PRIVACY POLICY

Privacy Policy & HIPAA Notice of Privacy Practices

Effective Date: July 14, 2026  |  Last Updated: July 14, 2026

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

1. Who We Are

outfitMD, LLC (“outfitMD,” “we,” “us,” or “our”) is a New York limited liability company with its corporate office at 9570 Transit Rd., Suite #150, East Amherst, NY 14051, USA, and an additional office at 88 South West 7th St., Unit 1812, Miami, FL 33130, USA.

outfitMD provides a technology and administrative services platform that enables wellness businesses (such as gyms, spas, and clinics) to offer physician-directed weight loss and wellness programs. Medical care is provided by independent, licensed physicians (“Program Physicians”) and licensed partner pharmacies — not by outfitMD itself. Program Physicians are licensed in all 50 U.S. states, and this Policy applies to patients regardless of the state in which they reside.

When outfitMD handles Protected Health Information (“PHI”) on behalf of Program Physicians, partner pharmacies, or its business clients, it does so as a business associate under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), pursuant to written business associate agreements, and in strict compliance with HIPAA and applicable state law.

2. Scope of This Policy

This Policy applies to:

  • Website visitors — anyone who browses outfitmd.com, submits a contact form, or books a demo;
  • Business clients and prospects — wellness businesses that use or evaluate the outfitMD platform;
  • Patients — individuals who receive care from Program Physicians through programs powered by the outfitMD platform, in any U.S. state.

3. Information We Collect

From website visitors and business clients

  • Contact information you provide (name, business name, email address, phone number);
  • Information submitted through demo bookings, contact forms, and support requests;
  • Usage data collected automatically through cookies and similar technologies (see Section 4).

From patients

  • Identification and contact information;
  • Health information submitted through secure, HIPAA-compliant intake forms (medical history, medications, lab results, treatment goals);
  • Payment and billing information;
  • Records generated during care (consultations, prescriptions, order and renewal history).

4. Cookies and Tracking Technologies

Our website uses cookies and similar technologies, including Google Tag Manager and analytics tools, to operate the site, understand how visitors use it, and improve our services.

  • We do not use advertising pixels or third-party trackers on pages where health information is collected.
  • We do not sell personal information collected through cookies.
  • You can control cookies through your browser settings and opt out of Google Analytics at tools.google.com/dlpage/gaoptout.

5. How We Use Information

  • To operate the platform and support treatment, payment, and healthcare operations of Program Physicians and partner pharmacies;
  • To respond to inquiries and provide customer and technical support;
  • To send service-related communications (appointment, order, and renewal notifications);
  • To send marketing communications to business clients and prospects, with the ability to opt out at any time (see Section 10);
  • To comply with legal obligations and enforce our agreements.

6. Use and Disclosure of Protected Health Information

PHI is used and disclosed only as permitted by HIPAA, including:

  • Treatment — sharing with Program Physicians, partner pharmacies, and other healthcare professionals involved in your care;
  • Payment — billing and payment processing;
  • Healthcare operations — quality assessment, compliance, and platform administration;
  • As required by law — including public health reporting and lawful requests by authorities.

Uses and disclosures not described in this Policy — including most uses for marketing, any sale of PHI, and disclosures of psychotherapy notes — will be made only with your prior written authorization, which you may revoke at any time.

7. Your Rights Regarding Your PHI

Under HIPAA, all patients, in every U.S. state, have the right to:

  • Access, inspect, and obtain a copy of your PHI;
  • Request an amendment (correction) of your PHI;
  • Receive an accounting of certain disclosures of your PHI;
  • Request restrictions on certain uses and disclosures;
  • Request confidential communications by alternative means or locations;
  • Receive a paper copy of this notice upon request;
  • File a complaint with us or with the U.S. Department of Health and Human Services, Office for Civil Rights (hhs.gov/ocr), without retaliation.

To exercise any of these rights, contact our Privacy Officer using the information in Section 13.

8. State Privacy Rights

Depending on your state of residence, you may have additional rights over personal information that is not covered by HIPAA — including rights of access, deletion, correction, and portability under laws such as the California Consumer Privacy Act (CCPA/CPRA), the Washington My Health My Data Act, and similar state laws. To submit a request, contact us using the information in Section 13. We do not sell your personal information.

9. Data Retention

We retain patient records for as long as required by applicable federal and state medical record retention laws. Other personal information is retained only as long as necessary for the purposes described in this Policy or as required by law, after which it is securely deleted or de-identified.

10. Marketing Communications and Opt-Out

You may opt out of marketing emails at any time by using the unsubscribe link in any message or by emailing [email protected]. If you have consented to receive text messages, reply STOP at any time to opt out. Service-related communications (such as order and renewal notifications) are not marketing and may still be sent.

11. Children’s Privacy

Our website and services are intended for adults 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us personal information, contact us and we will delete it.

12. Security and Breach Notification

We maintain administrative, technical, and physical safeguards designed to protect personal information and PHI from unauthorized access, use, or disclosure. In the event of a breach of unsecured PHI, affected individuals will be notified without unreasonable delay and no later than 60 days after discovery, as required by the HIPAA Breach Notification Rule and applicable state law.

13. Contact Us / Privacy Officer

Privacy Officer — outfitMD, LLC
9570 Transit Rd., Suite #150, East Amherst, NY 14051, USA
Phone: (833) 675-9001
Email: [email protected]
Hours: Monday–Friday, 9:00 AM–5:00 PM EST

14. Changes to This Policy

We reserve the right to update this Policy and to apply the revised terms to information we already hold. Material changes will be posted on this page with a new “Last Updated” date, and patients will be notified as required by HIPAA.

15. Governing Law

This Policy is governed by and construed in accordance with the laws of the State of New York, without giving effect to its conflicts of law rules, and by applicable federal law, including HIPAA.

Our mission is to unite wellness and medicine—giving forward-thinking wellness businesses a seamless, safe, and tech-powered path to expert clinical care.

Get in Touch

88 South West 7th St. Unit 1812, Miami, FL 33130, USA

© 2026 outfitMD. All rights reserved.