ACCESS RED TEAM — PATIENT-ACCESS WORKFLOW EVIDENCE CHECKLIST Version: 7 September 2026 https://accessredteam.com/readiness-check/ Use with security, patient-access and integration owners before a rollout or vendor-acceptance decision. This is a self-review aid, not a system test, certification or finding that your workflow is vulnerable. WORKFLOW AND DECISION Workflow / intended action: Configuration and sites: Decision and responsible owner: Current evidence and its date/version: For each question mark: DOCUMENTED / NOT VERIFIED / UNKNOWN. 1. PERMISSION Who may make this request for this patient and action? Ask security and the policy owner for the rule, enforcement point and paired allowed/denied tests, including relevant changes to authority. 2. OUTCOME Which milestone is promised, and what authoritative evidence proves it? Ask the integration owner for the correlated record/event, target, time, version and any intervening correction. 3. UNCERTAINTY AND RECOVERY What happens after a timeout, retry or conflicting outcome? Ask integration and operations for tests, duplicate-effect checks, reconciliation owner and the bounded recovery path. 4. OWNERSHIP Who accepts unfinished work or exceptions, and how is closure established? Ask the receiving team for acceptance, due time, escalation and closure reason. 5. HUMAN VERIFICATION Can the responsible reviewer find and correct a discrepancy? Ask operations and quality for an observed walkthrough using accessible authoritative evidence and the agreed recovery permissions. 6. CURRENT CONFIGURATION What changed, and were affected controls and legitimate requests retested? Ask release and security owners for versioned results and scope exclusions. NEXT STEP Record the evidence needed, its owner and the decision it affects. Unknown is a reason to clarify; it is not a confirmed vulnerability. Scope an assessment: https://accessredteam.com/request-scope/ No patient information, credentials or incident evidence in public inquiries.