skip to content

Introducing our new and improved online investment application!

Privacy Policy

Privacy Policy

PURPOSE

Texas Methodist Foundation ("TMF") shall protect the security and privacy of all information, including consumer financial information, entrusted to it. The purpose of this information security policy and related policies (the "Plan") is to provide a framework for protecting nonpublic, personal identifying information ("PII"). Specifically, the objective of this Plan is to: (a) ensure the security and confidentiality of PII; (b) protect against any reasonably anticipated threats or hazards to the security or integrity of PII; (c) ensure the secure and proper disposal of PII; and (d) protect against unauthorized access to or use of PII in a manner that creates a substantial risk of identity theft or fraud to those whom TMF seeks to protect under this Plan. In formulating and implementing this Plan, TMF has:

• Identified reasonably foreseeable internal and external risks to the security confidentiality, and/or integrity of any electronic, paper or other records containing PII

• Assessed the likelihood and potential damage of these threats, taking into consideration the sensitivity of the PII

• Evaluated the sufficiency of existing policies, procedures, information systems containing PII, and other safeguards in place to control risks

• Designed and implemented this information security Plan that puts safeguards in place to minimize those risks, consistent with the requirements under applicable laws

• Implemented regular monitoring of the effectiveness of those safeguards

• Applied each of the foregoing risk management steps to the secure and proper disposal of PII on our electronic or paper systems –and–

• Addressed the reasonably foreseeable risks to PII stored on the systems of our service providers and related third-parties

Personally Identifiable Information (PII)

For purposes of this policy, Personally Identifiable Information (PII) means any information that identifies, relates to, describes, or can reasonably be linked to a specific individual, either on its own or when combined with other information. PII includes both direct identifiers and indirect identifiers that, when combined with other data, could identify an individual.

In connection with loan origination, servicing, administration, investment account opening and management, and other related financial activities, the organization may receive, access, process, or maintain PII and other confidential customer information, including but not limited to:

  • Full name and contact information (mailing address, email address, telephone number)
  • Taxpayer Identification Number (TIN) or other government-issued identification numbers
  • Financial account information, including bank account and routing numbers
  • Loan application information, loan account numbers, payment history, balances, and other loan servicing records
  • Investment account applications, account ownership information, beneficiary designations, investment objectives, suitability information, and account transaction records
  • Investor, beneficiary, guarantor, authorized signer, or co-borrower information, when applicable
  • Any other personal, financial, organizational, or supporting documentation submitted by applicants, borrowers, investors, financial institutions, or third-party service providers in connection with these activities.

SCOPE

This Plan applies to all operating units of TMF, including its affiliates, employees, contractors, temporary employees, and other "users" at TMF, as well as those users affiliated with third parties who access/use such TMF’s information systems. The Plan (and other policies) use the term, "user," which refers collectively to all such individuals, and is not limited to all information systems located in TMF's offices and at offsite locations if these systems are under the jurisdiction or ownership of TMF.

TMF is committed to protecting the security and privacy of all information entrusted to it. Our services and internal operating processes and procedures will comply with applicable laws and regulations, as well as established industry practices.

An information security management policy is necessary to serve goals regarding operations, records and facilities.

Such goals include, among other things:

• Ensuring continuity of operations

• Protecting the integrity of business records

• Preventing unauthorized access to records

• Protecting privacy and security of sensitive information

The objective of this Plan is to document effective administrative, technical and physical safeguards for the protection of consumer and employee PII, and to comply with our obligations under various state and federal laws.

The Plan sets forth our protocols for evaluating and addressing our electronic and physical methods of accessing, collecting, processing, storing, using, transmitting, and protecting PII through to its proper and secure disposal. PII shall not include information that is lawfully obtained from publicly available information, or from federal, state or local government records lawfully made available to the general public.

For purposes of this Plan, PII is information protected under the following laws and their implementing regulations:

• The GLBA (15 U.S.C. §§ 6801 through 6809)

• The FTC Act (15 U.S.C. §§ 41 through 58, as amended)

o The FTC is responsible for enforcing its Privacy of Consumer Financial Information Rule (the "Privacy Rule"). Anyone who uses this guide should also review the Privacy Rule, found at 16 C.F.R. Part 313 (May 24, 2000).

INFORMATION SECURITY PLAN COORDINATOR

TMF designates a Director of Information Technology to implement, supervise, and maintain the Plan. This designated employee, known also as the Information Security Plan Coordinator ("ISPC"), will be responsible for:

• Implementation and enforcement of the Plan, including all related policies and procedures

Manage initial and ongoing monthly IT security awareness training for all employees with access to PII related to the Plan. Ensure employees complete assigned training courses and pass end-of-course assessments to demonstrate understanding of TMF's requirements for safeguarding and protecting PII

• Reviewing the scope of the security measures in the Plan at least annually or whenever there is a material change in our business practices that may implicate the security or integrity of records containing PII

• Reviewing the security procedures annually and fully apprising management of the results of that review and any recommendations for improved security arising out of that review

• Evaluating the ability of third-parties to implement and maintain appropriate security measures for the PII to which we have permitted them access

• Assessing and requiring such third-parties, by contract, to implement and maintain appropriate security measures

• Requiring that all employees, independent contractors and third-parties may be disciplined, or terminated for violations of this Plan

• Maintaining a secure and confidential primary list of all lock combinations, passwords, and keys. The list will identify which employee possesses keys, key cards, or other access devices and that only approved employees have been provided access credentials –and–

• Ensuring that access to personal information is restricted to approved and active user accounts

Authority and Reporting

• The ISPC is appointed by and reports to the President of TMF or her designee.

• Whenever a policy or procedure related to the Plan requires action or decision by a decision maker and the decision maker is not clearly identified in such policy or procedure, the ISPC shall be the decision maker or shall designate the decision maker.

SECURITY CONTROLS

The ISPC is responsible for developing an information security program to control the risks identified through its assessment, appropriate for the sensitivity of the information and the complexity and scope of TMF activities. The ISPC will implement the technical controls and measures necessary to address the identified risks. They shall include:

• Access controls on TMF’s constituents’ information systems, including controls to authenticate and permit access only to authorized individuals and controls to prevent employees from providing customer information to unauthorized individuals who may seek to obtain this information through fraudulent means

• Multi-factor authentication for any individual accessing any information system

• Access restrictions at physical locations containing customer information, such as buildings, computer facilities, and records storage facilities to permit access only to authorized individuals

• Encryption of electronic customer information, including while in transit or in storage on networks or systems to which unauthorized individuals may have access

• Procedures designed to ensure that customer information system modifications are consistent with the institution's information security program

• Dual control procedures, segregation of duties, and employee background checks for employees with responsibilities for or access to customer information

• Monitoring systems and procedures to detect actual and attempted attacks on or intrusions into customer information systems

• Installation of firewalls between the internal network and the internet to block unwanted traffic

• Software patch management

• Response programs that specify actions to be taken when the institution suspects or detects that unauthorized individuals have gained access to customer information systems, including appropriate reports to regulatory and law enforcement agencies –and–

• Measures to protect against destruction, loss, or damage of customer information due to potential environmental hazards, such as fire and water damage or technological failures

RISK ANALYSIS AND MANAGEMENT PROCEDURES

TMF shall conduct an initial risk assessment and subsequent risk assessment(s), as appropriate, to identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of Nonpublic Personal Information (as defined in the GLBA), proprietary or confidential information or other protected information (collectively referred to in this Plan as "protected information") that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and to assess the sufficiency of any safeguards in place to controls these risks. TMF shall further adopt and implement reasonable and appropriate safeguards and security measures to protect against any reasonably foreseeable threats to the privacy, integrity and availability of the protected information and the information systems in which protected information is created, received, transmitted and maintained.

Risk assessments should be performed based on sensitivity or criticality of the information used in the system or process. Systems that process sensitive information or provide critical services must be assessed more rigorously than those that do not. The risk assessment shall include, but is not limited to, the following four steps:

• Identifying reasonably foreseeable internal and external threats that could result in unauthorized disclosure, misuse, alteration, or destruction of customer information or customer information systems

• Assessing the likelihood and potential damage of identified threats, taking into consideration the sensitivity of the customer information

• Assessing the sufficiency of the policies, procedures, customer information systems, and other arrangements in place to control the identified risks –and–

• Applying each of the foregoing steps relating to the disposal of customer information

The risk assessment shall include criteria for the evaluation and categorization of identified security risks or threats faced by TMF; criteria for the assessment of confidentiality, integrity, and availability of information systems and customer information, including the adequacy of existing controls in the context of the identified risks; and requirements describing how identified risks will be mitigated or accepted based on the risk assessment and how the information security program will address the risks. The resulting analysis should guide management decisions on which safeguards are needed to address identified risks. The ISPC shall develop procedures for evaluating, selecting, rejecting and implementing safeguards under this Plan.

Risk Management Performance

Performance will be identified and measured by:

• Completion and reporting of reviews

• Compliance with regulations

• Results of annual penetration testing of TMF's information systems

• Information Security incidents that are investigated and analyzed for risk resulting in the appropriate response or controls implemented

• Testing of the effectiveness of the safeguards' key controls, systems, and procedures, including those to detect actual and attempted attacks on, or intrusions into, information systems

INFORMATION SYSTEMS ACTIVITY REVIEW PROCEDURES

TMF shall review information systems activity on a periodic basis to determine whether protected information is accessed or disclosed inappropriately.

The ISPC shall determine the records to be reviewed, the frequency of such reviews and the individual responsible. Examples of information system activity records may include, but are not limited to, audit logs, access reports and security incident reports.

Any security incidents identified as a result of information systems activity review shall be investigated as outlined in any related security incident policies and procedures.

EMPLOYEE SECURITY POLICY PROCEDURES

TMF shall ensure that employees requiring access to protected information have appropriate access while other workforce members who do not require protected information to perform their job duties are prevented from accessing such information.

All employees and others requiring access to protected information shall be identified in an access control list. Authorization to access protected information shall be granted as necessary based on job functions.

EDUCATION, TRAINING, AND AWARENESS

The information security and privacy policies and procedures of TMF will be communicated to all employees and a program to maintain effective awareness of information security policies and procedures will be implemented and maintained as follows:

• Use of the internet, email, and other TMF resources are strictly limited to business purposes

• Employees shall be made aware that they should have no expectation of privacy when using TMF resources or networks to access the internet, email, or otherwise using computer and information resources

• The ISPC shall ensure that all firewall protection and software security products (including, anti-virus, anti-malware, and internet security) shall be installed on all TMF computers, devices and other equipment that receives, stores or processes protected information. On a periodic basis, but no less than once every 12 months, the ISPC shall review the security products and safeguards utilized on TMF equipment and ensure that such products are reasonably current and sufficient to safeguard the protected information. TMF’s anti-virus software will be updated in accordance with the anti-virus vendors update recommendations, as often as daily

Email

• TMF shall employ virus protection software, including prevention of malware, on workstations to prevent transmission of viruses in email attachments

• Email that is not secure or encrypted should not be used to send protected information

• Unacceptable uses of TMF’s information technology include, among other things:

o Violation of the privacy of other users and their data

o Violation of the legal protection provided by copyright and licensing laws applied to programs and data

o Attempts by employees to monitor or intercept the files or electronic communications of other employees or third parties. This section will not apply to admin personnel ensuring enforcement with these protocols

o Attempts by employees to hack or obtain access to systems or accounts they are not authorized to use

o Use of other members' log-ins or passwords

o Use inconsistent with laws, regulations or accepted community standards

o Transmission of material in violation of any local, state or federal law or regulation is prohibited. It is not acceptable to transmit or knowingly receive threatening, obscene or harassing material

o Intentionally or knowingly releasing a virus or other program that damages, harms, or disrupts a system or network

o Violation of the integrity of computing systems

o Using TMF resources for unauthorized or illegal purposes or knowingly accepting or using information which has been obtained by illegal means

o Accessing or attempting to access data or information without proper authorization even if it is not securely protected

• Users are not permitted to install any unapproved software or attach any device to their computer or workstation without specific approval

• Equipment may not be removed from the office area without the President's prior approval

Virus Protection

To prevent computer viruses from being transmitted through the system, employees are not authorized to download any software from the internet onto their computer or any drive in that computer.

TMF maintains virus protection software on all network servers and filters all inbound and outbound email for virus attachments. Email containing a virus will be quarantined and both the sender and recipient will be informed. If the virus can be removed, the message will be forwarded to the recipient.

Employees may not open email from an unknown, suspicious or untrustworthy source nor download any attachments from such email.

Delete spam, chain, and other junk email without opening or forwarding such email.

PRIVACY AND SECURITY INCIDENT POLICY

Responses to Detected Cybersecurity Incidents

All privacy and security incidents shall be reported to the ISPC who shall take appropriate steps to block further incidents, repair and restore service, and preserve evidence. The incident response Plan is executed in coordination with relevant third parties once an incident is declared.

Incident Analysis

Any information concerning a known or suspected privacy or security breach (an "Incident") must be reported to the ISPC without delay and in writing. The ISPC is responsible for managing mitigation efforts. The ISPC shall conduct a prompt assessment of the nature and scope of the incident and identification of what PII has been accessed or misused. Incident reports should be triaged and validated. Investigations are conducted to ensure effective response and support forensics and recovery activities.

Incident Response Reporting and Communication

TMF shall promptly notify the appropriate authorities once TMF becomes aware of an incident involving unauthorized access to or use of PII. In collaboration with the President, the ISPC shall implement measures to contain and control the incident to prevent further authorized access to or misuse of PII, preserving records and other evidence.

If the ISPC determines that any security incident should be reported as a notification event, as that term is defined under the Safeguards Rule, then the ISPC, or its designee, shall report such event in the manner provided on the FTC website no later than 30 days after discovery of such notification event.

Incident Recovery Plan Execution

Restoration activities are performed to ensure operational availability of systems and services affected by cybersecurity incidents.

The ISPC commences recovery procedures during or after incident response processes. The ISPC makes all individuals with recovery responsibilities aware of the Plans for recovery and the authorizations required to implement each aspect of the Plan.

Recovery actions are selected, scoped, prioritized, and performed.

The integrity of backups and other restoration assets is verified before using them for restoration.

Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms.

The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed.

CONTIGENCY PLAN POLICY

TMF shall develop, implement and maintain appropriate procedures to respond to system emergencies or other occurrences (i.e., fire, vandalism, system failure, natural disaster, etc.). These procedures shall constitute TMF’s "contingency Plan."

Data Backup Plan

TMF maintains a comprehensive backup Plan for the entire TMF. Protected Information is stored and maintained at TMF's Austin office and within cloud-based systems hosted on secure cloud servers. Local data backups are performed nightly and stored on onsite Network Attached Storage (NAS) devices. Backup data is subsequently transmitted to secure cloud storage and retained for a period of thirty (30) days.

These backup procedures are designed to support business continuity, disaster recovery, and the timely restoration of data in the event of a system failure, data loss, or other disruption.

Administrators are responsible for backing up each system and are required to implement a tested and auditable process. Application software shall be copied to a separate backup medium as new applications are added. System software should be copied periodically and as major changes are made.

Disaster Recovery Plan

In an emergency, the ISPC or a designee shall assess the impact to protected information and operations. The ISPC or a designee shall activate the disaster recovery Plan by notifying the appropriate personnel. The ISPC shall identify an alternate location if necessary. The ISPC shall arrange for replacement equipment if necessary. The backup shall be retrieved from storage and restored.

Emergency Mode Operation

The ISPC shall ensure the technical security of protected information via several escalating in privilege, encrypted username and password credentials.

Contingency Operations

The ISPC shall grant temporary access as necessary to replace equipment and restore lost data. The ISPC shall grant access to workforce members as required for contingency operations.

Testing and Revision

TMF’s contingency Plan shall be tested (and revised as appropriate) periodically and whenever significant changes occur in TMF's information technology environment. All employees shall receive training in contingency Plan procedures.

Applications and Data Criticality Analysis

The ISPC shall determine the protected information most critical in an emergency. The systems and software used to access such protected information shall be prioritized for restoration.

EVALUATION ASSESSMENT

TMF shall perform a periodic technical and non-technical evaluation to make certain that TMF's security policies and procedures continue to comply with all applicable laws, regulations, and administrative policies.

The ISPC shall determine the frequency and scope of each evaluation. Documentation of such evaluations shall be maintained for a period of five (5) years. The evaluation shall consider:

• For initial evaluation under all applicable legal and regulatory standards

• For subsequent evaluation, including environmental and operational changes affecting the security of protected information

BACKUPS AND RECOVERY PROCEDURES

The Plan applies to all data stored on TMF systems. The Plan addresses specifics as the type of data to be backed up, frequency of backups, storage of backups, retention of backups, and restoration procedures.

Backups of critical information shall be conducted in a manner to allow timely recovery of information. TMF must identify what data is most critical to its organization. This can be done through a formal data classification process or through an informal review of information assets. Regardless of the method, critical data should be identified so that it can be given the highest priority during the backup process.

The backup policy must balance the importance of the data to be backed up with the burden such backups place on the users, network resources, and the backup administrator.

Data to be backed up includes:

• All data determined to be critical to TMF operation and/or employee job function

• All information stored on the file servers and email servers. It is the user's responsibility to ensure that all critical data (Word documents, spreadsheets, presentations, etc.) are stored in TMF’s designated cloud backup provider

• Backup frequency is critical to successful data recovery. TMF has determined that the following backup schedule will allow for sufficient data recovery in an incident, while avoiding an undue burden on the users, network, and backup administrator:

o Backups (real-time backup of primary server, with nightly backups of the backup server)

o Retention (local backups are saved daily; offsite backups are retained for 30 days in daily increments)

o Purge (protected information is purged every 30 days)

Backups are stored on secure cloud servers. The data restoration procedures must be tested and documented. Documentation should include exactly who is responsible for the restore, how it is performed, under what circumstances it is to be performed, and how long it should take from request to restoration. It is extremely important that the procedures are clear and concise such that they are not:

• Misinterpreted by readers other than the backup administrator –and–

• Confusing during a time of crisis

DESTRUCTION OF PROTECTED INFORMATION POLICY

This Plan covers all media containing protected information. All media shall be wiped or destroyed in a manner to safeguard confidentiality of protected information.

PLAN EXCEPTIONS

The information security officer acknowledges that, in rare circumstances, certain users will need to employ systems that are not compliant with these policies. The manager of information security must approve all such instances in writing in advance.

CONTACT POINT

Questions regarding this Plan and other information security policies may be directed to the ISPC and the information security department.

PLAN COMPLIANCE

Failure to comply with this Plan and all supporting or related information security policies, procedures, and guidelines will be investigated and presented to TMF's appropriate executive officers and management for disciplinary action, up to and including termination of employment and/or legal action, as appropriate.

EFFECTIVE DATE

This Plan is effective as of: June 1, 2026