SECURITY • PRIVACY • ACCOUNTABILITY
Security Overview
Security and HIPAA screens may contain workforce identity, Provider information, IP addresses, access history, support-session data, and protected health information. Screenshots in this guide use masked, redacted, or demonstration content. Unmasked content should be treated as authorized demo data only.
Purpose
True Care System brings authentication, role-based authorization, Provider isolation, PHI access monitoring, login history, audit logging, temporary support access, and investigation-ready event detail into one coordinated security framework. The objective is to give healthcare Providers practical control over who may access the system, what each person may do, which Provider and records are in scope, and how sensitive activity can be reviewed after the fact.
The Security module is designed to support administrative, physical, and technical safeguard practices used by healthcare organizations. It does not replace a Provider's own risk analysis, workforce training, policies, legal review, or incident-response obligations.

Security Architecture in Practice
Confirm the user through approved web or mobile sign-in workflows.
Apply roles, permissions, Provider scope, and assigned-record scope.
Capture login, PHI access, update, support, and administrative events.
Review actor, target, IP, route, browser, device, old values, new values, and metadata.
Security Documentation
Authentication
Secure web and mobile sign-in workflows, identity verification, and authentication event capture.
Open GuidePassword Policy
Password change controls, credential hygiene, complexity requirements, and administrative reset practices.
Open GuideAccess Control
Role-based permissions, data scope, least privilege, user lifecycle management, and separation of duties.
Open GuideSession Security
Login history, device and browser context, session accountability, and detection of suspicious access patterns.
Open GuideSupport Access and Impersonation
Provider-approved, time-limited Platform Support access with ticket linkage and audited impersonation sessions.
Open GuideSecurity Monitoring
Centralized audit logs, PHI access monitoring, filters, exports, and investigation-ready event detail.
Open GuideSecurity Incident Reporting
Security event review, evidence preservation, escalation, containment, correction, and follow-up workflow.
Open GuideSecurity FAQ
Common questions regarding accounts, access, audit records, support sessions, PHI, passwords, and user responsibilities.
Open GuideKey Security Capabilities
| Capability | How True Care System applies it | Provider value |
|---|---|---|
| Individual user accounts | Users are created, assigned roles, reset, deactivated, and reviewed individually. | Improves accountability and avoids shared-account ambiguity. |
| Role-based access control | Menu visibility and operational permissions are controlled by role and action groups. | Supports least privilege and separation of duties. |
| Provider isolation | Access is constrained to the authenticated Provider scope through backend enforcement. | Protects multi-tenant confidentiality. |
| PHI access monitoring | Records include user, role, Provider, Individual, module, action, purpose, decision, minimum necessary, IP, and device. | Supports privacy oversight and investigation. |
| Audited support access | Provider-approved support access is ticket-linked, time-limited, reason-based, and session-audited. | Creates controlled assistance without silent access. |
| Change history | Audit detail may show old values, new values, route, HTTP method, actor, target, device, and metadata. | Improves traceability and incident review. |
