REFUGE HOUSE, INC.
| Document Information | Details |
|---|---|
| DOCUMENT NAME | Management of Information (MIS) & HIPAA Policy and Procedures |
| DOCUMENT NUMBER | IT-MIS-01 |
| RELATED DOCUMENTS | IT-001 Information Technology Data Management and Security Policy; IT-001.1 IT System Access and Security Procedures; IT-001-05.1 Data Backup and Recovery Procedures; FC-SIR-01 Serious Incident Reporting |
| EFFECTIVE DATE | 5/22/2026 |
| REVISION DATE | 7/13/26 (pending approval) |
| LAST UPDATED | 5/15/2026 |
| LAST APPROVED | 5/22/2026 |
| DATE ADOPTED | 5/22/2026 |
| REVIEW DATE | 7/13/2027 |
Note on this rebuild. This document replaces the legacy MIS and HIPAA Policy and Procedures (~100 pages), whose workstation, password, and remote-access mechanics predate Refuge House's current infrastructure. It states the standard/required information-management and confidentiality elements at a governing level, reflects the current operating environment, and points to the live IT Policy/Procedure for technical operation.
1. PURPOSE & SCOPE
To govern how Refuge House manages, secures, retains, and discloses agency and client information — including confidential child-welfare records and protected health information (PHI) handled through medical coordination — across all media and systems. This document applies to all employees, contractors, volunteers, and caregivers who access Refuge House information (26 TAC §749.138(b)).
2. GOVERNING FRAMEWORK
Refuge House is a Texas Child-Placing Agency, not a health-care provider; its information obligations flow primarily from DFPS confidentiality law and contract, with HIPAA Security-Rule safeguards applied where PHI is created, received, or maintained (e.g., STAR Health / medical coordination):
- 26 TAC Chapter 749 — required record-keeping and confidentiality policies (§749.103, §749.105); protecting records (§749.531) and electronic records (§749.533); client/child records (§749.571, §749.577, §749.579); consent to release a child's record (§749.583); retention (§749.585 client records, §749.555 personnel records, §749.529 policies); confidential personnel information (§749.554).
- Texas Family Code §261.201 (confidentiality of abuse/neglect reports) and §264.408 (confidentiality of CPS/child records).
- DFPS Residential Child Care (RCC) Contract and the HHS Data Use Agreement (DUA) — agency-wide data-security, breach, and records obligations (see §10–§12).
- HIPAA Security Rule, 45 CFR §§164.308 (administrative), 164.310 (physical), 164.312 (technical) safeguards, and Privacy-Rule minimum necessary (45 CFR §164.502(b)) where PHI is handled.
3. MANAGEMENT & USE OF INFORMATION
- The Radius case-management system is the primary system of record for child, family, and caregiver records, configured for T3C requirements (see IT-001). Agency files and exchange use Egnyte, the Foster Parent Portal, and Pulse. All data resources are cloud-based and Azure-controlled — Refuge House operates no on-site servers.
- Records are complete, accurate, timely, and attributable (§749.535); information is collected and used only for legitimate child-welfare, treatment-coordination, contract, and business purposes.
- Agency information and systems are Refuge House property; users have no expectation of personal privacy in agency systems, email, or stored data.
4. CONFIDENTIALITY & MINIMUM NECESSARY
- Confidential client information and PHI are disclosed only (a) for treatment/care coordination, payment, and program operations; (b) as authorized in writing by the individual or their legal representative; or (c) as required or permitted by law (e.g., mandated abuse/neglect reporting, court order, DFPS/SSCC reporting). Release of a child's record follows the consent requirements of 26 TAC §749.583.
- Minimum necessary: workforce members access and disclose only the information needed for the task. Role- and jurisdiction-based access in Radius enforces this technically (see IT-001.1) (45 CFR §164.502(b)).
- Routine disclosures (to DFPS/SSCC, STAR Health, courts, schools, medical providers) follow established release pathways; non-routine disclosures require supervisory/Privacy Official review.
4A. RCC-SPECIFIC RECORDS ACCESS & CONFIDENTIALITY RULES (DFPS 24-Hour RCC, FY26)
(Added 7/13/26 — FY26 RCC gap remediation, audit Package 8. Section lettered 4A so existing section numbers are unchanged.)
4A.1 DFPS access to records (RCC §1721)
- "DFPS has absolute right of access to, and copies of, Child case records or other information relating to a Child served by the provider." Refuge House makes any and all records and information concerning the child available to DFPS upon written request and forwards legible records and information to DFPS within 14 calendar days of receiving the request. (RCC §1721)
- Emergency (verbal) requests: Refuge House makes any and all records and information concerning the child available to DFPS upon verbal request in emergency situations, submitting all records and information within DFPS's specified time frame. Emergency requests can include, but are not limited to: the need to review the child's service level in order to make a placement change; EBI Reports and Serious Incident Reports; court-ordered requests; or attorney requests. (RCC §1721, Emergency Access)
4A.2 STAR Health contractor access — PMUR (RCC §1722)
- On written request for a Psychotropic Medication Utilization Review (PMUR), Refuge House gives the STAR Health contractor (Superior/Cenpatico), for the specific child: the last three months of physician's notes, the last three months of medication logs, and the most recent psychological evaluation. (RCC §1722)
- If a written request from the STAR Health contractor does not involve PMUR, Refuge House "notifies the STAR Health contractor to contact the CPS Caseworker for assistance." (RCC §1722, Other Requests)
4A.3 Health Passport confidentiality and authorized-user changes (RCC §§1732, 1415)
- Only an employee designated with DFPS approval (the Authorized User) accesses a child's Health Passport. The Authorized User complies with the Health Passport user agreement; "must not share information from the Health Passport with anyone who does not have a direct need to know the information for purposes of providing health care to the Child, including Behavioral Health care"; shares the minimum amount of information required; and maintains the physical security and confidentiality of Health Passport information viewed, printed, copied, or downloaded (locking the computer, blanking the screen, promptly retrieving printouts from shared printers). (RCC §1732)
- The Authorized User must not share passwords; if a password has been shared, it is changed immediately via Forgot Password/Unlock Account on the Health Passport sign-in page. Authorized Users are informed that DFPS may restrict or deny Health Passport access for violations. (RCC §1732)
- The Authorized User limits access to Health Passport records to "Children who are served by the provider; or Children with whom the Authorized User has a relationship for which Health Passport access is authorized." (RCC §1732)
- User-change notification: Refuge House sends notification to the RESPASS@dfps.texas.gov email box within 48 hours of any additions or deletions of Health Passport Authorized Users. (RCC §1415)
4A.4 Confidentiality of children's photos (RCC §1733)
- A photo or image of a child may be released or otherwise used only when the release: is in the best interest of the child; poses no threat to the child's health or safety; and is not used for any commercial use, publicity, pecuniary benefit, or similar gain for Refuge House or anyone else. If released, no reference may be made to the fact the child is in the Managing Conservatorship of DFPS, and the use must not stigmatize the child in any way. (RCC §1733)
- If the child is old enough and developmentally able to read and write, the child must approve of the release or use of the photo or image. (RCC §1733)
- "In almost all cases the release or use of a photo or images of a Child must be approved in writing by the CPS Caseworker." Prior written CPS approval is not required only in the RCC-listed situations: the child or immediate caregiver sharing with the child's or caregiver's friends or family (e.g., school pictures traded with peers, a family photo in a holiday card); release by the child or caregiver to the child's biological family; or use as a normal part of a school or extracurricular activity (yearbook, church newsletter, honor-roll newspaper photo, scout-troop group photo, sports-team photo in a school showcase). (RCC §1733)
- These rules apply to all agency channels, including the Recruitment & Retention website/community-room photo-sharing feature (see FC-RR-01/-01.1) and any social-media or promotional use.
4A.5 Records access for persons appointed by the court (RCC §1740)
- Refuge House gives access to all records and information concerning the child to properly identified individuals appointed by a court of competent jurisdiction: CASA volunteers or employees, guardians ad litem, attorneys ad litem, or staff with TJJD or a county Juvenile Probation Department. Available records may include face-to-face visit documentation, the child's service plan, documentation of services provided, discipline logs, medical and dental information, educational documentation, and narratives. (RCC §1740)
- Identity verification: if an individual asks for confidential records and claims to be with CASA, staff or the caregiver must confirm this. For a claimed CASA employee, request a court order and review it to be sure it is valid. For a claimed CASA volunteer, request both a court order (reviewed for validity) and "a notification letter of volunteer assignment and acceptance that clarifies the individual's appointment to the Child." (RCC §1740)
- If staff or the caregiver "cannot readily determine the person's identity or authority, they must obtain approval from the Child's CPS Caseworker before granting the individual access to the Child" or the records. (RCC §1740)
Implementation guidance. The written CPS photo approvals (4A.4), RESPASS 48-hour user-change notices (4A.3), and CASA verification documentation (4A.5) are to be captured as dated records in the child/home record; a tracked Pulse step for each is planned. Until then, staff file the approval/notice/verification evidence in Radius under the child's record.
5. SAFEGUARDS (ADMINISTRATIVE, TECHNICAL, PHYSICAL)
Refuge House maintains administrative, technical, and physical safeguards, addressing the electronic-records requirements of 26 TAC §749.533. Technical and access safeguards are governed operationally by IT-001 and IT-001.1 and summarized here:
- Technical — Microsoft Azure cloud infrastructure; Azure AD with multi-factor / two-stage authentication; SQL Server on Azure with IP whitelisting; encryption in transit and at rest; access to case data only through Refuge House-managed secure environments (VDI, Pulse, approved secured browser); continuous monitoring via Azure Security Center (45 CFR §164.312).
- Administrative — workforce confidentiality agreements; role/jurisdiction-based authorization; quarterly access reviews; sanctions (§11); training (§13) (45 CFR §164.308).
- Physical — because all data resources are cloud-based (Azure-controlled), physical safeguards focus on facilities, workstations, and agency-issued devices: facility/workstation controls, clean-desk and screen-lock practices, and secure device handling (45 CFR §164.310).
6. ACCESS, AUTHENTICATION & WORKFORCE PRACTICES
- Access is provisioned, reviewed quarterly, and terminated per IT-001.1 (Azure AD account, MFA enrollment, Radius jurisdiction assignment; termination disablement within 1 hour).
- Authentication / passwords: staff work within the Azure Virtual Desktop Infrastructure, so Azure Active Directory password-complexity requirements are the minimum standard; two-factor authentication (2FA) is being rolled out across users.
- Devices: Refuge House issues mobile devices to staff. Contractors do not receive device access; contractors access information only through Pulse, where documents are presented through a secure wrapper that disables printing and downloading. All access — staff and contractor — is gated by a privacy and terms-of-use agreement; there is no anonymous access, per Refuge House's published Privacy Policy and Terms of Service (refugehouse.app/privacy, refugehouse.app/terms; updated November 2025).
- Foster parents access information only through the Foster Parent Portal and Pulse task links; that access is gated by completion of the e-signed Privacy Policy & Terms of Service Agreement and Foster Parent SMS Communication Agreement — no anonymous access.
- Remote/away-from-facility access uses these managed secure environments over encrypted networks (WPA3 minimum on home networks; public Wi-Fi prohibited for case data).
7. TRANSMISSION — EMAIL & FAX (PHI/CONFIDENTIAL)
No PHI or confidential client information is sent by unsecured email. Secure exchange uses Egnyte (assigned-folder upload / time-limited links), the Foster Parent Portal, or Pulse; where email is used with an SSCC, TLS is required (see IT-001 §5.2–§5.3).
Fax: confidential faxes use a cover sheet with a confidentiality notice, verified recipient numbers, and confirmation; misdirected faxes are handled as a possible incident/breach (§10). Secure digital faxing is used where available.
Foster-parent & stakeholder communications via SMS/voice (Twilio) and email (SendGrid) — including Pulse check-ins, document/medication task links, reminders, and notifications — are governed by the Foster Parent SMS Communication Agreement and the published Privacy Policy & Terms of Service (refugehouse.app/privacy, /terms). No detailed PHI is transmitted via standard SMS; task links are secure tokenized links that expire within 24 hours, and messages/responses are encrypted in the system. Agency SMS numbers (+1 972-440-1706 and +1 844-554-0363) are automated, send-only, and not monitored for inbound contact; recipients are directed to call 911 for emergencies and the main office (972) 662-5112 for assistance. Recipients retain the standard STOP opt-out (managed and honored through Twilio); the agreement reflects each active foster parent's commitment not to opt out — because the safety and security of the children in their care depend on instant communication — and an opt-out prompts establishing alternative check-in arrangements rather than any technical block. PHI/confidential exchange uses Egnyte/Portal/Pulse as above.
8. INDIVIDUAL / CLIENT RIGHTS (records access, amendment, accounting)
Consistent with DFPS rules and applicable law, individuals (or their legal representatives) may request access to and amendment of records and an accounting of disclosures, subject to child-welfare confidentiality limits (third-party and safety redactions, sealed/court-controlled records, and the consent rules of §749.583). As a CPA, Refuge House relies on DFPS consent and the Children's/Foster-Parent Bill of Rights rather than a covered-entity Notice of Privacy Practices. Intake & responsibility: requests for client/child records are routed to the Program Director; requests for personnel/HR records are routed to the HRQAD (HR & Quality Assurance Director). Requests are logged and answered with required redactions.
9. CONTRACTORS, BUSINESS ASSOCIATES & DATA-SHARING
- Presently, no external vendor or contractor has access to Refuge House-owned PHI, so no Business Associate Agreement is currently required. Contractors access information only through the Pulse environment (secure wrapper disabling print/download), gated by a privacy and terms-of-use agreement, with no anonymous access.
- Refuge House uses Twilio (SMS/voice) and SendGrid (email) as communications service providers, which process recipient contact information and message content under the published Privacy Policy and Terms of Service (refugehouse.app/privacy, /terms; updated November 2025) available to foster parents and recipients. These providers are not granted access to Radius case records or child PHI, and case content is not transmitted through them. Foster parents complete the Privacy Policy & Terms of Service Agreement and the Foster Parent SMS Communication Agreement by electronic signature compliant with ESIGN/UETA, consenting to automated SMS; the signed agreements are stored electronically and remain available in the portal. Completion of these agreements gates Foster Parent Portal and Pulse task-link access (no anonymous access).
- If Refuge House later engages a vendor to create, receive, store, or transmit PHI or confidential information, a Business Associate Agreement / HHS Subcontractor Agreement is executed before access, binding the vendor to equivalent terms (HHS DUA §3.01(F)). Cloud infrastructure (Microsoft Azure) is governed by Microsoft's enterprise/online-services terms.
- Data-sharing with DFPS/SSCCs, STAR Health, courts, and partners follows the agency's data-sharing agreements and the minimum-necessary standard.
10. BREACH & INCIDENT RESPONSE (implementation guidance — being built)
A security event or breach is reported and handled per the HHS DUA breach-notification workflow and the agency's incident-response plan: initial notice for federal information within 1 hour and for other confidential information within 24 hours, a single point of contact, and the formal report within 48 hours to the HHS privacy mailbox (HHS DUA §4.01(C)); child-specific incidents also follow FC-SIR-01 Serious Incident Reporting and the applicable SSCC channel. This workflow is governed by IT-SEC-01 Data Security & Breach Notification Policy and IT-SEC-01.1 Procedure.
11. SANCTIONS, ENFORCEMENT & NON-RETALIATION
- Violations of confidentiality, privacy, or information-security requirements are subject to documented sanctions up to and including termination (HHS DUA §3.01(C); 45 CFR §164.530(e)), administered through the agency's progressive-discipline process (personnel-hr).
- Non-retaliation: good-faith reporting of privacy/security concerns or violations (including by whistleblowers and workforce crime victims) is protected from retaliation.
12. RECORDS RETENTION & DESTRUCTION
- Refuge House retains client/case records perpetually — meeting and exceeding the minimum retention in 26 TAC §749.585 and the DFPS contract (≥7 years) — and does not perform routine destruction of case records. The HHS DUA return-or-destroy-on-termination provision is satisfied through this record-retention policy under the DUA's retention/litigation-hold exception (HHS DUA §3.01(O)–(P)).
- Personnel records are retained per §749.555; confidential personnel information is protected per §749.554.
- Any transient/duplicate confidential materials and decommissioned media are disposed of by secure means; production of records on request is met within the contract timeframe (5 business days).
13. TRAINING
All workforce members and caregivers complete confidentiality, privacy, and information-security training at orientation and annually (HHS DUA §3.01(B); 26 TAC §749 orientation/annual training; see Staff and Caregiver Training Policy/Procedure). Completion is documented.
14. ROLES & RESPONSIBILITIES
| Role | Responsibility |
|---|---|
| Privacy Official / Information Security Official / IT Administrator (currently consolidated in one official — Jeannie Duarte) | Privacy and security program, minimum-necessary determinations, records-access/amendment requests, NIST SP 800-53 baseline (per HHS DUA), risk assessment, incident response, access provisioning/termination, encryption, backup/monitoring. (Separation of these duties is identified as a future control improvement — see Open Improvements.) |
| Program Director | Intake point for client/child records-access requests. |
| HRQAD (HR & Quality Assurance Director) | Intake point for personnel/HR records-access requests. |
| Executive Director / Governing Body | Adopt this policy; ensure resources for compliance. |
| All workforce & caregivers | Follow this policy; protect confidential information; report incidents. |
15. PROCEDURE (thin — operational steps)
| Activity | Steps | Reference |
|---|---|---|
| Grant/terminate access | Follow IT-001.1 (Azure AD + MFA/2FA + Radius jurisdiction; quarterly review; termination within 1 hour). | IT-001.1 |
| Disclose confidential info / PHI | Verify legal basis (care coordination / written authorization / required by law); apply minimum necessary; obtain release consent per §749.583; log non-routine disclosures. | §4 |
| Send confidential info | Use Egnyte/Portal/Pulse (no unsecured email); TLS for SSCC email; secure fax with cover sheet + confirmation. | §7; IT-001 §5 |
| Records-access/amendment request | Log; route client/child records to the Program Director and HR records to the HRQAD; apply confidentiality redactions; respond with required limits. | §8 |
| Suspected breach/incident | Contain; notify the Information Security Official; run the DUA notice workflow (1/24/48-hr) + FC-SIR-01 + SSCC channel; document. | §10; FC-SIR-01 |
| Engage a contractor/vendor | Provide access only through Pulse (print/download disabled) under a signed privacy/terms agreement; execute a BAA/HHS Subcontractor Agreement first if PHI/confidential data access is involved. | §9 |
| Retention | Retain case records perpetually; apply litigation holds; no routine destruction of case records; dispose of transient materials/media securely. | §12 |
| Training | Deliver privacy/security training at orientation + annually; document completion. | §13 |
| DFPS records request | Written request → legible records to DFPS within 14 calendar days; verbal emergency request → produce within DFPS's specified time frame (RCC §1721). | §4A.1 |
| STAR Health written request | PMUR → last 3 months physician's notes + last 3 months medication logs + most recent psychological evaluation; non-PMUR → direct the STAR Health contractor to the CPS Caseworker (RCC §1722). | §4A.2 |
| Health Passport user change | Notify RESPASS@dfps.texas.gov within 48 hours of any addition/deletion of an Authorized User; enforce §1732 confidentiality/user-agreement duties (RCC §§1415, 1732). | §4A.3 |
| Child photo release | Verify best interest, no safety threat, no commercial use, no DFPS-conservatorship reference, child assent where able; obtain written CPS Caseworker approval unless an RCC §1733 exception applies; file the approval (RCC §1733). | §4A.4 |
| Court-appointed records request | Verify identity (CASA employee: valid court order; CASA volunteer: valid court order + assignment/acceptance letter); if identity/authority unclear, obtain CPS Caseworker approval before granting access (RCC §1740). | §4A.5 |
DEFINITIONS
Confidential Information — child, family, caregiver, and agency information protected by DFPS rules, the Texas Family Code, contract, or law. PHI — protected health information created/received/maintained in connection with medical care/coordination. Minimum Necessary — the least information needed to accomplish the purpose. (System definitions — Radius, Azure AD, MFA, Egnyte, Pulse, Foster Parent Portal — are in IT-001.)
REFERENCES
26 TAC Chapter 749 — §749.103, §749.105 (required record-keeping/confidentiality policies); §749.531 (protecting records); §749.533 (electronic records); §749.535 (currency of records); §749.554 (confidential personnel information); §749.555 (personnel-record retention); §749.571, §749.577, §749.579 (client/child records); §749.583 (consent to release a child's record); §749.585 (client-record retention). 26 TAC Chapter 745; Texas Human Resources Code Ch. 42; Texas Family Code §§261.201, 264.408; DFPS 24-Hour RCC Requirements (FY26) §§1415, 1721, 1722, 1732, 1733, 1740; HHS Data Use Agreement; HIPAA 45 CFR §§164.308, 164.310, 164.312, 164.502(b), 164.524, 164.530. Companion: IT-001 Information Technology Data Management and Security Policy; IT-001.1 IT System Access and Security Procedures; IT-001-05.1 Data Backup and Recovery Procedures; FC-SIR-01 Serious Incident Reporting; Staff and Caregiver Training Policy/Procedure. Foster-parent agreements/forms: Foster Parent SMS Communication Agreement; Privacy Policy & Terms of Service Agreement (Refuge House Pulse; ESIGN/UETA e-signed; published at refugehouse.app).
OPEN IMPROVEMENTS (planned)
- Data Security & Breach Notification policy/procedure — ✅ established as IT-SEC-01 / IT-SEC-01.1 (Privacy/Information Security Officials, NIST SP 800-53 baseline, 1/24/48-hour breach workflow, risk-assessment cadence, sanctions). Some mechanics remain implementation guidance.
- Separation of duties — the Privacy Official, Information Security Official, and IT Administrator functions are currently held by one official; separation is planned as the agency grows.
- Legacy disposition — the legacy ~100-page MIS and HIPAA Policy and Procedures is superseded by this document + the IT-001 family; the legacy PDF should be archived under
historical-docs/. - Emergency-contact reconciliation & routing — the public site lists an Emergency Line (682) 222-9444, while the Foster Parent SMS Communication Agreement directs emergencies to 911 and the main office (972) 662-5112, and the SMS numbers (972-440-1706 / 844-554-0363) are explicitly not monitored. Reconcile these into a single authoritative emergency path and define where (682) 222-9444 routes, who monitors it, and the escalation flow (flagged for follow-up).
- File the foster-parent agreements — store the signed Foster Parent SMS Communication Agreement and Privacy Policy & Terms of Service Agreement PDFs under
forms/foster-parent-agreements/and reference them from this policy and the Foster Parent Agreement. - Optional: add an
HHS-DUAsource code toregulatory-sources.jsonfor cleanerreview.basistraceability (currently cited inline).