ComfortFit Labs logo ComfortFit LabsPure Clinical Precision Return to main site →
Legal & Privacy

Privacy Policy & HIPAA Privacy Statement

How ComfortFit Labs collects, uses, maintains, protects, and discloses information obtained through our website, ordering systems, electronic communications, the ComfortPro mobile application, and services provided to healthcare professionals.

Effective August 24, 2026Last updated August 25, 2026

ComfortFit Labs (“ComfortFit Labs,” “ComfortFit,” “we,” “us,” or “our”) respects the privacy and security of information entrusted to us by healthcare providers, their patients, customers, employees, and website visitors.

This Privacy Policy describes how ComfortFit Labs collects, uses, maintains, protects, and discloses information obtained through comfortfitlabs.com, our ordering systems, electronic communications, our ComfortPro mobile application, and services we provide to healthcare providers.

When ComfortFit Labs receives, creates, maintains, or transmits Protected Health Information (“PHI”) on behalf of a healthcare provider or other HIPAA Covered Entity, we handle that information as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), as amended by the HITECH Act, and applicable implementing regulations.

This Privacy Policy is intended to describe our privacy practices. It does not replace or modify any Business Associate Agreement (“BAA”) between ComfortFit Labs and a healthcare provider or other Covered Entity. Where a BAA imposes more specific requirements, the applicable BAA will govern.

1. Information We Collect

Depending on how you interact with ComfortFit Labs, we may collect the following categories of information:

A. Business and Contact Information

We may collect information such as:

B. Patient and Healthcare Information

When a healthcare provider submits an order to ComfortFit Labs, the information provided may include information relating to a patient's foot, gait, diagnosis, treatment, prescription, orthotic requirements, measurements, scans, impressions, images, or other information necessary to manufacture or service an orthotic device.

Some of this information may constitute Protected Health Information under HIPAA.

ComfortFit Labs does not independently determine the medical treatment provided to a patient. We receive and use patient information primarily to perform services requested by healthcare providers and their authorized personnel.

C. Information Collected via the ComfortPro Mobile Application

Healthcare providers may use our ComfortPro application for iPad (“the App”) to capture patient information used in the design, manufacture, and servicing of custom orthotic devices. When a provider uses the App, we collect and process on the provider’s behalf:

Information collected through the App on behalf of a healthcare provider is Protected Health Information handled under HIPAA and the Business Associate provisions described in this Policy.

D. Website and Technical Information

When you visit our website, we may automatically receive certain technical information, including:

We use this information to operate, maintain, secure, and improve our website and systems.

2. How We Use Information

ComfortFit Labs may use information for legitimate business purposes, including:

When information constitutes PHI, ComfortFit Labs will use and disclose that PHI only as permitted or required by the applicable BAA, HIPAA, applicable law, or other authorized agreement.

3. HIPAA Business Associate Responsibilities

When acting as a Business Associate, ComfortFit Labs will use and disclose PHI only as permitted or required by the applicable Business Associate Agreement and applicable law.

ComfortFit Labs will not use or disclose PHI for purposes unrelated to the services for which we have been engaged unless such use or disclosure is permitted by the applicable BAA or otherwise authorized or required by law.

We maintain safeguards designed to protect the confidentiality, integrity, and availability of electronic PHI that we create, receive, maintain, or transmit.

These safeguards may include administrative, physical, and technical measures appropriate to the nature and sensitivity of the information and the risks associated with its use.

ComfortFit Labs also requires appropriate protections from applicable vendors, contractors, and subcontractors that may have access to PHI when required by HIPAA or applicable law.

4. Minimum Necessary Access

ComfortFit Labs seeks to limit access to PHI to authorized workforce members and service providers who require access to perform their assigned responsibilities.

Where applicable, access to PHI is limited to the information reasonably necessary to perform the intended function, subject to the requirements of HIPAA and the applicable Business Associate Agreement.

5. Permitted Disclosures of PHI

ComfortFit Labs may disclose PHI when permitted or required by HIPAA, applicable law, or the applicable BAA.

Examples may include disclosures:

ComfortFit Labs does not sell PHI.

ComfortFit Labs does not use PHI for advertising or independent marketing purposes unless specifically permitted and authorized under applicable law and the applicable BAA.

6. Business Associate Agreements

ComfortFit Labs enters into Business Associate Agreements with Covered Entities when required by HIPAA.

A BAA establishes the permitted and required uses and disclosures of PHI and requires appropriate safeguards for PHI.

Our workforce members, contractors, and applicable subcontractors are expected to comply with applicable privacy and security requirements.

7. The ComfortPro Mobile Application; 3D Foot Scans

The ComfortPro App captures three-dimensional surface scans of a patient’s foot for the purpose of designing and manufacturing a custom orthotic device prescribed by the patient’s healthcare provider. These scans are clinical imaging — a geometric record of foot surface shape — and are used solely for:

The App generates 3D models of the feet using the Apple TrueDepth® camera, the Structure Sensor®, or the device’s LiDAR camera. Camera and depth data are processed solely to render the geometry of the foot; they are not used for face mapping, facial recognition, or identification of any person. This information is stored securely and is necessary to accurately manufacture a custom orthotic. All orthotics are custom-made from this 3D information in lieu of traditional casting methods.

3D foot scans are NOT used for biometric identification, biometric authentication, facial recognition, fingerprinting, voiceprint analysis, or any purpose unrelated to the prescribed clinical device. Scans are encrypted in transit (TLS 1.2 or higher) and at rest. Access is limited to the patient’s healthcare provider, that provider’s authorized clinical staff, and authorized ComfortFit Labs personnel involved in producing the prescribed device; scans are not shared with third parties for any other purpose.

Patients seeking access to, correction of, or deletion of their 3D scans or other clinical records should contact their healthcare provider. ComfortFit Labs supports such requests through the provider under the applicable Business Associate Agreement. Providers may also request removal of 3D models at any time through the App’s support feature.

Device Permissions

The App requests the following device capabilities, each used only for the stated purpose:

Each permission is requested from the provider at first use and may be declined or revoked in iOS Settings.

8. Disclosure to Service Providers and Subcontractors

ComfortFit Labs may use third-party service providers to assist with business operations, including services relating to:

Specific service providers and subprocessors used in connection with the ComfortPro App include:

Where a service provider will create, receive, maintain, or transmit PHI on behalf of ComfortFit Labs in a manner subject to HIPAA, ComfortFit Labs will obtain appropriate contractual assurances and a Business Associate Agreement or other required agreement when required by HIPAA.

9. Security

ComfortFit Labs maintains reasonable administrative, physical, and technical safeguards designed to protect information against unauthorized access, acquisition, use, disclosure, alteration, or destruction.

Security measures may include:

No method of transmitting or storing information over the Internet can be guaranteed to be completely secure. Accordingly, although ComfortFit Labs works to protect information, we cannot guarantee absolute security.

10. HIPAA Security Incidents and Breaches

ComfortFit Labs maintains procedures for identifying, investigating, documenting, and responding to suspected security incidents and breaches involving PHI.

When required by HIPAA, the applicable BAA, or other applicable law, ComfortFit Labs will notify the affected Covered Entity or other appropriate party of a breach of unsecured PHI or other reportable incident within the time and manner required by applicable law or contract.

The Covered Entity remains responsible for making any notifications to affected individuals, the U.S. Department of Health and Human Services, or the media that are required of the Covered Entity under HIPAA, except to the extent that ComfortFit Labs has expressly agreed to perform such obligations on the Covered Entity's behalf.

11. Patient Privacy Rights

Because ComfortFit Labs generally acts as a Business Associate and not as the patient's healthcare provider, patients should ordinarily direct requests concerning their medical records, access to PHI, amendment of medical information, restrictions on use or disclosure, or other HIPAA rights to the healthcare provider that maintains the patient's medical record.

Where HIPAA or an applicable Business Associate Agreement requires ComfortFit Labs to assist a Covered Entity in responding to an individual's request concerning PHI maintained by ComfortFit Labs, ComfortFit Labs will provide appropriate assistance to the Covered Entity as required by applicable law and contract.

12. Website Privacy

Information submitted through comfortfitlabs.com may include contact information, account information, order information, or other information voluntarily provided by visitors.

We use website-submitted information to:

ComfortFit Labs does not intentionally request patients to submit medical records or PHI through general website contact forms unless the particular form or service is specifically designed and secured for that purpose.

Do not submit patient medical information through an ordinary website contact form unless ComfortFit Labs specifically instructs you to do so through an approved secure process.

13. Cookies and Analytics

Our website may use cookies, pixels, analytics technologies, or similar technologies to operate the website, understand website traffic, maintain security, and improve website functionality.

Where third-party analytics, advertising, or similar technologies are used, ComfortFit Labs will configure and use those technologies in accordance with applicable privacy laws and HIPAA requirements.

ComfortFit Labs will not knowingly transmit PHI to advertising or analytics services through website tracking technologies in a manner that violates HIPAA or an applicable Business Associate Agreement.

14. Marketing Communications

ComfortFit Labs may use business contact information to communicate with healthcare providers and customers regarding products, services, orders, account information, educational materials, or other legitimate business matters.

You may opt out of non-essential marketing communications by following the unsubscribe instructions in the communication or by contacting us using the information below.

Opting out of marketing communications does not prevent ComfortFit Labs from sending transactional, security-related, account-related, or other legally required communications.

15. Information Retention

ComfortFit Labs retains information for as long as reasonably necessary to:

3D foot scans are retained as part of the patient’s clinical record, consistent with medical-record retention requirements (at least six (6) years from creation or last use, or longer where state law requires), plus the duration of any applicable device warranty period.

PHI received from a Covered Entity will be retained, returned, destroyed, or otherwise handled in accordance with the applicable Business Associate Agreement and applicable law.

16. Children's Privacy

Our website is intended primarily for healthcare professionals, businesses, and adult users.

ComfortFit Labs does not knowingly collect personal information directly from children under 13 through our website for independent marketing purposes.

If you believe a child has submitted personal information to us, please contact us so that we can investigate and, where appropriate, delete the information.

17. Your State Privacy Rights

Depending on where you live, you may have additional privacy rights under applicable state law.

These rights may include rights relating to access, correction, deletion, portability, or restrictions on certain uses of personal information.

These rights may be subject to exceptions under applicable law, including exceptions relating to healthcare information and information maintained under HIPAA.

To exercise an applicable state privacy right, contact us using the information below.

Illinois (BIPA)

3D foot scans captured by the ComfortPro App are clinical imaging used for orthotic device design and manufacture; they are not used for biometric identification or biometric verification within the meaning of the Illinois Biometric Information Privacy Act. Scans are retained per the schedule in Section 15 and are protected by security measures consistent with industry standards for protected health information.

18. New Jersey Privacy

ComfortFit Labs is located in New Jersey and seeks to comply with applicable New Jersey privacy and data-security requirements.

Nothing in this Privacy Policy is intended to limit rights provided to individuals under applicable New Jersey law.

Where information is subject to HIPAA, other federal healthcare privacy requirements, or an applicable Business Associate Agreement, those requirements may affect the applicability of state-law rights and obligations.

19. App Store Distribution and Billing

The ComfortPro App is distributed through the Apple App Store. Orthotic devices are physical goods manufactured to clinical specification and are billed outside of Apple’s in-app purchase system, as permitted under Apple App Store Review Guideline 3.1.3(e) for physical goods and services consumed outside of an app. Payment processing is handled by Stripe; ComfortFit Labs does not store full payment card numbers.

20. Changes to This Privacy Policy

ComfortFit Labs may periodically update this Privacy Policy to reflect changes in our services, technology, legal requirements, or privacy practices.

When we make material changes, we will update the “Last Updated” date at the beginning of this Privacy Policy and may provide additional notice where required by law.

The updated Privacy Policy will be posted on comfortfitlabs.com.

21. Contact Us

Questions regarding this Privacy Policy, privacy practices, or requests concerning information maintained by ComfortFit Labs may be directed to:

ComfortFit Labs
Chief Operating Officer: Michael Mohring
246 Columbus Ave
Roselle, NJ 07203
Telephone: 888-523-1600
Email: michael.mohring@comfortfitlabs.com

For matters involving PHI received from a healthcare provider, individuals may also contact the healthcare provider that submitted or maintains the applicable patient information.

22. Complaints

ComfortFit Labs takes privacy complaints seriously.

If you believe that your privacy rights have been violated or that information has been improperly used or disclosed, you may contact ComfortFit Labs using the contact information above.

You may also have the right to submit a complaint to the U.S. Department of Health and Human Services, Office for Civil Rights.

ComfortFit Labs will not retaliate against any individual for making a good-faith privacy complaint.

23. No Waiver of Legal Rights

Nothing in this Privacy Policy limits any rights or protections provided by HIPAA, the HITECH Act, applicable federal law, applicable state law, or an applicable Business Associate Agreement.

If any provision of this Privacy Policy is determined to be inconsistent with applicable law, the applicable law will control to the extent required.