ComfortFit Labs (“ComfortFit Labs,” “ComfortFit,” “we,” “us,” or “our”) respects the privacy and security of information entrusted to us by healthcare providers, their patients, customers, employees, and website visitors.
This Privacy Policy describes how ComfortFit Labs collects, uses, maintains, protects, and discloses information obtained through comfortfitlabs.com, our ordering systems, electronic communications, our ComfortPro mobile application, and services we provide to healthcare providers.
When ComfortFit Labs receives, creates, maintains, or transmits Protected Health Information (“PHI”) on behalf of a healthcare provider or other HIPAA Covered Entity, we handle that information as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), as amended by the HITECH Act, and applicable implementing regulations.
This Privacy Policy is intended to describe our privacy practices. It does not replace or modify any Business Associate Agreement (“BAA”) between ComfortFit Labs and a healthcare provider or other Covered Entity. Where a BAA imposes more specific requirements, the applicable BAA will govern.
1. Information We Collect
Depending on how you interact with ComfortFit Labs, we may collect the following categories of information:
A. Business and Contact Information
We may collect information such as:
- Name
- Professional title
- Practice or company name
- Mailing address
- Telephone number
- Email address
- Billing and shipping information
- Account credentials
- Ordering and customer-service information
B. Patient and Healthcare Information
When a healthcare provider submits an order to ComfortFit Labs, the information provided may include information relating to a patient's foot, gait, diagnosis, treatment, prescription, orthotic requirements, measurements, scans, impressions, images, or other information necessary to manufacture or service an orthotic device.
Some of this information may constitute Protected Health Information under HIPAA.
ComfortFit Labs does not independently determine the medical treatment provided to a patient. We receive and use patient information primarily to perform services requested by healthcare providers and their authorized personnel.
C. Information Collected via the ComfortPro Mobile Application
Healthcare providers may use our ComfortPro application for iPad (“the App”) to capture patient information used in the design, manufacture, and servicing of custom orthotic devices. When a provider uses the App, we collect and process on the provider’s behalf:
- Three-dimensional (3D) foot scans and related anatomical imaging
- Patient demographic and clinical information maintained by the provider (such as name, date of birth, diagnoses, clinical notes, and prescriptions)
- Order and device-specification information
- Telehealth session metadata (appointment times and participants) when the provider conducts telehealth visits through the App
- Images of insurance cards photographed by the provider, processed to extract coverage information into the patient’s record
Information collected through the App on behalf of a healthcare provider is Protected Health Information handled under HIPAA and the Business Associate provisions described in this Policy.
D. Website and Technical Information
When you visit our website, we may automatically receive certain technical information, including:
- IP address
- Browser type
- Device type
- Operating system
- Pages viewed
- Date and time of access
- Referring website
- General website usage information
- Security and diagnostic information
We use this information to operate, maintain, secure, and improve our website and systems.
2. How We Use Information
ComfortFit Labs may use information for legitimate business purposes, including:
- Processing and manufacturing orthotic orders
- Reviewing prescriptions and specifications submitted by healthcare providers
- Creating, maintaining, and fulfilling customer orders
- Communicating with healthcare providers and customers
- Shipping and delivering products
- Providing customer service and technical support
- Processing payments and invoices
- Maintaining customer accounts
- Troubleshooting and maintaining our information systems
- Detecting, preventing, and investigating fraud, abuse, unauthorized access, or security incidents
- Complying with applicable laws and regulations
- Performing internal quality assurance and operational activities
- Protecting the rights, property, and safety of ComfortFit Labs and others
When information constitutes PHI, ComfortFit Labs will use and disclose that PHI only as permitted or required by the applicable BAA, HIPAA, applicable law, or other authorized agreement.
3. HIPAA Business Associate Responsibilities
When acting as a Business Associate, ComfortFit Labs will use and disclose PHI only as permitted or required by the applicable Business Associate Agreement and applicable law.
ComfortFit Labs will not use or disclose PHI for purposes unrelated to the services for which we have been engaged unless such use or disclosure is permitted by the applicable BAA or otherwise authorized or required by law.
We maintain safeguards designed to protect the confidentiality, integrity, and availability of electronic PHI that we create, receive, maintain, or transmit.
These safeguards may include administrative, physical, and technical measures appropriate to the nature and sensitivity of the information and the risks associated with its use.
ComfortFit Labs also requires appropriate protections from applicable vendors, contractors, and subcontractors that may have access to PHI when required by HIPAA or applicable law.
4. Minimum Necessary Access
ComfortFit Labs seeks to limit access to PHI to authorized workforce members and service providers who require access to perform their assigned responsibilities.
Where applicable, access to PHI is limited to the information reasonably necessary to perform the intended function, subject to the requirements of HIPAA and the applicable Business Associate Agreement.
5. Permitted Disclosures of PHI
ComfortFit Labs may disclose PHI when permitted or required by HIPAA, applicable law, or the applicable BAA.
Examples may include disclosures:
- To perform services for a healthcare provider
- To authorized healthcare providers or their workforce members
- To permitted subcontractors or service providers acting on ComfortFit Labs' behalf
- As required by federal, state, or local law
- To respond to valid legal process
- To address certain public-health or regulatory requirements
- To prevent or address a serious threat to health or safety when permitted by law
- For other purposes expressly permitted by HIPAA or the applicable BAA
ComfortFit Labs does not sell PHI.
ComfortFit Labs does not use PHI for advertising or independent marketing purposes unless specifically permitted and authorized under applicable law and the applicable BAA.
6. Business Associate Agreements
ComfortFit Labs enters into Business Associate Agreements with Covered Entities when required by HIPAA.
A BAA establishes the permitted and required uses and disclosures of PHI and requires appropriate safeguards for PHI.
Our workforce members, contractors, and applicable subcontractors are expected to comply with applicable privacy and security requirements.
7. The ComfortPro Mobile Application; 3D Foot Scans
The ComfortPro App captures three-dimensional surface scans of a patient’s foot for the purpose of designing and manufacturing a custom orthotic device prescribed by the patient’s healthcare provider. These scans are clinical imaging — a geometric record of foot surface shape — and are used solely for:
- Designing the prescribed orthotic device
- Manufacturing that device to clinical specification
- Attaching the scan to the patient’s clinical record at the provider’s organization for ongoing care
The App generates 3D models of the feet using the Apple TrueDepth® camera, the Structure Sensor®, or the device’s LiDAR camera. Camera and depth data are processed solely to render the geometry of the foot; they are not used for face mapping, facial recognition, or identification of any person. This information is stored securely and is necessary to accurately manufacture a custom orthotic. All orthotics are custom-made from this 3D information in lieu of traditional casting methods.
3D foot scans are NOT used for biometric identification, biometric authentication, facial recognition, fingerprinting, voiceprint analysis, or any purpose unrelated to the prescribed clinical device. Scans are encrypted in transit (TLS 1.2 or higher) and at rest. Access is limited to the patient’s healthcare provider, that provider’s authorized clinical staff, and authorized ComfortFit Labs personnel involved in producing the prescribed device; scans are not shared with third parties for any other purpose.
Patients seeking access to, correction of, or deletion of their 3D scans or other clinical records should contact their healthcare provider. ComfortFit Labs supports such requests through the provider under the applicable Business Associate Agreement. Providers may also request removal of 3D models at any time through the App’s support feature.
Device Permissions
The App requests the following device capabilities, each used only for the stated purpose:
- Camera: Capturing 3D foot scans and photographing insurance cards
- Bluetooth: Connecting to the external Structure Sensor® 3D scanner — not used for location tracking or advertising
- Location while the App is in use: Supporting telehealth session routing
- Notifications: Appointment and order updates
Each permission is requested from the provider at first use and may be declined or revoked in iOS Settings.
8. Disclosure to Service Providers and Subcontractors
ComfortFit Labs may use third-party service providers to assist with business operations, including services relating to:
- Information technology
- Cloud hosting and storage
- Software and application services
- Order processing
- Shipping and logistics
- Payment processing
- Customer support
- Security
- Communications
- Professional services
Specific service providers and subprocessors used in connection with the ComfortPro App include:
- Amazon Web Services — cloud hosting and storage (operated under a Business Associate Agreement)
- Ditto — real-time data synchronization between the App and backend systems (under BAA)
- Zoom Video Communications — embedded telehealth video sessions via the Zoom Video SDK (under BAA)
- Stripe — payment processing (no Protected Health Information is shared)
- Anthropic — AI-assisted clinical documentation summaries and insurance-card data extraction, processed transiently through a secured service (no data retained for model training)
- NPPES (CMS) — verification of provider NPI numbers against the public federal registry
Where a service provider will create, receive, maintain, or transmit PHI on behalf of ComfortFit Labs in a manner subject to HIPAA, ComfortFit Labs will obtain appropriate contractual assurances and a Business Associate Agreement or other required agreement when required by HIPAA.
9. Security
ComfortFit Labs maintains reasonable administrative, physical, and technical safeguards designed to protect information against unauthorized access, acquisition, use, disclosure, alteration, or destruction.
Security measures may include:
- Access controls
- User authentication
- Role-based access
- System monitoring
- Workforce security procedures
- Security awareness and training
- Secure transmission methods
- Physical security controls
- Data backup and recovery procedures
- Incident-response procedures
- Vendor and service-provider controls
No method of transmitting or storing information over the Internet can be guaranteed to be completely secure. Accordingly, although ComfortFit Labs works to protect information, we cannot guarantee absolute security.
10. HIPAA Security Incidents and Breaches
ComfortFit Labs maintains procedures for identifying, investigating, documenting, and responding to suspected security incidents and breaches involving PHI.
When required by HIPAA, the applicable BAA, or other applicable law, ComfortFit Labs will notify the affected Covered Entity or other appropriate party of a breach of unsecured PHI or other reportable incident within the time and manner required by applicable law or contract.
The Covered Entity remains responsible for making any notifications to affected individuals, the U.S. Department of Health and Human Services, or the media that are required of the Covered Entity under HIPAA, except to the extent that ComfortFit Labs has expressly agreed to perform such obligations on the Covered Entity's behalf.
11. Patient Privacy Rights
Because ComfortFit Labs generally acts as a Business Associate and not as the patient's healthcare provider, patients should ordinarily direct requests concerning their medical records, access to PHI, amendment of medical information, restrictions on use or disclosure, or other HIPAA rights to the healthcare provider that maintains the patient's medical record.
Where HIPAA or an applicable Business Associate Agreement requires ComfortFit Labs to assist a Covered Entity in responding to an individual's request concerning PHI maintained by ComfortFit Labs, ComfortFit Labs will provide appropriate assistance to the Covered Entity as required by applicable law and contract.
12. Website Privacy
Information submitted through comfortfitlabs.com may include contact information, account information, order information, or other information voluntarily provided by visitors.
We use website-submitted information to:
- Respond to inquiries
- Provide requested services
- Process business transactions
- Provide customer support
- Improve our website and services
- Protect our website and systems
- Communicate regarding existing business relationships
ComfortFit Labs does not intentionally request patients to submit medical records or PHI through general website contact forms unless the particular form or service is specifically designed and secured for that purpose.
13. Cookies and Analytics
Our website may use cookies, pixels, analytics technologies, or similar technologies to operate the website, understand website traffic, maintain security, and improve website functionality.
Where third-party analytics, advertising, or similar technologies are used, ComfortFit Labs will configure and use those technologies in accordance with applicable privacy laws and HIPAA requirements.
ComfortFit Labs will not knowingly transmit PHI to advertising or analytics services through website tracking technologies in a manner that violates HIPAA or an applicable Business Associate Agreement.
14. Marketing Communications
ComfortFit Labs may use business contact information to communicate with healthcare providers and customers regarding products, services, orders, account information, educational materials, or other legitimate business matters.
You may opt out of non-essential marketing communications by following the unsubscribe instructions in the communication or by contacting us using the information below.
Opting out of marketing communications does not prevent ComfortFit Labs from sending transactional, security-related, account-related, or other legally required communications.
15. Information Retention
ComfortFit Labs retains information for as long as reasonably necessary to:
- Fulfill the purposes for which the information was collected
- Perform our contractual obligations
- Maintain business and financial records
- Meet legal, regulatory, and contractual requirements
- Resolve disputes
- Enforce agreements
- Maintain security and operational records
3D foot scans are retained as part of the patient’s clinical record, consistent with medical-record retention requirements (at least six (6) years from creation or last use, or longer where state law requires), plus the duration of any applicable device warranty period.
PHI received from a Covered Entity will be retained, returned, destroyed, or otherwise handled in accordance with the applicable Business Associate Agreement and applicable law.
16. Children's Privacy
Our website is intended primarily for healthcare professionals, businesses, and adult users.
ComfortFit Labs does not knowingly collect personal information directly from children under 13 through our website for independent marketing purposes.
If you believe a child has submitted personal information to us, please contact us so that we can investigate and, where appropriate, delete the information.
17. Your State Privacy Rights
Depending on where you live, you may have additional privacy rights under applicable state law.
These rights may include rights relating to access, correction, deletion, portability, or restrictions on certain uses of personal information.
These rights may be subject to exceptions under applicable law, including exceptions relating to healthcare information and information maintained under HIPAA.
To exercise an applicable state privacy right, contact us using the information below.
Illinois (BIPA)
3D foot scans captured by the ComfortPro App are clinical imaging used for orthotic device design and manufacture; they are not used for biometric identification or biometric verification within the meaning of the Illinois Biometric Information Privacy Act. Scans are retained per the schedule in Section 15 and are protected by security measures consistent with industry standards for protected health information.
18. New Jersey Privacy
ComfortFit Labs is located in New Jersey and seeks to comply with applicable New Jersey privacy and data-security requirements.
Nothing in this Privacy Policy is intended to limit rights provided to individuals under applicable New Jersey law.
Where information is subject to HIPAA, other federal healthcare privacy requirements, or an applicable Business Associate Agreement, those requirements may affect the applicability of state-law rights and obligations.
19. App Store Distribution and Billing
The ComfortPro App is distributed through the Apple App Store. Orthotic devices are physical goods manufactured to clinical specification and are billed outside of Apple’s in-app purchase system, as permitted under Apple App Store Review Guideline 3.1.3(e) for physical goods and services consumed outside of an app. Payment processing is handled by Stripe; ComfortFit Labs does not store full payment card numbers.
20. Changes to This Privacy Policy
ComfortFit Labs may periodically update this Privacy Policy to reflect changes in our services, technology, legal requirements, or privacy practices.
When we make material changes, we will update the “Last Updated” date at the beginning of this Privacy Policy and may provide additional notice where required by law.
The updated Privacy Policy will be posted on comfortfitlabs.com.
21. Contact Us
Questions regarding this Privacy Policy, privacy practices, or requests concerning information maintained by ComfortFit Labs may be directed to:
Chief Operating Officer: Michael Mohring
246 Columbus Ave
Roselle, NJ 07203
Telephone: 888-523-1600
Email: michael.mohring@comfortfitlabs.com
For matters involving PHI received from a healthcare provider, individuals may also contact the healthcare provider that submitted or maintains the applicable patient information.
22. Complaints
ComfortFit Labs takes privacy complaints seriously.
If you believe that your privacy rights have been violated or that information has been improperly used or disclosed, you may contact ComfortFit Labs using the contact information above.
You may also have the right to submit a complaint to the U.S. Department of Health and Human Services, Office for Civil Rights.
ComfortFit Labs will not retaliate against any individual for making a good-faith privacy complaint.
23. No Waiver of Legal Rights
Nothing in this Privacy Policy limits any rights or protections provided by HIPAA, the HITECH Act, applicable federal law, applicable state law, or an applicable Business Associate Agreement.
If any provision of this Privacy Policy is determined to be inconsistent with applicable law, the applicable law will control to the extent required.