed documents then appear to the patient under Letters & Forms and Health Record’s Letters tab with view and download actions.
The chart Letters tab listing seven letters including a WA Paid Leave Form, FMLA Letter, and Work Excuse Letter, each with Approval Status badges reading Pending Review or Approved and a View action
The same documents on your side of the fence: the chart’s Letters tab tracks each request’s Approval Status from Pending Review to Approved.
A saved signature is required for approval. The Inbox blocks form approval until the physician has a saved signature on file (“A saved signature is required before approval.”); with one saved, approving embeds it (“This signature will be embedded when you approve.”) — so set one up before the first request arrives. And patients only see documents once generated and approved; until then the Letters area shows an empty state.
Beyond the basics: questionnaires and pre-visit paperwork reach patients as tasks on Home and Appointments — authoring and assignment rules are covered in Questionnaires & paperwork. Practices with APCM enabled also expose an APCM Care Plan page (Goals, Interventions, billing history) reached from APCM surfaces on Home — it exists only when APCM is enabled for the practice (see APCM).
14.8Family & caregiver access

Sharing & caregivers: letting family help

A patient can let a spouse, adult child, friend or paid caregiver help with their care — and a parent can ask the practice to add another parent or guardian for a child. Everyone uses their own login: nobody shares a password, and access always covers one person’s chart at your practice. The patient-facing page is Sharing & caregivers, reached from the account menu and from Profile Settings → Family. For a minor, what parents and guardians see from visits a clinician hid is set separately, in Teens & guardians.

SituationWho starts itBefore access begins
An adult patient wants helpThe patient: Invite someone to helpThe patient confirms their sign-in and authorizes; the helper signs in with the invited email and accepts. No staff approval.
A parent wants another parent or guardian added for a childThe parent: Request parent or guardian accessYour staff verify the adult’s authority and approve in Access requests; the adult then accepts the invitation.
An adult can’t manage the portal themselvesYour staff: Portal access → Caregivers & helpersStaff record how the patient authorized it, or the representative’s proof of authority; the helper accepts.
  1. The patient invites a helper. Invite someone to help walks three short steps: who (name, the helper’s own email, relationship), access, and review. Appointments & messages is always included; Also let them see shared health records starts off and is the patient’s choice. Access lasts Until I remove access or Until a date. For security the portal may ask the patient to confirm their password or passkey before sending.
  2. The helper accepts. The email invitation expires after 7 days. The helper signs in — or creates an account — with exactly the invited email, reviews what was shared, confirms they are 18 or older, and taps Accept (or Decline). A helper with no chart of their own goes straight to the patient’s portal, with a Helping … label so it’s always clear whose portal is open.
  3. The patient stays in control. The patient sees Shared by you, pending invitations (with a separate email-delivery status), and anything Managed by your practice. Change access turns health records off immediately; turning them on sends the helper a request to accept. End sharing stops access on the helper’s next click. The patient gets a short email when a helper accepts, declines, changes or loses access. A helper can also choose Stop helping.
  4. Parents request; staff decide. On a child’s portal, a parent taps Request parent or guardian access. Nothing is sent to the other adult yet — the request waits in Admin → Patient Registration → Access requests (the button shows a count). Review it, verify the adult’s identity and authority, tick the confirmation, record how you verified it, and approve: that sends the same parent or guardian invitation described in Patient registration. Choosing Unable to approve keeps your reason staff-only; the family simply sees “Unable to approve — contact the practice.” Pending requests for a child also appear at the top of that child’s Portal access panel.
  5. Staff can set it up for an adult. For an adult patient, Portal access shows Caregivers & helpers. Add helper asks who authorized it: Patient authorized (the patient asked you; they can end it from their portal) or Verified representative (you reviewed legal authority such as a healthcare POA or guardianship; the practice manages it). Record the evidence reference and reason — both are kept in the access history. Remove any helper with Remove access in the same dialog.
A helper can…A helper cannot…
Book, change and cancel visits; message your team in their own conversations; see shared health records only if the patient turned that on.Pay bills, change insurance or profile details, sign forms or consents, change the patient’s login or notification settings, join video visits for the patient, or invite anyone else.
Messages stay separate. A helper’s messages show who actually sent them, and replies go back to that helper. Messages your team starts still go to the patient’s own login — a helper never sees the patient’s private threads, or another helper’s. Notes you hide from guardians are hidden from caregivers too.
Two switches in Patient portal configuration: Caregiver sharing (adults inviting helpers) and Family access requests (parents asking for another guardian). Both ship switched on. Turning one off stops new invitations or requests only — people who already accepted keep their access until it is ended. Approving requests and adding helpers needs the patient.portal_access.manage staff permission (front desk, office manager and owner role profiles include it).
Caller says…What to do
“The invitation link doesn’t work”It expired after 7 days or was replaced by a resend. The patient (or staff, for a practice-set-up helper) can Resend it.
“It says the invitation is for a different email”The helper is signed in with another account. They choose Use a different account and sign in with the invited email.
“I can’t see Mom’s test results”Health records weren’t shared. The patient turns them on under Change access; the helper accepts the update.
“I asked for my ex-spouse to be added” / “my request is still waiting”Check Access requests. A request is never proof of authority — verify before approving.
14.9Teens & guardians

Teens & guardians: what parents and guardians see

A clinician can hide a visit from parents and guardians in the note’s Patient portal visibility dialog, and that always keeps the visit’s own notes and documents from them. Everything else about a minor’s portal is the practice’s choice: whether parents, guardians and other representatives see the lab results, medications, diagnoses, vitals and billing detail from those hidden visits, the questionnaires assigned from them, the teen’s homework check-ins, and each other’s questionnaire answers still in progress. You set a practice-wide default for each, and you can change any of them for one patient. Staff screens never change.

Your practice decides. The settings tab says it plainly: “Minor-consent and confidentiality rules vary by state. Your practice is responsible for these choices; Hero EMR does not give legal advice. These settings change what the patient portal and app show. They don’t change statements, superbills or estimates your practice has already issued (mailed, emailed or saved in the portal), insurance explanations of benefits sent to the policyholder, or the visit type and notes on appointments.”
  1. Open the practice settings. Admin → Patient Portal Configuration → Teens & guardians — “Choose what parents, guardians and other representatives see in a minor’s portal. You can change any of these for one patient in their Portal access.” Administrators find the tab beside the other portal settings; owners, office managers, and staff with the admin.portal.manage permission who aren’t administrators get their own Patient Portal Configuration item in the Admin menu, which opens only this tab. Each card has an Applies to choice — Teens (13–17) or All minors (under 18), using your practice’s own ages — and “Age ranges come from Scheduling → Organization → Minors.” The Minors settings point back here too.
  2. Choose what each card allows.
    CardChoicesShipped default
    Results and chart data from hidden visits: Lab results, Medications, Diagnoses, Vitals, Billing detailsShow / Hide for eachShow, for teens
    Questionnaires from hidden visitsShow / HideHide, for all minors
    Questionnaire answers in progressShared / PrivateShared, for teens
    Homework check-insFull / Status only / HiddenFull, for teens
    The first card applies to visits a clinician hid from parents and guardians: “its notes, summary, forms, documents, handouts, homework and follow-up details are always hidden from them. Choose what else from that visit they see.” Medications covers “Medicines started or prescribed at that visit, with their history and refill requests. A parent’s pre-visit medication check then covers only the medicines they can see, and is recorded that way.”; Billing details covers “What each charge was for: codes, descriptions and the visit reason. Dates and amounts always show, so the balance adds up.” The portal’s pre-visit interview and medication review use only what the parent or guardian can see. Hiding Questionnaires from hidden visits means those questionnaires, “such as PHQ-A or CRAFFT, with their photos, reminders and phone links, are hidden from parents and guardians. They can’t be filled in from a parent’s portal; staff can complete them with the teen on the office kiosk — hand the tablet to the teen.” Status only homework shows “what was assigned, when it is due and how many sessions are done — not the teen’s notes, how they felt, or the clinician’s instructions and replies.” Questionnaire answers in progress is different from the rest: it covers “everyone who fills in the patient’s questionnaires: parents and guardians, the patient, and the office kiosk.” With Private, “Answers and photos saved so far are seen only by the person who saved them, until the questionnaire is submitted. Each office kiosk visit counts as its own person. When someone submits, answers and photos that others started but didn’t submit are discarded.” (“In the mobile app, typed answers in progress stay on that phone; photos follow this setting.”)
  3. Save, with a reason if you like. Reason for this change (optional) is “Saved in the change history.” Press Save teen & guardian settings; the confirmation reads Teen & guardian settings saved — “Parents and guardians see the change the next time their portal loads.” Change history lists each change as {setting}: {old} → {new} with who made it, when, and the reason.
  4. Know what a parent or guardian sees. Anything a setting hides is simply left out — no placeholder, and it isn’t counted. Billing is the exception, because balances must add up: when Billing details is set to Hide, the billing lines of a hidden visit keep their date and amount but show the kind of charge (for example Visit charge) instead of its codes and description. With the default Show, those lines read as they always have.
  5. Set it for one patient. Admin → Patient Registration → Portal access on a minor’s row shows What parents & guardians see — “Applies to parents, guardians and other representatives until {First} turns 18 on {date}.” Each row offers Practice setting (Show) (or whatever the practice setting is) or an explicit choice, with a chip saying where the value comes from: Practice setting, Set for {First}, or Not covered at age {age}. The presets Use practice settings, Guardians see everything, and Guardians see the least fill every row at once. A change that lets parents and guardians see more than the practice setting needs a reason: the field becomes Reason (required), and saving without one is refused with “Add a reason when letting parents and guardians see more than the practice setting.” Other changes take an optional reason. Save confirms “Saved. Parents and guardians see the change the next time their portal loads.”; if a colleague saved first you’ll see “Someone else changed these settings. Reload to see the latest.” Changing these needs both the patient-management and the portal-access permissions (patient.manage and patient.portal_access.manage); without them the section is read-only (“Changing these needs the patient management and portal access permissions.”). The choice lasts until the patient reaches your practice’s adult age (18 unless you changed it under Minors).
  6. See it in the note. When you hide a minor’s visit from parents and guardians in the note’s Patient portal visibility dialog, What will be hidden adds a line such as “For parents and guardians, this practice also hides this visit’s lab results and diagnoses. They still see its medications, vitals, billing details and questionnaires.”, captioned Practice setting or Set for this patient in Portal access.
How these combine. “A visit a clinician hides always keeps its notes and documents hidden. Nothing here can show them.” “A choice made for one patient in Portal access replaces these settings for that patient until they turn 18.” “Patients outside the age range you pick keep today’s behavior.” “These settings never change what staff see. Apart from questionnaire answers in progress, they never change what the patient sees about themselves.”
What these settings don’t reach. Statements, superbills, and estimates already issued keep their line detail, and a hidden visit still appears in the appointment list with its visit type and appointment notes. Admin → Documentation lists the same limits under What this feature can’t do.

Need help? Email support@heroemr.com.