True Care SystemTrue Care SystemDocumentation
Return to Website

RECORD PRESERVATION

Audit Retention

Plan retention, archival, access, legal hold, and secure disposal practices.

Privacy, HIPAA, and audit-evidence notice

Audit records may contain workforce identities, Provider identifiers, Individual references, IP addresses, device details, routes, request metadata, support-session identifiers, and before-and-after values. Screenshots in this public guide use redacted or demonstration information. Production access must remain Provider-scoped, role-based, purpose-limited, and restricted to authorized personnel.

Audit evidence and Provider governance

True Care System records audit evidence to support accountability, privacy review, security investigation, operational integrity, and Provider governance. These capabilities support—but do not replace—the Provider's policies, workforce training, risk analysis, legal obligations, incident response, and retention program.

Purpose

Audit retention ensures that accountability evidence remains available for operational review, security investigation, compliance oversight, disputes, and legal obligations. True Care System provides the technical audit record; each Provider must define and approve its own retention schedule based on applicable federal, state, payer, contract, employment, and program requirements.

Retention Governance

FieldFunction
Retention periodDefine how long each event category must remain available.
Online availabilityDetermine which recent records remain immediately searchable.
ArchiveMove older records to controlled storage without breaking integrity.
Legal holdPrevent deletion of records relevant to litigation, investigation, complaint, or regulatory review.
Access controlLimit archived and retained evidence to authorized roles.
IntegrityPreserve timestamps, identifiers, event context, and before-and-after values.
Backup and recoveryEnsure retained audit evidence can be restored after an outage or disaster.
Secure disposalDestroy expired evidence using approved methods when no hold or obligation remains.

Provider Responsibilities

  • Approve a written retention schedule.
  • Coordinate compliance, legal, security, HR, billing, and program requirements.
  • Document exceptions and legal holds.
  • Periodically test retrieval and restoration.
  • Review retention settings after regulatory or contractual changes.