SECURITY • PRIVACY • ACCOUNTABILITY
Security Incident Reporting
Privacy and public-documentation notice
Security and HIPAA screens may contain workforce identity, Provider information, IP addresses, access history, support-session data, and protected health information. Screenshots in this guide use masked, redacted, or demonstration content. Unmasked content should be treated as authorized demo data only.
Purpose
Security Incident Reporting converts suspicious activity into a documented review process. True Care System audit detail provides evidence that can support triage, containment, investigation, correction, and follow-up.

Evidence Available for Review
| Evidence | Investigation value |
|---|---|
| Date, time, severity, and status | Establishes chronology and event outcome. |
| User, actor, target, Provider | Identifies who acted, on whose behalf, and within which tenant. |
| Individual, employee, entity type, entity ID | Identifies the affected record. |
| IP, browser, device, operating system | Provides access-context evidence. |
| HTTP method and route | Shows the technical operation that was requested. |
| Old values and new values | Supports change reconstruction. |
| Purpose, decision, minimum necessary | Supports privacy and authorization review. |
| Support ticket and impersonation session | Links activity to approved support access when applicable. |
Recommended Incident Workflow
- Record the report time, reporter, affected module, Provider, and suspected impact.
- Preserve relevant Audit Logs, Login History, PHI Access, support ticket, and session evidence.
- Restrict or deactivate compromised access when authorized.
- Escalate according to Provider policy.
- Document containment, correction, recovery, notifications, and follow-up.
