True Care SystemTrue Care SystemDocumentation
Return to Website
DocumentationSecuritySecurity Overview

SECURITY • PRIVACY • ACCOUNTABILITY

Security Overview

Privacy and public-documentation notice

Security and HIPAA screens may contain workforce identity, Provider information, IP addresses, access history, support-session data, and protected health information. Screenshots in this guide use masked, redacted, or demonstration content. Unmasked content should be treated as authorized demo data only.

Purpose

True Care System brings authentication, role-based authorization, Provider isolation, PHI access monitoring, login history, audit logging, temporary support access, and investigation-ready event detail into one coordinated security framework. The objective is to give healthcare Providers practical control over who may access the system, what each person may do, which Provider and records are in scope, and how sensitive activity can be reviewed after the fact.

The Security module is designed to support administrative, physical, and technical safeguard practices used by healthcare organizations. It does not replace a Provider's own risk analysis, workforce training, policies, legal review, or incident-response obligations.

True Care System security overview using login history, user management, role control, audit logs, PHI monitoring, and support-session evidence.
True Care System security overview using login history, user management, role control, audit logs, PHI monitoring, and support-session evidence.

Security Architecture in Practice

1. Authenticate

Confirm the user through approved web or mobile sign-in workflows.

2. Authorize

Apply roles, permissions, Provider scope, and assigned-record scope.

3. Monitor

Capture login, PHI access, update, support, and administrative events.

4. Investigate

Review actor, target, IP, route, browser, device, old values, new values, and metadata.

Security Documentation

Authentication

Secure web and mobile sign-in workflows, identity verification, and authentication event capture.

Open Guide

Password Policy

Password change controls, credential hygiene, complexity requirements, and administrative reset practices.

Open Guide

Access Control

Role-based permissions, data scope, least privilege, user lifecycle management, and separation of duties.

Open Guide

Session Security

Login history, device and browser context, session accountability, and detection of suspicious access patterns.

Open Guide

Support Access and Impersonation

Provider-approved, time-limited Platform Support access with ticket linkage and audited impersonation sessions.

Open Guide

Security Monitoring

Centralized audit logs, PHI access monitoring, filters, exports, and investigation-ready event detail.

Open Guide

Security Incident Reporting

Security event review, evidence preservation, escalation, containment, correction, and follow-up workflow.

Open Guide

Security FAQ

Common questions regarding accounts, access, audit records, support sessions, PHI, passwords, and user responsibilities.

Open Guide

Key Security Capabilities

CapabilityHow True Care System applies itProvider value
Individual user accountsUsers are created, assigned roles, reset, deactivated, and reviewed individually.Improves accountability and avoids shared-account ambiguity.
Role-based access controlMenu visibility and operational permissions are controlled by role and action groups.Supports least privilege and separation of duties.
Provider isolationAccess is constrained to the authenticated Provider scope through backend enforcement.Protects multi-tenant confidentiality.
PHI access monitoringRecords include user, role, Provider, Individual, module, action, purpose, decision, minimum necessary, IP, and device.Supports privacy oversight and investigation.
Audited support accessProvider-approved support access is ticket-linked, time-limited, reason-based, and session-audited.Creates controlled assistance without silent access.
Change historyAudit detail may show old values, new values, route, HTTP method, actor, target, device, and metadata.Improves traceability and incident review.