Medical-leave requests
Save a private draft or submit a leave request to your workplace's authorised reviewers.
Medical leave lets you prepare a request for a corporate workspace you have joined and follow its review. Your health passport, prescriptions and activity history remain separate. API 1.13.0 adds optional certificate photos. The mobile changes require an updated build and physical-device checks; an older installed app may not include these controls.
How do I create a request?
Open Medical leave from Records. Select the workplace that should receive the request, enter the first and last dates, and review the displayed details.
Dates use YYYY-MM-DD. The displayed duration includes both dates and counts calendar days, including weekends. It does not calculate paid leave, remaining entitlement or eligibility under an employment policy.
A note, certificate reference and certificate photo are optional. You do not need to put a diagnosis in the note. A text reference does not grant access to a document.
How do I attach an MC photo?
Choose Take certificate photo or Choose a photo, then check that the whole certificate is readable. Each request accepts one JPEG or PNG photo, up to 2 MiB (2,097,152 bytes). Photos are converted to JPEG and camera metadata, including EXIF, is removed before encrypted storage on MedBuk-controlled infrastructure.
Confirm Store this certificate photo before saving a draft or submitting. Photos expire after 90 days, with at most 20 unexpired photos per account. If the limit is reached or photo storage is unavailable, follow your employer's document process; a request can still use a text reference without a photo.
Storing the photo does not share it. To submit an attached photo, separately confirm Share this photo with [your employer] when I submit, as well as the request-sharing notice. A saved draft with a photo requires photo-sharing consent when submitted later.
MedBuk+ does not send MC photos to hosted AI, verify certificate authenticity or extract a diagnosis. PDF uploads and automatic clinical-record transfers are not supported. Workspace invitation and verification-code emails contain no medical records, leave notes or certificate attachments.
Is a draft visible to HR?
No. Save private draft keeps the request private until you submit it. Review the saved dates and details in your request history before choosing to share that draft.
To submit, read the employer-sharing notice, confirm the selected workplace and give consent for that request. Submit to HR makes the displayed leave details available to authorised reviewers in that workplace. It does not share your wider health passport.
Can I withdraw a submitted request?
You can withdraw while a request is awaiting review. Use Withdraw pending request, then check the result in your history. HR retains the submitted request and its withdrawal history; withdrawal is not deletion. Withdrawal stops new HR access to the certificate photo. It cannot recall a copy someone has already viewed or saved.
After a review, the history shows the recorded decision and any review note. MedBuk+ records that workflow; it does not establish medical validity or legal leave entitlement.
What can HR review?
Authorised reviewers can see the leave details you submitted to that workplace and an unexpired MC photo only if you explicitly shared it. They cannot see private drafts or your wider health passport. Another reviewer must handle an HR user's own request.
Company owners and HR should use the separate medical-leave review guide.
What happens when workplace access ends?
Access removal ends membership and clears its sharing choice and active workspace context. The employee keeps their MedBuk account and health records. Existing HR leave queries exclude ended memberships, and new submissions or HR decisions require active access. Removal is not account deletion or certificate transfer. Further HR photo access also stops when the employee or reviewer loses workplace access, the company is suspended, an applicable account-erasure request is in progress or has failed, or the photo expires. Completed erasure removes the photo. Expiration blocks viewing even before the cleanup job removes the stored file.
An employee's own request history and unexpired photo remain separate from the former employer's access, subject to account erasure and photo expiry. Removing access cannot recall a copy already viewed or saved. See Corporate workspaces.
What if the request was not confirmed?
Refresh your history before retrying. A network failure does not prove that a submission failed. The app reuses the request identifier when retrying unchanged details to avoid creating the same request twice.
If the app reports overlapping dates, check your pending and approved requests for that employer. If a workspace is unavailable, check that you joined it using the invited account. See Workspace invitations.