Empower Pharmacy patient data handling

Empower Pharmacy patient data handling

Empower Pharmacy handles patient information as part of filling compounded prescriptions, and as a HIPAA Covered Entity it is legally obligated to safeguard that protected health information. Empower has published a Privacy Policy, Notice of Privacy Practices, and Terms and Conditions, and confirms all data is encrypted in transit using TLS 1.2 and at rest in HIPAA-compliant cloud infrastructure. Its Privacy Officer is reachable at privacy@empowerpharmacy.com. What clinic operators should still confirm is whether a BAA covers the LifeFile prescriber portal workflow specifically, how role-based access controls work in the portal, and what the retention and export policy is for patient and order data.

This page maps the PHI flow in Empower Pharmacy's LifeFile ordering workflow and lists the data-handling questions a clinic should confirm before relying on it for compliance.

Proudly Partnered With

How does patient data flow through an Empower Pharmacy order?

To place a compounded prescription through Empower Pharmacy's LifeFile portal, the prescriber enters patient identity, the medication, and the SIG — all of which is protected health information. That data moves from the clinic through the LifeFile portal to Empower's compounding facility, and patient address information flows to the shipping carrier when the order ships. Because Empower Pharmacy is a licensed pharmacy and HIPAA Covered Entity, it is obligated to safeguard PHI under the Privacy Rule and Security Rule. It confirms encryption in transit and at rest. Clinic operators should still confirm whether the BAA framework Empower uses for API integrations also governs the LifeFile prescriber portal relationship, and ask about role-based access controls, audit logging, and retention for their specific workflow.

Data-handling checklist

How to evaluate Empower Pharmacy patient data handling

Each row is a data-handling criterion, what Empower Pharmacy publicly confirms, and what to verify before sending PHI.

HIPAA Covered Entity status
What Empower Pharmacy publicly confirmsEmpower Pharmacy is a HIPAA Covered Entity. It publishes a Privacy Policy, Notice of Privacy Practices, and Terms and Conditions.
What to verifyRequest copies of the Notice of Privacy Practices and confirm they address the LifeFile prescriber portal workflow.
Encryption
What Empower Pharmacy publicly confirmsEmpower confirms all data is encrypted in transit using TLS 1.2 and at rest in HIPAA-compliant cloud infrastructure.
What to verifyConfirm encryption applies to LifeFile portal data, not only API traffic, and ask where patient data is hosted.
BAA coverage
What Empower Pharmacy publicly confirmsEmpower uses a standard BAA with API integration partners; customized agreements are available for large health systems and telehealth platforms.
What to verifyAsk whether a BAA is executed for LifeFile prescriber portal accounts and request the template before routing PHI.
Access controls
What Empower Pharmacy publicly confirmsEmpower maintains documented physical and technical infrastructure policies. Role-based access controls for the LifeFile portal are not detailed publicly.
What to verifyAsk who can access patient data in LifeFile, whether access is role-based, and how access is logged.
Retention and export
What Empower Pharmacy publicly confirmsEmpower does not publish how long patient data is retained in LifeFile or whether it can be exported or deleted on request.
What to verifyAsk about retention periods, whether data can be exported on cancellation, and how long records are held after exit.

Sourced from Empower Pharmacy public website, FAQs, and API documentation (empowerpharmacy.com), reviewed June 2026. PHI and privacy terms should be confirmed in writing with Empower Pharmacy and reviewed by your own counsel. Privacy Officer: privacy@empowerpharmacy.com.

Covered Entity HIPAA obligations, or scoped access built into the product?

Empower Pharmacy fits if

Empower Pharmacy

You will confirm BAA scope and access controls during onboarding.

  • You are comfortable confirming a BAA covers your LifeFile portal workflow before routing PHI.
  • Empower's Covered Entity status meets your HIPAA vendor standard with documented safeguards.
  • You will direct access control and retention questions to privacy@empowerpharmacy.com.
Consider Fizy Health if

Fizy Health

You want PHI access scoped and audited per line from the first order.

  • You want patient records organization-scoped so only authorized users in your clinic see PHI.
  • You want patient-linked cart actions audited per line from day one.
  • You want a BAA at onboarding rather than a separate confirmation.
FAQ

What clinics ask about Empower Pharmacy and patient data.

  • Definition

    How does Empower Pharmacy handle patient data?

    Empower Pharmacy is a HIPAA Covered Entity. It handles patient information because filling prescriptions requires patient identity, medication, and SIG. It publishes a Privacy Policy, Notice of Privacy Practices, and Terms and Conditions, and confirms encryption in transit (TLS 1.2) and at rest. Confirm BAA scope and access control details for your LifeFile workflow directly.

  • Flow

    Where does patient data go when I place an Empower Pharmacy order?

    Patient details are entered at the clinic through the LifeFile prescriber portal, processed by Empower's systems, used to compound the order at Empower's facility, and shared with the carrier for shipping. Each step is subject to HIPAA safeguards as Empower is a Covered Entity.

  • Access

    Who can see patient data in Empower Pharmacy's LifeFile portal?

    Empower does not publish specific role-based access control details for the LifeFile portal. Ask who can access patient records, whether access is restricted by role or organization, and whether access is logged.

  • BAA

    Does Empower Pharmacy provide a BAA for prescriber portal users?

    Empower uses a standard BAA with API integration partners and offers customized agreements for large health systems and telehealth platforms. Ask whether a BAA is executed for LifeFile prescriber portal accounts specifically before routing PHI.

  • Retention

    How long does Empower Pharmacy keep patient data?

    Empower does not publish its retention or deletion policy for LifeFile data. Ask how long patient and order data is retained, whether it can be exported on request, and what happens to records after cancellation.

  • Alternative

    How does Fizy Health handle patient data?

    Fizy Health keeps patient records organization-scoped so only authorized users see PHI, audits patient-linked cart actions per line, and signs a BAA at onboarding. Access controls are built into the product rather than confirmed in a side conversation.

Sources reviewed June 2026

  • Empower Pharmacy public website, FAQs, and API documentation (empowerpharmacy.com), reviewed June 2026.
  • Privacy and data terms should be confirmed in writing with Empower Pharmacy at privacy@empowerpharmacy.com and reviewed by your own counsel.
  • Fizy Health platform capabilities reflect the live product.
Evaluate with real numbers

Keep patient data scoped from the first order.

Fizy Health organization-scopes patient records, audits actions per line, and signs a BAA at onboarding. Free to start.