SECURITY • PRIVACY • ACCOUNTABILITY
Security FAQ
Security and HIPAA screens may contain workforce identity, Provider information, IP addresses, access history, support-session data, and protected health information. Screenshots in this guide use masked, redacted, or demonstration content. Unmasked content should be treated as authorized demo data only.
Frequently Asked Questions
Does True Care System use shared user accounts?
Provider organizations should create individually assigned accounts so actions can be attributed to the correct workforce member.
Why do different users see different menus?
Menu visibility and available actions depend on assigned roles, permissions, Provider scope, and configured data scope.
Can Platform Support enter a Provider account at any time?
The documented workflow uses a Provider-created ticket, explicit temporary access approval, expiration, reason, and an audited support session.
What does PHI Access Monitoring record?
Available records may include user, role, Provider, Individual, module, action, purpose of use, access decision, minimum necessary status, IP address, and device.
What information appears in Audit Log Detail?
Depending on the event, detail may include actor, target, Provider, entity, route, HTTP method, browser, device, operating system, old values, new values, and metadata.
Does the Security module replace Provider policies?
No. It supports Provider safeguards but does not replace risk analysis, workforce training, contingency planning, legal review, incident response, or regulatory obligations.

