True Care SystemTrue Care SystemDocumentation
Return to Website

COMMON QUESTIONS

Audit Logs FAQ

Answers to common questions about access, visibility, exports, evidence, and investigations.

Privacy, HIPAA, and audit-evidence notice

Audit records may contain workforce identities, Provider identifiers, Individual references, IP addresses, device details, routes, request metadata, support-session identifiers, and before-and-after values. Screenshots in this public guide use redacted or demonstration information. Production access must remain Provider-scoped, role-based, purpose-limited, and restricted to authorized personnel.

Audit evidence and Provider governance

True Care System records audit evidence to support accountability, privacy review, security investigation, operational integrity, and Provider governance. These capabilities support—but do not replace—the Provider's policies, workforce training, risk analysis, legal obligations, incident response, and retention program.

Frequently Asked Questions

Who can view Audit Logs?

Only authorized roles within the appropriate Provider or platform scope should have access.

Can one Provider see another Provider's events?

No. Provider isolation should be enforced by the backend unless a separately authorized platform workflow is used.

What is the difference between User, Actor, and Target?

User is the authenticated identity, Actor is the person performing the action, and Target is the account or record affected.

Why are old and new values important?

They show exactly how a record changed and support integrity review.

Are exports audited?

They should be. Exporting sensitive evidence is itself an auditable action.

Can audit records be edited?

Audit evidence should be protected from routine modification. Corrections should be handled through controlled governance procedures.

How are support sessions traced?

Support ticket and impersonation session identifiers connect actions to approved support access.

Do Audit Logs alone guarantee compliance?

No. They support compliance, but Provider policies, training, access governance, contracts, risk analysis, and incident response remain essential.

What should be reviewed first?

Start with Provider scope, user identity, date/time, module, action, status, severity, and affected entity.