Occentra

Blog

Health Surveillance Forms: What Should an Occupational Health System Capture?

A health surveillance form captures information for a particular screening, assessment, test or review. It may collect an employee's answers, a technician's measurements, a clinician's findings or an authorised outcome.

That is a narrower responsibility than managing health surveillance.

The form is the instrument used at a defined point. The record is the submitted, dated instance of that instrument, bound to a person and to the programme around them. The software is what manages the wider surveillance process: people, recalls, assessments, records and the work that follows a completed form.

The employee, their work, the reason surveillance is required, programme membership, earlier assessments, recalls, appointments and follow-up all provide context for the form. Reproducing that context as questionnaire fields does not create a coherent programme. It creates more data to reconcile.

Our guide to health surveillance software looks at the whole category. This article goes deeper into one important component: what a well-designed health surveillance form should capture, what the system should already know and why the distinction matters over time.

What is a health surveillance form?

A health surveillance form is a structured record used at a defined point within a workplace health surveillance programme. Depending on its purpose, it might support initial screening, periodic surveillance, a clinical assessment, test recording, follow-up or outcome recording.

The person completing it also varies. An employee may report symptoms or changes since the previous review. A technician may enter measurements. A clinician may record observations, interpretation and advice. An administrator may complete limited operational fields where that is appropriate to their role.

These are not interchangeable records.

A questionnaire primarily collects answers from a respondent. A clinical assessment record may combine history, findings, measurements and professional judgement. The employer's health record contains appropriate employer-facing information, including fitness to continue exposure, while confidential clinical and medical information is held in clinical confidence. HSE's record-keeping guidance distinguishes the two.

Calling all four things “forms” may be convenient when discussing software components. It should not erase their different purposes, users or information boundaries.

If you need an official HSE or appointed-doctor template rather than software, HSE publishes health forms for appointed doctors and approved medical examiners of divers. Those documents belong to statutory medical surveillance processes. They are not a product category, and they are not a substitute for the health surveillance software that manages the wider programme.

What should a health surveillance form capture?

There is no universal employee health surveillance form. The right content depends on the hazard, the assessment stage, the intended respondent and the decisions the information needs to support. A useful design starts by separating information that belongs to this interaction from context that already exists elsewhere.

Enough employee context to identify the assessment

The form needs an unambiguous association with the right employee. That does not mean the employee's name, date of birth, employer, site, role and contact details should become answers copied into every template.

If the system already holds an employee record, the submission should reference it. Relevant details can be shown for confirmation without being stored again as questionnaire data.

Duplication appears harmless until something changes. If an employee moves site, should an old submission display their current site or the site at the time? A well-modelled system can preserve assessment-time context where it matters while keeping core identity authoritative in one place.

The design question is not “Could this be a field?” It is “Is this an answer, a reference or a historical snapshot?”

Surveillance context around the form

A submission should be understood in relation to the relevant programme or hazard, the type and stage of assessment, its date, the responsible practitioner where applicable and relevant earlier activity.

Much of that is system context rather than something the respondent should be asked to supply. An employee should not have to identify which tier of a surveillance pathway they are completing. A clinician should not need to type a programme name into free text when the assessment was created from that programme.

Employee-reported information

Health surveillance questionnaires may collect relevant symptoms, changes since an earlier assessment and other information appropriate to the programme. Questions should be specific enough to answer consistently, written for the intended respondent and limited to information that has a defined purpose.

HAVS provides a clear example of a questionnaire as one stage rather than the complete process. HSE's hand-arm vibration guidance describes basic surveillance as regularly seeking information about early symptoms using a questionnaire, with positive responses referred to an occupational health provider. The form records the response. The service must still make the referral, conduct any further assessment and act on the resulting advice.

A negative response, a reported change and a request for clinical review are not merely three values in a results table. They have different operational consequences.

Measurements and clinical observations

Where the programme requires them, forms can record structured measurements and findings. An audiometry record, for example, may need results in a format that supports comparison with earlier tests. Respiratory surveillance may include structured lung-function values alongside information needed for competent interpretation.

The form should capture the measurement, its units and the information needed to understand it. A numeric field does not make the result self-interpreting. Test conditions, quality considerations, clinical context and the applicable protocol may all affect review.

This is where generic “number” fields often prove too weak. A measurement is not just a number; it is a value with meaning, provenance and limits.

Outcome and follow-up information

The assessment record should capture enough structured information to support the next legitimate action. That may include whether further review is required, whether an authorised outcome has been recorded or when the assessment was completed.

The boundary matters. A form may record that clinical review is needed. The system should create or expose the resulting work, assign responsibility, track its status and prevent it from disappearing behind a completed-submission label.

A positive answer hidden inside a submitted form is data. A visible, owned clinical review is work.

Employee-completed and clinician-completed forms are different interfaces

An internal clinical form should rarely be exposed unchanged to employees.

Clinical terminology may be efficient between practitioners but unclear to a respondent. Fields intended for professional interpretation may invite employees to make judgements the clinician should make. Internal notes may be inappropriate to display. An employee questionnaire needs clear explanations, accessible language and no assumed knowledge of the system around it.

Design should account for:

  • who can see each question and answer;
  • terminology suited to the respondent;
  • which fields are required, and at what stage;
  • validation that helps rather than obstructs;
  • confirmation or signature where the process requires it;
  • review by the appropriate practitioner before an answer becomes an outcome.

Both interfaces can contribute to the same assessment. The employee's submission can remain intact while the clinician records a separate review, rather than overwriting what the employee reported.

Conditional questions should not become hidden workflow

Conditional presentation makes forms more relevant. A positive response can reveal follow-up questions. A selected exposure can show the measurements needed for that assessment. Irrelevant sections can remain hidden.

There is a limit. Form logic can decide what to present or validate during completion. It should not carry the entire operational process that follows.

If an answer indicates that clinical review is required, hiding or revealing another section is a form concern. Creating the review, placing it in the right queue, assigning an owner, tracking its completion and recording the eventual outcome are workflow concerns.

Encoding both responsibilities inside a maze of conditional questions makes the process difficult to see and harder to audit. The form may be “complete” while the surveillance cycle is not.

Form versioning protects historical meaning

Occupational health forms change. Wording is clarified. A response option is added. A clinical team adopts revised guidance. A provider standardises templates after taking on a new contract.

The current template should be allowed to improve. Earlier submissions should not change with it.

Suppose an employee completes a HAVS health surveillance questionnaire in March. The provider publishes a revised questionnaire in September. When a clinician reviews the March assessment a year later, they need to know which questions were presented, their wording at the time, the available answer options and the answers given.

If the system renders every old submission against the current template, history becomes unstable. The March record might appear to contain unanswered September questions. A renamed option might imply a meaning the employee never selected. Conditional logic introduced later might change which sections appear. Reports could group old and new answers as though they were equivalent when the underlying question changed.

Good versioning creates a fixed relationship between a submission and the published form version used to complete it. Publishing a new version affects future work; it does not rewrite past records.

That matters for:

  • clinical review, because later decisions depend on understanding what was known and asked at the time;
  • auditability, because the record should reproduce the interaction that occurred;
  • reporting, because changed questions may need an explicit mapping rather than silent aggregation;
  • defensibility, because historical decisions need evidence that retains its original meaning;
  • long-running programmes, where several template versions may appear in one employee's history.

Versioning also imposes useful discipline. Editing a draft is different from changing a published clinical instrument. Teams need to know which version new assessments will use and whether reporting remains comparable.

Templates should evolve. Submitted records should remain fixed.

Validation is an operational data-quality decision

Required fields, data types, sensible ranges, structured answer options and conditional validation can prevent incomplete or unusable submissions. Clear messages help the respondent correct a problem without guessing what the system expects.

Poor validation creates downstream work. A missing unit makes a measurement ambiguous. Free text used for a standard outcome fragments reporting. A required question shown to the wrong user invites an invented answer so they can continue.

More structure is not always better. Clinical work sometimes requires qualification, uncertainty or narrative that a dropdown cannot express. A sensible form combines structured fields where consistency changes what the system can safely do with sufficient space for professional context.

The aim is not to maximise the percentage of data held in coded fields. It is to make important information reliable without reducing clinical meaning to whatever fits the reporting model.

Permissions must follow the information, not the form builder

Health surveillance forms can contain confidential symptoms, clinical notes and test results. Those answers should not automatically become visible to a manager because the manager can see that surveillance took place.

HSE says an employer's health record should include information such as the worker's details, workplace, relevant hazards and fitness to continue exposure, but should not contain confidential medical information without written consent. Medical records may include clinical notes and test results and are kept in medical confidence by the occupational health professional.

Software therefore needs boundaries between clinical information, the employee health record and the employer-facing outcome or fitness advice. Those boundaries should apply to submitted data, exports, reports, search results and audit views, not only to who can open the form designer.

A system can have excellent access control around a questionnaire and still disclose too much through a dashboard assembled from its answers.

Why a generic form builder is not a health surveillance system

Generic form builders can be excellent at collecting information. They often support conditional questions, validation, structured submissions and a much better experience than paper or emailed documents.

A generic form tool does not inherently understand an Employee, a surveillance requirement, a programme, a recall, an Appointment, a historical assessment, clinical follow-up or an occupational health permission boundary. Those relationships can sometimes be recreated using hidden fields, naming conventions, integrations and spreadsheets. As they accumulate, the questionnaire starts acting as the database schema and the submission status starts acting as the workflow.

That approach works until the concepts move independently. An employee changes role, a recall date changes after clinical review, an appointment is cancelled or a submitted answer creates work that remains open. The programme exists between assessments as well as during them; it cannot be modelled reliably as extra fields on the latest questionnaire.

Data collection and health surveillance management are different responsibilities. A form captures an interaction. A record preserves that interaction. Health surveillance software has to manage the programme around both.

Forms belong within wider occupational health workflows

Forms are useful beyond health surveillance. The same configurable capability may support a Referral, a Case, an assessment or a consultation. Reuse is valuable, but it does not make those concepts equivalent.

A Referral is a request for occupational health services. A Case is the operational work resulting from an accepted Referral. A Form can capture structured information within either workflow; it is not itself the request or the work created from it.

This is an important principle for a wider occupational health platform. Shared capabilities should compose with domain workflows without flattening their meaning. An occupational health provider can configure different forms while retaining consistent records for employees, referrals, cases and surveillance activity.

Questions to ask when choosing software for health surveillance forms

A product demonstration should show more than how quickly a user can drag a question onto a page. Use a real assessment and ask:

  • Can employee and clinician forms present different language, fields and permissions?
  • Can we configure forms ourselves within controlled publishing arrangements?
  • Is every submission tied to the exact published version completed?
  • What happens to earlier submissions and reports when a question changes?
  • Can conditional questions improve completion without hiding the follow-up workflow?
  • How are measurements, validation, narrative and professional review handled?
  • Can authorised users report on structured information without exposing confidential detail?
  • Do forms participate in Referrals, Cases and surveillance workflows without defining those workflows?

The revealing part of the demonstration often begins after “Submit”. Ask where the record appears, who reviews it, how an exception becomes owned work and what somebody will see after the template has changed twice.

Occentra treats versioned Forms as a configurable, reusable capability within occupational health workflows. Submitted answers remain attached to the published version used, while Employees, Referrals, Cases, Appointments and other operational records retain their own meaning. You can explore the wider approach on our health surveillance solution page.

A well-designed form makes one interaction clear and dependable. A well-designed occupational health system preserves the context around that interaction before it begins, after it ends and long after the template has moved on.

← Back to blog