Policy and Procedure

Management of Information (MIS) and HIPAA Policy and Procedures

Refuge House, Inc.
Last updated: July 24, 2026 · Source: policies-procedures/Policy-and-Procedure/Management of Information (MIS) and HIPAA Policy and Procedures.md

REFUGE HOUSE, INC.

Document Information Details
DOCUMENT NAME Management of Information (MIS) & HIPAA Policy and Procedures
DOCUMENT NUMBER IT-MIS-01
RELATED DOCUMENTS IT-001 Information Technology Data Management and Security Policy; IT-001.1 IT System Access and Security Procedures; IT-001-05.1 Data Backup and Recovery Procedures; FC-SIR-01 Serious Incident Reporting
EFFECTIVE DATE 5/22/2026
REVISION DATE 7/13/26 (pending approval)
LAST UPDATED 5/15/2026
LAST APPROVED 5/22/2026
DATE ADOPTED 5/22/2026
REVIEW DATE 7/13/2027

Note on this rebuild. This document replaces the legacy MIS and HIPAA Policy and Procedures (~100 pages), whose workstation, password, and remote-access mechanics predate Refuge House's current infrastructure. It states the standard/required information-management and confidentiality elements at a governing level, reflects the current operating environment, and points to the live IT Policy/Procedure for technical operation.

1. PURPOSE & SCOPE

To govern how Refuge House manages, secures, retains, and discloses agency and client information — including confidential child-welfare records and protected health information (PHI) handled through medical coordination — across all media and systems. This document applies to all employees, contractors, volunteers, and caregivers who access Refuge House information (26 TAC §749.138(b)).

2. GOVERNING FRAMEWORK

Refuge House is a Texas Child-Placing Agency, not a health-care provider; its information obligations flow primarily from DFPS confidentiality law and contract, with HIPAA Security-Rule safeguards applied where PHI is created, received, or maintained (e.g., STAR Health / medical coordination):

3. MANAGEMENT & USE OF INFORMATION

4. CONFIDENTIALITY & MINIMUM NECESSARY

4A. RCC-SPECIFIC RECORDS ACCESS & CONFIDENTIALITY RULES (DFPS 24-Hour RCC, FY26)

(Added 7/13/26 — FY26 RCC gap remediation, audit Package 8. Section lettered 4A so existing section numbers are unchanged.)

4A.1 DFPS access to records (RCC §1721)

4A.2 STAR Health contractor access — PMUR (RCC §1722)

4A.3 Health Passport confidentiality and authorized-user changes (RCC §§1732, 1415)

4A.4 Confidentiality of children's photos (RCC §1733)

4A.5 Records access for persons appointed by the court (RCC §1740)

Implementation guidance. The written CPS photo approvals (4A.4), RESPASS 48-hour user-change notices (4A.3), and CASA verification documentation (4A.5) are to be captured as dated records in the child/home record; a tracked Pulse step for each is planned. Until then, staff file the approval/notice/verification evidence in Radius under the child's record.

5. SAFEGUARDS (ADMINISTRATIVE, TECHNICAL, PHYSICAL)

Refuge House maintains administrative, technical, and physical safeguards, addressing the electronic-records requirements of 26 TAC §749.533. Technical and access safeguards are governed operationally by IT-001 and IT-001.1 and summarized here:

6. ACCESS, AUTHENTICATION & WORKFORCE PRACTICES

7. TRANSMISSION — EMAIL & FAX (PHI/CONFIDENTIAL)

8. INDIVIDUAL / CLIENT RIGHTS (records access, amendment, accounting)

Consistent with DFPS rules and applicable law, individuals (or their legal representatives) may request access to and amendment of records and an accounting of disclosures, subject to child-welfare confidentiality limits (third-party and safety redactions, sealed/court-controlled records, and the consent rules of §749.583). As a CPA, Refuge House relies on DFPS consent and the Children's/Foster-Parent Bill of Rights rather than a covered-entity Notice of Privacy Practices. Intake & responsibility: requests for client/child records are routed to the Program Director; requests for personnel/HR records are routed to the HRQAD (HR & Quality Assurance Director). Requests are logged and answered with required redactions.

9. CONTRACTORS, BUSINESS ASSOCIATES & DATA-SHARING

10. BREACH & INCIDENT RESPONSE (implementation guidance — being built)

A security event or breach is reported and handled per the HHS DUA breach-notification workflow and the agency's incident-response plan: initial notice for federal information within 1 hour and for other confidential information within 24 hours, a single point of contact, and the formal report within 48 hours to the HHS privacy mailbox (HHS DUA §4.01(C)); child-specific incidents also follow FC-SIR-01 Serious Incident Reporting and the applicable SSCC channel. This workflow is governed by IT-SEC-01 Data Security & Breach Notification Policy and IT-SEC-01.1 Procedure.

11. SANCTIONS, ENFORCEMENT & NON-RETALIATION

12. RECORDS RETENTION & DESTRUCTION

13. TRAINING

All workforce members and caregivers complete confidentiality, privacy, and information-security training at orientation and annually (HHS DUA §3.01(B); 26 TAC §749 orientation/annual training; see Staff and Caregiver Training Policy/Procedure). Completion is documented.

14. ROLES & RESPONSIBILITIES

Role Responsibility
Privacy Official / Information Security Official / IT Administrator (currently consolidated in one official — Jeannie Duarte) Privacy and security program, minimum-necessary determinations, records-access/amendment requests, NIST SP 800-53 baseline (per HHS DUA), risk assessment, incident response, access provisioning/termination, encryption, backup/monitoring. (Separation of these duties is identified as a future control improvement — see Open Improvements.)
Program Director Intake point for client/child records-access requests.
HRQAD (HR & Quality Assurance Director) Intake point for personnel/HR records-access requests.
Executive Director / Governing Body Adopt this policy; ensure resources for compliance.
All workforce & caregivers Follow this policy; protect confidential information; report incidents.

15. PROCEDURE (thin — operational steps)

Activity Steps Reference
Grant/terminate access Follow IT-001.1 (Azure AD + MFA/2FA + Radius jurisdiction; quarterly review; termination within 1 hour). IT-001.1
Disclose confidential info / PHI Verify legal basis (care coordination / written authorization / required by law); apply minimum necessary; obtain release consent per §749.583; log non-routine disclosures. §4
Send confidential info Use Egnyte/Portal/Pulse (no unsecured email); TLS for SSCC email; secure fax with cover sheet + confirmation. §7; IT-001 §5
Records-access/amendment request Log; route client/child records to the Program Director and HR records to the HRQAD; apply confidentiality redactions; respond with required limits. §8
Suspected breach/incident Contain; notify the Information Security Official; run the DUA notice workflow (1/24/48-hr) + FC-SIR-01 + SSCC channel; document. §10; FC-SIR-01
Engage a contractor/vendor Provide access only through Pulse (print/download disabled) under a signed privacy/terms agreement; execute a BAA/HHS Subcontractor Agreement first if PHI/confidential data access is involved. §9
Retention Retain case records perpetually; apply litigation holds; no routine destruction of case records; dispose of transient materials/media securely. §12
Training Deliver privacy/security training at orientation + annually; document completion. §13
DFPS records request Written request → legible records to DFPS within 14 calendar days; verbal emergency request → produce within DFPS's specified time frame (RCC §1721). §4A.1
STAR Health written request PMUR → last 3 months physician's notes + last 3 months medication logs + most recent psychological evaluation; non-PMUR → direct the STAR Health contractor to the CPS Caseworker (RCC §1722). §4A.2
Health Passport user change Notify RESPASS@dfps.texas.gov within 48 hours of any addition/deletion of an Authorized User; enforce §1732 confidentiality/user-agreement duties (RCC §§1415, 1732). §4A.3
Child photo release Verify best interest, no safety threat, no commercial use, no DFPS-conservatorship reference, child assent where able; obtain written CPS Caseworker approval unless an RCC §1733 exception applies; file the approval (RCC §1733). §4A.4
Court-appointed records request Verify identity (CASA employee: valid court order; CASA volunteer: valid court order + assignment/acceptance letter); if identity/authority unclear, obtain CPS Caseworker approval before granting access (RCC §1740). §4A.5

DEFINITIONS

Confidential Information — child, family, caregiver, and agency information protected by DFPS rules, the Texas Family Code, contract, or law. PHI — protected health information created/received/maintained in connection with medical care/coordination. Minimum Necessary — the least information needed to accomplish the purpose. (System definitions — Radius, Azure AD, MFA, Egnyte, Pulse, Foster Parent Portal — are in IT-001.)

REFERENCES

26 TAC Chapter 749 — §749.103, §749.105 (required record-keeping/confidentiality policies); §749.531 (protecting records); §749.533 (electronic records); §749.535 (currency of records); §749.554 (confidential personnel information); §749.555 (personnel-record retention); §749.571, §749.577, §749.579 (client/child records); §749.583 (consent to release a child's record); §749.585 (client-record retention). 26 TAC Chapter 745; Texas Human Resources Code Ch. 42; Texas Family Code §§261.201, 264.408; DFPS 24-Hour RCC Requirements (FY26) §§1415, 1721, 1722, 1732, 1733, 1740; HHS Data Use Agreement; HIPAA 45 CFR §§164.308, 164.310, 164.312, 164.502(b), 164.524, 164.530. Companion: IT-001 Information Technology Data Management and Security Policy; IT-001.1 IT System Access and Security Procedures; IT-001-05.1 Data Backup and Recovery Procedures; FC-SIR-01 Serious Incident Reporting; Staff and Caregiver Training Policy/Procedure. Foster-parent agreements/forms: Foster Parent SMS Communication Agreement; Privacy Policy & Terms of Service Agreement (Refuge House Pulse; ESIGN/UETA e-signed; published at refugehouse.app).


OPEN IMPROVEMENTS (planned)