HIPAA COMPLIANCE FRAMEWORK
Support Sessions
Documents approved Provider support access, impersonation, expiration, ticket scope, and audit expectations.
These pages describe True Care System functionality and operating expectations. They do not replace Provider policies, legal advice, risk analysis, workforce training, contracts, or regulatory obligations. Use minimum-necessary access and protect PHI in screenshots, exports, tickets, messages, and reports.
Purpose
Documents approved Provider support access, impersonation, expiration, ticket scope, and audit expectations.
Core Requirements
Provider Approval
Support access should require explicit Provider authorization.
Ticket Linkage
Each session should be tied to a support ticket and approved purpose.
Time Limit
Access should expire automatically and end immediately when no longer needed.
Scope
Support should remain within the correct Provider and approved module or issue.
Audit
Record start, end, actor, Provider, ticket, impersonated user, and material actions.
Operational Review Checklist
| Review Area | Expectation |
|---|---|
| Provider Scope | Confirm the correct Provider before viewing, changing, exporting, or investigating records. |
| Authorized Purpose | Confirm the user’s role, approved purpose, and minimum-necessary scope. |
| Evidence | Retain relevant timestamps, actors, targets, identifiers, IP addresses, devices, reasons, and results. |
| Escalation | Escalate unexpected, denied, suspicious, cross-Provider, bulk, or high-risk activity. |
| Documentation | Record decisions, corrective action, validation, and required follow-up. |