HIPAA COMPLIANCE FRAMEWORK
Export History
Documents review of reports, CSV, PDF, DOC, Excel, print, and other data exports that may contain PHI or sensitive information.
These pages describe True Care System functionality and operating expectations. They do not replace Provider policies, legal advice, risk analysis, workforce training, contracts, or regulatory obligations. Use minimum-necessary access and protect PHI in screenshots, exports, tickets, messages, and reports.
Purpose
Documents review of reports, CSV, PDF, DOC, Excel, print, and other data exports that may contain PHI or sensitive information.
Core Requirements
Export Type
Capture format, module, report, filter, and purpose.
Actor
Capture user, role, Provider, and session context.
Scope
Capture date range, Individuals, employees, locations, and selected records.
Risk
Review bulk, unusual, repeated, denied, or after-hours exports.
Protection
Use secure storage, approved transmission, minimum necessary, and appropriate retention.
Operational Review Checklist
| Review Area | Expectation |
|---|---|
| Provider Scope | Confirm the correct Provider before viewing, changing, exporting, or investigating records. |
| Authorized Purpose | Confirm the user’s role, approved purpose, and minimum-necessary scope. |
| Evidence | Retain relevant timestamps, actors, targets, identifiers, IP addresses, devices, reasons, and results. |
| Escalation | Escalate unexpected, denied, suspicious, cross-Provider, bulk, or high-risk activity. |
| Documentation | Record decisions, corrective action, validation, and required follow-up. |