HIPAA COMPLIANCE FRAMEWORK
PHI Access History
Documents how supported PHI access events are recorded and reviewed.
These pages describe True Care System functionality and operating expectations. They do not replace Provider policies, legal advice, risk analysis, workforce training, contracts, or regulatory obligations. Use minimum-necessary access and protect PHI in screenshots, exports, tickets, messages, and reports.
Purpose
Documents how supported PHI access events are recorded and reviewed.
System Screenshot
Core Requirements
Actor
Capture user, role, Provider, session, and impersonation context.
Target
Capture Individual, record, module, action, and resource context.
Purpose
Record treatment, payment, health care operations, support, compliance, or another approved purpose.
Decision
Record allowed, denied, blocked, or otherwise evaluated access.
Context
Capture time, IP address, device, browser, source, and minimum-necessary status where available.
Operational Review Checklist
| Review Area | Expectation |
|---|---|
| Provider Scope | Confirm the correct Provider before viewing, changing, exporting, or investigating records. |
| Authorized Purpose | Confirm the user’s role, approved purpose, and minimum-necessary scope. |
| Evidence | Retain relevant timestamps, actors, targets, identifiers, IP addresses, devices, reasons, and results. |
| Escalation | Escalate unexpected, denied, suspicious, cross-Provider, bulk, or high-risk activity. |
| Documentation | Record decisions, corrective action, validation, and required follow-up. |