True Care SystemTrue Care SystemDocumentation
Return to Website

SUPPORT SESSION ACCOUNTABILITY

Impersonation Events

Trace approved support access and Login-as-Provider sessions.

Privacy, HIPAA, and audit-evidence notice

Audit records may contain workforce identities, Provider identifiers, Individual references, IP addresses, device details, routes, request metadata, support-session identifiers, and before-and-after values. Screenshots in this public guide use redacted or demonstration information. Production access must remain Provider-scoped, role-based, purpose-limited, and restricted to authorized personnel.

Audit evidence and Provider governance

True Care System records audit evidence to support accountability, privacy review, security investigation, operational integrity, and Provider governance. These capabilities support—but do not replace—the Provider's policies, workforce training, risk analysis, legal obligations, incident response, and retention program.

Purpose

Impersonation events document when an authorized platform support user temporarily enters a Provider context to investigate an approved ticket. The audit trail should preserve who initiated the session, which Provider and target account were used, the related support ticket, the session start and end, and actions performed during the session.

Expected Evidence

FieldFunction
Support ticket IDConnects the session to the Provider's request.
Access approvalShows whether the Provider approved support access.
ExpirationDefines when approval becomes invalid.
Actor userIdentifies the platform support person.
Target user or ProviderIdentifies the account or tenant being accessed.
Impersonation session IDCorrelates all actions performed in the same session.
Start and end eventsEstablishes the session duration.
Actions during sessionLinks views, updates, exports, or other activities to the impersonation session.

Security Expectations

  • No support access without a valid business purpose and authorization.
  • Provider scope must remain enforced throughout the session.
  • All material actions must remain attributable to the real actor.
  • Expired approvals must not permit new access.
  • Session termination must be recorded.