Policy

Information Technology Data Management and Security Policy

Refuge House, Inc.
Last updated: July 24, 2026 · Source: policies-procedures/Policy/Information Technology Data Management and Security Policy.md

REFUGE HOUSE, INC.

Policy Information Details
POLICY NAME Information Technology Data Management and Security Policy
POLICY NUMBER IT-001-01
ORIGINATED March 2025
APPROVED BY Board of Directors
APPROVED ON [Pending]
EFFECTIVE DATE April 1, 2025
LAST UPDATED 5/15/2026
LAST APPROVED 5/22/2026
SECTION IT-001
DATE(S) OF REVISION N/A
## APPLICABLE T3C PACKAGES: ## APPLICABLE T3C ADD-ON SERVICES:
☒ T3C Basic Foster Family Home ☒ Transition Support Services for Youth & Young Adults
☐ Substance Use Support Services ☒ Kinship Caregiver Support Services
☐ Short-Term Assessment ☒ Pregnant & Parenting Youth or Young Adult
☐ Mental & Behavioral Health
☐ Sexual Aggression/Sex Offender
☐ Complex Medical Needs or Medically Fragile
☐ Human Trafficking Victim/Survivor
☐ Intellectual or Developmental Disability (IDD)/Autism Spectrum Disorder
☐ T3C Treatment Foster Family Care

PURPOSE

This policy establishes Refuge House's commitment to maintaining secure, accurate, and comprehensive information technology systems that support quality service delivery while ensuring compliance with T3C System Blueprint requirements, HIPAA regulations, and Texas child welfare standards. Our IT infrastructure serves as the backbone for implementing our TBRI®-informed approach to care, enabling real-time monitoring of child safety and well-being while supporting our foster families with accessible, secure tools.

POLICY

Refuge House maintains enterprise-grade information technology systems that exceed industry standards for child welfare agencies. We recognize that effective IT systems are essential for tracking outcomes, ensuring child safety, supporting caregivers, and maintaining compliance with regulatory requirements. Our technology infrastructure directly supports our mission by enabling data-driven decision-making and facilitating communication among all members of the care team.

Our IT systems will:

PACKAGE-SPECIFIC REQUIREMENTS

1. CORE REQUIREMENTS - T3C BASIC FOSTER FAMILY HOME SUPPORT SERVICES

1.1 System Architecture and Security

Refuge House has implemented a multi-layered security architecture that provides protection beyond typical child welfare agency standards. Our cloud-based infrastructure leverages Microsoft Azure's enterprise security features, ensuring data protection, system availability, and regulatory compliance.

The organization will maintain:

1.2 Data Management and Documentation

Our IT systems support comprehensive documentation requirements essential for quality care and regulatory compliance. The Radius case management system serves as our primary repository for all child, family, and caregiver records, configured to meet T3C-specific requirements.

The system will capture and maintain:

1.3 Quality Assurance and Continuous Improvement

Technology serves as a critical tool in our CQI process, enabling data-driven decision-making and outcome tracking. Our systems provide real-time visibility into program effectiveness and support evidence-based practice improvements.

IT systems will support CQI through:

1.4 Billing and Financial Management

Accurate financial tracking ensures appropriate compensation for caregivers and maintains fiscal accountability. Our systems automate complex calculations while maintaining transparency and audit capabilities.

Financial systems will:

The billing and Foster Parent Pass-Through process these systems support is governed by the Billing System and Foster Parent Pass-Through Procedures (OPS-BILL-01.1). This section specifies only the IT-system capabilities that enable it; the operational steps, roles, and schedule live in OPS-BILL-01.1.

2. TRANSITION SUPPORT SERVICES FOR YOUTH & YOUNG ADULTS

IT systems will include specific fields and tracking mechanisms to support youth transitioning to adulthood, including:

3. KINSHIP CAREGIVER SUPPORT SERVICES

Systems will accommodate the unique documentation needs of kinship placements:

4. PREGNANT & PARENTING YOUTH OR YOUNG ADULT SUPPORT

Specialized tracking capabilities will support this vulnerable population:

HIPAA, PRIVACY & TRANSMISSION SECURITY (ALL PACKAGES)

5.1 Protected Health Information and Minimum Necessary

Refuge House protects the confidentiality, integrity, and availability of all protected health information (PHI) and personally identifiable information (PII) in accordance with the HIPAA Privacy and Security Rules (45 CFR Parts 160 and 164) and Texas confidentiality law. Access to, and use or disclosure of, PHI/PII is limited to the minimum necessary for the purpose and only by authorized users with a legitimate, role-based need. Refuge House designates Privacy Co-Leads — Lindsay Reed (Compliance & Cross System) and Brittney Wilson, HRQAD (Quality Assurance) — responsible for privacy compliance, privacy complaints, and minimum-necessary oversight, and a Security Lead (the Director of Operational Development — currently Jeannie Duarte — supported by F1IT for technical and infrastructure matters), responsible for information-security safeguards, access controls, and breach response.

5.2 No PHI by Email — Secure Document Exchange

Refuge House's standard is to eliminate transmission of PHI or PII by standard email, including between foster parents, staff, and external parties. Documents containing PHI/PII are exchanged only through gated, access-controlled channels:

Email that must reference a case contains no PHI/PII (for example, a secure-link notification only). This expectation is reinforced in the Foster/Adoptive Parent Agreement (Documentation & Reporting §5) and in workforce and caregiver training. Because the principal risk is behavioral rather than technical, compliance is supported through training, reminders, and monitoring — not technology alone.

5.3 Transmission Security & Encryption

Electronic PHI is encrypted in transit and at rest. The agency's cloud infrastructure (Microsoft Azure) provides enterprise encryption; secure-exchange platforms (Egnyte, Pulse) enforce encrypted transfer and authenticated access; and remote connections use Refuge House-managed secure environments over encrypted networks (WPA3 minimum on home networks; public Wi-Fi prohibited for case data).

5.3a 2INgage Network IT Requirements

SSCC-2INGAGE — addition start (provider-specific; remove this block if the 2INgage contract ends)

For the 2INgage network: Refuge House confirms confidential email is transmitted using TLS and that faxes are physically secured or sent via secure digital faxing, consistent with DFPS Data & System Security requirements. Refuge House designates a technical contact to liaise with 2INgage technical staff (account creation/deactivation, active-user verification, problem reporting), and completes the required network submissions — eCANS (ecans.org), Texas Provider Gateway (TPG) (resource-home information, placement-end, serious incidents, and supporting documents), and daily bed-vacancy updates. (2INgage Provider Manual Rev. 1.2026 §13, pp.54–55)

SSCC-2INGAGE — addition end

SSCC-EMPOWER — addition start (provider-specific; remove this block if the EMPOWER contract ends)

For the EMPOWER network: confidential email uses TLS and faxes are secured/secure-digital, per DFPS Data & System Security requirements; Refuge House designates a technical contact for EMPOWER systems and completes the required submissions — eCANS (ecans.org), Texas Provider Gateway, and daily bed-vacancy updates (IT help desk helpdesk@3empower.org) (EMPOWER Provider Manual Rev. 1.2026 §13, pp.56–57).

SSCC-EMPOWER — addition end

SSCC-BELONG — addition start (provider-specific; remove this block if the Belong contract ends)

For the Belong network, Refuge House designates a technical contact, uploads required documents to the Texas Provider Gateway at least once daily (excluding weekends/holidays) by 7:00 PM CST, and transmits PHI by encrypted email (Belong Stage I & II Provider Manual, p.65).

SSCC-BELONG — addition end

5.4 Access Environments

Authorized users access case-management systems only through Refuge House-managed secure environments — the VDI, Pulse, and the approved secured browser — each requiring multi-factor / two-stage authentication and enforcing jurisdiction-based access. Refuge House is transitioning away from VDI-exclusive access toward Pulse and related secure technologies.

5.5 Breach Notification

Suspected or confirmed unauthorized access, use, or disclosure of PHI is reported immediately to the Security Lead (Director of Operational Development, with F1IT technical support) and the Privacy Co-Leads (Compliance & Cross System / QA), then investigated, contained, and — where required — notified in accordance with the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D) and applicable contract terms.

5.6 Workforce & Caregiver Training

All workforce members and caregivers complete HIPAA and information-security/cybersecurity training at pre-service and annually, including secure-exchange practices and the no-PHI-by-email standard (45 CFR §164.308(a)(5); see FC-16 Staff and Caregiver Training).

DATA USE AGREEMENT — HHS DATA SECURITY, BREACH & RECORDS (implementation guidance)

The following flow from the Texas HHS Data Use Agreement (DUA) executed as part of Refuge House's DFPS/SSCC contracts and apply agency-wide to all confidential and protected data, regardless of placing SSCC. Mechanisms not yet operating are being built into Pulse and agency practice; this is implementation guidance, not a representation that each control is already in place.

These DUA obligations are formalized in IT-SEC-01 Data Security & Breach Notification Policy and IT-SEC-01.1 Procedure (Privacy/Information Security Officials, NIST SP 800-53 baseline, and the 1-hour/24-hour/48-hour breach-notification workflow); some mechanics remain implementation guidance.

DEFINITIONS

Azure Active Directory (Azure AD): Microsoft's cloud-based identity and access management service providing secure authentication

CANS 3.0 Assessment: Child and Adolescent Needs and Strengths assessment tool required by T3C for service planning and outcome measurement

Continuous Quality Improvement (CQI): Systematic process for analyzing data to improve service delivery and outcomes

Jurisdiction-Based Access: Security model restricting user access based on assigned roles and relationships to specific records

Multi-Factor Authentication (MFA): Security process requiring two or more verification methods for system access

Protected Health Information (PHI): Individually identifiable health information subject to HIPAA privacy regulations

Egnyte: Secure cloud document-management platform used for gated file storage and exchange, supporting assigned-folder upload-only access and password-protected, time-limited share links

Foster Parent Portal: Caregiver-facing portal for secure document exchange and communication; access is gated by a signed privacy and security agreement and authenticated by device- and/or email-based token or challenge

Personally Identifiable Information (PII): Information that can identify a specific individual, protected to the same standard as PHI

Pulse: Secure access and information-sharing platform gated by token-based and challenge-based authentication with two-factor authentication (2FA)

Radius: Comprehensive case management system designed specifically for child welfare agencies

Service Package: T3C-defined level of care with associated requirements and payment rates

Two-Stage Authentication: Security protocol requiring both network-level and application-level authentication

REFERENCES

SSCC alignment (FY-26): 2INgage Provider Manual Rev. 1.2026 — §13 Information Technology (pp.54–55). Cross-reference: FC-CQI-01 Continuous Quality Improvement Policy; FY-26 SSCC coverage tracker (temporary-reference/fy26-sscc-joint-monitoring/sscc-alignment/).

SSCC alignment (FY-26) — EMPOWER: EMPOWER Provider Manual Rev. 1.2026 — §13 Information Technology (pp.56–57). Cross-reference: FC-CQI-01 Continuous Quality Improvement Policy; FY-26 SSCC variance matrix.

SSCC alignment (FY-26) — OCOK: OCOK Network Management Operations Manual Rev. 7-1-2025 — not applicable; OCOK imposes no provider-specific requirement on this document (its provider data channel is the Texas Provider Gateway). Cross-reference: FC-CQI-01 Continuous Quality Improvement Policy; FY-26 SSCC variance matrix.

SSCC alignment (FY-26) — 4Kids: 4Kids4Families Joint Operations Manual (Dec 2025) / Subcontractor Agreement — not applicable; no provider-specific requirement on this document. Cross-reference: FC-CQI-01 Continuous Quality Improvement Policy; FY-26 SSCC variance matrix.

SSCC alignment (FY-26) — Belong: Belong Stage I & II Provider Manual (Aug 2025) / Provider Services Agreement — p.65. Cross-reference: FC-CQI-01 Continuous Quality Improvement Policy; FY-26 SSCC variance matrix.

SSCC alignment (FY-26) — SFCS: SFCS Placement Provider Manual (July 2020, publicly-sourced) — the SFCS requirements for this area (incidents/QI/IT) fall in the manual's truncated back-half; confirm against the current SFCS provider manual before relying on this. No additional provision applied yet. Cross-reference: FC-CQI-01 Continuous Quality Improvement Policy; FY-26 SSCC variance matrix.

RELATED PROCEDURES

FORMS/ATTACHMENTS


This policy document establishes the governing principles for Information Technology Data Management and Security. The corresponding procedure documents operationalize these principles by providing specific implementation details (who, when, where, and how). While policies require Board approval and remain relatively stable, procedures may be updated by the Executive Director to adapt to regulatory changes, technological advancements, or operational improvements without requiring Board approval, provided such changes maintain alignment with the policy's intent.