My Care › Privacy
Your Privacy.
Our work is governed by California law, the Board of Behavioral Sciences, and federal HIPAA standards.
Last updated: August 2026
Analytics & Site Data
This site uses Google Analytics to collect anonymized data: pages visited, time on site, and general region. No personally identifiable information is collected automatically.
IP anonymization is enabled. We do not use advertising pixels, session recorders, or third-party tracking tools. You may opt out via the Google Analytics Opt-out Add-on.
Under the California Consumer Privacy Act (CCPA), you have the right to know what personal information we collect, request its deletion, correct inaccuracies, and opt out of its sale. We do not sell yours. Exercising any of these rights will never affect the quality of care you receive. Protected health information covered by HIPAA is governed separately under HIPAA, not CCPA. Google Analytics data is used solely to improve the patient experience on this site and is never shared with advertisers or used to make clinical decisions about individual patients. To exercise any of these rights, contact us using the information at the bottom of this page.
Minimal Data Collection
We collect only what you voluntarily provide — typically your name, phone number, and email address — used solely to respond to you and schedule your care. We do not market to you or share your data with third parties.
If you contact us and do not become a patient, your information is retained for no more than 90 days from your last contact, then deleted. No marketing lists, no follow-up campaigns.
Active patient records are stored within SimplePractice, our HIPAA-compliant EHR. Under HIPAA, you have the right to access your records, request corrections, and file a complaint with HHS without retaliation.
This website does not use chatbots, live chat widgets, or third-party plugins to collect visitor data. Do not submit diagnoses, treatment history, or other sensitive clinical details through the contact form; once you are an active patient, share that information only through SimplePractice's secure messaging system.
Patient Confidentiality
Your health information is protected under HIPAA and California's Confidentiality of Medical Information Act (CMIA). All sessions are conducted through a HIPAA-compliant, end-to-end encrypted platform.
Your employer, family, and insurance company cannot access your records without your signed written consent. All release-of-information requests are handled through formal authorization forms within SimplePractice.
Minors aged 12 and older may have the right to consent to certain mental health treatment without parental consent under California Health & Safety Code §124260. Your clinician will explain these provisions during informed consent.
Sessions are never recorded without your explicit written consent. Our telehealth platform does not record by default, and PMHS does not record sessions for training, quality review, or any other purpose without your prior written authorization.
Professional Ethics & Legal Limits
Our clinicians are bound by the ethical codes of the American Counseling Association (ACA) and CAMFT, as well as licensing requirements enforced by the California Board of Behavioral Sciences (BBS).
Mandatory disclosure obligations include suspected child abuse under CANRA, elder or dependent adult abuse, and imminent danger to the patient or an identifiable third party under the Tarasoff duty to warn.
These limits are not loopholes. They exist to protect the most vulnerable. Every patient is informed of these limits in full before services begin. Questions about your specific situation belong in conversation with your clinician.
Informed Communication
Email and contact forms are not encrypted to the same clinical standard as our telehealth platform. Use them for general questions only. Do not share diagnoses, clinical details, or sensitive information through these channels.
Once active, all clinical communication occurs through SimplePractice's secure messaging system. Your clinician does not use personal email or text messaging for clinical matters.
Voicemails are checked during business hours only. We do not monitor communications in real time. For anything urgent, always use the crisis resources on our Connect page rather than waiting for a callback.
Operational Safeguards
All patient records are stored within SimplePractice under a HIPAA Business Associate Agreement. Clinical devices are encrypted and password-protected. Access is limited strictly to authorized personnel on a need-to-know basis.
All clinical staff complete training on HIPAA compliance, telehealth security, and California confidentiality law. These trainings are completed at onboarding and reviewed regularly.
In the event of a data breach affecting your protected health information, PMHS is required to notify you within 60 days of discovery under the HIPAA Breach Notification Rule. We have internal procedures in place to identify, contain, and report any such incident and will never withhold breach information from affected patients.
Questions or Requests
Contact Our Privacy Officer
This page is a plain-language summary. For the complete legal Notice of Privacy Practices required under HIPAA, see our HIPAA Notice of Privacy Practices.
For questions about this page, to exercise your CCPA rights, or to file a privacy concern directly with us, contact:
Privacy Officer: Ryan Frost
Director of Clinical Services & Training
Pacific Mental Health Services
Phone: (530) 604-4309
Email: rfrost@pacmhs.com
Legal Notice
No therapeutic relationship through this website
Visiting this site or submitting a form does not create a therapist-patient relationship. Services formally begin only after intake paperwork, informed consent, and scheduling with a licensed or pre-licensed clinician.