QUALITY ASSURANCE • TRUE CARE SYSTEM
HIPAA Testing
Validate PHI access controls, minimum-necessary behavior, auditability, and compliance evidence.
QA artifacts may contain workforce identity, Provider configuration, PHI, GPS, visit, payroll, billing, audit, or integration evidence. Public documentation and shared test evidence must use synthetic, demonstration, or properly redacted information. Never place production passwords, tokens, full SSNs, bank account numbers, or unnecessary PHI in screenshots, tickets, automated test output, or repositories.
Purpose
HIPAA testing verifies that True Care System technical behavior supports Provider privacy, security, minimum-necessary, audit, and incident-response obligations. Software controls support compliance but do not replace Provider policies, training, risk analysis, or legal review.
Required PHI Access Evidence
| Evidence | Expected validation |
|---|---|
| Actor | Authenticated user and role are recorded. |
| Provider | The event is stored and displayed only in the correct Provider scope. |
| Individual | The affected Individual is linked when applicable. |
| Module and action | The exact workflow and operation are identifiable. |
| Purpose of use | Treatment, Payment, Health Care Operations, or other approved purpose is recorded. |
| Access decision | Allowed, denied, or review-required outcome is recorded. |
| Minimum necessary | The compliance status is captured for the role-gated workflow. |
| Request context | Date/time, route, method, request ID, IP, browser, device, and OS are captured when available. |
| Change evidence | Old and new values are retained for audited changes when applicable. |
| Support context | Support ticket and impersonation session are linked during approved support. |
