HIPAA COMPLIANCE FRAMEWORK
HIPAA Settings
Documents Provider-specific HIPAA configuration for contacts, logging, retention, alerts, incident ownership, and operational defaults.
These pages describe True Care System functionality and operating expectations. They do not replace Provider policies, legal advice, risk analysis, workforce training, contracts, or regulatory obligations. Use minimum-necessary access and protect PHI in screenshots, exports, tickets, messages, and reports.
Purpose
Documents Provider-specific HIPAA configuration for contacts, logging, retention, alerts, incident ownership, and operational defaults.
Core Requirements
Privacy Contacts
Maintain current privacy, security, compliance, legal, and incident-response contacts.
Logging
Configure supported audit and security logging without weakening traceability.
Retention
Define approved retention settings for logs, exports, incidents, and evidence.
Alerts
Configure appropriate recipients and severity thresholds.
Governance
Limit settings changes to authorized roles and audit every material change.
Operational Review Checklist
| Review Area | Expectation |
|---|---|
| Provider Scope | Confirm the correct Provider before viewing, changing, exporting, or investigating records. |
| Authorized Purpose | Confirm the user’s role, approved purpose, and minimum-necessary scope. |
| Evidence | Retain relevant timestamps, actors, targets, identifiers, IP addresses, devices, reasons, and results. |
| Escalation | Escalate unexpected, denied, suspicious, cross-Provider, bulk, or high-risk activity. |
| Documentation | Record decisions, corrective action, validation, and required follow-up. |