Provider Manual · Part XIV

The patient portal

The patient's side of Hero EMR — and what staff need to support it: the portal tour, getting patients registered, sign-in help, booking, messaging, payments, and records.

7 sections~15 min read7 screenshots
XIV
Part XIV

The patient portal

The patient's side of Hero EMR — and what staff need to support it: the portal tour, getting patients registered, sign-in help, booking, messaging, payments, and records.

14.1Portal tour

Tour the portal: what your patients see

The patient portal is the patient-facing companion to Hero EMR — a separate site where your patients book and manage visits, message the care team, pay bills, complete pre-visit paperwork, and read their records. It carries your practice’s logo, colors, and name (set under Portal branding), so to patients it looks like your portal. The desktop navigation runs across the top, with a Schedule Visit button on the right and an avatar menu holding Notifications, Profile, and Sign Out.

Home Health Record Messages Appointments Letters & Forms Profile
  1. Home greets and orients. The patient lands on Welcome back, their first name, with two calls to action: Schedule appointment and Message care team. Once a visit is booked, a Next visit card shows the date and time in your practice’s time zone (with the patient’s local time labelled when it differs), the provider, and either the office location or Virtual visit · join from this portal.
  2. Tasks surface themselves. Below the hero sit a pre-visit checklist for the next appointment’s questionnaires and paperwork, a forms-to-sign card for practice-sent agreements, Follow-ups to schedule with per-item Schedule now buttons, and Quick actions (Schedule Appointment, Manage Prescriptions, Health History, Letters & Forms). While pre-visit work is pending, an amber banner counts the remaining tasks with a View All link.
  3. Profile holds the patient’s own record-keeping. The Profile page is tabbed: Personal Info, Allergies, Medications, Pharmacy, Guarantor, Insurance, Billing, and Settings. Personal Info autosaves as the patient types. On first sign-in a six-step orientation wizard walks through allergies, medications, pharmacy, guarantor, insurance, and billing; if the patient skips it, Home shows a Complete your patient profile reminder with a Go to profile button — handy when you ask a patient to finish intake before a visit.
  4. One login can manage a family. A single account can hold multiple patient profiles; a patient selector appears in the header when there’s more than one. Under Profile Settings, a Family section offers Add Myself and Add Child (which creates a minor profile). When a parent acts for a child, Home is labelled Proxied by the account name.
Patient portal home page at mobile width showing the welcome header for a signed-in patient and the main dashboard cards
The portal home page — welcome header, next-visit snapshot, and task cards. Empty sections hide themselves, so two patients can see quite different home pages.
About those badges: the amber count on Messages tallies follow-ups awaiting scheduling, not unread mail — which is why it can persist after a patient has read everything. The Appointments badge counts pending pre-visit tasks. The pre-visit checklist itself is driven by your questionnaire assignments — see the patient experience of paperwork.
14.2Invitations & registration

How a patient gets registered

Patients can’t self-enroll in the portal — access starts with an invitation your practice sends from the admin-only Patient Registration workspace. The staff-side mechanics (status pills, the invite dialog, delivery channels, teen account modes) are documented in Patient registration; this section follows what the patient experiences from the moment the link arrives.

  1. The link arrives. The patient receives the signup link by email, by text, or directly from your staff — the invite dialog can generate a Portal signup link with a Copy button for handing over in person. Invitations expire in 30 days; after that, staff use Resend invite.
  2. They verify identity on Complete Signup. The link opens the portal’s signup page with the patient’s name shown read-only. They confirm their Date of Birth, then create credentials — an email and password, or Continue with Google / Continue with Apple.
  3. They walk the registration steps. Registration collects insurance and personal details (teen flows add a parent step), then a review, and lands on a success screen showing their Medical Record Number and a What’s Next? list. From there the orientation wizard in the portal tour takes over.
  4. Abandoned signups can resume. A patient who created a login but stopped partway is routed to a resume-registration screen on their next sign-in — or staff can simply resend the invite.
The admin Patient Registration workspace listing patients with their portal access status, where invitations are sent and resent
The staff side of the story: invitations are sent, resent, and tracked from AdminPatient Registration.
Two prerequisites and one gotcha: invite delivery channels stay greyed out until email and SMS providers are configured under External providers (see also SMS setup). And the signup link is bound to the email address typed in the invite dialog — which may differ from the chart email — so confirm it with the patient before sending.
Teen patients: for patients in your practice’s configured teen age band, who signs in — and who signs forms — depends on the account mode chosen at invitation: in Parent-managed mode the parent does both; in Teen private mode the teen signs in and a parent or guardian email is collected separately for consent paperwork. Choosing or switching the mode is part of patient registration.
14.3Sign-in & security

Passwords, passkeys, and verification codes

Portal sign-in is Email Address + Password + Sign In, with Continue with Google and Continue with Apple as alternatives. Depending on how your practice’s portal is configured, patients may also see passkey sign-in and a second-step verification code. Knowing the patient’s-eye view here is what lets your front desk troubleshoot “I can’t log in” calls quickly.

  1. Password recovery is self-service. The Forgot your password? link on the login page emails the patient a reset link. That emailed link is the only reset path — there is no staff-side button that sets or resets a patient’s password.
  2. Passkeys, where enabled. On practices with passkeys enabled, returning patients get an automatic prompt (Checking for your passkey… or start typing to sign in another way.) plus a manual Sign in with passkey button. Patients add or remove passkeys under Profile SettingsPasskeys (“Sign in faster with your face, fingerprint, or device PIN”), and a dismissible banner after sign-in offers Set up now. Browsers without passkey support show a “not supported” notice — don’t promise passkeys on every device.
  3. Verification codes, where required. Practices can require a second step at sign-in: the patient sees Check Your Email or Check Your Phone, enters a 6-digit Verification Code, and taps Verify and Continue. Helpers include Resend Code, Text me a code instead / Email me a code instead, and Use a Different Account. Where trusted devices are enabled, a checkbox offers: Trust this browser on this portal so you do not need an email code on every sign-in.
  4. Text-message codes are the patient’s choice. Under Profile SettingsCell phone verification, the patient taps Add phone, verifies it with Send codeVerify, and controls the toggle Text me a code when I sign in (you can turn this off anytime). SMS verification is patient opt-in — never forced by the practice. Verified numbers list masked, with a Remove number action.
Patient says…What to do
“I forgot my password”Point them to Forgot your password? on the login page — the reset link arrives by email. Staff cannot reset it for them.
“My signup link doesn’t work”The invitation likely expired (30 days) or was never completed — use Resend invite in Patient Registration.
“It says an account already exists”They originally signed up with Google or Apple. Tell them to use the matching Continue with… button instead of a password.
“The code never arrives”Confirm the email on file matches what they’re typing, and have them try Resend Code or switch channels with Text me a code instead.
“I belong to two practices”That’s expected — after authenticating they pick a practice and tap Open Portal.
These are deployment settings, not Admin toggles. Passkey availability, the email-code requirement, and trusted devices are configured per practice as part of portal deployment — there is no switch for them in the Admin screens. If your practice wants to change sign-in behavior, raise it with Hero EMR support rather than hunting for a setting.
14.4Booking & visits

How patients book, change, and join appointments

Portal booking is self-service direct booking — when a patient confirms a slot, the visit is created on the physician’s calendar immediately, marked as coming from the patient portal. There is no approval step and no request queue to work. Confirmation email and your reminder policies fire automatically (see Notifications).

  1. Pick the visit, provider, and time. From Schedule Visit (or Home’s Schedule appointment), the patient toggles In-office visit or Remote visit, picks a Physician — grouped Seen before vs Other physicians — a Location for office visits, and a slot under Available Times on a month calendar. Only physicians and visit types you’ve enabled for online booking appear; a physician with no virtual offerings shows “This physician does not currently offer virtual visits.”
  2. See the cost up front. When visit billing policies apply, the confirm dialog states the money terms plainly — an amount required to hold the appointment, due before the visit, due at check-in, or billed afterward — or Your care team will confirm pricing before the appointment. If pricing changes mid-flow the patient must review and confirm again.
  3. Confirm. Confirm appointment (or Confirm reschedule) books the slot; on success the patient can Add appointment to Calendar (an .ics download) and Get Directions. A slot grabbed by someone else fails safely: This time slot is no longer available. Please select a different time.
  4. Manage everything from Appointments. An Action Needed panel lists pending questionnaires, the next appointment is featured with its pre-visit task list, later visits sit under Coming Up, and history under Past Visits. Cancelling shows a Cancel appointment? dialog with a refund/fee preview before Confirm cancellation; rescheduling reuses the scheduling screen.
  5. Join telehealth from the portal. Virtual visits show a Join video visit button that activates 15 minutes before the start time and stays open for about an hour after. If required pre-visit tasks are incomplete, the button reads Complete previsit to join instead. The clinician side of the video visit is covered in Run telehealth visits.
The patient portal schedule-a-visit flow where the patient picks a physician and an available time slot
Booking is direct: pick a provider, pick a slot, confirm — the visit lands straight on the calendar.
The patient portal Appointments list showing an upcoming visit
The Appointments tab manages what’s booked — pre-visit tasks, cancellations with a fee preview, and reschedules.
Two request-style flows do exist. Follow-up requests created at encounter completion appear to patients as Follow-ups to schedule cards with Schedule now links (see Schedule the follow-up), and waitlist offers appear on the Appointments tab under Active Waitlist with Claim this time / No thanks (see Waitlist).
Want gatekeeping? Shape the menu, not a queue. Since portal bookings confirm instantly, the way to control them is upstream: restrict which visit types are bookable online, set booking windows, and attach visit billing policies. Note that times display in the practice time zone with the patient’s local time as a secondary label — relevant for out-of-state telehealth patients.
14.5Portal messaging

Message the care team — and where it lands

Patients read and write secure messages under the portal’s Messages tab — Your Message Inbox, with a Search messages… box and a New Message button. Every message a patient sends arrives in your clinician Inbox, routed by category, so nothing depends on someone remembering to check a separate system.

  1. The patient composes with structure. New messages require a category — Clinical or Billing support — and a priority — Routine or Urgent / safety — plus a recipient chosen via the Select Physician picker. They enter a subject and message, can Add attachment, and hit Send.
  2. It lands in your Inbox by category. Clinical messages arrive in the Inbox’s Patient folder; billing questions arrive in Billing. Opening a thread shows the full Message History with linked-encounter context and a Your Response to Patient reply box with Send to Patient. Triage, forwarding, and reply mechanics live in Inbox threads; AI-drafted replies in AI responses.
  3. Patients tune their own alerts. Under the avatar’s Notifications page, patients control email, text, and push alerts (Messages from your care team, reminders, Quiet hours). Notification emails are alerts only — the portal reminds them “Full message details stay in your secure portal inbox.” — a privacy point patients often ask about.
Patient portal Messages page showing a secure message thread between the patient and the practice
The patient’s side: a secure thread with the practice, searchable and attachable.
The clinician Inbox in Patient view with a portal message thread open, showing the Message History, linked encounter context, and the Your Response to Patient reply box with an AI response chip and Send to Patient button
Your side: the same conversation in the Inbox Patient folder, with thread history and the Send to Patient reply box.
Urgent / safety is a triage flag, not an emergency channel. The portal is not monitored in real time — make sure your patient-facing materials say emergencies go to 911 or urgent care, not a portal message.
Two more nuances: follow-up scheduling reminders are injected at the top of the patient’s Messages screen — they’re scheduling tasks, not chat threads (and they’re what the nav badge counts). And if your practice runs membership-gated messaging, new clinical messages can be blocked by the membership policy — with the explanation shown inline — while billing-support messages still go through.
14.6Portal payments

How patients pay their bills

Patients reach billing from Home’s Account panel (Bills & payments) or the Profile Billing tab — both open the same screen. It leads with the Account balance and a Pay balance button, a snapshot rail (past due, due soon, Open charges, “Secured by Stripe”), and a Transactions view split across Open / Pending / Paid tabs, with an Insurance tab alongside. This section covers the patient-side checkout only — staff-side balances, statements, and collections live in Patient AR.

  1. Pay a charge. Pay charge shows the Amount due and a Pay with choice between Saved card and Link or new card, plus an Express checkout row (Apple Pay, Google Pay, Link, or card) — all powered by Stripe. Charge details itemizes the Original charge, Paid so far, status, and provider so the patient can see exactly what they owe.
  2. Store a card for pre-visit billing. Add a card saves and authorizes a default card — this is the card your visit billing policies charge against for holds and pre-visit payments. The patient sees “Securely stored for next time.”
  3. Review history and statements. Lower on the page, Payment history collects payments, refunds, and in-progress billing updates automatically, and Statements keeps anything the practice has sent available for reference.
  4. Manage a membership, if your practice offers one. Practices with recurring plans get a Membership section with enrollment, Billing history, Invoices, payment-recovery prompts, and a Cancel membership flow that asks for a reason. Plan setup and the staff-side view are owned by Memberships.
Stripe Connect is the prerequisite. Portal payments work once your practice completes Stripe setup; until then patients see Online payments are unavailable. The charges patients pay here are the ones produced by encounter charges and your billing policies. Trust messaging shown at checkout — “Encrypted · PCI-compliant via Stripe — This practice does not retain saved cards.” — is a useful line for your front desk to echo.
Refund expectations live in the cancel dialog. When a patient cancels a visit, the refund or fee preview appears in the Cancel appointment? dialog (see Booking & visits), not on the billing page — point patients there if they ask what cancelling will cost.
14.7Records & documents

Records, letters, and documents patients can access

The Health Record tab is the patient’s window into the chart. Everything here is downstream of clinician work: signed notes, patient instructions, and orders published by Sign & close, plus lab and imaging results released to the chart (see Results in the portal) and documents from the Media tab. The page organizes it all under pill tabs:

Past Appointments Lab Results Imaging Letters Media
  1. Browse the visit history. Past Appointments is a searchable Visit history. Opening a visit shows Patient instructions (“Care guidance from this visit”), the Visit note, the message exchange, Diagnoses, medications from the visit, and lab/imaging orders that deep-link to their own tabs. The instructions are the ones you drafted at encounter completion.
  2. Pull in outside records. An Import Records button opens Import Medical Records, where the patient searches for their outside health system and connects via Epic to bring external records into the chart. Availability depends on the outside system supporting Epic patient access, so set expectations accordingly.
  3. Request letters and forms. Letters & Forms is the patient-initiated document desk. Request New Medical Form / Letter walks Visit → Type → (Dates) → Review, with types including Work Excuse Letter, School Excuse Letter, FMLA Form, Paid Leave Certification, Disability Form, Travel Medical Clearance, Accommodation Request, and Custom Form Upload (the patient uploads their own PDF). My Request History tracks submissions, and a How it works panel explains the flow.
  4. You approve; they download. Requests arrive in your clinician Inbox under Forms/Letters (see Inbox queues), where the physician reviews the generated PDF, can quick-edit corrections, and approves with their saved signature embedded — or rejects with a reason. Completed documents then appear to the patient under Letters & Forms and Health Record’s Letters tab with view and download actions.
The chart Letters tab listing seven letters including a WA Paid Leave Form, FMLA Letter, and Work Excuse Letter, each with Approval Status badges reading Pending Review or Approved and a View action
The same documents on your side of the fence: the chart’s Letters tab tracks each request’s Approval Status from Pending Review to Approved.
A saved signature is required for approval. The Inbox blocks form approval until the physician has a saved signature on file (“A saved signature is required before approval.”); with one saved, approving embeds it (“This signature will be embedded when you approve.”) — so set one up before the first request arrives. And patients only see documents once generated and approved; until then the Letters area shows an empty state.
Beyond the basics: questionnaires and pre-visit paperwork reach patients as tasks on Home and Appointments — authoring and assignment rules are covered in Questionnaires & paperwork. Practices with APCM enabled also expose an APCM Care Plan page (Goals, Interventions, billing history) reached from APCM surfaces on Home — it exists only when APCM is enabled for the practice (see APCM).

Need help? Email support@heroemr.com.