HIPAA COMPLIANCE FRAMEWORK
Minimum Necessary
Defines how roles, purposes, fields, exports, support access, and workflow design should limit PHI exposure.
These pages describe True Care System functionality and operating expectations. They do not replace Provider policies, legal advice, risk analysis, workforce training, contracts, or regulatory obligations. Use minimum-necessary access and protect PHI in screenshots, exports, tickets, messages, and reports.
Purpose
Defines how roles, purposes, fields, exports, support access, and workflow design should limit PHI exposure.
Core Requirements
Role Scope
Grant only modules and actions required for approved duties.
Record Scope
Limit access to the correct Provider, Individual, date range, location, and workflow.
Field Scope
Avoid displaying unnecessary PHI in lists, alerts, exports, screenshots, and support tickets.
Support Scope
Time-limit and ticket-link Provider-authorized support sessions.
Review
Periodically review roles, permissions, exports, and unusual access.
Operational Review Checklist
| Review Area | Expectation |
|---|---|
| Provider Scope | Confirm the correct Provider before viewing, changing, exporting, or investigating records. |
| Authorized Purpose | Confirm the user’s role, approved purpose, and minimum-necessary scope. |
| Evidence | Retain relevant timestamps, actors, targets, identifiers, IP addresses, devices, reasons, and results. |
| Escalation | Escalate unexpected, denied, suspicious, cross-Provider, bulk, or high-risk activity. |
| Documentation | Record decisions, corrective action, validation, and required follow-up. |