REFUGE HOUSE, INC.
| Procedure Information | Details |
|---|---|
| PROCEDURE NAME | IT System Access and Security Procedures |
| PROCEDURE NUMBER | IT-001-01.1 |
| RELATED POLICY | IT-001-01 Information Technology Data Management and Security Policy |
| EFFECTIVE DATE | April 1, 2025 |
| REVISION DATE | N/A |
| LAST UPDATED | 5/15/2026 |
| LAST APPROVED | 5/22/2026 |
| ## APPLICABLE T3C PACKAGES: | ## APPLICABLE T3C ADD-ON SERVICES: |
|---|---|
| ☒ T3C Basic Foster Family Home | ☒ Transition Support Services for Youth & Young Adults |
| ☐ Substance Use Support Services | ☒ Kinship Caregiver Support Services |
| ☐ Short-Term Assessment | ☒ Pregnant & Parenting Youth or Young Adult |
| ☐ Mental & Behavioral Health | |
| ☐ Sexual Aggression/Sex Offender | |
| ☐ Complex Medical Needs or Medically Fragile | |
| ☐ Human Trafficking Victim/Survivor | |
| ☐ Intellectual or Developmental Disability (IDD)/Autism Spectrum Disorder | |
| ☐ T3C Treatment Foster Family Care |
PURPOSE
This procedure operationalizes our commitment to maintaining secure IT systems by providing step-by-step guidance for managing user access, ensuring appropriate security controls, and protecting sensitive information. These procedures ensure that every team member understands their role in maintaining system security while enabling efficient access to the tools needed for quality service delivery.
RESPONSIBILITY
- Executive Director: Overall security oversight and policy compliance
- IT Administrator: Technical implementation and system maintenance
- F1IT Consultant: Infrastructure management and security monitoring
- Department Managers: User access approval and staff compliance
- All Staff: Following security protocols and reporting concerns
- Quality Development Director: Audit and compliance verification
PROCEDURE
1. NEW USER ACCESS PROVISIONING
Purpose and Overview
Getting new team members connected to our systems quickly and securely is essential for both operational efficiency and child safety. Our multi-layered approach ensures that each person has exactly the access they need—no more and no less—to perform their duties effectively while protecting confidential information.
CRITICAL REQUIREMENT: All system access must be provisioned within 2 business days of hire date to ensure staff can complete required documentation timely per TAC §749.1301.
| Who | How | When | Where | Regulatory Reference |
|---|---|---|---|---|
| HR Manager |
|
Within 24 hours of hire confirmation | Email to IT Administrator with PDF attachment | TAC §749.1029 - Personnel Records |
| IT Administrator |
|
Within 1 business day of receiving request | Azure AD Admin Portal | HIPAA Security Rule 45 CFR §164.308 |
| IT Administrator with Department Manager |
|
Within 2 business days of hire | Radius Admin Module via Virtual Desktop | T3C Blueprint p.464 - Role-Based Access |
| Department Manager |
|
Within first week of employment | Training room or virtual session | TAC §749.1059 - Orientation |
2. ONGOING ACCESS MANAGEMENT
Purpose and Overview
System access is not a "set it and forget it" process. Regular reviews ensure that access remains appropriate as roles change and that we maintain the principle of least privilege—giving people access to only what they need for their current responsibilities.
HIGH-WEIGHT STANDARD: Quarterly access reviews are critical for maintaining compliance and preventing unauthorized access to confidential information.
| Who | How | When | Where | Regulatory Reference |
|---|---|---|---|---|
| IT Administrator |
|
First Monday of each quarter | Azure AD and Radius reporting tools | DFPS IS Requirements 1800 |
| Department Managers |
|
Within 5 business days of receiving report | Secure email response | T3C Blueprint p.466 - Access Controls |
| IT Administrator |
|
Within 2 business days of change request | System admin portals | HIPAA §164.308(a)(4) |
3. TERMINATION AND ROLE CHANGE PROCEDURES
Purpose and Overview
When staff leave the organization or change roles, swift action protects both the organization and the individuals we serve. Our procedures ensure that access is appropriately modified without disrupting ongoing services.
CRITICAL: Access must be terminated immediately upon notification of employee termination to prevent unauthorized access to PHI.
| Who | How | When | Where | Regulatory Reference |
|---|---|---|---|---|
| HR Manager |
|
Immediately upon termination decision | Phone followed by secure email | HIPAA §164.308(a)(3) |
| IT Administrator |
|
Within 1 hour of notification | All system admin portals | DFPS Contract Term 8.11 |
| F1IT Consultant |
|
Within 4 hours of notification | Azure Portal and firewall config | HIPAA Security Rule |
3A. 2INgage Gateway Administration (provider-specific)
SSCC-2INGAGE — addition start (provider-specific; remove this block if the 2INgage contract ends)
For the 2INgage network, a designated agency Texas Provider Gateway (TPG) administrator creates additional Gateway logins and deactivates a user's Gateway login upon termination or transfer, and trains each authorized user on protection of confidential information. Refuge House also maintains a designated technical contact for 2INgage system access, alongside the internal account-deprovisioning steps above. (2INgage Provider Manual Rev. 1.2026 §13, pp.54–55)
SSCC-2INGAGE — addition end
SSCC-EMPOWER — addition start (provider-specific; remove this block if the EMPOWER contract ends)
For the EMPOWER network, a designated agency Texas Provider Gateway administrator creates additional Gateway logins and deactivates a user's login upon termination or transfer (initial setup via bharding@teammns.org), and Refuge House maintains a designated technical contact for EMPOWER system access, alongside the internal account-deprovisioning steps above (EMPOWER Provider Manual Rev. 1.2026 §13, pp.56–57).
SSCC-EMPOWER — addition end
SSCC-BELONG — addition start (provider-specific; remove this block if the Belong contract ends)
For the Belong network, Refuge House maintains a designated technical contact and completes daily Texas Provider Gateway uploads by 7:00 PM CST (excluding weekends/holidays) (Belong Stage I & II Provider Manual, p.65).
SSCC-BELONG — addition end
4. SECURITY MONITORING AND INCIDENT RESPONSE
Purpose and Overview
Proactive monitoring helps us identify potential security issues before they become problems. Our partnership with F1IT provides 24/7 monitoring capabilities that exceed what most child welfare agencies can achieve independently.
| Who | How | When | Where | Regulatory Reference |
|---|---|---|---|---|
| F1IT Consultant |
|
Continuous automated monitoring with daily review | Azure Security Center | DFPS IS 1800.16 |
| IT Administrator |
|
Weekly review, immediate for critical alerts | Virtual Desktop secure session | HIPAA §164.308(a)(6) |
| All Staff |
|
Immediately upon discovery | Phone to IT Administrator | T3C Blueprint p.11 - Incident Reporting |
5. FOSTER PARENT AND EXTERNAL ACCESS
Purpose and Overview
Our foster parents need secure access to specific information while maintaining appropriate boundaries. We've implemented user-friendly solutions that balance accessibility with security.
| Who | How | When | Where | Regulatory Reference |
|---|---|---|---|---|
| Case Manager |
|
Upon home verification or as needed | Email to IT Administrator | TAC §749.1407 - Information Sharing |
| IT Administrator |
|
Within 2 business days of request | Google Workspace Admin | HIPAA §164.514 - Minimum Necessary |
| Foster Parents |
|
As needed for payment verification | Personal device with internet | RCC Contract Payment Terms |
6. EXTERNAL TOOL INTEGRATION (Effective August 2025)
Purpose and Overview
As we implement new tools like the Learning Management System and caregiver check-in system, maintaining our security standards while improving functionality is paramount.
| Who | How | When | Where | Regulatory Reference |
|---|---|---|---|---|
| IT Administrator with F1IT |
|
Prior to go-live date | Development environment first | T3C Blueprint p.404 - System Integration |
| Training Coordinator |
|
2 weeks before launch | LMS platform | TAC §749.1059 |
REGULATORY REFERENCES
- HIPAA Security Rule - 45 CFR Part 164, Subpart C
- HIPAA Privacy Rule - 45 CFR Part 164, Subpart E
- TAC §749 Subchapter C - Personnel
- T3C System Blueprint (April 2026) - Information Technology Requirements
- DFPS Information Security Requirements Section 1800
- DFPS Vendor Supplemental Conditions Section II Article 8
SSCC alignment (FY-26): 2INgage Provider Manual Rev. 1.2026 — §13 Information Technology (pp.54–55). Cross-reference: FC-CQI-01 Continuous Quality Improvement Policy; FY-26 SSCC coverage tracker (temporary-reference/fy26-sscc-joint-monitoring/sscc-alignment/).
SSCC alignment (FY-26) — EMPOWER: EMPOWER Provider Manual Rev. 1.2026 — §13 Information Technology (pp.56–57). Cross-reference: FC-CQI-01 Continuous Quality Improvement Policy; FY-26 SSCC variance matrix.
SSCC alignment (FY-26) — OCOK: OCOK Network Management Operations Manual Rev. 7-1-2025 — not applicable; OCOK imposes no provider-specific requirement on this document (its provider data channel is the Texas Provider Gateway). Cross-reference: FC-CQI-01 Continuous Quality Improvement Policy; FY-26 SSCC variance matrix.
SSCC alignment (FY-26) — 4Kids: 4Kids4Families Joint Operations Manual (Dec 2025) / Subcontractor Agreement — not applicable; no provider-specific requirement on this document. Cross-reference: FC-CQI-01 Continuous Quality Improvement Policy; FY-26 SSCC variance matrix.
SSCC alignment (FY-26) — Belong: Belong Stage I & II Provider Manual (Aug 2025) / Provider Services Agreement — p.65. Cross-reference: FC-CQI-01 Continuous Quality Improvement Policy; FY-26 SSCC variance matrix.
SSCC alignment (FY-26) — SFCS: SFCS Placement Provider Manual (July 2020, publicly-sourced) — the SFCS requirements for this area (incidents/QI/IT) fall in the manual's truncated back-half; confirm against the current SFCS provider manual before relying on this. No additional provision applied yet. Cross-reference: FC-CQI-01 Continuous Quality Improvement Policy; FY-26 SSCC variance matrix.
FORMS/ATTACHMENTS
- IT-F01 - System Access Request Form
- IT-F03 - Security Incident Report Form
- IT-F05 - Access Change Request Form
- IT-G01 - New User Security Checklist
- IT-G02 - Quarterly Access Review Template
- IT-G03 - Termination IT Checklist
This procedure document operationalizes the principles established in the corresponding policy by providing specific implementation details (who, when, where, and how). While policies require Board approval and remain relatively stable, procedures may be updated by the Executive Director to adapt to regulatory changes, technological advancements, or operational improvements without requiring Board approval, provided such changes maintain alignment with the policy's intent.