Olympia Pharmacy HIPAA and BAA: what to confirm
Olympia Pharmacy is the compounding pharmacy that receives and fills your patients' orders, which means protected health information flows directly from your clinic to Olympia — making Olympia a business associate under HIPAA. A signed business associate agreement governs how Olympia handles that PHI: how it is stored, accessed, and protected. Olympia positions itself as HIPAA-compliant in their public materials, but does not publish a BAA template or safeguard documentation on their website. The right move before sharing any patient data is to request a signed BAA and their safeguard documentation in writing, and this page shows exactly what to ask for.
This page explains why HIPAA applies when ordering through Olympia Pharmacy and what to verify about their BAA and data safeguards before you share PHI.
Why does HIPAA apply when ordering through Olympia Pharmacy?
A business associate agreement is the HIPAA contract required when a vendor handles protected health information on behalf of a covered entity. When a clinic places a compounded order, patient details — identity, prescriber, SIG, and diagnosis context — must reach Olympia so they can compound and ship the medication. This makes Olympia a business associate that holds and processes PHI on the clinic's behalf, which triggers the BAA requirement. Olympia publicly positions itself as HIPAA-compliant, but does not publish its BAA template or safeguard documentation. A clinic should obtain a signed BAA and review the administrative, physical, and technical safeguards before transmitting any PHI. Because Olympia is the compounder — not an intermediary routing to third parties — the HIPAA inquiry is concentrated at Olympia directly.
What to confirm about Olympia Pharmacy and HIPAA
Each row is a HIPAA criterion, what is publicly known about Olympia Pharmacy, and what to request before sharing PHI.
Sourced from Olympia Pharmacy public website (olympiapharmacy.com), reviewed June 2026. HIPAA terms should be confirmed in writing with Olympia Pharmacy and reviewed by your own counsel.
Negotiate HIPAA terms with the compounder, or start with a BAA at onboarding?
Olympia Pharmacy
You will request and review HIPAA documentation during the onboarding process.
- You are prepared to request a BAA and safeguard documentation before transmitting any PHI.
- Your compliance team is comfortable reviewing BAA terms directly with the compounder.
- Email-based coordination of HIPAA compliance questions fits your workflow.
Fizy Health
You want a BAA signed at onboarding and PHI access scoped from the first order.
- You want a clinic BAA executed at onboarding before you place an order.
- You want patient-linked cart actions audited per line with organization-scoped access.
- You want PHI access controls built into the product, not negotiated separately.
What HIPAA-aware ordering looks like in practice.
A strong HIPAA posture shows up as scoped access, audited actions, and a clear trail — not just a clause in a contract.
Patient data scoped to the right team
Patient records and cart lines stay organization-scoped, so only authorized users in your clinic see PHI.
An audit trail on every order
Per-line order status and history give compliance a defensible record of fulfillment across partners.
Fewer paid orders rejected by the pharmacy
Cart validation catches issues before payment, reducing the back-and-forth that scatters PHI across email.
What clinics ask about Olympia Pharmacy and HIPAA.
- Definition
Is Olympia Pharmacy HIPAA-compliant?
Olympia Pharmacy publicly positions itself as HIPAA-compliant, but does not publish the specifics of its safeguards or a standard BAA on its site. Because they receive patient PHI as the compounder, request a signed business associate agreement and safeguard documentation in writing before transmitting patient data.
- BAA
Does Olympia Pharmacy provide a business associate agreement?
Olympia does not publish a BAA template publicly. Because they receive and process patient information as the compounding pharmacy, request a signed BAA before sharing any PHI and have your counsel review the terms.
- Why
Why does a compounder need a BAA?
A BAA is the HIPAA contract required when a vendor processes PHI on behalf of a covered entity. When you place a patient order through Olympia's DrScript portal, Olympia receives patient identity, prescriber, and medication details — making them a business associate that must sign a BAA.
- Safeguards
What HIPAA safeguards should I verify with Olympia Pharmacy?
Ask for documentation of administrative safeguards (access policies, training), physical safeguards (facility controls), and technical safeguards (encryption in transit and at rest, role-based access, audit logging). Also confirm their breach notification policy and timeline.
- Access
Who within Olympia can see patient data?
Olympia does not publish access control specifics. Ask who within their organization can access patient data submitted through DrScript, whether access is role-based and organization-scoped, and how access events are logged.
- Alternative
How does Fizy Health handle HIPAA and BAAs?
Fizy Health signs a clinic BAA at onboarding, keeps patient records organization-scoped, and audits patient-linked cart actions per line. PHI access controls are built into the product rather than negotiated separately after signing.
Sources reviewed June 2026
- Olympia Pharmacy public website (olympiapharmacy.com), reviewed June 2026.
- HIPAA Business Associate Agreement requirements from HHS.gov.
- Any BAA and HIPAA terms should be confirmed in writing with Olympia Pharmacy and reviewed by your own counsel.
- Fizy Health platform capabilities reflect the live product.
Start with a BAA at onboarding — not after a contract fight.
Fizy Health signs a clinic BAA before your first order and keeps patient access audited and scoped. Free to start.