
Information
Security Policy.
Information Security Policy, 2026
Effective date: August 2026 · Last reviewed: August 2026
I. Purpose and Scope
The purpose of this Information Security Policy is to establish safeguards to protect the confidentiality, integrity, and availability of Protected Health Information (PHI), Electronic Protected Health Information (ePHI), and other sensitive Practice information.
This policy applies to all workforce members, 1099 clinicians, contractors, supervisors, consultants, Business Associates, and vendors who access Practice systems, applications, devices, or information containing PHI.
The Practice maintains compliance with HIPAA, HITECH, applicable state privacy laws, 42 CFR Part 2 (when applicable), OCR cybersecurity guidance, and OIG Compliance Program Guidance.
II. Security Responsibilities
The Compliance Officer oversees security compliance activities, including risk assessments, incident response, vendor oversight, and policy maintenance.
All workforce members and contractors must:
- Protect Practice information and credentials
- Use only approved systems and applications
- Complete required security training
- Report suspected security incidents immediately
- Follow all applicable security policies
Failure to comply may result in corrective action, removal of system access, contract termination, or other appropriate action.
III. Access Control
Access to ePHI shall be limited to the minimum necessary information required to perform assigned responsibilities.
The Practice shall maintain:
- Unique user accounts and passwords
- Role-based access controls
- Multi-Factor Authentication (MFA)
- Access reviews
- Audit logging where available
- Prompt removal of access upon termination or role change
Shared accounts are prohibited.
IV. Multi-Factor Authentication (MFA)
MFA is required for all systems that access, store, transmit, or process ePHI, including:
- Electronic health records
- Telehealth platforms
- Email systems
- Cloud applications
- Administrative systems containing PHI
Users may not disable MFA or bypass required security controls.
V. Encryption Requirements
All ePHI must be encrypted when stored and transmitted. The Practice requires:
- Encryption of devices used to access Practice systems
- Encryption of cloud storage containing ePHI
- Secure transmission of PHI through approved platforms
- Secure telehealth technology
Unencrypted storage or transmission of ePHI is strictly prohibited.
VI. Network and System Security
Systems containing ePHI must be protected through appropriate technical safeguards, including network segmentation or equivalent controls designed to limit unauthorized access and contain security incidents.
The Practice shall maintain appropriate protections for:
- Telehealth systems
- Cloud applications
- Clinical systems
- Administrative systems
VII. Asset Management and Approved Technology
The Practice shall maintain an inventory of technology used to access, store, or process ePHI, including:
- Computers and mobile devices
- EHR and telehealth systems
- Cloud applications
- Artificial Intelligence (“AI”) tools
- Software applications
Only approved technology may be used for Practice operations involving PHI.
AI tools must undergo appropriate privacy, security, and compliance review before use and must be included in the Practice asset inventory.
VIII. Risk Analysis and Management
The Practice shall complete a comprehensive security risk analysis no less than annually. Risk assessments shall evaluate:
- Security vulnerabilities
- Cybersecurity threats
- Vendor risks
- Telehealth systems
- Mobile devices
- AI technologies
Identified risks shall be documented and addressed through appropriate corrective actions.
IX. Security Training
All workforce members and contractors must complete security and privacy training:
- Before accessing Practice systems
- Annually thereafter
- When significant policy changes occur
Training shall include HIPAA security requirements, phishing awareness, password security, incident reporting, and appropriate use of technology.
X. Incident Response
The Practice shall maintain procedures to identify, investigate, mitigate, document, and respond to security incidents. Workforce members and contractors must report suspected incidents immediately, including:
- Unauthorized access
- Lost or stolen devices
- Credential compromise
- Malware or ransomware events
- Improper disclosures
- Vendor security incidents
The Practice shall investigate incidents, assess potential impact, document findings, and complete required notifications. Security incidents and potential breaches shall be evaluated promptly and escalated within seventy-two (72) hours of discovery when notification obligations may apply.
XI. Business Associate Management
Business Associates must execute a Business Associate Agreement (BAA) before accessing PHI. Business Associates must:
- Maintain appropriate security safeguards
- Protect PHI and ePHI information in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), applicable federal and state privacy laws, professional ethical standards, and Practice policies
- Cooperate with security investigations
- Report suspected breaches or security incidents without unreasonable delay to the Practice Compliance Officer
Business Associates shall notify the Practice of suspected breaches within forty-eight (48) hours of discovery unless a shorter timeframe is required by law or contract.
Compliance Officer — Contact
- Name
- Rachael Vaughn, CHC
- info@veteransroom.com
XII. Mobile Device Security
Devices used to access Practice information must:
- Require authentication
- Utilize encryption
- Maintain current security updates
- Use an automated time-out locking feature
- Support appropriate security protections
Contractor-owned devices used for Practice activities are subject to these requirements.
XIII. Audit and Monitoring
The Practice shall maintain appropriate audit controls to monitor system activity, identify unauthorized access, support investigations, and demonstrate compliance.
XIV. Substance Use Disorder (SUD) Records
When applicable, records protected under 42 CFR Part 2 shall receive appropriate privacy and security protections.
Effective February 16, 2026, the Practice Notice of Privacy Practices shall include required information regarding the use and disclosure of Substance Use Disorder (SUD) records.
Workforce members shall comply with applicable requirements related to SUD records, including restrictions on unauthorized redisclosure.
XV. Policy Review
This policy shall be reviewed annually and updated as necessary based on regulatory changes, security risks, technology changes, and incidental findings.
Ready to Start Your Own Care Journey?
Veterans Room provides veteran-informed, trauma-informed therapy, covered by TriWest CCN and TRICARE at no cost to most veterans in Texas and Washington State. Review 2026 TRICARE costs & fees ↗