True Care SystemTrue Care SystemDocumentation
Return to Website

PRIVACY RULE MONITORING

PHI Access Events

Review access to protected health information by user, Individual, module, purpose, and decision.

Privacy, HIPAA, and audit-evidence notice

Audit records may contain workforce identities, Provider identifiers, Individual references, IP addresses, device details, routes, request metadata, support-session identifiers, and before-and-after values. Screenshots in this public guide use redacted or demonstration information. Production access must remain Provider-scoped, role-based, purpose-limited, and restricted to authorized personnel.

Audit evidence and Provider governance

True Care System records audit evidence to support accountability, privacy review, security investigation, operational integrity, and Provider governance. These capabilities support—but do not replace—the Provider's policies, workforce training, risk analysis, legal obligations, incident response, and retention program.

Purpose

PHI Access Events document when protected health information is viewed, listed, printed, exported, created, updated, or otherwise accessed. They help the Provider review workforce access, purpose of use, access decisions, and minimum-necessary status.

Key Evidence

FieldFunction
User and roleIdentifies the workforce member and assigned authority.
ProviderConfirms the tenant that owns the PHI.
IndividualIdentifies the affected person where applicable.
Module and actionShows where and how the PHI was accessed.
Purpose of useSupports review of treatment, payment, health-care operations, or another documented purpose.
Access decisionShows whether access was allowed, denied, or requires review.
Minimum necessarySupports review of whether the access was limited to information reasonably needed for the documented purpose.
IP and deviceAdds technical context for investigation.

Examples

  • Viewing an Individual profile or medication order.
  • Opening a Daily Note, incident report, authorization, or visit record.
  • Printing or exporting a report containing PHI.
  • Reviewing PHI during an approved support session.
  • Access denied because the role or Provider scope was not authorized.
PHI audit detail
Detailed event evidence may include Individual references, purpose of use, access decision, and minimum-necessary metadata.