Privacy Policy
Bright Star Behavioral Health Services
Last Updated: August 17, 2026
1. Introduction and Scope
This Privacy Policy explains how Bright Star Behavioral Health Services (“Company,” “we,” “us,” or “our”) collects, uses, and protects information gathered through our website located at https://brightstarbhs.com/ (the “Site”), including our employee training portal.
This Policy applies to:
- Visitors who browse our Site without creating an account
- Prospective clients or their parents/guardians who submit inquiries, contact forms, or intake requests
- Employees and contractors (“Staff”) who use our Site’s training portal to complete required training courses
Important note on health information: This Policy does not govern how we handle Protected Health Information (PHI) belonging to our therapy clients in the course of providing ABA therapy services. That information is governed separately by our HIPAA Notice of Privacy Practices, which is provided directly to clients and their guardians. If you are a current or prospective client of our therapy services, please also review our HIPAA Notice of Privacy Practices (https://brightstarbhs.com/notice-of-privacy-practices/) for information about how your or your child’s clinical/health records are handled.
2. Information We Collect
From all visitors
- Standard technical data (IP address, browser type, device type, pages visited) collected automatically through website analytics and server logs
- Cookie data (see Section 5)
From prospective clients / guardians who contact us
- Name, email address, phone number
- Information voluntarily submitted through contact or intake forms (e.g., child’s age, general reason for inquiry)
- We do not request detailed clinical information through public web forms; any clinical intake happens through secure, HIPAA-compliant channels once a client relationship begins
From Staff using the training portal
- Name, work email address, job role/title
- Login credentials (encrypted; we do not store passwords in plain text)
- Course enrollment, progress, quiz scores, completion dates, and certificates
- Time spent on training content (tracked for compliance and reporting purposes)
3. How We Use Information
We use collected information to:
- Respond to inquiries from prospective clients or guardians
- Operate, maintain, and improve the Site
- Enroll and track Staff in required compliance and role-specific training (e.g., HIPAA, OSHA, anti-harassment, supervisor training)
- Generate and issue training completion certificates
- Maintain training records for regulatory and audit purposes
- Send administrative notifications (e.g., training deadline reminders, completion confirmations)
- Comply with applicable legal, licensing, and accreditation obligations relevant to an ABA therapy practice
4. Legal Basis and Employee Training Records
For Staff, participation in required compliance training (HIPAA, OSHA, anti-harassment, and role-specific courses) is a condition of employment. Training records, including completion timestamps, quiz results, and certificates, are retained as part of our regulatory compliance obligations and may be reviewed during audits, licensing reviews, or investigations. Staff should have no expectation that training activity and completion records are private from the Company, though we limit internal access to this data to personnel with a legitimate administrative need.
5. Cookies and Tracking Technologies
Our Site may use cookies and similar technologies to:
- Keep Staff logged into the training portal securely
- Understand general Site usage through analytics tools
- Remember basic preferences
You can control cookies through your browser settings. Disabling cookies may affect your ability to log into the training portal or use certain Site features.
6. How We Share Information
We do not sell personal information. We may share information with:
- Service providers who help us operate the Site and training portal (e.g., our web hosting provider, our learning management system provider, email delivery services), under confidentiality obligations
- Legal or regulatory authorities, if required by law, subpoena, licensing board request, or audit
- Successors, in the event of a merger, acquisition, or sale of company assets, subject to the same privacy commitments described here
We do not share prospective client inquiry information with third parties for marketing purposes.
7. Data Retention
- Staff training records (course completions, quiz results, and certificates) are retained for the duration of employment and for a minimum of four (4) years following separation of employment, consistent with standard employment recordkeeping practice.
- Prospective client inquiry data submitted through our contact or intake forms is retained only as long as necessary to respond to the inquiry, or until the individual becomes an active client, at which point records related to that individual’s care are instead governed by the retention periods described in our HIPAA Notice of Privacy Practices.
- General Site analytics data is retained per our analytics provider’s standard retention settings.
At the end of the applicable retention period, we securely delete or de-identify the information.
8. Your Rights and Choices
Depending on your role and applicable law, you may have the right to:
- Request access to personal information we hold about you
- Request correction of inaccurate information
- Request deletion of certain personal information
Important limitation for Staff: Requests to delete data will not remove training completion records, quiz results, or certificates required for regulatory compliance and audit purposes. We may retain this data even after an erasure request, and will inform you if this limitation applies to your request.
To exercise any of these rights, contact us using the information in Section 11.
9. Children’s Privacy
Our Site’s public pages are not directed at children, and we do not knowingly collect personal information directly from children through the Site. Intake and clinical information about minor clients is collected through secure channels as part of the clinical intake process, handled by parents/guardians, and is governed by our HIPAA policies, not this Privacy Policy.
10. Data Security
We use reasonable administrative, technical, and physical safeguards to protect information collected through the Site, including encrypted login credentials, access controls limiting Staff data to authorized administrators, and secure hosting. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last Updated” date at the top of this page will reflect the most recent revision. Material changes affecting Staff training data handling will be communicated directly to Staff.
12. Contact Us
If you have questions about this Privacy Policy, or wish to submit a request regarding your personal information, please reach us through the Contact page on our website (https://brightstarbhs.com/contact/ — update this link if your actual contact page URL differs) or by phone at (310) 925-5113. We do not publish a direct email address on this page in order to limit spam and unsolicited contact.
Bright Star Behavioral Health Services 11400 W. Olympic Blvd., Suite 200 Los Angeles, CA 90064

