Skip to main content
Veterans Crisis Line988

Information
Security Policy.

Information Security Policy, 2026

Effective date: August 2026 · Last reviewed: August 2026

I. Purpose and Scope

The purpose of this Information Security Policy is to establish safeguards to protect the confidentiality, integrity, and availability of Protected Health Information (PHI), Electronic Protected Health Information (ePHI), and other sensitive Practice information.

This policy applies to all workforce members, 1099 clinicians, contractors, supervisors, consultants, Business Associates, and vendors who access Practice systems, applications, devices, or information containing PHI.

The Practice maintains compliance with HIPAA, HITECH, applicable state privacy laws, 42 CFR Part 2 (when applicable), OCR cybersecurity guidance, and OIG Compliance Program Guidance.

II. Security Responsibilities

The Compliance Officer oversees security compliance activities, including risk assessments, incident response, vendor oversight, and policy maintenance.

All workforce members and contractors must:

  • Protect Practice information and credentials
  • Use only approved systems and applications
  • Complete required security training
  • Report suspected security incidents immediately
  • Follow all applicable security policies

Failure to comply may result in corrective action, removal of system access, contract termination, or other appropriate action.

III. Access Control

Access to ePHI shall be limited to the minimum necessary information required to perform assigned responsibilities.

The Practice shall maintain:

  • Unique user accounts and passwords
  • Role-based access controls
  • Multi-Factor Authentication (MFA)
  • Access reviews
  • Audit logging where available
  • Prompt removal of access upon termination or role change

Shared accounts are prohibited.

IV. Multi-Factor Authentication (MFA)

MFA is required for all systems that access, store, transmit, or process ePHI, including:

  • Electronic health records
  • Telehealth platforms
  • Email systems
  • Cloud applications
  • Administrative systems containing PHI

Users may not disable MFA or bypass required security controls.

V. Encryption Requirements

All ePHI must be encrypted when stored and transmitted. The Practice requires:

  • Encryption of devices used to access Practice systems
  • Encryption of cloud storage containing ePHI
  • Secure transmission of PHI through approved platforms
  • Secure telehealth technology

Unencrypted storage or transmission of ePHI is strictly prohibited.

VI. Network and System Security

Systems containing ePHI must be protected through appropriate technical safeguards, including network segmentation or equivalent controls designed to limit unauthorized access and contain security incidents.

The Practice shall maintain appropriate protections for:

  • Telehealth systems
  • Cloud applications
  • Clinical systems
  • Administrative systems

VII. Asset Management and Approved Technology

The Practice shall maintain an inventory of technology used to access, store, or process ePHI, including:

  • Computers and mobile devices
  • EHR and telehealth systems
  • Cloud applications
  • Artificial Intelligence (“AI”) tools
  • Software applications

Only approved technology may be used for Practice operations involving PHI.

AI tools must undergo appropriate privacy, security, and compliance review before use and must be included in the Practice asset inventory.

VIII. Risk Analysis and Management

The Practice shall complete a comprehensive security risk analysis no less than annually. Risk assessments shall evaluate:

  • Security vulnerabilities
  • Cybersecurity threats
  • Vendor risks
  • Telehealth systems
  • Mobile devices
  • AI technologies

Identified risks shall be documented and addressed through appropriate corrective actions.

IX. Security Training

All workforce members and contractors must complete security and privacy training:

  • Before accessing Practice systems
  • Annually thereafter
  • When significant policy changes occur

Training shall include HIPAA security requirements, phishing awareness, password security, incident reporting, and appropriate use of technology.

X. Incident Response

The Practice shall maintain procedures to identify, investigate, mitigate, document, and respond to security incidents. Workforce members and contractors must report suspected incidents immediately, including:

  • Unauthorized access
  • Lost or stolen devices
  • Credential compromise
  • Malware or ransomware events
  • Improper disclosures
  • Vendor security incidents

The Practice shall investigate incidents, assess potential impact, document findings, and complete required notifications. Security incidents and potential breaches shall be evaluated promptly and escalated within seventy-two (72) hours of discovery when notification obligations may apply.

XI. Business Associate Management

Business Associates must execute a Business Associate Agreement (BAA) before accessing PHI. Business Associates must:

  • Maintain appropriate security safeguards
  • Protect PHI and ePHI information in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), applicable federal and state privacy laws, professional ethical standards, and Practice policies
  • Cooperate with security investigations
  • Report suspected breaches or security incidents without unreasonable delay to the Practice Compliance Officer

Business Associates shall notify the Practice of suspected breaches within forty-eight (48) hours of discovery unless a shorter timeframe is required by law or contract.

Compliance Officer — Contact

Name
Rachael Vaughn, CHC

XII. Mobile Device Security

Devices used to access Practice information must:

  • Require authentication
  • Utilize encryption
  • Maintain current security updates
  • Use an automated time-out locking feature
  • Support appropriate security protections

Contractor-owned devices used for Practice activities are subject to these requirements.

XIII. Audit and Monitoring

The Practice shall maintain appropriate audit controls to monitor system activity, identify unauthorized access, support investigations, and demonstrate compliance.

XIV. Substance Use Disorder (SUD) Records

When applicable, records protected under 42 CFR Part 2 shall receive appropriate privacy and security protections.

Effective February 16, 2026, the Practice Notice of Privacy Practices shall include required information regarding the use and disclosure of Substance Use Disorder (SUD) records.

Workforce members shall comply with applicable requirements related to SUD records, including restrictions on unauthorized redisclosure.

XV. Policy Review

This policy shall be reviewed annually and updated as necessary based on regulatory changes, security risks, technology changes, and incidental findings.

Ready to Start Your Own Care Journey?

Veterans Room provides veteran-informed, trauma-informed therapy, covered by TriWest CCN and TRICARE at no cost to most veterans in Texas and Washington State. Review 2026 TRICARE costs & fees ↗