Define the record before collecting it
Programs should distinguish a resident-owned learning record, formal assessment evidence, program administration data, and any patient-related information. Each category needs a clear purpose, access boundary, and retention rule.
Use role-based access
Program directors, coordinators, faculty, committee members, and residents do not need identical views. Access should reflect the task and avoid exposing detailed records merely because someone belongs to the institution.
Protect trust through transparency
Residents should understand what is private, what can be shared, what the program can see, and how exports work. Clear boundaries are an adoption feature as much as a privacy control.
- Document data ownership.
- Limit patient identifiers.
- Audit important access and decisions.
- Provide export and deletion pathways.
- Review subprocessors and incident procedures.