RECORD PRESERVATION
Audit Retention
Plan retention, archival, access, legal hold, and secure disposal practices.
Audit records may contain workforce identities, Provider identifiers, Individual references, IP addresses, device details, routes, request metadata, support-session identifiers, and before-and-after values. Screenshots in this public guide use redacted or demonstration information. Production access must remain Provider-scoped, role-based, purpose-limited, and restricted to authorized personnel.
True Care System records audit evidence to support accountability, privacy review, security investigation, operational integrity, and Provider governance. These capabilities support—but do not replace—the Provider's policies, workforce training, risk analysis, legal obligations, incident response, and retention program.
Purpose
Audit retention ensures that accountability evidence remains available for operational review, security investigation, compliance oversight, disputes, and legal obligations. True Care System provides the technical audit record; each Provider must define and approve its own retention schedule based on applicable federal, state, payer, contract, employment, and program requirements.
Retention Governance
| Field | Function |
|---|---|
| Retention period | Define how long each event category must remain available. |
| Online availability | Determine which recent records remain immediately searchable. |
| Archive | Move older records to controlled storage without breaking integrity. |
| Legal hold | Prevent deletion of records relevant to litigation, investigation, complaint, or regulatory review. |
| Access control | Limit archived and retained evidence to authorized roles. |
| Integrity | Preserve timestamps, identifiers, event context, and before-and-after values. |
| Backup and recovery | Ensure retained audit evidence can be restored after an outage or disaster. |
| Secure disposal | Destroy expired evidence using approved methods when no hold or obligation remains. |
Provider Responsibilities
- Approve a written retention schedule.
- Coordinate compliance, legal, security, HR, billing, and program requirements.
- Document exceptions and legal holds.
- Periodically test retrieval and restoration.
- Review retention settings after regulatory or contractual changes.
