Live in Minnesota · 80% EVV threshold in effect since July 1 · See what it means
Minnesota DHS · 2026

The Minnesota 245D Individual Abuse Prevention Plan: what has to be in it

Not the program-wide policy. The one-per-person plan a licensor pulls out of an individual file — what it must contain, who signs it, and the one mistake that gets it flagged every time.

New to Minnesota compliance? Start with the Minnesota overview, or see the full 245D documentation checklist this plan is one piece of.

Most of what's written about Individual Abuse Prevention Plans online comes from law firms and compliance consultants explaining that the requirement exists. Fewer explain what a licensor is actually checking for when they open a person's file to page 1 of the plan. This is that page, with the citations behind it.

1. What it is, and what it isn't

Minnesota Statutes § 245A.65, subd. 2 requires every DHS license holder to maintain two separate written documents: a program abuse prevention plan covering the population, physical plant and environment the license holder controls, and an individual abuse prevention plan (IAPP) for each person receiving services. For providers of intensive support services — group homes, adult foster care, integrated community supports — § 245D.071, subd. 2 names the same obligation directly, rooted in the Vulnerable Adults Act's abuse-prevention-plan requirement at § 626.557, subd. 14.

The distinction matters because the two documents answer different questions. The program plan asks: given who we serve and where, what could go wrong here in general? The IAPP asks a narrower question about one specific person: given this person's history, cognition, mobility, and living situation, what is their specific risk, and what will staff specifically do about it? A licensor who finds a strong program plan and an empty or copy-pasted individual file has found exactly nothing about the population plan is protecting against.

2. Timing: before services start, then at least annually

Before or upon initiating services — the plan is developed as part of the person's initial service planning, not added later once someone gets around to it.

At least annually after that, using the person's individual assessment and any reports of abuse that occurred, with the plan revised to reflect what that review finds. And sooner than annually whenever something changes the person's actual risk: a move, a new diagnosis, a change in mobility or cognition, or after an incident involving that person specifically. An IAPP that was accurate a year ago and hasn't been touched since a fall, a hospitalization, or a new roommate is not current, and "current" is the standard § 245A.65 sets.

3. What the plan has to actually say

DHS's own sample IAPP document (the form most agencies start from) organizes the individual risk assessment into five categories. A complete plan addresses each one for the specific person, not as a checklist of boxes but as short, specific findings:

Sexual abuse — does the person understand sexuality and consent well enough to protect themselves; are they likely to seek out or go along with an abusive situation; can they assert a refusal.
Physical abuse — can they recognize a dangerous situation and remove themselves from it; do they have a documented history as a victim; how do they interact with unfamiliar people and handle aggression directed at them.
Self-abuse and self-neglect — safety awareness, self-injurious behavior, medication compliance, basic self-care, appropriate dress for conditions.
Financial exploitation — the person's actual ability to handle money and recognize when someone is taking advantage of them.
Risk the person may pose to others — any known history of violence or physical aggression, and what staff do to protect visitors, roommates, and the public if the person is unsupervised.

For every risk actually identified, the plan documents a specific protective measure — what staff do about it, in this program, for this person. Where a risk falls outside what the licensed service can address, the plan documents a referral instead of leaving the risk unaddressed. And where an assessment finds no elevated risk in a category, the plan says that too, rather than leaving the section blank.

4. Who has to be in the room

The person receiving services participates in developing their own plan to the full extent of their abilities — this is a participation right, not paperwork the program fills out about someone. Where the person has a legal representative, that representative must be given the opportunity to participate with or for them. DHS's sample document also carries a case manager signature line and a program representative signature line alongside the person's and legal representative's.

A plan with only a staff signature, developed without documented participation from the person or their representative, is missing the element regulators look for first — not because the signature itself matters, but because its absence is evidence the plan was written about someone rather than with them.

The one mistake that gets flagged every time

It isn't a missing signature or a late annual review — those are real findings, but they're visible and usually get fixed once. The recurring one is a plan that reads like a template: every category filled in with the same generic sentence regardless of who the person actually is, or a protective measure that doesn't connect to any risk named above it. That pattern is the fastest way to signal that thirty individual files were produced by copying one document thirty times, which is the opposite of what an individual abuse prevention plan is supposed to prove.

A note on what software can and cannot do

Software does not write the risk assessment for you, and it shouldn't try to. That judgment belongs to the person, their team, and whoever knows them best.

What a system can reasonably do is make sure the plan exists before services start, flag it the moment the annual review window is closing, and tie the review date to the person's actual assessment record instead of a spreadsheet nobody remembers to open. That is a narrower, more honest claim than "compliance software" usually makes — and it is the part that is genuinely easy to lose track of across a caseload with different admission dates and different review anniversaries for every person.

How Sothcare tracks 245D IAPP due dates →

Common questions

What is an Individual Abuse Prevention Plan (IAPP)?

A written, person-specific plan required for each person receiving 245D services. It documents that person's individual susceptibility to abuse — sexual, physical, self-abuse or self-neglect, financial exploitation, and any risk the person may pose to others — and the specific measures staff will take to reduce that risk. Required under Minn. Stat. § 245A.65, subd. 2, referenced for intensive support services at § 245D.071, subd. 2, and rooted in the Vulnerable Adults Act at § 626.557, subd. 14.

Is the IAPP the same as the program abuse prevention plan?

No. Minn. Stat. § 245A.65, subd. 2 requires two separate documents: a program abuse prevention plan covering the population, physical plant and environment the license holder controls, and an individual abuse prevention plan for each person served. A licensor will ask for both, and a generic program plan does not substitute for a missing individual plan.

When must the IAPP be completed, and how often is it reviewed?

Prior to or upon initiating services, developed as part of the person's initial service planning. After that, at least annually, using the person's individual assessment and any reports of abuse, and revised sooner whenever there is a change in the person's condition, living situation, or after an incident.

Who has to participate in and sign the plan?

The person receiving services participates to the full extent of their abilities; their legal representative, if any, must be given the opportunity to participate. DHS's own sample document also calls for the case manager's and the program's signatures.

What is the most common reason DHS flags an IAPP?

A plan that lists a risk category with no specific detail underneath it, or a protective measure that does not connect to any risk named above it. Both read as boilerplate copied across every person's file rather than an individualized assessment, which is the entire point of the document.

Want us to look at how you're tracking IAPP reviews today?

20 minutes, founder-led. Bring your current process — spreadsheet, shared drive, whatever it is.

Book my 20-min demo

Regulatory details on this page reflect the current text of Minn. Stat. §§ 245A.65, 245D.071 and 626.557, and DHS's published sample IAPP document, as of September 2026. Requirements and DHS guidance change — confirm current rules with your licensor before relying on this summary. Sothcare is documentation and workflow software; it supports your compliance program but does not replace your licensing, policies, or clinical judgment.