Privacy Policy
Last updated: February 2026
Comfort Care Medical (“Comfort Care,” “we,” “us,” or “our”) is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you visit our website, submit forms, or interact with our services. As a durable medical equipment (DME) supplier serving patients since 1984, we take your privacy seriously.
Information We Collect
We may collect the following types of information when you interact with services:
- Personal Information: Name, email address, phone number, and mailing address provided through contact forms or referral forms.
- Health-Related Information: Diagnosis details, prescription information, insurance policy numbers, and other health data necessary to verify insurance coverage and provide compression garment services.
- Insurance Information: Insurance carrier and related details needed for benefits verification and billing.
SMS Communications and Mobile Data
If you provide your mobile phone number and consent to receive SMS text messages from Comfort Care Medical, this section explains how we collect, use, protect, and share your mobile information and SMS communications.
2.1 Information We Collect
When you opt in to SMS communications, we collect and retain:
- Your mobile phone number
- Date and time of opt-in consent
- Consent method (DocuSign electronic form)
- Opt-out requests and timestamps
- Message delivery status and logs
- Responses to STOP, HELP, or other keywords
2.2 How We Use Your Mobile Number
We use your mobile number exclusively for transactional healthcare communications related to your orders and care:
- Confirming order placement and providing status updates
- Sending appointment reminders and scheduling notifications
- Notifying you about pending consent forms (DocuSign)
- Updating you on prescription status
- Sending payment and billing reminders
- Coordinating deliveries, exchanges, and product remakes
We do not use your mobile number for marketing, promotional messages, or any purpose unrelated to your healthcare orders.
2.3 Data Sharing and Third Parties
Your mobile phone number is shared only with trusted service providers who have signed Business Associate Agreements (BAAs) to comply with HIPAA requirements: Our SMS messaging platform and DocuSign (our electronic consent form platform). We will never sell your mobile number to third parties, telemarketers, or data brokers. Your number is never used for marketing lists or shared outside of the necessary service providers for your care.
2.4 PHI Protection in SMS
We maintain a strict policy: no protected health information (PHI) is included in SMS messages. Our text messages contain only general reminders, order numbers, and instructions — never specific diagnoses, medical conditions, treatment details, or other sensitive health data. Examples of our information-light messages:
“Hello from Comfort Care Medical! Your order no. [ORDER NUMBER] has been successfully placed. Questions? Call us at [PHONE] or email customerservice@comfortcaremd.com”
“Hello. We sent your Order Consent Form via DocuSign to sign electronically. Once completed, we can proceed with your order. If you’ve requested a mailed copy, please return it as soon as possible. Questions? Call [PHONE] or email customerservice@comfortcaremd.com. Thank you!”
“Hi [FIRST NAME], this is a reminder about your upcoming appointment for case [CASE ID]. Please call us if you need to reschedule. Reply STOP to unsubscribe.”
“We’ve sent a prescription to your physician for their signature. To expedite the process, we encourage you contact your physician and ask them to return it to us as soon as possible. For any questions, contact us at [PHONE] or email customerservice@comfortcaremd.com”
Notice that these messages contain no medical details — only order/case identifiers and administrative instructions. This approach protects your privacy while still providing helpful transactional updates.
2.5 SMS Security Measures
We implement multiple security measures to protect your SMS communications:
- Encrypted transmission: All SMS messages are transmitted over secure, encrypted channels
- Access controls: Only authorized Comfort Care personnel can initiate SMS messages
- Consent verification: Our system automatically checks consent status before sending any message
- Audit logging: All SMS activity is logged for compliance monitoring and security review
- No PHI policy: Technical safeguards prevent inclusion of protected health information in templates
2.6 Consent Records and Documentation
We retain comprehensive documentation of SMS consent for a minimum of 7 years, as required by healthcare and telecommunications regulations. This includes DocuSign audit trails showing when and how you signed electronic consent forms, scanned copies of paper intake forms with your signature, and call logs documenting verbal consent obtained during phone orders. These records are stored securely and accessed only by authorized compliance and patient support staff.
2.7 Your Rights and Choices
You have complete control over SMS communications. You may opt out at any time using any of the following methods, per the 2025 TCPA update requiring “any reasonable means” acceptance:
- Reply STOP to any SMS message
- Call us at 888-358-1580
- Email customerservice@comfortcaremd.com
- Mail a written opt-out request to our office
- Use informal language like “no more texts” or “leave me alone” — we honor all expressions of your desire to stop receiving messages
All opt-out requests are processed within 10 business days.
2.8 HIPAA Compliance Statement
Comfort Care Medical is a HIPAA-covered entity. While SMS is generally not considered a secure communication method under HIPAA due to inherent risks (messages may be visible on locked screens, readable by anyone with physical access to your phone, or intercepted by mobile carriers), we mitigate these risks through strict safeguards:
- No PHI transmission: We never include diagnoses, conditions, medications, or other protected health information in SMS
- Business Associate Agreements: SMS provider and DocuSign (consent platform) both operate under signed BAAs
- Encryption in transit: Messages are encrypted during transmission
- Secure storage: SMS logs and consent records are stored in HIPAA-compliant systems
- Consent verification: Automated checks ensure we only message patients who have explicitly opted in
- Audit logging: All SMS activity is tracked for compliance monitoring
By consenting to receive SMS messages, you acknowledge these inherent risks and agree that the convenience and timeliness of SMS communications outweigh the potential privacy concerns for non-PHI transactional messages. If you prefer more secure communication methods, please opt out of SMS and we will contact you via phone or secure patient portal instead.
2.9 State-Specific Privacy Rights
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights: the right to know what mobile data we have collected about you, the right to request deletion of your mobile number and SMS history (subject to legal recordkeeping requirements), and the right to opt out of any sale of personal information (though we never sell your data). To exercise these rights, contact us using the information at the end of this policy.
2.10 Children’s Privacy
Our SMS program is intended for patients age 18 and older. If a minor (under age 18) requires SMS notifications for their care, we require parental or guardian consent. The parent or guardian must provide their own mobile number or explicitly authorize use of the minor’s number on the consent form. We do not knowingly collect mobile numbers from minors without parental consent.
2.11 International Considerations
Our SMS program is designed for patients in the United States with U.S.-based mobile phone numbers. International texting may incur significant carrier charges and is not supported by our system. If you are located outside the United States or use an international phone number, please do not opt in to SMS communications.
2.12 Policy Updates
We may update this SMS section of our Privacy Policy periodically to reflect changes in regulations, technology, or our practices. Material changes will be communicated to active SMS participants via text message and email, and the “Last updated” date at the top of this page will be revised. Your continued participation in the SMS program after such changes constitutes acceptance of the updated policy.
2.13 Contact for Privacy Questions
If you have questions about how we handle your mobile data, SMS communications, or privacy practices, please contact our compliance officer at customerservice@comfortcaremd.com or call 888-358-1580. We are committed to addressing your privacy concerns promptly and transparently.
How We Use Your Information
We use the information we collect for the following purposes:
- Verifying your insurance coverage and benefits for compression garments and related DME supplies.
- Coordinating patient care, including scheduling fittings, processing orders, and managing deliveries.
- Communicating with you about your orders, appointments, and account status.
- Processing referrals from healthcare providers and therapists.
- Improving our website, services, and patient experience.
- Complying with legal and regulatory requirements.
HIPAA Compliance
Comfort Care Medical is a HIPAA-covered entity. We comply with the Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations, including the Privacy Rule and Security Rule. We maintain a separate Notice of Privacy Practices that describes in detail how your protected health information (PHI) may be used and disclosed, and your rights regarding that information. You may request a copy of our Notice of Privacy Practices at any time by contacting us.
How We Protect Your Data
We implement appropriate technical and organizational measures to protect your personal and health information. These safeguards include encryption of data in transit and at rest, role-based access controls limiting information access to authorized personnel, regular security assessments, and employee training on privacy and security practices. While no method of transmission or storage is 100% secure, we are committed to protecting your information using industry-standard practices.
Third-Party Sharing
We do not sell your personal information. We may share your information only in the following limited circumstances:
- Insurance Providers: We share information with your insurance company as necessary to verify benefits, obtain prior authorizations, and process claims for your compression garments.
- Healthcare Providers: We may share information with your referring physician or therapist to coordinate your care.
- Legal Requirements: We may disclose information as required by law, regulation, court order, or other legal process.
- Service Providers: We may use trusted third-party vendors who assist in operating our website and services, subject to confidentiality agreements.
Your Rights
You have the right to access, review, and request correction of your personal information that we hold. You may also request deletion of your personal information, subject to certain legal and regulatory exceptions. For health-related information protected under HIPAA, additional rights may apply, including the right to request restrictions on certain uses and disclosures and the right to receive an accounting of disclosures. To exercise any of these rights, please contact us using the information provided below.
Cookies and Analytics
Our website uses cookies and similar technologies to collect basic site analytics, such as page views, visitor counts, and traffic sources. This information helps us understand how visitors use our site so we can improve your experience. We do not use cookies to collect personal health information. You can manage your cookie preferences through your browser settings. Disabling cookies may affect some website functionality.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights regarding your personal information, please contact us: