NOTICE OF PRIVACY PRACTICES & WEBSITE PRIVACY POLICY
Effective Date: May 2, 2026
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN ACCESS THIS INFORMATION. PLEASE REVIEW CAREFULLY.
1. LEGAL FRAMEWORK & COMPLIANCE
Los Feliz Detox Center complies with all applicable federal and state privacy laws, including:
Health Insurance Portability and Accountability Act (HIPAA)
Confidentiality of Substance Use Disorder Patient Records (42 CFR Part 2)
California Confidentiality of Medical Information Act (CMIA)
California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA)
Where multiple laws apply, the most restrictive standard governs.
2. PROTECTED HEALTH INFORMATION (PHI)
We maintain and protect your Protected Health Information (PHI), which includes any information that identifies you and relates to your past, present, or future physical or mental health, including substance use disorder treatment.
3. SPECIAL CONFIDENTIALITY FOR SUBSTANCE USE DISORDER (42 CFR PART 2)
Records related to substance use disorder diagnosis, treatment, or referral are protected under 42 CFR Part 2.
We will not disclose any information identifying you as a patient in a substance use disorder program without your written consent, except as permitted by law.
A general medical release is NOT sufficient for Part 2-protected information.
Unauthorized disclosure is prohibited and may be subject to federal penalties.
4. HOW WE MAY USE AND DISCLOSE INFORMATION
A. Treatment, Payment, and Healthcare Operations (TPO)
We may use and disclose your information without authorization for:
Most disclosures involving substance use disorder information
Marketing communications
Release of psychotherapy notes (where applicable)
You may revoke authorization at any time in writing.
5. OTHER PERMITTED OR REQUIRED DISCLOSURES
We may disclose information without authorization when required by law, including:
Medical emergencies
Mandatory reporting (e.g., abuse, neglect)
Court orders (with appropriate legal standards)
Public health activities
Law enforcement (as permitted by HIPAA and 42 CFR Part 2)
6. YOUR RIGHTS REGARDING YOUR INFORMATION
You have the following rights:
Right to Access: Obtain a copy of your medical record
Right to Amend: Request corrections to your record
Right to Restrict: Request limits on certain uses/disclosures
Right to Confidential Communications: Request alternative contact methods
Right to Accounting: Receive a list of disclosures
Right to Revoke Authorization
Right to File a Complaint
Complaints may be filed with us or with the
U.S. Department of Health and Human Services.
You will not be retaliated against.
7. WEBSITE DATA COLLECTION
When using our website, we may collect:
Contact information submitted voluntarily
Insurance-related information for eligibility verification
Technical data (IP address, browser type, usage patterns)
We do not intentionally collect or transmit PHI through tracking technologies.
8. COOKIES, ANALYTICS, AND THIRD-PARTY TOOLS
We may use analytics tools (e.g., Google Analytics) to improve functionality.
These tools are configured to avoid the collection of PHI
We do not use tracking technologies to disclose sensitive health information
Any vendors are required to comply with applicable privacy laws and agreements
9. CALIFORNIA PRIVACY RIGHTS (CCPA/CPRA)
California residents have the right to:
Know what personal information is collected
Request deletion (subject to legal retention requirements)
Limit use of sensitive personal information
Receive equal service regardless of exercising rights
10. DATA SECURITY & SAFEGUARDS
We implement administrative, technical, and physical safeguards, including:
Role-based access controls
Unique user authentication
Encryption of data in transit (SSL/TLS)
Secure data storage systems
Workforce HIPAA and confidentiality training
Ongoing risk assessments and monitoring
11. BREACH NOTIFICATION
In the event of a breach of unsecured PHI:
You will be notified without unreasonable delay and within the required legal timeframes
Notifications will include details, risks, and recommended protective actions
Regulatory authorities will be notified as required
12. MINIMUM NECESSARY STANDARD
We limit use, disclosure, and requests for PHI to the minimum necessary to accomplish the intended purpose, in accordance with HIPAA and Part 2 requirements.
13. RETENTION OF RECORDS
We retain medical and personal records in accordance with:
California law
DHCS requirements
Accreditation standards
14. THIRD-PARTY LINKS
We are not responsible for the privacy practices of external websites.
15. CHANGES TO THIS NOTICE
We reserve the right to modify this notice. Updated versions will be posted with a revised effective date.