Legal & Privacy Notice
Raven's Eye Mental Wellness and Nursing Services, Inc.
Effective date: August 3, 2026
Last updated: August 3, 2026
1. Purpose and Scope of This Notice
This Legal & Privacy Notice describes how Raven's Eye Mental Wellness and Nursing Services, Inc., doing business as Raven's Eye Wellness, together with its authorized clinicians, workforce members, contractors, and service providers, may collect, use, disclose, retain, and protect information.
This Notice applies to information obtained through or in connection with:
- The public Raven’s Eye website and its webpages;
- Public contact forms and appointment inquiries;
- Email, telephone, voicemail, and SMS text communications;
- Patient portals, electronic intake systems, and telehealth systems;
- Provider directories, referral platforms, and scheduling services;
- Administrative and clinical encounters;
- Cookies, server logs, security tools, and website analytics;
- Artificial intelligence, transcription, automation, and language-processing tools; and
- Other online or offline interactions that refer to this Notice.
Different privacy laws may apply depending on the information, the context in which Raven’s Eye receives it, the services requested, and the state in which the individual is located.
2. Relationship to the HIPAA Notice of Privacy Practices
When Raven’s Eye is acting as a healthcare provider subject to the Health Insurance Portability and Accountability Act, commonly called HIPAA, protected health information is governed primarily by Raven’s Eye’s formal HIPAA Notice of Privacy Practices and applicable federal and state health-information laws.
This website Legal & Privacy Notice supplements, but does not replace, the formal HIPAA Notice of Privacy Practices.
The formal HIPAA Notice of Privacy Practices explains how protected health information may be used and disclosed, Raven’s Eye’s legal duties, patient privacy rights, complaint procedures, and the person or office patients may contact for additional information.
Raven’s Eye will provide or make its formal Notice of Privacy Practices available as required by law, including through the patient portal, intake process, electronic delivery, direct request, or another appropriate method.
If this website Notice conflicts with the formal HIPAA Notice of Privacy Practices concerning protected health information, the formal HIPAA notice and applicable law will control.
3. Categories of Information We May Collect
The information Raven’s Eye collects depends upon how a visitor, patient, authorized representative, provider, insurer, or other person interacts with Raven’s Eye.
Identifiers and contact information
- Name, preferred name, and pronouns;
- Date of birth;
- Residential or mailing address;
- Email address;
- Telephone number;
- Emergency-contact information;
- Patient, account, or internal identification numbers;
- Account username or portal identifier; and
- Information used to verify identity or authority.
Appointment and service information
- Requested services;
- Appointment dates and times;
- Provider selection or preference;
- Referral source;
- Scheduling availability;
- Cancellation and attendance information;
- Patient location at the time of telehealth care; and
- Administrative communications concerning services or care.
The fact that a person searched for, considered, requested, scheduled, or received a mental-health service may itself constitute sensitive personal information, medical information, protected health information, or consumer health data.
Medical and health information
- Medical and psychiatric history;
- Symptoms, conditions, and diagnoses;
- Medication and pharmacy information;
- Allergies and adverse reactions;
- Prior and current treatment information;
- Family, social, behavioral, and occupational history;
- Pregnancy, postpartum, reproductive, or sexual-health information;
- Substance-use information;
- Disability and accommodation information;
- Laboratory, diagnostic, and monitoring information;
- Treatment plans and clinical documentation;
- Information received from another provider, health plan, or pharmacy;
- Information provided by an authorized representative; and
- Other information relevant to evaluation, treatment, safety, payment, or healthcare operations.
Insurance, billing, and transaction information
- Insurance carrier and member information;
- Eligibility and benefit information;
- Claims and authorization information;
- Billing address;
- Amounts charged, paid, adjusted, refunded, or outstanding;
- Transaction identifiers;
- Payment status; and
- Limited information received from a payment processor.
Complete payment-card information may be collected directly by a contracted payment processor rather than stored by Raven’s Eye.
Communications information
- Contact-form submissions;
- Emails and email metadata;
- SMS text messages;
- Patient-portal messages;
- Telephone calls and call metadata;
- Voicemails;
- Telehealth or video-meeting communications;
- Documents and attachments;
- Support requests; and
- Communications sent through directories, intake systems, or scheduling platforms.
When separately disclosed and consented to as required, communications may also produce an audio recording, video recording, transcript, summary, draft note, draft response, workflow classification, or quality-review record.
Website, device, and analytics information
- Internet Protocol address;
- Browser, device, and operating-system type;
- Approximate location inferred from an IP address;
- Date, time, and duration of a visit;
- Referring and exit pages;
- Pages, articles, providers, or services viewed;
- Links, forms, or buttons selected;
- General interaction, navigation, and performance data;
- Cookie and similar-technology identifiers;
- Error, security, and diagnostic logs; and
- Consent and privacy-preference records.
Inferences and derived information
Raven’s Eye or a contracted service provider may derive limited information such as:
- Approximate location from an IP address;
- Likely scheduling needs from an inquiry;
- Whether a message is administrative, billing-related, or potentially clinical;
- Whether a message may require expedited human review;
- Website and service-performance patterns; and
- Security, fraud, spam, or abuse indicators.
4. Sources of Information
Raven’s Eye may collect or receive information:
- Directly from you;
- From a parent, guardian, personal representative, caregiver, or other person acting with legal authority;
- From a Raven’s Eye clinician or authorized workforce member;
- From a referring, consulting, or treating healthcare provider;
- From a health plan, pharmacy, laboratory, clearinghouse, or benefit administrator;
- From a provider directory, referral service, intake service, or scheduling platform;
- From IntakeQ, Headway, Zocdoc, Psychology Today, or another platform when the platform is used;
- From a payment processor or billing provider;
- From website cookies, logs, analytics, and security systems;
- From communications, telecommunications, email, hosting, and cybersecurity providers;
- From public or governmental sources where legally permitted; and
- As otherwise authorized or required by law.
5. Purposes for Which Information May Be Used
Subject to applicable law, Raven’s Eye may collect, use, organize, analyze, store, or otherwise process information to:
- Respond to inquiries and requests;
- Determine provider or service availability;
- Verify identity, authority, eligibility, and patient location;
- Schedule and administer appointments;
- Complete intake and consent procedures;
- Conduct evaluations and provide treatment;
- Coordinate care with authorized persons and organizations;
- Prescribe and monitor medication when clinically and legally appropriate;
- Communicate with pharmacies, providers, laboratories, and health plans;
- Process insurance claims, billing, payment, refunds, and account administration;
- Maintain medical, clinical, administrative, accounting, and business records;
- Operate telehealth and patient-portal services;
- Provide technical, administrative, and patient support;
- Send appointment, billing, portal, security, and operational notifications;
- Protect patient, workforce, organizational, and public safety;
- Detect fraud, abuse, spam, malware, and cybersecurity events;
- Audit and improve services, workflows, and communications;
- Measure website and system reliability and performance;
- Train, supervise, and evaluate authorized workforce members where permitted;
- Comply with professional, contractual, insurance, legal, and regulatory obligations;
- Establish, exercise, investigate, or defend legal claims; and
- Fulfill another purpose disclosed at the time of collection and permitted by law.
6. Artificial Intelligence and Automated Processing
Raven’s Eye may use artificial intelligence, machine-learning, language-processing, transcription, automation, and analytics systems to support administrative, security, operational, and clinical workflows.
Potential uses
Depending on the enabled technology and circumstances, these tools may assist with:
- Classifying, routing, or prioritizing an inquiry;
- Filtering spam, phishing, malware, or suspected fraud;
- Scheduling and intake administration;
- Identifying missing information or incomplete documentation;
- Summarizing a message, document, form, or communication;
- Extracting appointment, contact, or administrative information;
- Preparing a draft administrative response;
- Transcribing a separately disclosed and consented call or meeting;
- Preparing a draft clinical or administrative note;
- Organizing patient-reported information;
- Measuring workflow, response time, or service performance;
- Reviewing website traffic and technical performance;
- Supporting quality assurance;
- Detecting technical errors or security events; and
- Creating de-identified or aggregated operational information where permitted.
Human review and professional responsibility
AI-generated transcripts, summaries, drafts, classifications, and other output may contain errors, omissions, fabricated statements, incorrect speaker identification, or inappropriate recommendations.
AI output is not a substitute for professional judgment. An appropriately authorized Raven’s Eye clinician or workforce member remains responsible for reviewing AI-assisted material before relying upon it for a material clinical, billing, legal, safety, or patient-care decision.
Raven’s Eye does not authorize an AI system to autonomously make a final diagnosis, autonomously prescribe medication, or make an unreviewed final clinical decision.
AI-generated patient communications
When a communication containing clinical information is materially generated by generative AI and has not been reviewed by an appropriately licensed or certified human professional, Raven’s Eye will provide an appropriate disclosure and a method for contacting a human when required by law.
AI vendors and protected health information
When a technology vendor creates, receives, maintains, or transmits protected health information on behalf of Raven’s Eye, Raven’s Eye will require an appropriate written agreement, including a Business Associate Agreement when required by HIPAA, before authorizing that processing.
Raven’s Eye’s policy is not to authorize a vendor to use identifiable protected health information to train a general-purpose AI model for the vendor’s independent benefit unless that use is separately disclosed, lawfully permitted, and supported by any required authorization.
Appropriately de-identified or aggregated information may be processed as permitted by law when the information is not reasonably capable of being used to identify an individual.
7. Calls, Meetings, Recording, and Transcription
The publication of this Notice does not, by itself, constitute consent to record a confidential telephone call, video meeting, telehealth encounter, or other confidential communication.
Before Raven’s Eye records, live-transcribes, or sends the substantive contents of a confidential call or meeting to an AI-assisted transcription or documentation system, Raven’s Eye will provide an additional notice and obtain consent when required by applicable law or Raven’s Eye policy.
The additional notice may explain:
- That the communication will be recorded, transcribed, or processed;
- The general purpose of the processing;
- Whether audio or video will be retained;
- Whether a contracted technology provider will process the information;
- That automated transcripts and summaries may contain errors;
- How the participant may ask questions; and
- How the participant may agree, decline, or withdraw consent prospectively.
Where recording or AI transcription is optional, declining it will not, by itself, cause Raven’s Eye to deny otherwise available care. Raven’s Eye may use manual documentation or another lawful documentation method.
Raven’s Eye may collect limited technical or operational information about calls, including the date, time, duration, routing, response time, connection quality, and whether a call was answered or abandoned.
Collecting call metadata does not necessarily mean that Raven’s Eye recorded the substantive contents of the call.
8. Emails, Text Messages, Forms, and Portal Communications
Raven’s Eye may use security, automation, analytics, or AI-assisted tools to process emails, SMS text messages, patient-portal messages, intake forms, voicemails, and other written or recorded communications.
These tools may be used to:
- Filter spam, malware, and phishing attempts;
- Route a communication to the appropriate person or workflow;
- Identify potentially urgent language for human review;
- Summarize a communication;
- Extract appointment, insurance, billing, or contact information;
- Prepare a draft response for authorized human review;
- Track delivery, response time, or communication status;
- Maintain an appropriate business or medical record; and
- Protect the security and availability of communications systems.
You should not rely on an automated system to identify or respond to an emergency. Emergency communications must be directed to 911, 988, an emergency department, or another appropriate emergency resource.
Ordinary email and SMS text messaging may not be fully secure. Communications may be delayed, misdirected, intercepted, displayed on a shared device, backed up to a personal cloud account, or accessed by a telecommunications, email, operating-system, or mobile-device provider.
Patients may request confidential communications by a reasonable alternative method or at an alternative location, subject to applicable law and reasonable administrative requirements.
9. Cookies, Website Analytics, and Similar Technologies
The website may use cookies, server logs, local storage, tags, scripts, and similar technologies.
Essential technologies
Essential technologies may be used for:
- Website functionality;
- Security and abuse prevention;
- Load balancing and availability;
- Form submission;
- Session management;
- Accessibility features; and
- Remembering privacy or cookie preferences.
Analytics technologies
Analytics technologies may be used to measure:
- General website traffic;
- Pages and resources viewed;
- Approximate visit duration;
- Referring websites or campaigns;
- Browser and device categories;
- Website errors and performance;
- General navigation patterns; and
- Whether website features are functioning as intended.
Health-related browsing information
Because page views may reveal or permit an inference concerning mental-health interests, Raven’s Eye seeks to minimize the unnecessary collection and disclosure of identifiable health-related browsing information.
Raven’s Eye does not authorize an analytics or advertising provider to use protected health information for the provider’s independent advertising purposes.
Raven’s Eye does not knowingly use identifiable patient health information to target advertisements based on a diagnosis, symptom, medication, pregnancy status, reproductive-health status, or other sensitive health characteristic.
Cookie and browser choices
Where legally required or technically available, visitors may be provided with controls for nonessential cookies or similar technologies.
Visitors may also configure their browsers to block or delete cookies. Blocking essential cookies may interfere with website functionality.
Raven’s Eye will process legally recognized browser or device opt-out preference signals, including Global Privacy Control signals, when required by applicable law and when the signal applies to the relevant processing activity.
Because there is no universally accepted standard for every browser “Do Not Track” signal, Raven’s Eye may not respond to every such signal. This does not limit Raven’s Eye’s obligation to honor a legally recognized opt-out preference signal where required.
10. How Information May Be Disclosed
Subject to applicable law, authorization requirements, and contractual restrictions, Raven’s Eye may disclose information:
- To Raven’s Eye clinicians and authorized workforce members;
- For treatment, payment, and healthcare operations;
- To a health plan, pharmacy, laboratory, clearinghouse, or treating provider;
- To vendors providing hosting, communications, intake, scheduling, telehealth, billing, payment, analytics, cybersecurity, document-management, transcription, or AI services;
- To a business associate operating under an appropriate agreement;
- At your direction or with your authorization;
- To a legally authorized personal representative, guardian, or caregiver;
- To address a serious and imminent threat when permitted or required by law;
- For public-health, abuse-reporting, oversight, or other legally permitted purposes;
- In response to valid legal process or a lawful government request;
- To professional advisors, legal counsel, insurers, auditors, and consultants;
- To investigate or defend a legal claim;
- In connection with a lawful organizational transaction, subject to applicable confidentiality requirements; and
- As otherwise permitted or required by law.
Contracted service providers should receive only the information reasonably necessary to perform the contracted service and should be subject to applicable legal and contractual restrictions.
11. Third-Party Platforms
Raven’s Eye may maintain profiles, accept referrals, schedule services, process intake information, communicate with patients, administer insurance, or provide other services using independent third-party platforms.
These platforms may include IntakeQ, Headway, Zocdoc, Psychology Today, telehealth providers, insurers, clearinghouses, payment processors, telecommunications providers, and other technology vendors.
When you interact directly with a third-party platform, that platform may collect information under its own privacy policy and terms before Raven’s Eye receives the information.
For example, a directory or scheduling platform may independently collect:
- Account and contact information;
- Search and browsing activity;
- Provider and appointment selections;
- Insurance information;
- Device and network information;
- Approximate location;
- Messages sent through the platform; and
- Health-related information or inferences.
A third-party platform’s privacy policy is not Raven’s Eye’s privacy policy. Questions concerning the platform’s independent data collection, advertising, account management, cookies, or privacy-rights process should also be directed to that platform.
Raven’s Eye remains responsible for information under Raven’s Eye’s control to the extent required by applicable law.
12. Sale, Sharing, Advertising, and Model Training
Raven’s Eye does not sell protected health information.
Raven’s Eye’s policy is not to sell identifiable consumer health data for monetary consideration.
Raven’s Eye does not knowingly use protected health information or identifiable consumer health data for cross-context behavioral advertising based on a person’s mental-health condition, diagnosis, treatment, medication, pregnancy status, reproductive-health status, or other sensitive health characteristic.
Certain website analytics, advertising cookies, or similar technical disclosures may be defined as a “sale” or “sharing” under a broadly worded state privacy law, even when no money is paid for the information. Raven’s Eye will provide an applicable opt-out method when legally required.
Raven’s Eye’s policy is not to authorize a technology vendor to use identifiable patient information to train a general-purpose AI model for the vendor’s independent purposes unless the use is separately disclosed and lawfully authorized.
13. Data Retention
Raven’s Eye retains information for periods reasonably necessary to:
- Provide healthcare and administer the patient relationship;
- Maintain medical records for legally required periods;
- Complete insurance, billing, accounting, and payment functions;
- Maintain legally required business and employment records;
- Comply with licensing, professional, contractual, and insurance obligations;
- Investigate security events and prevent fraud or abuse;
- Resolve disputes and enforce agreements;
- Establish, exercise, or defend legal claims;
- Comply with a litigation hold, subpoena, court order, or other legal requirement; and
- Fulfill the purpose disclosed when the information was collected.
Retention periods vary according to the category of information, the patient’s age, the jurisdiction, payer requirements, licensing requirements, contractual obligations, backup schedules, litigation holds, and other circumstances.
Raven’s Eye does not represent that one fixed retention period applies to every category of information.
Temporary audio, transcript, or AI-processing files may be deleted after the requested output is produced unless the information is incorporated into the medical record, retained for a disclosed quality or operational purpose, retained pursuant to consent, or required to be retained by law.
A deletion request may be denied or limited when retention is required for healthcare records, billing, fraud prevention, security, legal claims, professional obligations, backups, or another lawful purpose.
14. Information Security
Raven’s Eye uses administrative, technical, and physical safeguards intended to protect information according to its sensitivity and applicable legal requirements.
Safeguards may include:
- Role-based or need-based access controls;
- Authentication and password requirements;
- Encryption where appropriate;
- Workforce confidentiality and privacy requirements;
- Business Associate Agreements and vendor contracts where required;
- Security logging and monitoring;
- Backups and recovery procedures;
- Security awareness and workforce training;
- Device, network, and endpoint protections; and
- Incident-response and breach-assessment procedures.
No website, cloud service, email system, telecommunications network, portal, device, or storage system can be guaranteed to be completely secure.
Users should protect their account credentials, use approved patient portals for sensitive communications when available, and promptly report suspected unauthorized account access.
15. HIPAA Privacy Rights
To the extent HIPAA applies, patients generally have the right, subject to lawful limitations, to:
- Inspect and obtain an electronic or paper copy of information in the designated record set;
- Request correction or amendment of information believed to be incorrect or incomplete;
- Request confidential communications by an alternative method or at an alternative location;
- Request restrictions on certain uses or disclosures;
- Request that information concerning a service paid for fully out of pocket not be disclosed to a health plan for payment or operations, where the legal requirements are satisfied;
- Obtain an accounting of certain disclosures;
- Obtain a paper or electronic copy of the Notice of Privacy Practices;
- Designate a personal representative where legally permitted;
- Withdraw a written authorization prospectively, subject to lawful limitations; and
- Submit a complaint to Raven’s Eye or the United States Department of Health and Human Services without retaliation.
The formal HIPAA Notice of Privacy Practices contains additional explanations, procedures, timeframes, exceptions, and contact information.
16. California Privacy Rights
Medical information
Medical information under Raven’s Eye’s control may be protected by HIPAA, the California Confidentiality of Medical Information Act, professional confidentiality requirements, and other applicable laws.
Raven’s Eye will use and disclose individually identifiable medical information only as authorized or permitted by applicable law.
California website privacy requirements
This Notice describes categories of information collected through the website, the purposes of collection, categories of recipients, privacy choices, and methods for contacting Raven’s Eye.
CCPA and CPRA rights
The California Consumer Privacy Act and California Privacy Rights Act contain business thresholds, exemptions, and exclusions. Protected health information governed by HIPAA and certain medical information governed by California law may be excluded from some requirements.
To the extent the CCPA or CPRA applies to particular information and to Raven’s Eye, a California resident may have the right to:
- Know the categories of covered personal information collected;
- Know the sources, purposes, and categories of recipients;
- Request access to specific pieces of covered personal information;
- Request correction of inaccurate covered personal information;
- Request deletion, subject to legal exceptions;
- Opt out of covered sale or sharing;
- Limit certain uses of sensitive personal information where the statutory right applies;
- Use an authorized agent where legally permitted; and
- Receive equal service without unlawful discrimination for exercising a protected privacy right.
Raven’s Eye may voluntarily honor a reasonable privacy request even when a particular statutory right does not strictly apply, provided that doing so does not conflict with healthcare, medical-record, billing, safety, identity verification, security, professional, or legal obligations.
17. Washington Consumer Health Data
Washington’s My Health My Data Act broadly regulates certain consumer health data that is not subject to specified exemptions.
Protected health information governed by HIPAA and information maintained under certain Washington healthcare laws may be exempt from the Act. This section applies to the extent Raven’s Eye collects consumer health data subject to the Act rather than exempt healthcare information.
Categories of Washington consumer health data
Covered consumer health data may include information that identifies or permits an inference concerning:
- A request for mental-health information or services;
- An appointment, attempted appointment, or provider search;
- Symptoms, conditions, diagnoses, or treatment;
- Medication or pharmacy services;
- Pregnancy, reproductive health, or sexual health;
- Substance use;
- Healthcare provider selection;
- Health-insurance information;
- Location information associated with seeking healthcare;
- Website activity reasonably capable of revealing a health interest; and
- Inferences drawn from other information concerning physical or mental health.
Sources
Raven’s Eye may collect covered consumer health data from:
- The consumer;
- A legally authorized representative;
- Website and service interactions;
- Provider directories and referral services;
- Scheduling and intake platforms;
- Healthcare providers, insurers, pharmacies, or laboratories;
- Communications and documents submitted to Raven’s Eye; and
- Contracted service providers acting on Raven’s Eye’s behalf.
Purposes
Raven’s Eye may collect or use covered consumer health data with consent for specified purposes or to the extent reasonably necessary to provide a product or service requested by the consumer.
Purposes may include:
- Responding to an inquiry;
- Locating or scheduling an appropriate provider;
- Completing intake and eligibility procedures;
- Providing requested healthcare or administrative services;
- Processing billing or payment;
- Providing customer or technical support;
- Protecting security and preventing fraud;
- Maintaining reliable service operations; and
- Complying with legal obligations.
Sharing
Where separate consent to share covered consumer health data is legally required, Raven’s Eye will seek consent that is distinct from collection consent and that identifies:
- The categories of consumer health data to be shared;
- The purpose of the sharing;
- The categories of recipients; and
- How the consumer may withdraw consent from future sharing.
Raven’s Eye may share covered consumer health data as reasonably necessary to provide a service requested by the consumer, including with contracted service providers, healthcare providers, payment processors, communications providers, scheduling providers, and other entities necessary to provide the requested service.
Washington rights
To the extent applicable, a Washington consumer may request:
- Confirmation of whether Raven’s Eye is collecting, sharing, or selling covered consumer health data;
- Access to covered consumer health data;
- A list of applicable third parties and affiliates with whom the data was shared or sold;
- Withdrawal of consent for future collection or sharing;
- Deletion, subject to applicable exemptions and healthcare obligations; and
- An appeal if Raven’s Eye refuses to act on a request.
Raven’s Eye may take reasonable steps to authenticate the identity and authority of the person making a request.
A consumer will not be required to create a new account solely to exercise a statutory privacy right.
If an appeal is denied, Raven’s Eye will provide information about contacting the Washington State Attorney General when required.
Geofencing
Raven’s Eye does not knowingly use a geofence around a healthcare facility for a purpose prohibited by Washington consumer-health law, including unlawfully identifying or tracking consumers seeking healthcare, collecting consumer health data, or sending health-related messages.
18. Privacy Requests and Identity Verification
A privacy request should provide sufficient information to allow Raven’s Eye to understand and process the request.
A request should ordinarily identify:
- The requester’s full name;
- The state of residence;
- The nature of the request;
- The email address or telephone number associated with the information;
- Whether the request concerns website information, consumer health data, or a patient medical record; and
- Information reasonably necessary to verify identity and legal authority.
Do not send unnecessary medical details, Social Security numbers, complete identification documents, account passwords, or payment-card information through unsecured email.
Raven’s Eye may provide a secure verification method and may request additional documentation when a person seeks records on behalf of another individual.
Submit privacy requests to:
Raven's Eye Mental Wellness and Nursing Services, Inc.Attn: Legal & Privacy Officer
Email: privacy@ravenseyewellness.com
Telephone: +1 (415) 488-8353
California mailing address
727 Broadway Street, No. 1057
Vallejo, California 94590
Washington mailing address
600 First Avenue, Suite 102, PMB 2653
Seattle, Washington 98104
Raven’s Eye may retain a record of the request, identity-verification process, response, and appeal for legal, security, and compliance purposes.
19. Children and Minors
The public website is intended primarily for adults.
Raven’s Eye does not knowingly use the public website to collect personal information from a child under 13 without legally sufficient involvement of a parent, guardian, or authorized representative.
Clinical eligibility, consent, authorization, parental access, confidentiality, and privacy rights concerning a minor depend upon the applicable jurisdiction, the type of service, the minor’s circumstances, and other legal requirements.
A minor does not become eligible for clinical services merely by accessing or submitting information through the website.
20. Privacy and Professional Complaints
A person may submit a privacy, security, billing, communications, AI, recording, or professional-conduct concern directly to Raven’s Eye.
Raven's Eye Mental Wellness and Nursing Services, Inc.Attn: Legal & Privacy Officer
Email: privacy@ravenseyewellness.com
Telephone: +1 (415) 488-8353
Raven’s Eye will not retaliate against a patient or consumer for making a good-faith privacy complaint or exercising a legally protected privacy right.
United States Department of Health and Human Services
A person who believes a HIPAA-covered entity or business associate violated the HIPAA Privacy, Security, or Breach Notification Rules may submit a complaint to the United States Department of Health and Human Services, Office for Civil Rights.
Complaints may be submitted through the OCR Complaint Portal or in writing. HIPAA complaints ordinarily must be filed within 180 days after the complainant knew or should have known of the alleged violation. OCR may extend the period for good cause.
Office for Civil RightsUnited States Department of Health and Human Services
200 Independence Avenue SW
Room 509F, HHH Building
Washington, DC 20201
File or learn about an HHS health-information privacy complaint
California Board of Registered Nursing
A complaint concerning a California registered nurse or nurse practitioner may be submitted through the California Department of Consumer Affairs BreEZe system or sent to:
Board of Registered NursingAttn: Complaint Intake
PO Box 944210
Sacramento, California 94244-2100
Email: Enforcement.BRN@dca.ca.gov
Fax: (916) 574-7693
California Board of Registered Nursing complaint information
Washington State Board of Nursing
A complaint concerning a Washington-licensed nurse or advanced registered nurse practitioner may be submitted to the Washington State Board of Nursing.
Washington State Board of Nursing111 Israel Road SE
PO Box 47864
Olympia, Washington 98504
Email: nursing@doh.wa.gov
Telephone: (360) 236-4703
Washington State Board of Nursing complaint information
California privacy and consumer complaints
A California consumer may submit an applicable consumer complaint to the California Department of Justice, Office of the Attorney General.
A complaint concerning rights governed by the California Consumer Privacy Act may also be submitted to the California Privacy Protection Agency.
Washington Attorney General
A Washington consumer may submit an applicable consumer or consumer-health-data complaint to the Washington State Office of the Attorney General.
Washington Attorney GeneralConsumer Resource Center
800 Fifth Avenue, Suite 2000
Seattle, Washington 98104-3188
Telephone within Washington: (800) 551-4636
Telephone outside Washington: (206) 464-6684
Washington Attorney General consumer complaint
A patient or consumer may contact an applicable regulator directly and is not required to complete Raven’s Eye’s internal complaint process first.
21. Changes to This Notice
Raven’s Eye may revise this Notice to reflect changes in law, technology, vendors, services, website functionality, or information practices.
The current version will be posted with a revised effective date.
Where required by law, Raven’s Eye will provide an additional notice or obtain additional consent before materially changing a collection, use, disclosure, recording, or consumer-health-data practice.
Changes to this website Notice do not automatically amend a signed patient authorization, treatment agreement, or other document that requires a separate amendment or consent process.
22. Legal and Privacy Contact
Questions, privacy requests, appeals, complaints, or legal notices concerning this Notice may be directed to:
Raven's Eye Mental Wellness and Nursing Services, Inc.Attn: Legal & Privacy Officer
Email: privacy@ravenseyewellness.com
Telephone: +1 (415) 488-8353
California mailing address
727 Broadway Street, No. 1057
Vallejo, California 94590
Washington mailing address
600 First Avenue, Suite 102, PMB 2653
Seattle, Washington 98104
These contact methods are not continuously monitored and must not be used for emergency or time-sensitive clinical communications.
23. Legal and Policy References
The following official authorities and independent platform policies were reviewed when preparing this Notice. Raven’s Eye is not affiliated with the independent platforms listed below, and their policies govern their own systems and services.
View legal and policy references
- HHS: Notice of Privacy Practices for Protected Health Information Federal guidance concerning the required contents and distribution of HIPAA Notices of Privacy Practices.
- HHS: Model Notice of Privacy Practices for Healthcare Providers Federal model language describing patient rights, permitted uses, complaints, and covered-entity responsibilities.
- HHS: Filing a Health Information Privacy Complaint Federal complaint procedures for HIPAA, security, breach-notification, and Part 2 concerns.
- California Attorney General: Online Privacy and CalOPPA California guidance concerning website privacy-policy requirements.
- California Privacy Protection Agency California agency responsible for CCPA and CPRA administration and enforcement.
- Washington RCW 19.373.020 Washington Consumer Health Data Privacy Policy requirements.
- Washington RCW 19.373.030 Washington requirements governing collection and sharing of consumer health data.
- Washington RCW 19.373.040 Washington consumer health data access, deletion, withdrawal, and appeal rights.
- Washington Attorney General: My Health My Data Guidance Official guidance concerning Washington consumer health data requirements.
- California Board of Registered Nursing: File a Complaint California nursing complaint procedures and contact information.
- Washington State Board of Nursing: File a Complaint Washington nursing complaint procedures.
- Zocdoc Privacy Policy Benchmark review of categories, sources, disclosures, analytics, AI, cookies, and state privacy rights.
- Zocdoc Consumer Health Data Privacy Policy Benchmark review of non-HIPAA consumer health data categories and rights.
- Headway Privacy Policy Benchmark review of personal information, audio, analytics, security, and state privacy rights.
- Headway HIPAA Notice of Privacy Practices Benchmark review of HIPAA notice organization and patient rights.
- Headway Washington Consumer Health Data Privacy Policy Benchmark review of Washington consumer health data disclosures and appeal rights.
- Psychology Today Directory Privacy Policy Benchmark review of directory messages, identifiers, analytics, advertising, and California rights.
- IntakeQ Terms and Conditions Benchmark review of AI features, transcription, recording consent, customer responsibilities, and HIPAA agreements.
- IntakeQ Privacy Notice Benchmark review of IntakeQ information collection, storage, use, and disclosure practices.