Parent Portal
1. What does this feature do? (High-Level Overview)
Section titled “1. What does this feature do? (High-Level Overview)”The Parent Portal gives parents secure, self-service access to their child’s clinical information directly within the application. Parents log in using their own credentials through a dedicated parent login flow and can view consent forms for their linked patients. This feature is currently in development.
2. Who is this for? (Roles & Permissions)
Section titled “2. Who is this for? (Roles & Permissions)”- Parents: Users with an
activeparent account linked to at least one patient.
Parent portal access is controlled by the built-in PARENT role, which carries the following permissions:
fill_consent_forms— view and sign consent forms.access_all_locations— access information across all locations where their patients are seen.
Parents use a separate authentication system (
apiparentguard) from clinic staff. Their credentials and session are fully independent from staff accounts.
3. Business Rules & Enforcements
Section titled “3. Business Rules & Enforcements”- Only active parents can log in. Parents with
inactive,incoming, orblack liststatus are blocked at login. Blacklisted parents receive an explicit access-denied response. - Parents can log in using email or phone number. Either contact method can be used as the login identifier, combined with the parent’s password.
- Parents see only their linked patients’ data. All clinical information — consent forms — is filtered to show records belonging exclusively to the parent’s assigned patients.
- Two-factor authentication (2FA) is supported. If 2FA is enabled on a parent account, the parent must complete a verification step (via SMS or email) before accessing the portal.
- The parent portal uses the same application as staff. There is no separate URL or app for parents. The same login page detects the user type and routes accordingly. The sidebar and available sections are filtered to show only what the parent has access to.
- Parent sessions are independent from staff sessions. Logging out as a parent does not affect any active staff session, and vice versa.
4. UI Placement
Section titled “4. UI Placement”- Login page (
/login) — The shared login page presents a role selection prompt on first visit: Login as a Parent or Login as an Employee. Parents select the parent option. The choice can be saved for future visits. - Dashboard — After login, the parent is taken to their dashboard, which shows only the sections relevant to their permissions.
- Consent Forms — Parents can view and sign consent forms linked to their patients.
5. How-To Guide (Step-by-Step)
Section titled “5. How-To Guide (Step-by-Step)”Scenario A: Parent logging in for the first time
- Navigate to the application login page.
- A dialog appears asking whether to log in as a Parent or an Employee. Select Parent. Optionally check Remember my choice to skip this prompt on future visits.
- Enter the Email or Phone number associated with the parent account, along with the Password set by the clinic.
- Click Log in.
- If two-factor authentication is enabled, select a verification method (SMS or email), enter the code received, and confirm.
- The parent dashboard loads, showing available sections based on their permissions.
Scenario B: Parent signing a consent form
- Log in to the portal as described in Scenario A.
- From the dashboard or sidebar, navigate to the Consent Forms section.
- Locate the consent form pending signature for the linked patient.
- Review the form content.
- Provide a signature and submit. The signed form and timestamp are saved and immediately visible to the clinic staff.
6. What happens if…? (Edge Cases / FAQ)
Section titled “6. What happens if…? (Edge Cases / FAQ)”-
Q: What should a parent do if they cannot log in?
- A: The most common causes are an incorrect password, a non-active account status, or using the wrong login identifier. The parent should contact their clinic to verify that their account is set to
activeand that the email or phone on file is correct. Staff can update the status and contact details from the parent profile.
- A: The most common causes are an incorrect password, a non-active account status, or using the wrong login identifier. The parent should contact their clinic to verify that their account is set to
-
Q: Can a parent see information for patients at different locations?
- A: Yes. The PARENT role includes
access_all_locations, so if a parent has patients seen at multiple locations, they can view clinical data across all of them from a single portal session.
- A: Yes. The PARENT role includes
-
Q: Does a parent account expire or get deactivated automatically?
- A: No. Parent accounts remain in the state set by clinic staff. Status changes (e.g., from
activetoinactive) must be made manually by a staff member withupdate_parentspermission.
- A: No. Parent accounts remain in the state set by clinic staff. Status changes (e.g., from