HIPAA COMPLIANCE FRAMEWORK
Security Events
Documents detection, review, investigation, classification, containment, and closure of security events.
These pages describe True Care System functionality and operating expectations. They do not replace Provider policies, legal advice, risk analysis, workforce training, contracts, or regulatory obligations. Use minimum-necessary access and protect PHI in screenshots, exports, tickets, messages, and reports.
Purpose
Documents detection, review, investigation, classification, containment, and closure of security events.
Core Requirements
Event Type
Classify authentication, authorization, export, support, data integrity, availability, or policy events.
Severity
Assign Low, Medium, High, or Critical based on impact and scope.
Evidence
Preserve logs, timestamps, IP addresses, devices, identifiers, screenshots, and actions.
Containment
Use the smallest safe step to stop further risk.
Closure
Document cause, impact, remediation, validation, and preventive action.
Operational Review Checklist
| Review Area | Expectation |
|---|---|
| Provider Scope | Confirm the correct Provider before viewing, changing, exporting, or investigating records. |
| Authorized Purpose | Confirm the user’s role, approved purpose, and minimum-necessary scope. |
| Evidence | Retain relevant timestamps, actors, targets, identifiers, IP addresses, devices, reasons, and results. |
| Escalation | Escalate unexpected, denied, suspicious, cross-Provider, bulk, or high-risk activity. |
| Documentation | Record decisions, corrective action, validation, and required follow-up. |