Human services programs collect some of the most sensitive information any organization holds. Case notes, housing history, health details, and family situations all live in client records. Protecting that information honors the trust people place in you when they ask for help.
This guide covers the practical steps that keep case files confidential, whether they live in software, on paper, or on a laptop in the field.
Confirm which rules apply to your programs
Different programs fall under different rules, so start by confirming your obligations with legal counsel. HIPAA, for example, applies to covered entities and their business associates. Covered entities include health care providers that conduct standard transactions, such as insurance billing, electronically.
Some nonprofit programs meet that definition, while many others do not. So confirm whether HIPAA applies to each program rather than assuming either way.
Other rules may apply instead or in addition. For instance, federally assisted substance use disorder programs follow separate federal confidentiality regulations. State laws often protect mental health and child welfare information, and government contracts frequently set their own data terms.
Limit access to the minimum needed
Staff should see only the information their role requires. For example, a front desk volunteer may need a name and appointment time but not case notes.
Most case management systems support role-based permissions. Use them, and review who has access whenever someone changes roles or leaves. In addition, turn on audit logs, so you can see who viewed or changed a file.
Also, think about volunteers and interns. Give them the narrowest access possible, and remove it the day their assignment ends.
Secure case management systems and devices
Your case management platform is only as safe as the logins and devices that reach it. Therefore, require MFA for every user, and set sessions to time out after inactivity.
Next, protect the laptops and tablets that staff carry to home visits. Encrypt them, manage them centrally, and confirm you can wipe them remotely. Also, block program data from syncing to personal cloud storage.
In addition, ask your software vendor about backups, audit logs, and how they handle security incidents. Their answers affect your own obligations.
A checklist for protecting client records
Review these items with program directors and your IT partner. Then assign an owner to each gap.
- A written list of the laws, regulations, and contract terms that apply to each program
- Role-based access in the case management system, reviewed quarterly
- MFA on every account that can view client information
- Encryption and remote wipe on all laptops, tablets, and phones
- Signed releases on file before you share information with partners
- Encrypted methods for sending files outside the organization
- Locked storage and a shredding process for paper files
- A retention schedule that sets how long you keep files and how you destroy them
Share data with partners carefully
Human services work often involves referrals to shelters, clinics, schools, and government agencies. Each exchange creates risk if it happens over regular email or open file links.
Instead, use encrypted email or a secure portal for anything with client details. Also confirm that you have written consent when the law or your policies require it. Some programs, such as domestic violence services, face strict limits on sharing identifying information at all.
For shared community databases, such as a homeless management information system, follow the lead agency’s policies and train staff on them.
Do not forget paper and retention
Many programs still use paper intake forms, sign-in sheets, and signed consents. So store them in locked cabinets, and never leave them on desks or in cars.
Also, train staff to handle paper in the field. Carry only what a visit requires, and bring documents back to the office rather than leaving them at home.
Likewise, set a retention schedule based on legal and funder requirements. Keeping files longer than necessary increases exposure without helping anyone. When the time comes, shred paper and securely wipe digital copies.
How WEBIT helps
WEBIT helps human services nonprofits protect client records with layered security on every managed device, including Zero Trust EDR, endpoint management, and application allowlisting. We also baseline every client to the CIS Controls, which gives you a clear, documented starting point.
For programs with formal compliance needs, our managed compliance add-on helps track policies and evidence. Visit our nonprofit IT page, or contact us to review your setup.
Key takeaways
- Confirm with counsel whether HIPAA or other confidentiality rules apply to each program.
- Limit access by role, and use audit logs to see who opens case files.
- Encrypt and manage every device that staff take into the field.
- Share client records with partners only through secure channels and with proper consent.
- Set retention schedules, and destroy paper and digital files safely.