True Care SystemTrue Care SystemDocumentation
Return to Website
Documentation/Admin/Role Management

PROVIDER ADMINISTRATION

Role Management

Define, review, and maintain role-based permissions and minimum-necessary administrative access.

Privacy, security, and administrative access notice

Administrative pages may display workforce identity, Provider identifiers, contact information, organizational assignments, role permissions, and access-control data. Public screenshots use redacted or demonstration information.

Purpose

Role Management is the central access-governance workspace for defining what each workforce role may view, create, update, approve, export, or administer. It supports Provider-level access control across operational, clinical, financial, payroll, support, and compliance workflows.

Core Controls

  • Role definition: maintain clear role names and approved business purpose.
  • Permission scope: assign only the modules and actions required for the role.
  • Least privilege: avoid granting administrative or clinical access that is not necessary.
  • Minimum necessary: limit PHI access to the smallest reasonable scope for the documented duty.
  • Separation of duties: reduce conflicts between payroll, billing, approvals, compliance, and user administration.
  • Role review: periodically review assignments after transfers, promotions, leave, or termination.
  • Auditability: preserve role changes for review through HIPAA Audit Logs.

Recommended Workflow

  1. Review the employee’s current job description and approved duties.
  2. Select an existing role or create an approved role configuration.
  3. Review module-level and action-level permissions.
  4. Confirm PHI access is limited to minimum necessary use.
  5. Assign the role to the user.
  6. Validate the user can access required workspaces and cannot access restricted areas.
  7. Review the resulting change in Audit Logs.
Role Management screen
Role Management workspace in True Care System.

Admin Guides

FunctionPurposeDocumentation
UsersCreate and maintain Provider user accounts, status, password resets, and role assignments.Open Guide →
Role ManagementDefine role-based permissions, access scope, least privilege, and separation of duties.Current guide
Department ManagementCreate departments, assign managers, and organize employees for KPI and approvals.Open Guide →
AnnouncementsSend role-targeted internal communications.Open Guide →
Branches / LocationsMaintain regions, branches, offices, addresses, codes, and status.Open Guide →
Change PasswordUpdate authenticated-user credentials securely.Open Guide →
Provider ProfileMaintain Provider identity, branding, contacts, identifiers, alerts, and defaults.Open Guide →

Security, HIPAA, and Audit Expectations

  • Verify the correct Provider scope before changing data.
  • Grant only access necessary for approved duties.
  • Use Role Management to enforce least privilege and minimum necessary access.
  • Do not include credentials, SSNs, full payment data, or unnecessary PHI.
  • Use deactivation instead of deleting records required for accountability.
  • Review significant changes through Audit Logs.