Policy

Data Security and Breach Notification Policy

Refuge House, Inc.
Last updated: July 24, 2026 · Source: policies-procedures/Policy/Data Security and Breach Notification Policy.md

REFUGE HOUSE, INC.

Policy Information Details
POLICY NAME Data Security & Breach Notification Policy
POLICY NUMBER IT-SEC-01
RELATED PROCEDURE IT-SEC-01.1 Data Security & Breach Notification Procedure
RELATED DOCUMENTS IT-001 Information Technology Data Management and Security Policy; IT-001.1 IT System Access and Security Procedures; IT-MIS-01 MIS & HIPAA Policy and Procedures; FC-SIR-01 Serious Incident Reporting
EFFECTIVE DATE 5/22/2026
REVISION DATE 6/18/26
LAST UPDATED 5/15/2026
LAST APPROVED 5/22/2026
DATE ADOPTED 5/22/2026
REVIEW DATE 5/22/2027

PURPOSE

To protect the confidentiality, integrity, and availability of Refuge House information — including confidential child-welfare records and protected health information (PHI) — and to define how Refuge House prevents, detects, responds to, and reports security incidents and breaches. This policy formalizes the data-security and breach obligations of the Texas HHS Data Use Agreement (DUA) that Refuge House executes through its DFPS/SSCC contracts.

SCOPE

Applies to all employees, contractors, volunteers, and caregivers, and to all Refuge House information, systems, devices, and service providers (26 TAC §749.138(b)). Technical and access controls are operated under IT-001 and IT-001.1; this policy is the governing data-security and breach umbrella.

GOVERNING FRAMEWORK

POLICY

  1. Designated officials. Refuge House designates a Privacy Official and an Information Security Official responsible for the development and implementation of privacy and security requirements (HHS DUA §3.01(S)). *Implementation note: these functions, with the IT Administrator role, are currently consolidated in a single designated official (Jeannie Duarte); separation of duties is a planned control improvement as the agency grows.*

  2. Written program & risk assessment. Refuge House maintains written privacy, security, and breach policies and an incident-response plan (HHS DUA §3.01(V)–(W)), and adopts the NIST SP 800-53 control baseline and completes the HHS Security & Privacy Inquiry (SPI) (HHS DUA §3.01(Q)). A security risk assessment is conducted at least annually and upon significant change (45 CFR §164.308(a)(1)).

  3. Safeguards. Administrative, physical, and technical safeguards are maintained per IT-001 / IT-001.1 (45 CFR §§164.308/.310/.312): Microsoft Azure cloud infrastructure (all data resources are cloud-based and Azure-controlled — no on-site servers); Azure AD with multi-factor / two-stage authentication (2FA rollout in progress); jurisdiction-based access in Radius; access only through Refuge House-managed secure environments (VDI, Pulse, approved secured browser); continuous monitoring via Azure Security Center.

  4. Encryption. Confidential data is encrypted in transit and at rest (Azure enterprise encryption; SFTP/TLS for transfers); proof of encryption is producible to HHS within 48 hours of request (HHS DUA §3.01(Y)).

  5. Authorized-user roster. Refuge House maintains a numbered, signed list of Authorized Users — name, title, and date each agreed to be bound (HHS DUA §3.01(U)).

  6. Workforce training & sanctions. Workforce members and caregivers complete confidentiality, privacy, and security training at orientation and annually, with evidence retained (HHS DUA §3.01(B)); violations are subject to documented sanctions up to termination (HHS DUA §3.01(C); 45 CFR §164.530(e)). Good-faith reporting is protected from retaliation.

  7. Service providers / business associates. Any vendor that creates, receives, stores, or transmits PHI or confidential information first executes a Business Associate Agreement / HHS Subcontractor Agreement binding it to equivalent terms (HHS DUA §3.01(F); 45 CFR §164.314). Presently, no external vendor has access to Refuge House-owned PHI; Twilio/SendGrid process communications data only (see IT-MIS-01 §9).

  8. Incident & breach response. Security events and breaches are detected, contained, assessed, and reported under the incident-response plan and the notification timeframes in §9. A breach risk assessment uses the HIPAA four-factor analysis (45 CFR §164.402). Child-specific incidents also follow FC-SIR-01 and the applicable SSCC channel.

  9. Breach notification. On discovery of a breach or reportable event, Refuge House provides initial notice — federal information within 1 hour, other confidential information within 24 hours — designates a single point of contact, and submits the formal report (required elements) within 48 hours to the HHS privacy mailbox (HHS DUA §4.01(C)). Where PHI is involved, Refuge House also notifies affected individuals/legal representatives without unreasonable delay and no later than 60 days (45 CFR §164.404), the HHS Secretary (45 CFR §164.408), and media if more than 500 individuals in a jurisdiction are affected (45 CFR §164.406); the Texas Attorney General is notified if at least 250 Texans are affected (Tex. Bus. & Com. Code §521.053).

  10. Records & retention. Case records are retained perpetually (no routine destruction); on contract termination, confidential information is returned or destroyed with written certification except where retention or a litigation hold applies (HHS DUA §3.01(O)–(P)). Security and breach documentation is retained at least six (6) years (45 CFR §164.316(b)(2)).

DEFINITIONS

Breach — acquisition, access, use, or disclosure of confidential information/PHI not permitted by law or contract that compromises its security or privacy. Event — a suspected or actual security incident. PHI — protected health information. (System/term definitions are in IT-001.)

REFERENCES

Texas HHS Data Use Agreement (§§3.01(B),(C),(F),(O)–(Q),(S),(U),(V)–(W),(Y); 4.01(C)); HIPAA 45 CFR §§164.308, 164.310, 164.312, 164.314, 164.316, 164.402, 164.404, 164.406, 164.408, 164.530(e); Tex. Bus. & Com. Code §521.053; NIST SP 800-53; 26 TAC §§749.531, 749.533; DFPS RCC Contract (FY26). Companion: IT-001; IT-001.1; IT-MIS-01; FC-SIR-01.


Policies require governing-body approval and remain relatively stable; the companion procedure (IT-SEC-01.1) may be updated by the Executive Director to reflect operational or regulatory changes consistent with this policy's intent.