Skip to main content

Requesting and Enabling PHI Reporting

PHI reporting gives CBO Advanced organizations deeper insight into client data — with the privacy safeguards to match.

Written by Jules Roebbelen

Organizations on a CBO Advanced subscription can request access to Personal Health Information (PHI) reporting — the ability to include identifying client details in the Inbound Referral Raw Data spreadsheet report. This article explains what the feature does, who can request and use it, and how to run a report once it's enabled.

Who can use this feature

  • Organizations on the CBO Advanced subscription*.

  • Only users with both Organization Administrator and Referral Delegate permissions can run PHI reports. Once enabled, anyone at your organization with both roles can download PHI reports, not just the person who requested it, so we recommend keeping that group as small as possible.

⚠️ Before you request it: what enabling PHI reporting means

Enabling this feature is a privacy decision, not just a configuration change, so written confirmation from the Lead Organization Administrator is required before Caredove staff will turn it on. Keep the following in mind when deciding:

  • Once enabled, any user with Organization Administrator + Referral Delegate permissions can download lists containing client names, date of birth, health card number, postal code, address, phone number, etc., and/or any custom form fields you choose to enable.

  • The more fields you enable, the more identifying each row of raw data becomes, increasing the risk of client re-identification.

  • Reportable fields only return data for referrals that still fall within your organization's data retention period.

  • Downloaded reports are saved locally on the user's computer. Consider where staff are working from. A user downloading this on a personal device at home, for example, introduces additional privacy risk.

  • Enabling and disabling this feature both require contacting Caredove staff; it cannot be self-served.

  • Your privacy officer can request to review Caredove's privacy and security documentation if they have questions before authorizing the request.

❓ What data can be included

⚠️ Caution: These are all potentially high-risk fields. The more fields you enable, the higher the risk of client re-identification. Proceed only with explicit authorization and appropriate data protection measures in place.

Standard fields

Standard fields are the built-in client and alternate contact fields collected on most referral forms: Client Identifier, First/Last Name, Email, Phone, Address, Date of Birth, Language, Health Card Number, etc.

A full breakdown of standard report fields is available in Understand the Referral Raw Data Report.

Custom fields

Custom fields are pulled from questions on your organization's referral forms and are specific to each form.

A few things to know about custom field reporting:

  • If two forms ask the same question, that question's answers will still appear in two separate columns in the report, one column per form.

  • Custom field reporting is typically limited to 5 questions per organization. Requests for additional fields can be made and will be reviewed case by case.

  • Aggregated fields: for example, reporting an age range (e.g., 0–10 years old) instead of a specific date of birth can be requested to support ministry or funder reporting requirements while reducing identifiability.

⏳ Time-limited data retention

Standard and custom PHI fields are only reportable for referrals that still fall within your organization's PHI data retention period, as set on your subscription. 90 days is the standard retention period for CBO Advanced customers.

💬 How to request PHI reporting

  1. Have your Lead Organization Administrator contact Caredove staff via email or chat to request PHI reporting.

  2. Review the list of users at your organization who currently hold both Organization Administrator and Referral Delegate permissions, and confirm you are comfortable with all of them having access to PHI downloads.

  3. Confirm in writing which fields you want enabled (standard fields and/or custom form fields), understanding the privacy considerations above.

  4. Once approved, Caredove staff will enable the requested fields for your organization.

📊 How to run the report once enabled

  1. Go to Reports.

  2. Under Select Report, choose Spreadsheet: Inbound Referral Raw Data.

  3. Choose your Calendar, Category, and appropriate date range.

  4. Check Include Registrant Personal Information Fields under Sensitive Data.

  5. Depending on what reporting has been enabled for your organization, you may see both the Standard Form Fields and Custom Fields sections, or just one section. Check off the specific fields you want included in the report.

  6. Click Download Data (.xlsx).

⚠️ Remember: This will download a spreadsheet of identifying client data to your computer. Caredove maintains an audit history of all downloaded reports for privacy and security purposes.

*Downloadable PHI reports are only available at an organizational level, not at a network level. They can be enabled without a CBO Advanced subscription by exception.

Did this answer your question?