Privacy Policy

Daybreak Health is devoted to safeguarding our customers, patients, and employee personal information and ensuring confidentiality of records. This Privacy Policy describes the personal information we collect, how we use it, and the standards and procedures in place to safeguard your personal information. At the bottom of this Privacy Policy is the Provider Group’s HIPAA Notice of Privacy Practices, which describes how the Providers and we treat your protected health information under HIPAA. Defined terms in this Privacy Policy may refer to the terms in our Terms of Use.

1. Information we Collect

Daybreak Health collects PI/PHI from customers to include the following:

We may also receive personal information from our partner schools, which is subject to the terms of our agreements with those schools and applicable laws, such as FERPA.

2. How We Use Your Personal Information

We use your personal information for various purposes described below, including to:

3. How We Disclose Your Personal Information

We do not share, sell, or otherwise disclose your personal information for purposes other than those outlined in this Privacy Policy.

We may disclose personal information that we collect or you provide as described in this Privacy Policy:

We may also disclose your personal information:

In addition, we may disclose aggregated information about our users, and information that does not identify any individual, without restriction.

4. Service Providers

We may employ third party companies and individuals to facilitate our Platform, to perform certain tasks which are related to the Platform, or to provide audit, legal, operational or other services for us. These tasks include, but not limited to, customer service, technical maintenance, monitoring, email management and communication, database management, billing and payment processing, reporting and analytics. We will share with them only the minimum necessary information to perform their task for us and only after entering into appropriate confidentiality agreements.

5. How We Protect Personal Information

We restrict access to information about you to those individuals who need to know that information as part of their job responsibilities. We also educate our employees about the importance of confidentiality and customer privacy through standard operating procedures, special training programs, and our Code of Conduct. We take appropriate disciplinary measures to enforce privacy responsibilities. We have developed precautions that comply with applicable law to ensure the security and confidentiality of customer records and information, to guard against any anticipated threats or hazards to the security or integrity of such records, and to protect against unauthorized access to or use of such records or information which could result in substantial harm or inconvenience to our customers or our employees.

We protect personal information by:

Information transmitted over the Internet is not completely secure, but we do our best to protect your personal information. You can help protect your personal information and other information by keeping your password to the Platform confidential. We ask you not to share your password with anyone.

We have implemented measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure. We use encryption technology for information sent and received by us.

Unfortunately, the transmission of information via the Internet is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmitted through the Platform.

6. Children's Privacy

We do not knowingly collect or solicit any information from anyone under the age of 13 or knowingly allow such persons to become our user without parental consent per COPPA. The Platform is not directed and not intended to be used by children under the age of 13 without parental consent. If you're aware that we have collected Personal Information from a child under age 13 without parental consent please let us know by contacting us and we will delete that information.

HIPAA Privacy Statement

Last updated: January 8th, 2026

Overview

This Notice of Privacy Practices (“Notice”) describes how the Provider Groups — including Daybreak Medical, P.C., Daybreak Medical, P.A., and AS Medical of NY, P.C. — may use and disclose your Protected Health Information (PHI) for treatment, payment, business operations, and other purposes allowed by law.

It also explains your rights to access and control your PHI.

Your Rights

You have the right to:

Your Choices

You can tell us your preferences for PHI sharing in certain cases:

Our Uses and Disclosures

Typical Uses

Other Uses (allowed/required by law)

Our Responsibilities

Changes to This Notice

Additional Daybreak Health Disclosures

Contact Information

Privacy Officer: Christine Cauwels, LCMHC, LCPC, LMHC, LPC, NCC

christinecauwels@daybreakhealth.com

447 Sutter St, Suite 405, San Francisco, CA 94108

www.daybreakhealth.com