Procedure

Data Security and Breach Notification Procedure

Refuge House, Inc.
Last updated: July 24, 2026 · Source: policies-procedures/Procedure/Data Security and Breach Notification Procedure.md

REFUGE HOUSE, INC.

Procedure Information Details
PROCEDURE NAME Data Security & Breach Notification Procedure
PROCEDURE NUMBER IT-SEC-01.1
RELATED POLICY IT-SEC-01 Data Security & Breach Notification Policy
EFFECTIVE DATE 5/22/2026
REVISION DATE 6/18/26
LAST UPDATED 5/15/2026
LAST APPROVED 5/22/2026

PURPOSE

To operationalize IT-SEC-01 — the data-security program (controls, training, vendors) and the incident/breach detection, assessment, notification, and documentation workflow.

A. SECURITY PROGRAM (ongoing)

Who Action Cadence Standard
Information Security Official Maintain the written security/privacy program + incident-response plan; adopt the NIST SP 800-53 baseline; complete/refresh the HHS SPI At adoption; reviewed annually HHS DUA §3.01(Q),(V)–(W)
Information Security Official Conduct a security risk assessment (threats/vulnerabilities; remediation plan) Annually + on significant change 45 CFR §164.308(a)(1)
IT Administrator Operate technical/access controls — Azure AD MFA/2FA, jurisdiction-based Radius access, encryption in transit/at rest, Azure Security Center monitoring, backup validation Continuous (per IT-001.1) HHS DUA §3.01(Y); 45 CFR §164.312
IT Administrator Maintain the Authorized-User roster (name, title, date bound); reconcile against quarterly access reviews Quarterly HHS DUA §3.01(U)
Privacy/Security Official Produce proof of encryption to HHS on request Within 48 hours of request HHS DUA §3.01(Y)
Department Managers Ensure workforce/caregiver security & privacy training; retain evidence Orientation + annually HHS DUA §3.01(B)
Privacy/Security Official Before any vendor accesses PHI/confidential data, execute a BAA / HHS Subcontractor Agreement; record in the BAA inventory Before access HHS DUA §3.01(F); 45 CFR §164.314

B. INCIDENT DETECTION & TRIAGE

Who Action Timeframe Standard
Any workforce member/caregiver Report a suspected event (lost device, misdirected email/fax, unauthorized access, malware, exposed credentials) to the Information Security Official Immediately IT-SEC-01 §8
Information Security Official Contain (disable accounts, isolate device/system, revoke access, preserve logs) and open an incident record Upon notice 45 CFR §164.308(a)(6)
Information Security Official Triage severity and whether confidential information/PHI was involved Within hours of containment IT-SEC-01 §8

C. BREACH DETERMINATION

Who Action Standard
Privacy Official Apply the HIPAA four-factor risk assessment (nature/extent of data; who accessed/received; whether actually acquired/viewed; extent of mitigation) to determine whether a reportable breach occurred 45 CFR §164.402
Privacy Official Document the determination and rationale (breach vs. low-probability-of-compromise) 45 CFR §164.402; §164.316

D. NOTIFICATION (when a reportable breach/event is confirmed)

Recipient Timeframe Standard
HHS — initial notice (single point of contact) 1 hour (federal information) / 24 hours (other confidential information) of discovery HHS DUA §4.01(C)
HHS — formal report (required elements) Within 48 hours of discovery HHS DUA §4.01(C)
Affected individuals / legal representatives (PHI) Without unreasonable delay, ≤60 days 45 CFR §164.404
HHS Secretary (OCR) (PHI) Per rule (≤60 days if ≥500; annual log if <500) 45 CFR §164.408
Media (PHI) If >500 individuals in a state/jurisdiction 45 CFR §164.406
Texas Attorney General If ≥250 Texans affected Tex. Bus. & Com. Code §521.053
DFPS / SSCC + FC-SIR-01 Per child-incident timeframes FC-SIR-01; SSCC contract

E. POST-INCIDENT

Who Action Standard
Information Security Official Remediate root cause; update controls/risk assessment 45 CFR §164.308(a)(8)
Privacy/Security Official Apply sanctions for any workforce violation; document HHS DUA §3.01(C); 45 CFR §164.530(e)
Privacy Official Retain all incident/breach documentation (assessment, notices, evidence) for at least 6 years 45 CFR §164.316(b)(2)
Quality Development / CQI Review incident trends; feed into PQI FC-CQI-01

FORMS / ATTACHMENTS

REFERENCES

Same as Policy IT-SEC-01.


This procedure operationalizes IT-SEC-01. Mechanics still being built (incident-response tooling, automated logging, formal sanctions schedule) are implementation guidance, not a representation that each is fully operational.