1. Introduction & scope
This Privacy Policy describes how Safer Health Solutions collects, uses, discloses, and safeguards information in the course of operating our business and delivering Enhanced Care Management (ECM) and Community Supports (CS) to Medi-Cal members under California's CalAIM initiative.
It applies to our public website, to individuals we serve through our care programs, and to the providers, managed care plans, and community organizations we partner with. Where we handle protected health information (PHI) on behalf of a health plan, that information is also governed by HIPAA and by our agreements with those plans, as described in Section 6.
2. Who we are
Safer Health Solutions is a community-based care organization that provides Enhanced Care Management and Community Supports to Medi-Cal members with complex health and social needs. We contract with Medi-Cal managed care plans to deliver whole-person care that spans medical, behavioral, and social services. In many of these relationships we act as a Business Associate (or downstream subcontractor) of the health plan under HIPAA.
3. Information we collect
The information we handle depends on your relationship with us.
Members and participants
To deliver care, we process protected health information and personal information such as name, date of birth, contact details, Medi-Cal / member ID (CIN), demographic information, diagnoses and clinical information, care and service history, housing and social-needs information, and details necessary to coordinate benefits and Community Supports. We generally receive this information from the member's managed care plan, from the member directly, or from their providers.
Website visitors
When you visit our website or contact us, we may collect the information you submit (such as your name, email, phone, and message) and limited technical information such as IP address, browser type, and pages viewed. Please do not send protected health information through our general contact forms or email.
Providers, partners, and staff
We process business-contact and credentialing information for the providers, plans, and community organizations we work with, and standard employment information for our workforce.
4. How we use information
We use information to:
- Provide and coordinate Enhanced Care Management and Community Supports;
- Assess member needs, build care plans, and connect members to services;
- Communicate with members, providers, and managed care plans about care;
- Perform care coordination, reporting, and quality activities required by our plan partners and by law;
- Operate, secure, and improve our website and services;
- Meet our legal, regulatory, and contractual obligations.
We use PHI only for treatment, payment, and health care operations as permitted by HIPAA and our agreements — not for advertising, and never sold.
5. How we share information
We share information only as needed to deliver care and run our business, including with:
- The member's Medi-Cal managed care plan, for care coordination and required reporting;
- Providers and community organizations involved in the member's care;
- Service providers ("business associates") who support our operations under written agreements requiring them to protect the information;
- Government agencies or others when required by law, regulation, or valid legal process.
We do not sell or rent personal information or PHI, and we do not share it for third-party marketing.
6. HIPAA & protected health information
Protected health information we handle on behalf of a managed care plan is governed by the Health Insurance Portability and Accountability Act (HIPAA) and applicable California law. In these relationships we typically act as a Business Associate and handle PHI under a Business Associate Agreement that limits how the information may be used and disclosed.
Members' rights with respect to their health information — including the right to access, amend, and request restrictions — are described in the Notice of Privacy Practices of their managed care plan. We support those rights and coordinate with the plan as appropriate.
7. Website, cookies & analytics
Our website may use strictly necessary cookies and limited analytics to keep the site working and understand how it is used. We do not use our website to collect PHI, and we do not use it for behavioral advertising. You can control cookies through your browser settings; disabling some cookies may affect site functionality.
8. Data security
We maintain administrative, technical, and physical safeguards designed to protect the information we hold. These include access controls and least-privilege permissions, encryption of data in transit and at rest where appropriate, endpoint protections such as full-disk encryption, workforce training, and audit and monitoring practices. No method of transmission or storage is completely secure, but we work to protect information consistent with HIPAA, our contractual obligations, and industry practice.
9. Data retention
We retain information for as long as needed to provide services, to meet the requirements of our managed care plan agreements, and to comply with legal, regulatory, and record-keeping obligations. When information is no longer needed for these purposes, we dispose of it securely.
10. Your rights & choices
Depending on your relationship with us and applicable law, you may have the right to access the personal information we hold about you, request corrections, or ask questions about our practices. Members' rights regarding health information are handled in coordination with their managed care plan and its Notice of Privacy Practices.
California residents may have additional rights under state privacy law regarding personal information that is not otherwise exempt as HIPAA-regulated or medical information. To exercise any right, contact us using the details in Section 14, and we will respond as required by law. We will not discriminate against you for exercising your privacy rights.
11. Children's privacy
Our website is not directed to children, and we do not knowingly collect personal information from children through it. Where we serve minors as part of our care programs, we handle their information under the direction of the managed care plan and applicable law, with appropriate consent from a parent or guardian.
12. Third-party links & services
Our website and communications may link to third-party sites or services, such as our secure staff application. Those third parties have their own privacy practices, and this policy does not govern them. We encourage you to review the privacy notices of any third-party site you visit.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make changes, we will revise the "Last updated" date at the top of this page and, where appropriate, provide additional notice. Your continued use of our website or services after an update reflects the current policy.
14. Contact us
For questions about this policy or our privacy practices, contact: