
# REFUGE HOUSE, INC.

| Policy Information | Details |
| :---- | :---- |
| **POLICY NAME** | Information Technology Data Management and Security Policy |
| **POLICY NUMBER** | IT-001-01 |
| **ORIGINATED** | March 2025 |
| **APPROVED BY** | Board of Directors |
| **APPROVED ON** | \[Pending\] |
| **EFFECTIVE DATE** | April 1, 2025 |
| **LAST UPDATED** | 5/15/2026 |
| **LAST APPROVED** | 5/22/2026 |
| **SECTION** | IT-001 |
| **DATE(S) OF REVISION** | N/A |

| \#\# APPLICABLE T3C PACKAGES: | \#\# APPLICABLE T3C ADD-ON SERVICES: |
| :---- | :---- |
| ☒ T3C Basic Foster Family Home | ☒ Transition Support Services for Youth & Young Adults |
| ☐ Substance Use Support Services | ☒ Kinship Caregiver Support Services |
| ☐ Short-Term Assessment | ☒ Pregnant & Parenting Youth or Young Adult |
| ☐ Mental & Behavioral Health |  |
| ☐ Sexual Aggression/Sex Offender |  |
| ☐ Complex Medical Needs or Medically Fragile |  |
| ☐ Human Trafficking Victim/Survivor |  |
| ☐ Intellectual or Developmental Disability (IDD)/Autism Spectrum Disorder |  |
| ☐ T3C Treatment Foster Family Care |  |

## PURPOSE

This policy establishes Refuge House's commitment to maintaining secure, accurate, and comprehensive information technology systems that support quality service delivery while ensuring compliance with T3C System Blueprint requirements, HIPAA regulations, and Texas child welfare standards. Our IT infrastructure serves as the backbone for implementing our TBRI®-informed approach to care, enabling real-time monitoring of child safety and well-being while supporting our foster families with accessible, secure tools.

## POLICY

Refuge House maintains enterprise-grade information technology systems that exceed industry standards for child welfare agencies. We recognize that effective IT systems are essential for tracking outcomes, ensuring child safety, supporting caregivers, and maintaining compliance with regulatory requirements. Our technology infrastructure directly supports our mission by enabling data-driven decision-making and facilitating communication among all members of the care team.

Our IT systems will:

- Protect the confidentiality and integrity of all protected health information (PHI) and personally identifiable information (PII)  
- Support comprehensive case management documentation aligned with T3C requirements  
- Enable accurate billing and foster parent payment processes  
- Facilitate quality assurance and continuous quality improvement initiatives  
- Provide secure access to authorized users while preventing unauthorized access  
- Maintain complete audit trails for all system activities  
- Support outcome tracking at both child and foster home levels

## PACKAGE-SPECIFIC REQUIREMENTS

### 1\. CORE REQUIREMENTS \- T3C BASIC FOSTER FAMILY HOME SUPPORT SERVICES

#### 1.1 System Architecture and Security

Refuge House has implemented a multi-layered security architecture that provides protection beyond typical child welfare agency standards. Our cloud-based infrastructure leverages Microsoft Azure's enterprise security features, ensuring data protection, system availability, and regulatory compliance.

The organization will maintain:

- **Azure Active Directory with multi-factor authentication** for all system users  
- **SQL Server hosted on Azure** with explicit IP whitelisting for database protection  
- **Refuge House-managed secure access environments** — Virtual Desktop Infrastructure (VDI), **Pulse**, and the approved secured browser — for accessing case management systems (transitioning away from VDI-exclusive access toward Pulse and related secure technologies)  
- **Two-stage authentication** requiring both Azure credentials and Radius-specific login  
- **Jurisdiction-based access controls** within Radius ensuring users only access authorized records  
- **Continuous security monitoring** through Azure Security Center

#### 1.2 Data Management and Documentation

Our IT systems support comprehensive documentation requirements essential for quality care and regulatory compliance. The Radius case management system serves as our primary repository for all child, family, and caregiver records, configured to meet T3C-specific requirements.

The system will capture and maintain:

- **Service Package designations** for each child with appropriate billing codes  
- **Add-On Service tracking** integrated with primary service packages  
- **CANS 3.0 Assessment data** with longitudinal tracking capabilities  
- **Safety plan documentation** including compliance monitoring fields  
- **Family engagement activities** and progress toward permanency  
- **TBRI® intervention documentation** linked to child outcomes  
- **Foster Parent Pass-Through payment calculations** with audit trails

#### 1.3 Quality Assurance and Continuous Improvement

Technology serves as a critical tool in our CQI process, enabling data-driven decision-making and outcome tracking. Our systems provide real-time visibility into program effectiveness and support evidence-based practice improvements.

IT systems will support CQI through:

- **Automated data collection** aligned with Logic Model components  
- **Real-time dashboards** displaying key performance indicators  
- **Outcome tracking** at child, caregiver, and program levels  
- **Report generation** for internal review and external compliance  
- **Trend analysis** capabilities to identify areas for improvement  
- **Integration with external tools** for comprehensive data analysis

#### 1.4 Billing and Financial Management

Accurate financial tracking ensures appropriate compensation for caregivers and maintains fiscal accountability. Our systems automate complex calculations while maintaining transparency and audit capabilities.

Financial systems will:

- **Calculate daily rates** based on Service Package and Add-On combinations  
- **Process Foster Parent Pass-Through payments** with appropriate documentation  
- **Handle Intermittent Alternative Care** (respite) billing with continuity  
- **Generate financial reports** for management and Board review  
- **Maintain audit trails** for all financial transactions  
- **Interface with state payment systems** as required

> The billing and Foster Parent Pass-Through *process* these systems support is governed by the **Billing System and Foster Parent Pass-Through Procedures (`OPS-BILL-01.1`)**. This section specifies only the IT-system capabilities that enable it; the operational steps, roles, and schedule live in `OPS-BILL-01.1`.

### 2\. TRANSITION SUPPORT SERVICES FOR YOUTH & YOUNG ADULTS

IT systems will include specific fields and tracking mechanisms to support youth transitioning to adulthood, including:

- **Independent living skills assessments** and progress tracking  
- **Educational goal monitoring** and achievement documentation  
- **Employment readiness** indicators and job placement tracking  
- **Housing stability** metrics and support service utilization

### 3\. KINSHIP CAREGIVER SUPPORT SERVICES

Systems will accommodate the unique documentation needs of kinship placements:

- **Relationship verification** fields and supporting documentation  
- **Kinship-specific training** completion tracking  
- **Family dynamics** assessment tools and progress notes  
- **Support service utilization** specific to kinship families

### 4\. PREGNANT & PARENTING YOUTH OR YOUNG ADULT SUPPORT

Specialized tracking capabilities will support this vulnerable population:

- **Prenatal care appointment** tracking and compliance  
- **Parenting skills assessment** documentation  
- **Child development milestone** monitoring for babies  
- **Dual case management** features for parent and child

## HIPAA, PRIVACY & TRANSMISSION SECURITY (ALL PACKAGES)

### 5.1 Protected Health Information and Minimum Necessary

Refuge House protects the confidentiality, integrity, and availability of all protected health information (PHI) and personally identifiable information (PII) in accordance with the HIPAA Privacy and Security Rules (45 CFR Parts 160 and 164) and Texas confidentiality law. Access to, and use or disclosure of, PHI/PII is limited to the **minimum necessary** for the purpose and only by authorized users with a legitimate, role-based need. Refuge House designates **Privacy Co-Leads** — Lindsay Reed (Compliance & Cross System) and Brittney Wilson, HRQAD (Quality Assurance) — responsible for privacy compliance, privacy complaints, and minimum-necessary oversight, and a **Security Lead** (the Director of Operational Development — currently Jeannie Duarte — supported by F1IT for technical and infrastructure matters), responsible for information-security safeguards, access controls, and breach response.

### 5.2 No PHI by Email — Secure Document Exchange

Refuge House's standard is to **eliminate transmission of PHI or PII by standard email**, including between foster parents, staff, and external parties. Documents containing PHI/PII are exchanged only through gated, access-controlled channels:

- **Egnyte** — direct upload to an assigned secure folder (upload-only; no access to other documents) or via password-protected, time-limited share links;
- **Foster Parent Portal** — access gated by a signed privacy and security agreement and authenticated by device- and/or email-based token or challenge;
- **Pulse** — secure sharing gated by token-based and challenge-based authentication with two-factor authentication (2FA);
- **Physical delivery** of paper copies, handled and stored under the physical-safeguard standards above.

Email that must reference a case contains no PHI/PII (for example, a secure-link notification only). This expectation is reinforced in the Foster/Adoptive Parent Agreement (Documentation & Reporting §5) and in workforce and caregiver training. Because the principal risk is behavioral rather than technical, compliance is supported through training, reminders, and monitoring — not technology alone.

### 5.3 Transmission Security & Encryption

Electronic PHI is encrypted **in transit and at rest**. The agency's cloud infrastructure (Microsoft Azure) provides enterprise encryption; secure-exchange platforms (Egnyte, Pulse) enforce encrypted transfer and authenticated access; and remote connections use Refuge House-managed secure environments over encrypted networks (WPA3 minimum on home networks; public Wi-Fi prohibited for case data).

### 5.3a 2INgage Network IT Requirements

**SSCC-2INGAGE — addition start** *(provider-specific; remove this block if the 2INgage contract ends)*

For the **2INgage** network: Refuge House confirms confidential email is transmitted using **TLS** and that faxes are physically secured or sent via secure digital faxing, consistent with DFPS Data & System Security requirements. Refuge House designates a **technical contact** to liaise with 2INgage technical staff (account creation/deactivation, active-user verification, problem reporting), and completes the required network submissions — **eCANS** (ecans.org), **Texas Provider Gateway (TPG)** (resource-home information, placement-end, serious incidents, and supporting documents), and **daily bed-vacancy** updates. *(2INgage Provider Manual Rev. 1.2026 §13, pp.54–55)*

**SSCC-2INGAGE — addition end**

**SSCC-EMPOWER — addition start** *(provider-specific; remove this block if the EMPOWER contract ends)*

For the **EMPOWER** network: confidential email uses **TLS** and faxes are secured/secure-digital, per DFPS Data & System Security requirements; Refuge House designates a **technical contact** for EMPOWER systems and completes the required submissions — **eCANS** (ecans.org), **Texas Provider Gateway**, and **daily bed-vacancy** updates (IT help desk helpdesk@3empower.org) *(EMPOWER Provider Manual Rev. 1.2026 §13, pp.56–57)*.

**SSCC-EMPOWER — addition end**

**SSCC-BELONG — addition start** *(provider-specific; remove this block if the Belong contract ends)*

For the **Belong** network, Refuge House designates a technical contact, uploads required documents to the Texas Provider Gateway at least once daily (excluding weekends/holidays) **by 7:00 PM CST**, and transmits PHI by encrypted email *(Belong Stage I & II Provider Manual, p.65)*.

**SSCC-BELONG — addition end**

### 5.4 Access Environments

Authorized users access case-management systems only through Refuge House-managed secure environments — the VDI, **Pulse**, and the approved secured browser — each requiring multi-factor / two-stage authentication and enforcing jurisdiction-based access. Refuge House is transitioning away from VDI-exclusive access toward Pulse and related secure technologies.

### 5.5 Breach Notification

Suspected or confirmed unauthorized access, use, or disclosure of PHI is reported **immediately** to the **Security Lead** (Director of Operational Development, with F1IT technical support) and the **Privacy Co-Leads** (Compliance & Cross System / QA), then investigated, contained, and — where required — notified in accordance with the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D) and applicable contract terms.

### 5.6 Workforce & Caregiver Training

All workforce members and caregivers complete HIPAA and information-security/cybersecurity training at pre-service and annually, including secure-exchange practices and the no-PHI-by-email standard (45 CFR §164.308(a)(5); see FC-16 Staff and Caregiver Training).

## DATA USE AGREEMENT — HHS DATA SECURITY, BREACH & RECORDS (implementation guidance)

The following flow from the Texas HHS **Data Use Agreement (DUA)** executed as part of Refuge House's DFPS/SSCC contracts and apply **agency-wide** to all confidential and protected data, regardless of placing SSCC. Mechanisms not yet operating are being built into Pulse and agency practice; this is implementation guidance, not a representation that each control is already in place.

- **Designated officials** — a **Privacy Official** and an **Information Security Official** responsible for privacy/security implementation. *(HHS DUA §3.01(S))*
- **Written security/privacy P&P + breach incident-response plan**, producible to HHS on request. *(HHS DUA §3.01(V)–(W))*
- **Breach notification** — initial notice for federal information within **1 hour** and other confidential information within **24 hours**, a single point of contact, and the formal report within **48 hours** to the HHS privacy mailbox. *(HHS DUA §4.01(C))*
- **Security control baseline — NIST SP 800-53**; complete the HHS Security & Privacy Inquiry (SPI). *(HHS DUA §3.01(Q))*
- **Encryption** of confidential data in transit (SFTP/TLS) and at rest; proof producible within **48 hours** of request. *(HHS DUA §3.01(Y))*
- **Authorized-user roster** — a numbered, signed list of Authorized Users with titles and date bound. *(HHS DUA §3.01(U))*
- **Confidentiality/security training + documented sanctions** for violations. *(HHS DUA §3.01(B)–(C))*
- **Subcontractor flow-down** — any subcontractor handling confidential information executes the HHS Subcontractor Agreement. *(HHS DUA §3.01(F))*
- **Return/destruction & retention** — on termination, return or destroy confidential information with written certification, except under a retention policy or litigation hold *(HHS DUA §3.01(O)–(P))*; program records retained **7 years** after contract completion and produced within **5 business days** of request *(2INgage Provider Services Agreement §4.16)*.

These DUA obligations are formalized in **IT-SEC-01 Data Security & Breach Notification Policy** and **IT-SEC-01.1 Procedure** (Privacy/Information Security Officials, NIST SP 800-53 baseline, and the 1-hour/24-hour/48-hour breach-notification workflow); some mechanics remain implementation guidance.

## DEFINITIONS

**Azure Active Directory (Azure AD)**: Microsoft's cloud-based identity and access management service providing secure authentication

**CANS 3.0 Assessment**: Child and Adolescent Needs and Strengths assessment tool required by T3C for service planning and outcome measurement

**Continuous Quality Improvement (CQI)**: Systematic process for analyzing data to improve service delivery and outcomes

**Jurisdiction-Based Access**: Security model restricting user access based on assigned roles and relationships to specific records

**Multi-Factor Authentication (MFA)**: Security process requiring two or more verification methods for system access

**Protected Health Information (PHI)**: Individually identifiable health information subject to HIPAA privacy regulations

**Egnyte**: Secure cloud document-management platform used for gated file storage and exchange, supporting assigned-folder upload-only access and password-protected, time-limited share links

**Foster Parent Portal**: Caregiver-facing portal for secure document exchange and communication; access is gated by a signed privacy and security agreement and authenticated by device- and/or email-based token or challenge

**Personally Identifiable Information (PII)**: Information that can identify a specific individual, protected to the same standard as PHI

**Pulse**: Secure access and information-sharing platform gated by token-based and challenge-based authentication with two-factor authentication (2FA)

**Radius**: Comprehensive case management system designed specifically for child welfare agencies

**Service Package**: T3C-defined level of care with associated requirements and payment rates

**Two-Stage Authentication**: Security protocol requiring both network-level and application-level authentication

## REFERENCES

- T3C System Blueprint (April 2026\) \- Information Technology System Requirements  
- TAC §749 \- Minimum Standards for Child-Placing Agencies  
- HIPAA Privacy and Security Rules \- 45 CFR Parts 160, 164 (incl. §164.308 administrative, §164.310 physical, §164.312 technical safeguards / §164.312(e) transmission security)  
- HIPAA Breach Notification Rule \- 45 CFR Part 164, Subpart D  
- Texas DFPS Information Security Requirements Section 1800  
- RCC Contract Information Technology Terms

**SSCC alignment (FY-26):** 2INgage Provider Manual Rev. 1.2026 — §13 Information Technology (pp.54–55). Cross-reference: FC-CQI-01 Continuous Quality Improvement Policy; FY-26 SSCC coverage tracker (`temporary-reference/fy26-sscc-joint-monitoring/sscc-alignment/`).

**SSCC alignment (FY-26) — EMPOWER:** EMPOWER Provider Manual Rev. 1.2026 — §13 Information Technology (pp.56–57). Cross-reference: FC-CQI-01 Continuous Quality Improvement Policy; FY-26 SSCC variance matrix.

**SSCC alignment (FY-26) — OCOK:** OCOK Network Management Operations Manual Rev. 7-1-2025 — not applicable; OCOK imposes no provider-specific requirement on this document (its provider data channel is the Texas Provider Gateway). Cross-reference: FC-CQI-01 Continuous Quality Improvement Policy; FY-26 SSCC variance matrix.

**SSCC alignment (FY-26) — 4Kids:** 4Kids4Families Joint Operations Manual (Dec 2025) / Subcontractor Agreement — not applicable; no provider-specific requirement on this document. Cross-reference: FC-CQI-01 Continuous Quality Improvement Policy; FY-26 SSCC variance matrix.

**SSCC alignment (FY-26) — Belong:** Belong Stage I & II Provider Manual (Aug 2025) / Provider Services Agreement — p.65. Cross-reference: FC-CQI-01 Continuous Quality Improvement Policy; FY-26 SSCC variance matrix.

**SSCC alignment (FY-26) — SFCS:** SFCS Placement Provider Manual (July 2020, publicly-sourced) — the SFCS requirements for this area (incidents/QI/IT) fall in the manual's truncated back-half; **confirm against the current SFCS provider manual** before relying on this. No additional provision applied yet. Cross-reference: FC-CQI-01 Continuous Quality Improvement Policy; FY-26 SSCC variance matrix.

## RELATED PROCEDURES

- IT-001-01.1 \- IT System Access and Security Procedures  
- IT-001-02.1 \- Data Collection and Documentation Procedures  
- IT-001-04.1 \- System Training and Support Procedures  
- IT-001-05.1 \- Data Backup and Recovery Procedures  
- IT-001-06.1 \- External Tool Integration Procedures

## FORMS/ATTACHMENTS

- IT-F01 \- System Access Request Form  
- IT-F02 \- Data Quality Audit Checklist  
- IT-F03 \- Security Incident Report  
- IT-F04 \- Training Completion Certificate  
- IT-F05 \- System Change Request Form

---

*This policy document establishes the governing principles for Information Technology Data Management and Security. The corresponding procedure documents operationalize these principles by providing specific implementation details (who, when, where, and how). While policies require Board approval and remain relatively stable, procedures may be updated by the Executive Director to adapt to regulatory changes, technological advancements, or operational improvements without requiring Board approval, provided such changes maintain alignment with the policy's intent.*  
