Olympia Pharmacy patient data handling

Olympia Pharmacy patient data handling

When you place an order through Olympia's DrScript prescriber portal, patient information — identity, prescriber details, and medication SIG — flows directly from your clinic to Olympia Pharmacy, who compounds and ships the order. Unlike platforms that route orders to third-party pharmacies, Olympia is the single endpoint for your patient PHI. Olympia positions itself as HIPAA-compliant but does not publish the specifics of how it stores, transmits, and restricts access to patient data. This page maps the PHI flow in Olympia's model and lists the data-handling questions to verify before sharing patient information.

This page explains where patient data goes in the Olympia Pharmacy ordering flow and what to confirm about access, encryption, and safeguards.

Proudly Partnered With

What patient data does Olympia Pharmacy handle, and how?

To compound and ship a patient-specific medication, Olympia must receive the patient identity tied to the medication, the prescribing provider, the directions for use, and any other clinical details required for compounding — all of which is protected health information. That data is entered at the clinic through the DrScript prescriber portal and transmitted to Olympia, who processes it as the compounder and pharmacy. The PHI flow in Olympia's model is: clinic enters order in DrScript → Olympia receives and stores the patient and prescription data → Olympia compounds and ships the medication. Because Olympia is the pharmacy rather than a routing intermediary, there is no third-party hop; the data goes directly to Olympia. This concentrates the PHI handling at Olympia, making their HIPAA safeguards and BAA the primary compliance concern.

Data-handling checklist

How to evaluate Olympia Pharmacy patient data handling

Each row is a data-handling criterion, what is publicly known about Olympia Pharmacy, and what to confirm before transmitting patient PHI.

What PHI is collected
What is publicly knownOrdering requires patient identity, prescribing provider, and medication SIG at minimum. Olympia does not publish a full data inventory for their DrScript portal.
What to verifyAsk what patient fields are required to place an order through DrScript and how long each field is stored.
Access controls
What is publicly knownOlympia does not publish whether access to patient data within DrScript is restricted by role or organization.
What to verifyAsk who within Olympia and within your clinic can access patient data, whether access is role-based, and how it is logged.
Encryption
What is publicly knownOlympia does not publish encryption specifications for patient data in transit or at rest.
What to verifyConfirm encryption standards in transit (TLS) and at rest, and ask where patient data is hosted.
Retention and deletion
What is publicly knownOlympia does not publish how long patient data is retained or whether it can be deleted or exported on request.
What to verifyAsk about retention periods, deletion policy on account exit, and whether you can export patient records.
Breach notification
What is publicly knownHIPAA requires business associates to notify covered entities of breaches. Olympia does not publish a breach notification policy.
What to verifyConfirm their breach notification timeline and process and ensure it is documented in your BAA.

Sourced from Olympia Pharmacy public website (olympiapharmacy.com), reviewed June 2026. Confirm data-handling terms in writing with Olympia and review with your own counsel.

Negotiate data terms per compounder, or start with scoped access built in?

Olympia Pharmacy fits if

Olympia Pharmacy

You will request and review data-handling documentation during onboarding.

  • You are prepared to request a BAA, encryption details, and access control documentation before sharing PHI.
  • Your compliance team reviews vendor data terms with each compounder you use.
  • A direct relationship with a single compounder simplifies your PHI flow and audit trail.
Consider Fizy Health if

Fizy Health

You want PHI access scoped and audited from the first order.

  • You want patient records organization-scoped so only authorized users see PHI.
  • You want patient-linked cart actions audited per line.
  • You want a BAA at onboarding rather than a separate compliance negotiation.
FAQ

What clinics ask about Olympia Pharmacy and patient data.

  • Definition

    How does Olympia Pharmacy handle patient data?

    Patient information flows directly from your clinic through Olympia's DrScript portal to Olympia Pharmacy, which compounds and ships the medication. Olympia is the compounder and the single recipient of patient PHI in their model. Confirm their HIPAA safeguards and obtain a signed BAA before transmitting patient data.

  • Flow

    Where does patient data go when I place an Olympia Pharmacy order?

    Patient details are entered at the clinic through the DrScript prescriber portal and transmitted directly to Olympia Pharmacy. Because Olympia is the pharmacy rather than a routing intermediary, the PHI goes to Olympia — not to third-party pharmacies.

  • Access

    Who can see patient data on Olympia Pharmacy?

    Olympia does not publish access control specifics for DrScript. Ask who within Olympia and your clinic can access patient data, whether access is role-based and logged, and how the BAA governs internal access.

  • BAA

    Does Olympia Pharmacy provide a BAA?

    Olympia does not publish a BAA template. Because they receive and process PHI as the compounding pharmacy, request a signed BAA before placing any patient-specific orders.

  • Retention

    How long does Olympia Pharmacy keep patient data?

    Olympia does not publish retention or deletion policies publicly. Ask how long patient data is retained, whether it can be deleted or exported on request, and what happens to your records if you leave.

  • Alternative

    How does Fizy Health handle patient data?

    Fizy Health keeps patient records organization-scoped so only authorized users see PHI, audits patient-linked cart actions per line, and signs a BAA at onboarding. Access controls are built into the product rather than negotiated separately.

Sources reviewed June 2026

  • Olympia Pharmacy public website (olympiapharmacy.com), reviewed June 2026.
  • HIPAA Business Associate Agreement requirements from HHS.gov.
  • Data-handling and privacy terms should be confirmed in writing with Olympia Pharmacy and reviewed by your own counsel.
  • Fizy Health platform capabilities reflect the live product.
Evaluate with real numbers

Keep patient data scoped from the first order.

Fizy Health organization-scopes patient records, audits actions per line, and signs a BAA at onboarding. Free to start.