True Care SystemTrue Care SystemDocumentation
Return to Website

AUTHENTICATION EVIDENCE

Login Events

Review successful, failed, blocked, and session-related authentication activity.

Privacy, HIPAA, and audit-evidence notice

Audit records may contain workforce identities, Provider identifiers, Individual references, IP addresses, device details, routes, request metadata, support-session identifiers, and before-and-after values. Screenshots in this public guide use redacted or demonstration information. Production access must remain Provider-scoped, role-based, purpose-limited, and restricted to authorized personnel.

Audit evidence and Provider governance

True Care System records audit evidence to support accountability, privacy review, security investigation, operational integrity, and Provider governance. These capabilities support—but do not replace—the Provider's policies, workforce training, risk analysis, legal obligations, incident response, and retention program.

Purpose

Login events help authorized reviewers identify who attempted to access the platform, whether authentication succeeded, what device and browser were used, and whether the attempt should be investigated.

Common Login Event Types

FieldFunction
Successful loginRecords a completed authentication event and the identity, Provider, device, browser, IP address, and session context.
Failed loginRecords an unsuccessful sign-in attempt and supports review of repeated failures or credential issues.
Blocked attemptRecords an attempt denied by account status, security controls, policy, or another protective condition.
Password resetRecords the security workflow used to reset or change credentials.
Session createdRecords creation of an authenticated session after successful verification.
Session endedRecords logout, expiration, administrative termination, or another session-ending event.

Review Procedure

  • Confirm the user, Provider, date/time, and status.
  • Compare IP address, location, browser, device, and operating system with expected patterns.
  • Look for repeated failed attempts, unusual timing, or unexpected device changes.
  • Correlate suspicious activity with Audit Logs, Security, Support, and user account status.
  • Escalate according to the Provider's incident-response and workforce-security procedures.