Last updated: July 24, 2026
· Source: policies-procedures/Procedure/Data Security and Breach Notification Procedure.md
REFUGE HOUSE, INC.
| Procedure Information |
Details |
| PROCEDURE NAME |
Data Security & Breach Notification Procedure |
| PROCEDURE NUMBER |
IT-SEC-01.1 |
| RELATED POLICY |
IT-SEC-01 Data Security & Breach Notification Policy |
| EFFECTIVE DATE |
5/22/2026 |
| REVISION DATE |
6/18/26 |
| LAST UPDATED |
5/15/2026 |
| LAST APPROVED |
5/22/2026 |
PURPOSE
To operationalize IT-SEC-01 — the data-security program (controls, training, vendors) and the incident/breach detection, assessment, notification, and documentation workflow.
A. SECURITY PROGRAM (ongoing)
| Who |
Action |
Cadence |
Standard |
| Information Security Official |
Maintain the written security/privacy program + incident-response plan; adopt the NIST SP 800-53 baseline; complete/refresh the HHS SPI |
At adoption; reviewed annually |
HHS DUA §3.01(Q),(V)–(W) |
| Information Security Official |
Conduct a security risk assessment (threats/vulnerabilities; remediation plan) |
Annually + on significant change |
45 CFR §164.308(a)(1) |
| IT Administrator |
Operate technical/access controls — Azure AD MFA/2FA, jurisdiction-based Radius access, encryption in transit/at rest, Azure Security Center monitoring, backup validation |
Continuous (per IT-001.1) |
HHS DUA §3.01(Y); 45 CFR §164.312 |
| IT Administrator |
Maintain the Authorized-User roster (name, title, date bound); reconcile against quarterly access reviews |
Quarterly |
HHS DUA §3.01(U) |
| Privacy/Security Official |
Produce proof of encryption to HHS on request |
Within 48 hours of request |
HHS DUA §3.01(Y) |
| Department Managers |
Ensure workforce/caregiver security & privacy training; retain evidence |
Orientation + annually |
HHS DUA §3.01(B) |
| Privacy/Security Official |
Before any vendor accesses PHI/confidential data, execute a BAA / HHS Subcontractor Agreement; record in the BAA inventory |
Before access |
HHS DUA §3.01(F); 45 CFR §164.314 |
B. INCIDENT DETECTION & TRIAGE
| Who |
Action |
Timeframe |
Standard |
| Any workforce member/caregiver |
Report a suspected event (lost device, misdirected email/fax, unauthorized access, malware, exposed credentials) to the Information Security Official |
Immediately |
IT-SEC-01 §8 |
| Information Security Official |
Contain (disable accounts, isolate device/system, revoke access, preserve logs) and open an incident record |
Upon notice |
45 CFR §164.308(a)(6) |
| Information Security Official |
Triage severity and whether confidential information/PHI was involved |
Within hours of containment |
IT-SEC-01 §8 |
C. BREACH DETERMINATION
| Who |
Action |
Standard |
| Privacy Official |
Apply the HIPAA four-factor risk assessment (nature/extent of data; who accessed/received; whether actually acquired/viewed; extent of mitigation) to determine whether a reportable breach occurred |
45 CFR §164.402 |
| Privacy Official |
Document the determination and rationale (breach vs. low-probability-of-compromise) |
45 CFR §164.402; §164.316 |
D. NOTIFICATION (when a reportable breach/event is confirmed)
| Recipient |
Timeframe |
Standard |
| HHS — initial notice (single point of contact) |
1 hour (federal information) / 24 hours (other confidential information) of discovery |
HHS DUA §4.01(C) |
| HHS — formal report (required elements) |
Within 48 hours of discovery |
HHS DUA §4.01(C) |
| Affected individuals / legal representatives (PHI) |
Without unreasonable delay, ≤60 days |
45 CFR §164.404 |
| HHS Secretary (OCR) (PHI) |
Per rule (≤60 days if ≥500; annual log if <500) |
45 CFR §164.408 |
| Media (PHI) |
If >500 individuals in a state/jurisdiction |
45 CFR §164.406 |
| Texas Attorney General |
If ≥250 Texans affected |
Tex. Bus. & Com. Code §521.053 |
| DFPS / SSCC + FC-SIR-01 |
Per child-incident timeframes |
FC-SIR-01; SSCC contract |
E. POST-INCIDENT
| Who |
Action |
Standard |
| Information Security Official |
Remediate root cause; update controls/risk assessment |
45 CFR §164.308(a)(8) |
| Privacy/Security Official |
Apply sanctions for any workforce violation; document |
HHS DUA §3.01(C); 45 CFR §164.530(e) |
| Privacy Official |
Retain all incident/breach documentation (assessment, notices, evidence) for at least 6 years |
45 CFR §164.316(b)(2) |
| Quality Development / CQI |
Review incident trends; feed into PQI |
FC-CQI-01 |
FORMS / ATTACHMENTS
- Incident report / log
- Breach four-factor risk-assessment worksheet
- Breach notification letter template(s)
- Authorized-User roster
- BAA / HHS Subcontractor Agreement template
REFERENCES
Same as Policy IT-SEC-01.
This procedure operationalizes IT-SEC-01. Mechanics still being built (incident-response tooling, automated logging, formal sanctions schedule) are implementation guidance, not a representation that each is fully operational.