ComfortFit Labs (“ComfortFit Labs,” “ComfortFit,” “we,” “us,” or “our”) respects the privacy and security of information entrusted to us by healthcare providers, their patients, customers, employees, and website visitors.
This Privacy Policy describes how ComfortFit Labs collects, uses, maintains, protects, and discloses information obtained through comfortfitlabs.com, our ordering systems, electronic communications, and services we provide to healthcare providers.
When ComfortFit Labs receives, creates, maintains, or transmits Protected Health Information (“PHI”) on behalf of a healthcare provider or other HIPAA Covered Entity, we handle that information as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), as amended by the HITECH Act, and applicable implementing regulations.
This Privacy Policy is intended to describe our privacy practices. It does not replace or modify any Business Associate Agreement (“BAA”) between ComfortFit Labs and a healthcare provider or other Covered Entity. Where a BAA imposes more specific requirements, the applicable BAA will govern.
1. Information We Collect
Depending on how you interact with ComfortFit Labs, we may collect the following categories of information:
A. Business and Contact Information
We may collect information such as:
- Name
- Professional title
- Practice or company name
- Mailing address
- Telephone number
- Email address
- Billing and shipping information
- Account credentials
- Ordering and customer-service information
B. Patient and Healthcare Information
When a healthcare provider submits an order to ComfortFit Labs, the information provided may include information relating to a patient's foot, gait, diagnosis, treatment, prescription, orthotic requirements, measurements, scans, impressions, images, or other information necessary to manufacture or service an orthotic device.
Some of this information may constitute Protected Health Information under HIPAA.
ComfortFit Labs does not independently determine the medical treatment provided to a patient. We receive and use patient information primarily to perform services requested by healthcare providers and their authorized personnel.
C. Website and Technical Information
When you visit our website, we may automatically receive certain technical information, including:
- IP address
- Browser type
- Device type
- Operating system
- Pages viewed
- Date and time of access
- Referring website
- General website usage information
- Security and diagnostic information
We use this information to operate, maintain, secure, and improve our website and systems.
2. How We Use Information
ComfortFit Labs may use information for legitimate business purposes, including:
- Processing and manufacturing orthotic orders
- Reviewing prescriptions and specifications submitted by healthcare providers
- Creating, maintaining, and fulfilling customer orders
- Communicating with healthcare providers and customers
- Shipping and delivering products
- Providing customer service and technical support
- Processing payments and invoices
- Maintaining customer accounts
- Troubleshooting and maintaining our information systems
- Detecting, preventing, and investigating fraud, abuse, unauthorized access, or security incidents
- Complying with applicable laws and regulations
- Performing internal quality assurance and operational activities
- Protecting the rights, property, and safety of ComfortFit Labs and others
When information constitutes PHI, ComfortFit Labs will use and disclose that PHI only as permitted or required by the applicable BAA, HIPAA, applicable law, or other authorized agreement.
3. HIPAA Business Associate Responsibilities
When acting as a Business Associate, ComfortFit Labs will use and disclose PHI only as permitted or required by the applicable Business Associate Agreement and applicable law.
ComfortFit Labs will not use or disclose PHI for purposes unrelated to the services for which we have been engaged unless such use or disclosure is permitted by the applicable BAA or otherwise authorized or required by law.
We maintain safeguards designed to protect the confidentiality, integrity, and availability of electronic PHI that we create, receive, maintain, or transmit.
These safeguards may include administrative, physical, and technical measures appropriate to the nature and sensitivity of the information and the risks associated with its use.
ComfortFit Labs also requires appropriate protections from applicable vendors, contractors, and subcontractors that may have access to PHI when required by HIPAA or applicable law.
4. Minimum Necessary Access
ComfortFit Labs seeks to limit access to PHI to authorized workforce members and service providers who require access to perform their assigned responsibilities.
Where applicable, access to PHI is limited to the information reasonably necessary to perform the intended function, subject to the requirements of HIPAA and the applicable Business Associate Agreement.
5. Permitted Disclosures of PHI
ComfortFit Labs may disclose PHI when permitted or required by HIPAA, applicable law, or the applicable BAA.
Examples may include disclosures:
- To perform services for a healthcare provider
- To authorized healthcare providers or their workforce members
- To permitted subcontractors or service providers acting on ComfortFit Labs' behalf
- As required by federal, state, or local law
- To respond to valid legal process
- To address certain public-health or regulatory requirements
- To prevent or address a serious threat to health or safety when permitted by law
- For other purposes expressly permitted by HIPAA or the applicable BAA
ComfortFit Labs does not sell PHI.
ComfortFit Labs does not use PHI for advertising or independent marketing purposes unless specifically permitted and authorized under applicable law and the applicable BAA.
6. Business Associate Agreements
ComfortFit Labs enters into Business Associate Agreements with Covered Entities when required by HIPAA. A BAA establishes the permitted and required uses and disclosures of PHI and requires appropriate safeguards for PHI.
Our workforce members, contractors, and applicable subcontractors are expected to comply with applicable privacy and security requirements.
7. Disclosure to Service Providers and Subcontractors
ComfortFit Labs may use third-party service providers to assist with business operations, including services relating to:
- Information technology
- Cloud hosting and storage
- Software and application services
- Order processing
- Shipping and logistics
- Payment processing
- Customer support
- Security
- Communications
- Professional services
Where a service provider will create, receive, maintain, or transmit PHI on behalf of ComfortFit Labs in a manner subject to HIPAA, ComfortFit Labs will obtain appropriate contractual assurances and a Business Associate Agreement or other required agreement when required by HIPAA.
8. Security
ComfortFit Labs maintains reasonable administrative, physical, and technical safeguards designed to protect information against unauthorized access, acquisition, use, disclosure, alteration, or destruction.
Security measures may include:
- Access controls
- User authentication
- Role-based access
- System monitoring
- Workforce security procedures
- Security awareness and training
- Secure transmission methods
- Physical security controls
- Data backup and recovery procedures
- Incident-response procedures
- Vendor and service-provider controls
No method of transmitting or storing information over the Internet can be guaranteed to be completely secure. Accordingly, although ComfortFit Labs works to protect information, we cannot guarantee absolute security.
9. HIPAA Security Incidents and Breaches
ComfortFit Labs maintains procedures for identifying, investigating, documenting, and responding to suspected security incidents and breaches involving PHI.
When required by HIPAA, the applicable BAA, or other applicable law, ComfortFit Labs will notify the affected Covered Entity or other appropriate party of a breach of unsecured PHI or other reportable incident within the time and manner required by applicable law or contract.
The Covered Entity remains responsible for making any notifications to affected individuals, the U.S. Department of Health and Human Services, or the media that are required of the Covered Entity under HIPAA, except to the extent that ComfortFit Labs has expressly agreed to perform such obligations on the Covered Entity's behalf.
10. Patient Privacy Rights
Because ComfortFit Labs generally acts as a Business Associate and not as the patient's healthcare provider, patients should ordinarily direct requests concerning their medical records, access to PHI, amendment of medical information, restrictions on use or disclosure, or other HIPAA rights to the healthcare provider that maintains the patient's medical record.
Where HIPAA or an applicable Business Associate Agreement requires ComfortFit Labs to assist a Covered Entity in responding to an individual's request concerning PHI maintained by ComfortFit Labs, ComfortFit Labs will provide appropriate assistance to the Covered Entity as required by applicable law and contract.
11. Website Privacy
Information submitted through comfortfitlabs.com may include contact information, account information, order information, or other information voluntarily provided by visitors.
We use website-submitted information to:
- Respond to inquiries
- Provide requested services
- Process business transactions
- Provide customer support
- Improve our website and services
- Protect our website and systems
- Communicate regarding existing business relationships
ComfortFit Labs does not intentionally request patients to submit medical records or PHI through general website contact forms unless the particular form or service is specifically designed and secured for that purpose.
12. Cookies and Analytics
Our website may use cookies, pixels, analytics technologies, or similar technologies to operate the website, understand website traffic, maintain security, and improve website functionality.
Where third-party analytics, advertising, or similar technologies are used, ComfortFit Labs will configure and use those technologies in accordance with applicable privacy laws and HIPAA requirements.
ComfortFit Labs will not knowingly transmit PHI to advertising or analytics services through website tracking technologies in a manner that violates HIPAA or an applicable Business Associate Agreement.
13. Marketing Communications
ComfortFit Labs may use business contact information to communicate with healthcare providers and customers regarding products, services, orders, account information, educational materials, or other legitimate business matters.
You may opt out of non-essential marketing communications by following the unsubscribe instructions in the communication or by contacting us using the information below.
Opting out of marketing communications does not prevent ComfortFit Labs from sending transactional, security-related, account-related, or other legally required communications.
14. Information Retention
ComfortFit Labs retains information for as long as reasonably necessary to:
- Fulfill the purposes for which the information was collected
- Perform our contractual obligations
- Maintain business and financial records
- Meet legal, regulatory, and contractual requirements
- Resolve disputes
- Enforce agreements
- Maintain security and operational records
PHI received from a Covered Entity will be retained, returned, destroyed, or otherwise handled in accordance with the applicable Business Associate Agreement and applicable law.
15. Children's Privacy
Our website is intended primarily for healthcare professionals, businesses, and adult users.
ComfortFit Labs does not knowingly collect personal information directly from children under 13 through our website for independent marketing purposes.
If you believe a child has submitted personal information to us, please contact us so that we can investigate and, where appropriate, delete the information.
16. Your State Privacy Rights
Depending on where you live, you may have additional privacy rights under applicable state law.
These rights may include rights relating to access, correction, deletion, portability, or restrictions on certain uses of personal information.
These rights may be subject to exceptions under applicable law, including exceptions relating to healthcare information and information maintained under HIPAA.
To exercise an applicable state privacy right, contact us using the information below.
17. New Jersey Privacy
ComfortFit Labs is located in New Jersey and seeks to comply with applicable New Jersey privacy and data-security requirements.
Nothing in this Privacy Policy is intended to limit rights provided to individuals under applicable New Jersey law.
Where information is subject to HIPAA, other federal healthcare privacy requirements, or an applicable Business Associate Agreement, those requirements may affect the applicability of state-law rights and obligations.
18. Changes to This Privacy Policy
ComfortFit Labs may periodically update this Privacy Policy to reflect changes in our services, technology, legal requirements, or privacy practices.
When we make material changes, we will update the “Last Updated” date at the beginning of this Privacy Policy and may provide additional notice where required by law.
The updated Privacy Policy will be posted on comfortfitlabs.com.
19. Contact Us
Questions regarding this Privacy Policy, privacy practices, or requests concerning information maintained by ComfortFit Labs may be directed to:
246 Columbus Avenue
Roselle, NJ 07203
Telephone: (888) 523-1600
Email: contact@comfortfitlabs.com
For matters involving PHI received from a healthcare provider, individuals may also contact the healthcare provider that submitted or maintains the applicable patient information.
20. Complaints
ComfortFit Labs takes privacy complaints seriously.
If you believe that your privacy rights have been violated or that information has been improperly used or disclosed, you may contact ComfortFit Labs using the contact information above.
You may also have the right to submit a complaint to the U.S. Department of Health and Human Services, Office for Civil Rights.
ComfortFit Labs will not retaliate against any individual for making a good-faith privacy complaint.
21. No Waiver of Legal Rights
Nothing in this Privacy Policy limits any rights or protections provided by HIPAA, the HITECH Act, applicable federal law, applicable state law, or an applicable Business Associate Agreement.
If any provision of this Privacy Policy is determined to be inconsistent with applicable law, the applicable law will control to the extent required.