True Care SystemTrue Care SystemDocumentation
Return to Website
DocumentationSecuritySecurity Incident Reporting

SECURITY • PRIVACY • ACCOUNTABILITY

Security Incident Reporting

Privacy and public-documentation notice

Security and HIPAA screens may contain workforce identity, Provider information, IP addresses, access history, support-session data, and protected health information. Screenshots in this guide use masked, redacted, or demonstration content. Unmasked content should be treated as authorized demo data only.

Purpose

Security Incident Reporting converts suspicious activity into a documented review process. True Care System audit detail provides evidence that can support triage, containment, investigation, correction, and follow-up.

Audit Log Detail showing actor, target, Provider, entity, IP, route, browser, device, operating system, old values, new values, and metadata.
Audit Log Detail showing actor, target, Provider, entity, IP, route, browser, device, operating system, old values, new values, and metadata.

Evidence Available for Review

EvidenceInvestigation value
Date, time, severity, and statusEstablishes chronology and event outcome.
User, actor, target, ProviderIdentifies who acted, on whose behalf, and within which tenant.
Individual, employee, entity type, entity IDIdentifies the affected record.
IP, browser, device, operating systemProvides access-context evidence.
HTTP method and routeShows the technical operation that was requested.
Old values and new valuesSupports change reconstruction.
Purpose, decision, minimum necessarySupports privacy and authorization review.
Support ticket and impersonation sessionLinks activity to approved support access when applicable.

Recommended Incident Workflow

  1. Record the report time, reporter, affected module, Provider, and suspected impact.
  2. Preserve relevant Audit Logs, Login History, PHI Access, support ticket, and session evidence.
  3. Restrict or deactivate compromised access when authorized.
  4. Escalate according to Provider policy.
  5. Document containment, correction, recovery, notifications, and follow-up.