True Care System True Care SystemDocumentation
Return to Website
Documentation/ HIPAA/ Security Events

HIPAA COMPLIANCE FRAMEWORK

Security Events

Documents detection, review, investigation, classification, containment, and closure of security events.

Privacy, security, legal, and Provider responsibility notice

These pages describe True Care System functionality and operating expectations. They do not replace Provider policies, legal advice, risk analysis, workforce training, contracts, or regulatory obligations. Use minimum-necessary access and protect PHI in screenshots, exports, tickets, messages, and reports.

Purpose

Documents detection, review, investigation, classification, containment, and closure of security events.

Core Requirements

Event Type

Classify authentication, authorization, export, support, data integrity, availability, or policy events.

Severity

Assign Low, Medium, High, or Critical based on impact and scope.

Evidence

Preserve logs, timestamps, IP addresses, devices, identifiers, screenshots, and actions.

Containment

Use the smallest safe step to stop further risk.

Closure

Document cause, impact, remediation, validation, and preventive action.

Operational Review Checklist

Review AreaExpectation
Provider ScopeConfirm the correct Provider before viewing, changing, exporting, or investigating records.
Authorized PurposeConfirm the user’s role, approved purpose, and minimum-necessary scope.
EvidenceRetain relevant timestamps, actors, targets, identifiers, IP addresses, devices, reasons, and results.
EscalationEscalate unexpected, denied, suspicious, cross-Provider, bulk, or high-risk activity.
DocumentationRecord decisions, corrective action, validation, and required follow-up.

Related Documentation