Information Security Plan

EFFECTIVE DATE: AUGUST 1, 2026

BIRCH INTEGRATED BEHAVIORAL HEALTH, P.C.

SECURITY PLAN FOR MAINTENANCE OF PERSONAL INFORMATION OF MASSACHUSETTS RESIDENTS

  1. OBJECTIVES & SCOPE OF PLAN 

This information security plan (“Plan”) sets forth this Practice’s policies, rules and procedures relating to the collection, storage, use, transmittal, protection and disposal of Personal Information of Massachusetts residents, and is intended to create effective administrative, technical and physical safeguards for the protection of such Personal Information and to comply with this Practice’s obligations under 201 CMR 17.00. 

This Plan supplements the Practice’s Health Information Policies and Procedures which include compliance with state and federal regulations, including the Health Insurance Portability and Accountability Act of 1996 (“HIPPA”) and the related regulations, 45 CFR Parts 160 and 164, and the FTC’s Red Flag Rule. 

As used in this Plan, “Personal Information” means a Massachusetts resident’s first name and last name or first initial and last name in combination with any one or more of the following data elements that relate to such resident: (a) Social Security number; (b) driver’s license number or state-issued identification card number; or (c) financial account number, or credit or debit card number, with or without any required security code, access code, personal identification number or password, that would permit access to a resident’s financial account; provided, however, that “Personal Information” shall not include information that is lawfully obtained from publicly available information, or from federal, state or local government records lawfully made available to the general public. 

In developing and maintaining the Plan, the Practice will (1) identify reasonably foreseeable internal and external risks to the security, confidentiality, and/or integrity of any electronic, paper or other records containing Personal Information; (2) assess the likelihood and potential damage of these threats; (3) evaluate the sufficiency of existing policies and procedures in place to control risks; (4) implement a plan that puts safeguards in place to minimize those risks, consistent with the requirements of 201 CMR 17.00; and (5) regularly monitor the effectiveness of those safeguards. 

  1. DATA SECURITY COORDINATOR 

The initial Data Security Coordinator for the Practice is Alina Birch, who also serves as the Practice’s Compliance Officer.   The Data Security Coordinator will be responsible for the implementation, supervision and maintenance of this Plan. The Data Security Coordinator may be changed by the Board of Directors from time to time. 

The responsibilities of The Data Security Coordinator will include the following: 

(a) Initial implementation of the Plan and periodic review of the Plan as outlined in clause (f) of Part III below. 

(b) Training of employees, including temporary and contract employees, who have access to Personal Information on the provisions of the Plan and the proper use of the computer security system. Such training will be conducted at least annually, and attendees will be required to certify their attendance at the training and their familiarity with the Practice’s policies on the protection of Personal Information outlined in such training. 

(c) Monitoring compliance with the requirements of clause

(d) of Part III of this Plan relating to the selection of third-party Service Providers. 

(d) Maintaining the master list of passwords, access codes and other information as outlined in clause (n) of Part III below. 

(e) Coordinating the response to incidents outlined in Part V of this Plan. 

III. INTERNAL RISKS 

To combat internal risks to the security, confidentiality, and/or integrity of any electronic, paper or other records containing Personal Information, and to evaluate and improve, where necessary, the effectiveness of the current safeguards for limiting such risks, the following measures are mandatory and are effective immediately. To the extent that any of these measures require a phase-in period, such phase-in shall be completed on or before March 1, 2010. 

(a) A copy of the Plan must be distributed to each employee who may have access to Personal Information, including each temporary and contract employee, who shall, upon receipt of the Plan, acknowledge in writing that he/she has received a copy of the Plan. 

(b) There will be immediate training of employees who may have access to Personal Information, including temporary and contract employees, on the provisions of the Plan and the proper use of the computer security system. 

(c) All employment contracts, independent contractor agreements or similar contracts with parties who may have access to Personal Information, entered into after the date hereof, shall include a provision requiring the employee, independent contractor or other party to comply with the provisions of the Plan, and prohibiting them from any nonconforming use of Personal Information during or after the term of employment or engagement, with mandatory disciplinary action to be taken for violation of security provisions of the Plan by any employee, the nature of such disciplinary action to be determined by the Board of Directors in light of all of the circumstances of the violation. 

(d) With respect to third-party Service Providers who may have access to Personal Information, the Practice shall take reasonable steps to select and retain only Service Providers that are capable of maintaining appropriate security measures to protect Personal Information consistent with this Plan and with 201 CMR 17.00 and any applicable federal regulations, including HIPPA; and the Practice shall require such third-party Service Providers to agree in writing to implement and maintain appropriate security measures for the handling of Personal Information meeting the standards of 201 C.M.R 17.00 and any applicable federal regulations, including the HIPAA privacy and security regulations; provided, however, that any contract the Practice  has entered into with a third party Service Provider shall be deemed to be in compliance herewith, notwithstanding the absence in any such contract of a requirement that the Service Provider maintain such protective security measures, so long as the contract was entered into before March 1, 2010. 

As used in this Plan, “Service Provider” means any person that receives, maintains, processes, or otherwise is permitted access to Personal Information through its provision of services directly to the Practice; provided, however, that “Service Provider” shall not include the U.S. Postal Service. 

(e) To the extent determined by Board of Directors, existing employment contracts and other contracts will be amended to meet the requirements set forth in clause (c) and clause (d) above. 

(f) All security measures included in this Plan shall be reviewed at least annually, or whenever there is a material change in our business practices that may reasonably implicate the security or integrity of records containing Personal Information. The Data Security Coordinator shall be responsible for this review and shall report to management the results of that review and any recommendations for improved security arising out of that review. 

(g) We will try to limit the amount of Personal Information collected to that reasonably necessary to accomplish our legitimate business purposes and to limit the time such Personal Information is retained to that reasonably necessary to accomplish such purposes. We will also try to limit access to those persons who are reasonably required to know such Personal Information. 

(h) Paper or electronic records containing Personal Information shall be disposed of only in a manner that complies with M.G.L. c. 93I as follows: (1) paper documents containing Personal Information shall be either redacted, burned, shredded or otherwise destroyed so that personal data cannot practicably be read or reconstructed; (2) electronic media and other non-paper media containing Personal Information shall be destroyed or erased so that Personal Information cannot practicably be read or reconstructed; and (3) if we contract with a third party to dispose of Personal Information, we will ensure that they do so in accordance with M.G.L. c. 93I. 

(i) Employees are prohibited from keeping open files containing Personal Information on their desks when they are away from their desks. Employees must lock their computer terminals when they step away from their desks even for a brief period of time and must secure all files containing Personal Information, log off of their computers, and lock their desk/cabinet/office door when they leave at the end of the day or for any extended period of time. 

(j) Employees will only be allowed to place Personal Information on computers, portable devices or storage media that are properly encrypted and previously approved by the Data Security Coordinator. When Employees carry Personal Information off business premises, they must keep it in their physical possession, or locked in a safe location, at all times. As soon as practicable, they should remove the Personal Information from portable devices and media and return it to the business premises. 

(k) Access to electronically stored Personal Information shall be electronically limited to those employees having a unique log-in ID; and re-log-in shall be required when a computer has been inactive for more than ten minutes. Current employees’ user IDs, passwords and other security access codes must be changed periodically. Electronic access to Personal Information must be blocked after multiple unsuccessful attempts to log in using unique user identification information. 

(l) When shipping files containing Personal Information, we will encrypt the information, if possible, keep an inventory of the Personal Information being shipped, and use a carrier with delivery tracking if reasonably practicable. 

(m) Terminated employees must return all records (paper and electronic) and devices containing Personal Information then in their possession. A terminated employee’s physical and electronic access to Personal Information must be blocked immediately upon termination. Terminated employees shall be required to surrender all keys, IDs or badges, access codes, passwords, and similar items that may permit access to our premises, computer systems or information. Immediately upon termination, a terminated employee’s remote electronic access to Personal Information must be disabled; his/her voicemail access, e-mail access, and Internet access must be terminated, and all of his/her passwords and log-in information must be invalidated. 

(n) The Data Security Coordinator shall maintain and keep up-to-date, in a secured location, a master list of all lock combinations, keys, passwords, access codes, log-in information and similar information, including the names of all persons who have possession or access to such items. 

(o) All visitors shall be logged in and shall not be permitted to visit unescorted any area within our premises that contains Personal Information. 

(p) Employees will be encouraged to promptly report to the Data Security Coordinator any suspicious or unauthorized use of Personal Information. 

(q) An employee who violates any of the policies or procedures set forth in this Plan will be subject to disciplinary action, up to and including termination of employment under appropriate circumstances.

IV. EXTERNAL RISKS 

To combat external risks to the security, confidentiality, and/or integrity of any electronically stored or transmitted Personal Information, the following measures are mandatory and are effective immediately, and shall be met to the extent technically feasible. 

To the extent that any of these measures require a phase-in period, such phase-in shall be completed on or before March 1, 2010. 

(a) There must be reasonably up-to-date firewall protection and operating system security patches, reasonably designed to maintain the integrity of the Personal Information, installed on all systems processing Personal Information. 

(b) There must be reasonably up-to-date versions of system security agent software which must include malware protection and reasonably up-to-date patches and virus definitions, installed on all systems processing Personal Information, or a version of such software that can be supported with up-to-date patches and virus definitions and is set to receive the most current security updates on a regular basis. 

(c) All Personal Information stored on laptops, flash drives, PDAs, CDs or DVDs or other portable devices or storage media must be encrypted, as must all records and files transmitted across public networks or transmitted wirelessly. Encryption shall mean the transformation of data through the use of an algorithmic process, or an alternative method at least as secure, into a form in which meaning cannot be assigned without the use of a confidential process or key, unless further defined by regulation by the Massachusetts Office of Consumer Affairs and Business Regulation. The deadline for ensuring encryption of laptops and other portable devices is March 1, 2010. 

(d) There must be secure user authentication protocols in place, including: (1) protocols for control of user IDs and other identifiers; (2) a reasonably secure method of assigning and selecting passwords, or use of unique identifier technologies, such as biometrics or token devices; (3) control of data security passwords to ensure that such passwords are kept in a location and/or format that does not compromise the security of the data they protect; (4) restriction of access to active users and active user accounts only; and (5) blocking of access to user identification after multiple unsuccessful attempts to gain access. 

(e) The secure access control measures in place must include assigning unique identifications plus passwords, which are not vendor-supplied default passwords, to each person with computer access to Personal Information. Access to Personal Information should be restricted to just those persons who need such information to perform their job duties. 

(f) All computer systems must be monitored regularly for unauthorized use of or access to Personal Information. 

(g) Training of employees should include training on the proper use of the computer security system. 

V. RESPONSE TO INCIDENTS 

Whenever there is an incident involving a breach of security or that requires notification under M.G.L. c. 93H, §3 or the HIPAA breach notification rule, there shall be an immediate mandatory post-incident review of events and the responsive actions taken, if any, with a view to determining whether any changes in the Plan or our security practices are required to improve the security of Personal Information. We will also contact legal counsel under appropriate circumstances to assure compliance with applicable law and revision of internal policies and procedures if necessary. 

Massachusetts Law

When we know or have reason to know of a security breach, or know or have reason to know that Personal Information was acquired or used by an unauthorized person or used for an unauthorized purpose, shall provide notice as soon as possible to (1) the Massachusetts Attorney General, (2) the Director of the Massachusetts Office of Consumer Affairs and Business Regulation, and (3) the Massachusetts resident whose Personal Information is or may have been involved, as required by M.G.L. c. 93H, §3; provided, however, that if we do not own or license the data which includes the Personal Information, but merely maintain or store it for a third-party owner or licensor, then we shall provide notice only to the owner or licensor, and we shall cooperate with the owner or licensor as required by M.G.L. c. 93H, §3(a). 

The notice to be provided to the Massachusetts Attorney General and the Director of the Massachusetts Office of Consumer Affairs and Business Regulation (and any consumer reporting agencies or state agencies that they may direct us to notify) shall include, but not be limited to, (i) a detailed description of the nature and circumstances of the breach of security or unauthorized acquisition or use, (ii) the number of Massachusetts residents affected by such incident at the time of notification, (iii) any steps we have already taken relating to the incident, (iv) any steps we intend to take subsequent to notification, and (v) information regarding whether law enforcement is investigating the incident. 

The notice to be provided to the Massachusetts resident shall include, but not be limited to, the individual’s right to obtain a police report, how an individual requests a security freeze and the necessary information to be provided when requesting the security freeze, and any fees required to be paid to any of the consumer reporting agencies, provided, however, that said notification shall not include the nature of the breach or unauthorized acquisition or use or the number of residents of Massachusetts affected by said breach or unauthorized access or use. 

HIPAA Breach Notification Rule

The Practice shall also conduct a risk assessment to determine if the breach included any personal health information (PHI) and determine if there is any significant risk of financial, reputational or other harm to the affected individual(s).  Specifically, we will look at the following factors: 

  1. Nature of the breach; 
  2. Number of individuals affected; 
  3. Likelihood the information is accessible and unusable; 
  4. Likelihood the breach may lead to harm; and 
  5. Ability to mitigate the harm; 

The risk assessment shall be documented and if it results in a determination that there is a breach of PHI which poses a significant financial, reputational or other harm to the affected individual(s), then the Practice shall notify the individual as soon as possible and the Secretary of Health and Human Services as required. If the risk assessment results in a minimal risk and no harm to the individual, no notice is required.  

The individual notice shall be sent first class mail or by electronic mail, if the individual has authorized such communications.  The notice shall include (i) a description of the breach; (ii) the PHI involved; (iii) the steps the individual can take to protect him or herself from the harm; (iv) the actions the Practice has taken to investigate the breach, mitigate the harm and prevent future breaches; and, (v) the Practice’s contact information. 

If the breach has affected more than 500 individuals, the Practice will immediately notify the Secretary of Health and Human Services. For all breaches which affect less than 500 individuals, the Practice shall keep a log and notify the Secretary on an annual basis.