Menu
Log in

Medstar Ambulance of Mendocino County Inc., a 501(c)(3) non-profit community service dba Ukiah Ambulance

Medstar and Ukiah Ambulance patches

Privacy Policy — Medstar Ambulance of Mendocino County

Medstar Ambulance of Mendocino County, Inc.

A California 501(c)(3) Nonprofit Corporation

Privacy Policy

Effective Date: July 18, 2026  |  Last Revised: July 18, 2026

Applies to: medstarmendocino.org and all associated digital services, platforms, and physical systems

Notice Regarding Protected Health Information (PHI)
This Privacy Policy does not govern Protected Health Information (PHI) collected in connection with patient care, emergency medical services, or ambulance transport. PHI is handled separately under Medstar Ambulance's Notice of Privacy Practices (NPP), in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, and their implementing regulations. In any conflict between this Privacy Policy and the NPP regarding PHI, the NPP shall prevail. A copy of our NPP is available upon request and at our facilities.

1.  Introduction and Who We Are

Medstar Ambulance of Mendocino County, Inc. (“Medstar,” “we,” “our,” or “us”) is a California 501(c)(3) nonprofit corporation providing emergency and non-emergency ambulance services in Mendocino County, California. We do not sell your personal information. We are committed to protecting the privacy and security of the information we collect through our digital services, physical systems, and operational activities.

This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and your rights with respect to it. It applies to:

  • Our website (medstarmendocino.org) and any associated subdomains
  • Online donation, membership enrollment, class registration, and application forms
  • SMS/MMS text messaging campaigns and communications
  • Guest Wi-Fi networks at Medstar facilities and in Medstar vehicles
  • Our telephone and voicemail systems
  • Video recording systems at our facilities and in our vehicles
  • Any mobile applications we may operate

By using our services or interacting with any of the above, you acknowledge this Privacy Policy. If you have questions, contact us at [email protected] or at the address in Section 14.

2.  Information We Collect

2.1  Information You Provide Directly

We collect personal information you voluntarily provide through forms, applications, and communications, including:

  • Membership enrollment: name, date of birth, address, email, phone, household member names, dates of birth and emails, and payment information
  • Donation forms: name, email, phone, and payment information
  • CPR/training class registration: name, email, phone, certificate or license number, job title and affiliated agency (if applicable), and payment information
  • Employment applications: name, contact information including mobile phone number (with optional consent to receive SMS communications), work history, and required employment documents including driver license, ambulance certificate, medical examiner’s certificate, driving record, and other certifications; date of birth and Social Security Number as collected via required employment documents and where required to verify employment eligibility; employee photo collected for identification, ID badge production, and access control purposes
  • Contact/inquiry forms: name, email, and any other information you choose to include
  • Inbound SMS messages: your mobile phone number and message content when you text us

2.2  Information Collected Automatically

When you visit our website, we may automatically collect:

  • IP address and general geographic location
  • Browser type, operating system, and device identifiers
  • Pages visited, time spent, referring URLs, and navigation patterns
  • Cookies and similar tracking technologies (see Section 6)

2.3  Information Collected Through Physical and Network Systems

Telephone and Voicemail Systems

Our telephone system may record calls for quality assurance, training, and operational purposes. Calls to or from Medstar may be recorded. Caller ID information and call metadata (date, time, duration) are logged by our phone system and underlying telecommunications providers. Call recordings are stored on our secure systems.

SMS/MMS Communications

When you interact with our SMS campaigns or respond to text messages, we collect your mobile phone number, message content, timestamps, and delivery status. Our SMS services are registered under applicable 10DLC (10-Digit Long Code) campaign requirements with The Campaign Registry (TCR).

Guest Wi-Fi Networks

We operate password-protected guest Wi-Fi networks at our facilities and in our vehicles. These networks are not public hotspots; access is limited to individuals with the network password. When you connect to a Medstar guest Wi-Fi network, we collect connection data including your device MAC address, device name, connection timestamps, and bandwidth usage.

Notice regarding deep packet inspection (DPI): Our network infrastructure, including guest Wi-Fi networks, utilizes deep packet inspection technology. DPI analyzes the characteristics and metadata of network traffic for purposes of network security, threat detection, bandwidth management, and operational integrity. DPI is used for network management and security purposes only — not to monitor, read, or log the content of personal communications beyond what is necessary for those purposes.

Use of our guest Wi-Fi constitutes acknowledgment of these network monitoring practices. If you prefer not to have your traffic subject to DPI, we recommend using your cellular data connection instead.

Video Recording — Facilities

NOTICE: Video recording is in operation at and around Medstar facilities, including parking areas and building exteriors. Recording occurs continuously or on motion detection. Audio recording is disabled on all facility security cameras. The areas monitored are not private spaces, and signage is posted at facility entrances providing notice of video recording. Recordings are used for security, safety, and operational purposes only.

AI-assisted motion detection: Facility security cameras use AI-assisted motion detection to classify movement within defined areas as persons, vehicles, or animals for alert and notification purposes. This classification does not involve facial recognition, individual identification, or the creation of any persistent biometric identifier.

Video Recording and AI Monitoring — Vehicles

NOTICE: One or more Medstar Ambulance vehicles are equipped with dual-facing video recording and AI-assisted behavior monitoring systems. Cameras record both the road-facing exterior environment and the vehicle cab interior, including the driver and front seat passenger. Audio recording is disabled on in-vehicle cameras. Vehicle cameras are not positioned or intended to capture the patient care compartment and are not expected to capture PHI related to patient care.

AI-assisted monitoring and video capture events: In-vehicle cameras use artificial intelligence to continuously analyze driver and front seat passenger behavior in real time and automatically capture and upload a video clip to the fleet management platform when any of the following events are detected:

Behavior and performance events: cell phone use while driving; distracted driving; driver seat belt undone; passenger seat belt undone; driver yawning (drowsy driving); smoking; tailgating; rolling stop; speeding (currently configured at 18 or more MPH over the posted limit to account for emergency vehicle operation); possible collision; lens obstruction; incorrect PIN entry; unauthorized device removal.

Vehicle and system events: battery drain; critical low tire pressure; engine abuse (RPMs over 7,000); camera button pressed. Vehicle and system events may still result in capture of footage of vehicle occupants.

Detection of driver behavior involves real-time analysis of eye movement, head position, and body position. Tailgating and collision detection use road-facing video analysis. This system does not create, store, or transmit persistent biometric identifiers or facial recognition templates. Video capture rules and detection thresholds are subject to change. When a capture event occurs, the system generates a record including the event type, timestamp, GPS location, vehicle ID, and an associated video clip, which is transmitted to and stored within our fleet management platform.

Recordings and behavioral event data are used for safety monitoring, driver coaching, quality assurance, incident review, insurance, and legal and compliance purposes. Crew members have been separately notified and have acknowledged in-vehicle recording and AI monitoring as a condition of employment or service.

3.  How We Use Your Information

We use the information we collect for the following purposes:

  • Service delivery: processing memberships, donations, class registrations, and applications; responding to inquiries
  • Communications: sending transaction confirmations, membership renewals, class reminders, and responding to messages
  • SMS campaigns: sending crew scheduling notifications, CAD (computer-aided dispatch) alerts, application status updates, and responding to inbound texts; monitoring and analyzing trends, usage, and activities related to our SMS services
  • Employment: evaluating job applications and communicating with applicants
  • Safety and security: monitoring facilities and vehicles via video recording systems and network security tools including deep packet inspection; AI-assisted analysis of driver behavior and road conditions to promote crew and public safety
  • Quality assurance and training: reviewing call recordings, vehicle footage, AI-generated behavioral event data, and operational data to improve performance and support driver coaching
  • Legal and compliance: maintaining records as required by law, responding to lawful requests from government authorities, and defending legal claims
  • Website improvement: analyzing traffic patterns and user behavior to improve our online services

4.  Legal Basis for Processing (CCPA / California Privacy Rights)

Medstar operates primarily in California and complies with the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). As a nonprofit organization, certain CCPA provisions apply with limitations; however, Medstar voluntarily extends meaningful privacy rights to all individuals whose data we process.

We collect and process personal information based on one or more of the following:

  • Your consent (e.g., SMS opt-in, form submissions, Wi-Fi use)
  • Performance of a contract or pre-contractual steps (e.g., membership enrollment, employment applications)
  • Legitimate organizational interests (e.g., security monitoring, network management, quality assurance)
  • Legal obligations (e.g., record retention requirements applicable to EMS agencies in California)

We do not sell personal information. We do not share personal information with third parties for cross-context behavioral advertising.

5.  Information Sharing and Disclosure

We do not sell, rent, or trade personal information. We may share information only in the following circumstances:

5.1  Service Providers and Platform Partners

We share data with vendors and platform partners who help us operate our services, subject to data processing agreements and confidentiality obligations. Current providers are listed below; this table will be updated as our vendor relationships change without requiring amendment to the substantive provisions of this Policy.

Provider / PlatformPurposeData Categories Shared
Wild ApricotMember database, website, event registrationName, contact info, membership data, payment records
AffiniPayPayment processing (PCI-compliant)Name, billing address, payment card data
JotformOnline forms and applicationsName, contact info, application data, consent records
Microsoft 365Productivity and document managementDocuments, email, operational data
VoxtelesysSIP trunking, hosted DIDs, SIP voice and SMS services; 10DLC campaign registrationPhone numbers, call metadata, SMS content
TwilioSIP trunking, hosted DIDs, SIP voice and SMS services (redundant carrier)Phone numbers, call metadata, SMS content
3CXUnified communications platform; telephone system, voicemail, and SMS messaging clientCall records, voicemail, call recordings, SMS message logs
Ubiquiti / UniFiGuest Wi-Fi infrastructure and network management — facilitiesDevice identifiers, connection logs, DPI traffic metadata
Ericsson / CradlepointVehicle-based Wi-Fi infrastructure and network managementDevice identifiers, connection logs, DPI traffic metadata
GeotabFleet management platform; AI-assisted driver behavior monitoring and vehicle telematicsGPS/location data, vehicle telematics, behavioral event records (alert type, timestamp, location, video clip) for enabled AI detections; no biometric identifiers or facial embeddings generated or stored
AladtecEmployee shift scheduling, workforce management, and certification/qualification trackingEmployee name, contact info, schedule, availability, shift records, certifications, qualifications, and expiration dates
Vector Solutions / Target SolutionsOnline employee training and certification trackingEmployee name, training records, completion status, certification history
Operative IQVehicle maintenance, rig checks, and supply managementEmployee name associated with rig check and maintenance records; vehicle and equipment data
Bryx 911CAD dispatch alerting applicationEmployee name, mobile device identifiers, dispatch notifications
SRFaxOnline fax transmission serviceContent of faxed documents; may include sensitive operational, HR, or clinical data
Google WorkspaceEmail, document storage, collaboration, and directory; primary identity provider (IdP) via OAuth/SAML for connected vendor platformsEmail content, documents, employee contact info, employee photos, authentication tokens, login activity, and user identity assertions shared with connected services
Amazon / RingFacility security camerasVideo recordings only (audio disabled)
ImageTrend EliteElectronic patient care records (ePCR) — PHIGoverned separately by HIPAA NPP
ImageTrend ElitePersonnel and credentialing database; Medstar user administrationEmployee name, contact info, and supplemental certifications added by Medstar; core EMT/paramedic certification and licensure records are maintained by CVEMSA (Coastal Valleys EMS Agency) as the local EMS agency under their ImageTrend contract
Intuit / QuickBooks WorkforcePayroll processing and employee pay portalEmployee name, SSN, compensation, tax records, W-2 data

Note: Employee ID numbers — internally assigned identifiers used to distinguish personnel records — may be present across multiple platforms listed above. These numbers are not independently personally identifiable and are used solely as internal record-keeping references.

SMS Opt-In Data — Special Disclosure Restriction
All categories of data sharing described above exclude SMS/text messaging opt-in data and consent records. Mobile phone numbers collected for SMS purposes and records of your consent to receive text messages will not be shared with any third party for marketing or promotional purposes, except as required by law or as necessary for message delivery through our messaging platform. This restriction is consistent with CTIA Messaging Principles and Best Practices and The Campaign Registry (TCR) 10DLC requirements.

5.2  Legal Requirements

We may disclose information when required by law, court order, or government authority, including in response to valid subpoenas, public records requests under the California Public Records Act (where applicable), or lawful requests from law enforcement.

5.3  Safety and Emergency Situations

We may disclose information to protect the safety of individuals or the public in emergency situations, consistent with applicable law.

5.4  Business Transfers

In the event of a merger, acquisition, consolidation, or transfer of substantially all assets of Medstar (including to another nonprofit organization), personal information may be transferred as part of that transaction. We will provide notice of any such transfer and the privacy protections that will apply to the transferred data.

6.  Cookies and Tracking Technologies

Our website uses cookies and similar technologies to enable site functionality, remember preferences, and analyze usage. Cookie categories include:

  • Strictly necessary: required for the website to function (session management, security)
  • Functional: remember your preferences and settings
  • Analytics: help us understand how visitors use our site (e.g., page views, traffic sources)

Our website hosting platform may set its own cookies as part of the hosted service. You can control cookies through your browser settings; however, disabling certain cookies may limit site functionality. We do not use cookies for cross-site advertising or behavioral tracking.

Identity provider and single sign-on: Medstar uses Google Workspace as its primary identity provider (IdP), enabling employee authentication across connected vendor platforms via OAuth and SAML protocols. When you sign in to Medstar services or integrated vendor platforms using Google Workspace credentials — or using a “Sign in with Google,” “Sign in with Microsoft,” or “Sign in with Apple” option on any of our platforms or services — the respective identity provider (Google, Microsoft, or Apple) receives authentication signals including login activity, user identity, and the service being accessed. This authentication data is governed by the identity provider’s own privacy policy. Medstar does not control the data practices of these identity providers beyond the scope of our service agreements with them.

7.  SMS Messaging — Consent, Opt-Out, and Program Details

7.1  SMS Campaign Overview

Medstar operates SMS messaging campaigns for the following purposes, registered with The Campaign Registry (TCR) under applicable 10DLC requirements:

  • Employee scheduling: shift notifications and scheduling updates for Medstar crew members
  • CAD alerts: computer-aided dispatch call notifications to responding crew
  • Application status: updates to job applicants regarding their application
  • Inbound response: replies to unsolicited inbound SMS messages from patients, members, or the public

7.2  Consent

We send SMS messages only to individuals who have provided prior express written consent. Consent is obtained through:

  • Our online employment application form, which includes a clearly labeled, unchecked opt-in checkbox; consent obtained at application extends to scheduling and CAD messages upon hire
  • Individuals who initiate unsolicited contact with us via SMS are considered to have consented to a reply

Consent to receive SMS is voluntary. Denial of consent will not affect your ability to apply for employment or access our services.

7.3  Standard Messaging Disclosures

Message frequency varies. Message & data rates may apply. Consent to receive SMS is not required to apply for employment or access our services. Text STOP to opt out at any time. Text HELP for assistance. Medstar Ambulance of Mendocino County — Ukiah, CA. Carriers are not liable for delayed or undelivered messages.

7.4  How to Opt Out

You may opt out of SMS communications at any time by replying STOP, END, CANCEL, UNSUBSCRIBE, or QUIT to any message from us. After opting out, you will receive a single confirmation and no further messages. Reply START to re-subscribe. Reply HELP for contact information. You may also email [email protected] to opt out or request assistance.

Medstar’s SMS service is available on most major U.S. carriers. Not all carriers or devices may support all features of the service. Message and data rates may apply; contact your wireless provider for details.

8.  Data Retention Schedule

Medstar retains personal information for the periods listed below, or as otherwise required by applicable law. Retention periods reflect California EMS regulatory requirements, generally accepted nonprofit governance practices, and operational needs.

Data CategoryRetention PeriodLegal / Regulatory Basis
Website analytics / cookies13 monthsStandard analytics retention; CalOPPA compliance
Contact / inquiry form submissions3 yearsStatute of limitations; operational records
Donation records7 yearsIRS / nonprofit tax records; CA Revenue & Tax Code
Membership enrollment records7 years after membership endsNonprofit recordkeeping; statute of limitations
CPR / training class records5 yearsCertification recordkeeping; liability
Employment applications (hired)Duration of employment + 7 yearsCalifornia Labor Code; EEOC requirements
Employment applications (not hired)3 yearsEEOC / CA DFEH recordkeeping requirement
Payroll and HR records7 years after separationCalifornia Labor Code § 1198.5; IRS requirements
Call records / metadata1 yearOperational; no specific EMS mandate
Call recordings90 days routine; indefinite if on holdQuality assurance; legal hold policy
SMS consent records (opt-in documentation)5 yearsFTC Telemarketing Sales Rule (16 C.F.R. § 310.5); TCPA compliance; maintained in form submission platform
SMS message logs (content and metadata)4 yearsTCPA statute of limitations; maintained in telephone system archive on local file server
Wi-Fi connection logs / DPI metadata90 daysNetwork security and troubleshooting
Facility video recordings60 days routine; indefinite if incidentSecurity; Cal. Penal Code compliance
Vehicle dash cam recordings30 days cloud (Surfsight/Geotab platform limit); SD card loops continuously; incident recordings must be downloaded within 30 days of the event for preservationSafety; quality assurance; legal hold
AI behavioral event data (Geotab/Surfsight)30 days cloud (Surfsight/Geotab platform limit); incident events must be downloaded within 30 days of the event for preservationDriver safety; coaching; legal hold; insurance
Incident-related recordingsIndefinitely or until legal resolutionLitigation hold; regulatory investigations
PHI / Patient care recordsGoverned by HIPAA NPPHIPAA; CA Health & Safety Code § 123111

9.  Data Security

Medstar implements reasonable administrative, technical, and physical security measures to protect personal information from unauthorized access, disclosure, alteration, or destruction. These measures include:

  • Encrypted storage for sensitive files, including HIPAA-compliant cloud storage and encrypted local file servers
  • Role-based access controls limiting data access to authorized personnel
  • Password-protected and monitored network infrastructure, including DPI-enabled security systems
  • Use of PCI-compliant payment processors — Medstar does not store payment card data
  • Regular review of third-party vendor security practices

On-premises data storage: Certain employee data — including photos used for identification and ID badge production, and employee names used for physical access control — is maintained exclusively on secure on-premises systems under Medstar’s direct control, including encrypted local file servers and locally installed software. This data is not transmitted to or processed by third-party cloud services.

No method of transmission or storage is 100% secure. In the event of a security breach affecting your personal information, we will notify affected individuals as required by California Civil Code § 1798.82 (California Data Breach Notification Law).

10.  Your Privacy Rights (California Residents)

Under the CCPA/CPRA, California residents have the following rights with respect to their personal information:

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, and how it is used and shared.
  • Right to Delete: You may request deletion of personal information we hold about you, subject to certain legal exceptions.
  • Right to Correct: You may request correction of inaccurate personal information.
  • Right to Opt Out: You may opt out of the sale or sharing of personal information. We do not sell or share personal information for advertising purposes.
  • Right to Limit Use of Sensitive Information: You may request that we limit the use of sensitive personal information to purposes authorized under the CPRA.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

To exercise your rights, contact us at [email protected] or by mail at the address in Section 14. We will respond within 45 days as required by law. We may need to verify your identity before processing requests. Authorized agents may submit requests on your behalf with written authorization.

11.  Children’s Privacy

Our online Services are not intended for or directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If we learn that we have inadvertently collected personal information from a child under 13, we will delete it promptly.

We do, however, collect information regarding minors when voluntarily provided by a parent or legal guardian for the purpose of household membership enrollment. Such information is used solely in connection with the membership and is not used for marketing or shared with third parties beyond what is necessary to administer the membership. Medical information related to minors is governed by our HIPAA NPP. If you believe a child has had information submitted about them inappropriately, please contact us at [email protected].

12.  Third-Party Links and Services

Our website and services integrate with or link to third-party platforms. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you access through our website or forms. Links to external websites do not constitute endorsement.

13.  Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or operational systems. When we make material changes, we will update the “Last Revised” date at the top of this Policy and, where appropriate, provide additional notice such as a notice on our website or via email to members. Your continued use of our services following an update constitutes acceptance of the revised Policy.

14.  Contact Us

For privacy questions, requests, or concerns, contact Medstar Ambulance of Mendocino County, Inc.:

Privacy Contact / Compliance Officer Medstar Ambulance of Mendocino County, Inc.
960 N State St, Ukiah, CA 95482
Mailing: PO Box 277, Ukiah, CA 95482
Email: [email protected]
Phone: (707) 462-3808

Copyright © 2013 Medstar Ambulance of Mendocino County Inc.,
a 501(c)(3) non-profit public charity dba Ukiah Ambulance.
960 N State St, PO Box 277, Ukiah, CA 95482
(707) 462-3808 Business • (707) 462-3001 Dispatch
IN AN EMERGENCY, DIAL 911

Powered by Wild Apricot Membership Software