Effective Date: July 14, 2026 | Last Updated: July 29, 2026
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
outfitMD, LLC (“outfitMD,” “we,” “us,” or “our”) is a New York limited liability company with its corporate office at 9570 Transit Rd., Suite #150, East Amherst, NY 14051, USA, and an additional office at 88 South West 7th St., Unit 1812, Miami, FL 33130, USA.
outfitMD provides a technology and administrative services platform that enables wellness businesses (such as gyms, spas, and clinics) to offer physician-directed weight loss and wellness programs. Medical care is provided by independent, licensed physicians (“Program Physicians”) and licensed partner pharmacies — not by outfitMD itself. Program Physicians are licensed in all 50 U.S. states, and this Policy applies to patients regardless of the state in which they reside.
When outfitMD handles Protected Health Information (“PHI”) on behalf of Program Physicians, partner pharmacies, or its business clients, it does so as a business associate under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), pursuant to written business associate agreements, and in strict compliance with HIPAA and applicable state law.
This Policy applies to:
Our website uses cookies and similar technologies, including Google Tag Manager and analytics tools, to operate the site, understand how visitors use it, and improve our services.
PHI is used and disclosed only as permitted by HIPAA, including:
Uses and disclosures not described in this Policy — including most uses for marketing, any sale of PHI, and disclosures of psychotherapy notes — will be made only with your prior written authorization, which you may revoke at any time.
Under HIPAA, all patients, in every U.S. state, have the right to:
To exercise any of these rights, contact our Privacy Officer using the information in Section 14.
Depending on your state of residence, you may have additional rights over personal information that is not covered by HIPAA — including rights of access, deletion, correction, and portability under laws such as the California Consumer Privacy Act (CCPA/CPRA), the Washington My Health My Data Act, and similar state laws. To submit a request, contact us using the information in Section 14. We do not sell your personal information.
We retain patient records for as long as required by applicable federal and state medical record retention laws. Other personal information is retained only as long as necessary for the purposes described in this Policy or as required by law, after which it is securely deleted or de-identified.
You may opt out of marketing emails at any time by using the unsubscribe link in any message or by emailing [email protected]. Text message consent and opt-out are described in Section 11. Service-related communications (such as order and renewal notifications) are not marketing and may still be sent.
By providing your mobile phone number and opting in — through a form on our website, a patient intake or enrollment form, a written or verbal agreement, or by texting us first — you consent to receive text messages from outfitMD. Depending on the opt-in you complete, these messages may include:
Consent to receive marketing text messages is not a condition of purchasing any product or service. Text messaging consent is collected separately from any other consent and is never assumed, pre-checked, or transferred from another program.
Message frequency may vary. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages.
You can opt out at any time by replying STOP to any message from us. You will receive a single confirmation message and will not receive further texts from that program. Reply HELP for assistance, or contact us at [email protected] or (833) 675-9001.
We do not share or sell your mobile information or SMS opt-in data — including your mobile phone number and consent status — with third parties or affiliates for marketing or promotional purposes. This information is shared only with subprocessors that help us deliver the service (for example, our SMS platform provider and our messaging carriers), and, where applicable, with Program Physicians and partner pharmacies for treatment, payment, and healthcare operations as described in Section 6. No mobile opt-in data is disclosed to any other party for its own marketing use.
Standard text messaging is not an encrypted or fully secure channel. We limit the content of text messages so that they do not disclose diagnoses, medication names, or other sensitive health information, and we direct you to a secure channel when such information must be exchanged.
Our website and services are intended for adults 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us personal information, contact us and we will delete it.
We maintain administrative, technical, and physical safeguards designed to protect personal information and PHI from unauthorized access, use, or disclosure. In the event of a breach of unsecured PHI, affected individuals will be notified without unreasonable delay and no later than 60 days after discovery, as required by the HIPAA Breach Notification Rule and applicable state law.
We reserve the right to update this Policy and to apply the revised terms to information we already hold. Material changes will be posted on this page with a new “Last Updated” date, and patients will be notified as required by HIPAA.
This Policy is governed by and construed in accordance with the laws of the State of New York, without giving effect to its conflicts of law rules, and by applicable federal law, including HIPAA.