Privacy Policy & Terms
Your privacy is clinical. This document explains what we do with your information, what your rights are, and where the boundaries are.
Overview
This practice is HIPAA-compliant. This page describes what information we collect, how we use it, and what your rights are as a client or prospective client. It is written in plain language on purpose — if you want the formal HIPAA Notice of Privacy Practices, request it during your consultation.
What we collect
- —Information you provide on the contact form (name, email, phone, brief description).
- —Clinical information gathered during intake and sessions — encrypted and stored in a HIPAA-compliant EHR (Simple Practice).
- —Billing information (payment processor is HIPAA-BAA compliant; we do not store full card numbers).
- —Analytics about this website (anonymized — pages visited, rough geographic region, no tracking across sites).
How we use it
Clinical information is used solely for your care. Contact-form information is used to respond to your inquiry and schedule a consultation. We do not sell, rent, or share your information with advertisers, marketers, or data brokers — ever.
Your rights
- —You have the right to access your records.
- —You have the right to request amendments to your records.
- —You have the right to a copy of the full HIPAA Notice of Privacy Practices.
- —You have the right to file a complaint with the U.S. Department of Health & Human Services Office for Civil Rights.
- —You have the right to revoke consent for disclosure at any time.
Confidentiality limits
Content of therapy sessions is confidential with limited legal exceptions: (1) imminent danger to self or others, (2) suspected abuse of a child, elder, or dependent adult, (3) court order. These limits are discussed in detail during intake.
Telehealth security
All telehealth sessions use a HIPAA-compliant, end-to-end encrypted platform. Nothing is recorded. You will receive a unique session link before each appointment.
Email and texting
Standard email and SMS are not HIPAA-secure. We use them for logistics only — please do not include clinical content. Secure messaging is available via the client portal once you are an established client.
Website & cookies
This site uses minimal, first-party analytics (no third-party ad networks, no cross-site tracking). Cookies are limited to essential session functionality.
Licensure & jurisdiction
Matthew Darst, LCSW is licensed to provide clinical services in California (LCSW #126410) and Florida. Therapy cannot be provided to residents of other states. This website is not, itself, a clinical service.
Not medical advice
Content on this website — including blog posts and the Stoic Check-In — is educational, not a substitute for therapy, diagnosis, or treatment. If you are in crisis, call or text 988.
Contact
Questions about this policy: matt.darst.lcsw@gmail.com · (949) 805-1831. Last updated April 2026.