Skip to content

Who We Are

Privacy & Compliance

Protecting the confidentiality and security of the sensitive information that counties, clients, employees, and partners entrust to CalMHIN is core to our mission.

Our commitment

CalMHIN's compliance and privacy program governs how the organization protects protected health information (PHI), substance use disorder (SUD) records, personally identifiable information (PII) and other sensitive data at every stage of its life, from the moment it is received to the moment it is no longer needed.

The regulatory landscape we operate in

CalMHIN's work involves both federal and California privacy law, including the following:

  • Health Insurance Portability and Accountability Act (HIPAA), which governs protected health information.
  • 42 CFR Part 2, which governs substance use disorder information.
  • California's Confidentiality of Medical Information Act (CMIA), which governs medical information and, in certain instances, enhances HIPAA's privacy regulations.
  • California's Lanterman-Petris-Short (LPS) Act, California's specific privacy protections for certain mental health information.
  • The California Consumer Privacy Act (CCPA), governing privacy related to personal information.
  • The California Health and Safety Code, which includes additional patient privacy provisions.

What CalMHIN's compliance and privacy program is designed to do

  • Meet every applicable federal and California requirement that governs how we handle sensitive information.
  • Detect, prevent, and address potential instances of fraud, waste, and abuse through effective controls and active oversight.
  • Protect sensitive data throughout its life, from intake through storage, use, and eventual disposal.
  • Foster a culture of integrity, accountability, and ethical behavior among all CalMHIN workforce members, contractors, and business associates.
  • Give counties a partner they can trust with sensitive data, supporting their service delivery while respecting the boundary between what CalMHIN is responsible for and what belongs to the county.

Where CalMHIN's responsibility begins and ends

CalMHIN does not deliver behavioral health services directly. Counties do. But in providing the technology, administrative, and fiscal support behind those services, CalMHIN regularly handles PHI and other sensitive information on a county's behalf, which places CalMHIN in the role of a HIPAA business associate. That role carries its own compliance obligations, which CalMHIN works diligently to meet.

An integrated approach

CalMHIN treats privacy and compliance as one integrated program, not two separate efforts. While our privacy program receives heightened focus due to the sensitive nature of the information we handle, privacy and compliance operate as part of the same framework, built around clear standards, defined accountability, and ongoing assessment of the program.

Website privacy

This website sets no cookies, runs no analytics, and has no forms. Every page is static HTML and CSS with no scripts and nothing loaded from another organization's servers. The web server that delivers these pages keeps ordinary access logs, as any web server does, which ordinarily record the requesting address, the time, the page requested and the browser the request came from.

Questions or reporting a concern

Questions or concerns about privacy or compliance, including reporting an issue, can be directed to privacyofficer@calmhin.org with the subject line "Attention Compliance and Privacy Officer."

Get in touch

For general inquiries, reach us at