Join us on september 27 @ UCLA

Click Here For More Details!

Search

Newsletter

Stay connected with us

Fill out the form. We’ll send mental health updates and resources right to your inbox.

Privacy Policy

Effective Date: November 11, 2025
Contact: [email protected] | (310) 390-6612
Website: https://didihirsch.org

1. Purpose and Scope

Didi Hirsch Mental Health Services (“Didi Hirsch,” “we,” “our,” or “us”) is a California-based 501(c)(3) nonprofit organization providing mental-health, substance-use, and suicide-prevention services.

We are a HIPAA-covered entity for clinical operations and a nonprofit for community education, training, and fundraising activities.
We collect and use information to support our mission of providing equitable, trauma-informed, and culturally responsive care.

This Policy explains how we collect, use, share, and safeguard information obtained through our websites, online forms, email communications, virtual events, and donation platforms (collectively, the “Site”).

When you receive or inquire about clinical or behavioral-health services, your data may constitute Protected Health Information (PHI) and is then governed by our Notice of Privacy Practices (HIPAA).

2 Information We Collect

Category Examples Purpose
Personal Identifiers Name, email, phone Service coordination and communication
Transaction Data Donation or event registration info Payment processing and receipts
Technical Data IP address, device type, cookies Website functionality and analytics
Sensitive Data Health or demographic info Care coordination or equity reporting (with consent)

A. Information You Provide Directly

Includes information submitted through service, referral, donation, employment, volunteer, media, or training forms—such as contact details, program preferences, payment data, and optional demographics.

B. Information Collected Automatically

IP address, approximate location, browser and device type, pages visited, and analytics identifiers (see § 11).

C. Sensitive or Health-Related Information

If you describe symptoms, crises, or service needs in a form, that information becomes PHI once entered into our clinical systems and is protected under HIPAA and 42 CFR Part 2.
Sensitive data such as race, ethnicity, gender, or disability is collected only when voluntarily provided or required by law.

3 Legal and Operational Bases for Use

We process information to:

  • Deliver requested services and respond to inquiries.
  • Administer donations and maintain required financial records.
  • Operate legitimate nonprofit interests such as education and quality improvement.
  • Comply with laws and regulations.
  • Protect vital interests, including life-safety and crisis response.
  • Act with your consent when required (e.g., using a testimonial or photo).

4 How We Use Information

We use information to: provide services, process donations, communicate updates, analyze Site performance, recruit personnel, and ensure accessibility and equity.

We never sell personal or donor data and never use PHI for marketing without authorization.

5 When and How We Disclose Information

We share information only when necessary and under strict controls:

  • Service Providers performing functions such as donation processing, email distribution, cloud hosting, analytics, or security.
  • Legal and Safety Obligations to comply with laws or protect individuals from harm.
  • Program Transitions if operations merge or reorganize, with confidentiality protections.
  • With Consent for donor recognition or stories.

All vendors must meet privacy and security standards equal to HIPAA and CPRA requirements.

6 Third-Party Vendors and Examples

  • Blackbaud / JustGiving / Stripe / PayPal – Donation processing (PCI-DSS Level 1)
  • Constant Contact / Mailchimp – Email distribution and event invitations
  • Google Analytics / Tag Manager – Website analytics and performance
  • Microsoft 365 / Salesforce Nonprofit Cloud – Secure document and constituent management

Vendors are periodically reviewed and contracted under written data-protection obligations.

7 Data Security and Incident Response

We maintain administrative, technical, and physical safeguards:

  • 256-bit SSL/TLS encryption in transit
  • Multifactor authentication and role-based access
  • Annual HIPAA and cybersecurity training
  • Encrypted backups and disaster recovery
  • Continuous intrusion and malware monitoring

If a data incident occurs, we activate our incident-response plan: containment, forensic review, notification to affected individuals, and regulatory reporting per HIPAA and state law.

8 Donations and Financial Information

  • All donations are processed via PCI-compliant vendors; we do not store full payment data.
  • Recurring donations use tokenized credentials.
  • Donor records are retained seven years for IRS and audit purposes.
  • Anonymous donations are respected.
  • Opt out of future solicitations any time via [email protected].

9 HIPAA and Protected Health Information (PHI)

PHI is used and disclosed only for treatment, payment, and health-care operations. We execute Business Associate Agreements with vendors handling PHI and never use PHI for marketing without authorization.

For details, see our Notice of Privacy Practices (HIPAA) or request a copy at [email protected].

10 Cookies, Analytics, and Tracking Technologies

We use cookies and similar tools to remember preferences, analyze traffic, and enhance security.

Type Purpose Retention
Essential Enable core functions Session
Analytics Aggregate performance data (Google Analytics) 26 months
Performance Load balancing and speed 12 months

You can disable cookies in your browser. We do not respond to “Do Not Track” signals. Opt out of Google Analytics at tools.google.com/dlpage/gaoptout.

See our Cookie & Tracking Notice for additional detail.

11 Automated Tools and AI

We use limited automated technologies, spam filters, form validation, and analytics, to protect and improve our Site. These tools never make decisions about service eligibility or care.

12 Third-Party Links and Social Media

Our Site may link to external sites or embed social content. We do not control those platforms. Pages protected by Google reCAPTCHA are subject to the Google Privacy Policy and Terms of Service.

13 Email and Text Communications

  • Marketing emails include unsubscribe links.
  • Transactional emails (e.g., receipts or policy updates) may still be sent.
  • SMS programs are optional; reply STOP to cancel, HELP for assistance. We do not share contact information for third-party advertising.
Record Type Typical Retention Legal Basis
Clinical records (PHI) ≥ 10 years or per law Health record rules
Donor records 7 years IRS and audit
Website logs / analytics ≤ 26 months Security analysis
HR applications 3 years Employment law
General inquiries 2 years Operational needs

We regularly review retention schedules to ensure compliance with evolving laws and grant requirements. Data slated for deletion is securely erased or de-identified under NIST SP 800-88.

15 Children and Youth Privacy

Our public Site is not intended for children under 13. We do not knowingly collect data from children online. Youth accessing crisis or clinical services are protected under federal and state confidentiality laws and our NPP.

16 California Privacy Rights (CPRA)

Although most nonprofits are exempt, we may voluntarily honor CPRA principles.

Right Description
Access / Portability Request a summary of personal data we maintain (excluding PHI).
Correction Request correction of inaccurate data.
Deletion Request deletion where permitted by law.
Opt-Out We do not sell or share personal data.
Authorized Agent Designate an agent to submit a request on your behalf.
Appeal If a request is denied, email [email protected] with subject “Privacy Rights Appeal.”
Non-Discrimination We will not deny services for exercising privacy rights.

We verify identity before fulfilling requests and respond within 45 days.

17 Cross-Border Data Transfers

Our systems are hosted in the United States. International users consent to transfer and processing here. We apply reasonable contractual and technical safeguards, including standard contractual clauses where required.

18 Updates to This Policy

We may revise this Policy periodically. Material changes will be posted on our homepage or communicated by email. We archive previous versions and make them available upon request.

19 Contact Us

Didi Hirsch Mental Health Services
Compliance & Privacy Office
4760 Sepulveda Blvd., Culver City, CA 90230
[email protected]
(310) 390-6612
You may also report accessibility issues or suspected privacy violations to this address.

Connect with us

Whether you’re looking for help, interested in joining our mission, or want to learn more, reach out to Didi Hirsch today.

Smiling woman wearing glasses and a black checkered top, talking on a mobile phone, framed in a circular lime green background against a dark backdrop

Get help

If you or someone you know is in crisis, call or text:

9-8-8

Chat Now

24/7, free & confidential

Teen Line

Peer-to-peer support for teens

(800) 852-8336

6 p.m. – 10 p.m. PST