A locked record is one that has been sent for review or otherwise finalized as part of a sign-off workflow. Once a record is locked, its data is protected from further edits so the reviewed information stays accurate.
Locking can apply to:
An entire record (every field is protected), or
Specific fields on a record (a field-level lock), while the rest of the record can still be edited.
A specific section of a visit (for example, one built-in chart tab), while the rest of the visit workspace stays editable.
Locking started with clinical records such as Visits and Ultrasounds, but it now applies consistently across CoolFocus: any record type can be locked, and every save or delete attempt is checked, no matter which screen, grid, or list you use to make the change. Signed charts follow the strictest rule: once a chart is signed, it is immutable. It cannot be edited or deleted, and it cannot be reopened for editing. It can only be corrected through the addendum flow described below, or, in the one exception described further down, reopened by an administrator using an explicit reset that voids the signature.
Some records can be opened and edited from more than one screen because they represent the same underlying data. Ultrasounds are the clearest example: an Ultrasound and its parent Visit share the same underlying record. If that record is sent for review from the Ultrasound screen, the record is locked, and it stays locked if you try to edit it from the Visit side too, since it's the same record either way. You'll see the same locked message and the same reason regardless of which screen you were using when you hit it. This keeps one record from having two reviews open against it at the same time under different names.
In the visit workspace, each built-in chart section, Pregnancy Test, Ultrasound, STI Test, Client Advocacy/Counseling, and Vitals, has its own Send for Review action and locks on its own when sent. Sending one section for review does not lock the others, so staff can keep working the rest of the visit while a section is with its reviewer.
An approved section becomes read-only and shows a locked/signed state on its tab.
A returned section unlocks automatically so staff can see the reviewer's notes and make corrections, then send it again.
Whether a section actually locks when sent depends on your organization's notes-locking settings in Settings; some organizations allow notes to stay unlocked, or only lock them automatically after save.
Client Advocacy/Counseling and STI Test also lock their case-stored fields. Most chart fields live on the Visit, but a few fields in the Client Advocacy/Counseling Initial Assessment and in the STI Test's Physical Symptoms fields are stored on the client's Case instead. When one of these sections is sent for review, signed, or returned/denied, CoolFocus now locks or unlocks those Case-stored fields at the same time as the rest of the section, so they can't be changed behind the reviewer's back after the section shows as locked. Unrelated fields on the same Case (fields not part of that chart section) are left editable.
Within the Ultrasound chart's Physician Review section, some fields are only ever set by the review workflow itself, not typed in directly by staff. This includes fields such as:
Reviewed by physician, and the date/time it was reviewed
Physician signature and physician notes
Sent to physician, and the date/time it was sent
The medical director authorization name, date, and authorized flag
These fields always appear locked (read-only) in the visit workspace, even before the section is sent for review, because they are filled in automatically as part of sending for review and signing off, not edited by hand. If a request tries to update one of these fields directly through the API, CoolFocus rejects it with an error explaining that the field can only be set through the review workflow.
Two related fields remain staff-editable and must be filled in before you can send an Ultrasound chart for review:
Physician name - who the chart is being sent to.
Notify on sign-off - who should be notified once the physician signs off.
If either of these is left blank, the field shows a "Required before sending for review" hint, and the Send for Review button is disabled. Hovering over the disabled button (or checking the message shown near it) explains exactly what's missing, for example "Select a physician in Physician Review." or "Select who to notify on sign-off in Physician Review." The button is also disabled while you have unsaved changes or while the chart is already locked for review.
If you try to save a change to a locked record or a locked field, CoolFocus blocks the save and shows a message explaining that the record (or specific fields) is locked, along with the reason it was locked when one is available.
If you try to delete a locked record, for example from a batch entry grid, the row stays in place and you'll see an error message explaining that the record is locked, instead of the record disappearing. This is expected. If the row appeared to be removed but you weren't shown an error, refresh the list, the record is still there. A signed chart cannot be deleted even if something unusual left it without a lock; CoolFocus blocks the delete based on the chart's signed status either way.
Any chart entry that has been signed and locked shows an addendum panel. The panel lists the chart's full amendment history in order (type, author, date and reason, and, for corrections, the previous value alongside the new one) and lets you add a new entry. The original, signed values are always left in place; amendments are appended alongside them and never edit the original data. This append-only history is the record of every correction made after sign-off.
To add an entry, choose one of three types:
Late Entry - information that should have been recorded before the chart was signed but was missed. Requires a reason and content.
Addendum - additional information added after the fact that supplements the signed record. Requires a reason and content.
Amendment - a correction to a specific field that was signed with an incorrect value. Requires a reason and the name of the field being corrected; the previous and new values are recorded alongside it.
Every addendum requires a reason, and submitting one requires re-verifying your identity (the same step used elsewhere for other sensitive actions) because addendums are a compliance-critical record used to answer questions like "how do you amend a locked record" during an AAAHC survey.
Only an administrator can unlock a signed/locked record. From the record's lock/addendum panel, an admin can unlock the entity by entering a reason, which is required. The unlock, who performed it, and the reason are recorded in the record's history and on the clinical timeline, alongside the addendum history, so the full sequence of what happened to a signed record stays visible. A non-administrator cannot unlock a record from this UI.
Unlocking is meant to be an exception, used when a record genuinely needs to be reopened rather than corrected through an addendum. For routine corrections after sign-off, use the addendum flow instead of asking an admin to unlock the record.
Signed charts are immutable by design, corrections are made through addenda, not by editing the signed content. The one sanctioned way to fully reopen a signed chart is an explicit admin reset, available directly from the chart's addendum panel as a Reset to draft (admin) action.
Who can do it: Administrators only. The action is not shown to non-admin users, and the server rejects the request even if a non-admin somehow submits it.
When it's available: Only on a chart that is currently signed. It appears on the chart's own addendum panel (not on a visit-level section lock display), including when a signed chart is unexpectedly showing no active lock.
What it requires: A reason (required) and re-verifying your identity, the same re-verification step used for addenda.
What it does: Voids the chart's signature, cancels the review workflow and any pending approvals tied to that chart, releases the chart's sign-off lock, and returns the chart to draft status so it can be edited and resubmitted through the normal review process. A note is added to the chart's timeline ("Reset to draft by {admin}: {reason}"), and the action is recorded as an audit event.
What is preserved: The reset voids the signature, it does not erase history. The prior signature, any earlier addenda, and any earlier unlock history remain visible in the addendum panel and in printed/PDF output.
This is the one exception to the immutable-signed-chart rule; it exists for the rare case where a signed chart genuinely needs to go back through approval, rather than be corrected with an addendum. For legacy Ultrasound records using the DocAlert workflow, reopening still works the same way it always has, through the reset action on the Ultrasound/DocAlert record itself.
Use the addendum system to add new information to a locked record or locked field rather than editing the original entry. This preserves the original reviewed data while still letting you document follow-up information.
If you believe a record was locked in error, or you need it unlocked to make a correction, contact an administrator. Unlocking is limited to specific, approved workflows (such as an admin unlock, an admin reset of a signed chart, or the completion of a review workflow).
Visits and Ultrasounds records that have been sent for review.
Built-in chart sections in the visit workspace (Pregnancy Test, STI Test, Client Advocacy/Counseling, and Vitals), each locking independently when sent for review, including the case-stored Initial Assessment and Physical Symptoms fields described above.
The Ultrasound chart's Physician Review section, where sign-off fields stay locked until the review workflow sets them, and Physician name / Notify on sign-off must be filled in before you can send for review.
Signed chart entries, where the addendum panel appears directly on the chart, along with the admin reset action described above when you're signed in as an administrator.
Any other record type your organization has configured to lock as part of a review or compliance workflow, including records edited through batch entry grids (for example, in Giving).
A printed or PDF chart no longer stops at the original reviewed content, if the chart has any amendments, they print with it. This closes a compliance gap: a printed record missing its own amendments would otherwise look like the chart was never corrected.
The Ultrasound report PDF, and any other chart print/PDF template that includes the Amendments block, prints an Amendments section after the main chart content.
Each entry shows the addendum type (Late Entry, Addendum, or Amendment), the author, the date, the reason, and, for field corrections, the previous value and the new value.
Unlock events are included too, when the record was unlocked and relocked, shown the same way (reason, user, date) so the printed history matches what you'd see in the on-screen addendum/lock history.
The original values in the body of the chart are never changed or replaced, addenda are always shown as an appended, chronological record, the same append-only shape as the addendum flow described above.
If a chart has no addenda or unlock history, the Amendments section is left off the printout entirely, you won't see an empty "Amendments" heading.
This applies to standard chart print templates as well as custom document templates your organization builds with the template editor's Amendments block. See Email & Document Templates.