Olympia Pharmacy patient data handling
When you place an order through Olympia's DrScript prescriber portal, patient information — identity, prescriber details, and medication SIG — flows directly from your clinic to Olympia Pharmacy, who compounds and ships the order. Unlike platforms that route orders to third-party pharmacies, Olympia is the single endpoint for your patient PHI. Olympia positions itself as HIPAA-compliant but does not publish the specifics of how it stores, transmits, and restricts access to patient data. This page maps the PHI flow in Olympia's model and lists the data-handling questions to verify before sharing patient information.
This page explains where patient data goes in the Olympia Pharmacy ordering flow and what to confirm about access, encryption, and safeguards.
What patient data does Olympia Pharmacy handle, and how?
To compound and ship a patient-specific medication, Olympia must receive the patient identity tied to the medication, the prescribing provider, the directions for use, and any other clinical details required for compounding — all of which is protected health information. That data is entered at the clinic through the DrScript prescriber portal and transmitted to Olympia, who processes it as the compounder and pharmacy. The PHI flow in Olympia's model is: clinic enters order in DrScript → Olympia receives and stores the patient and prescription data → Olympia compounds and ships the medication. Because Olympia is the pharmacy rather than a routing intermediary, there is no third-party hop; the data goes directly to Olympia. This concentrates the PHI handling at Olympia, making their HIPAA safeguards and BAA the primary compliance concern.
How to evaluate Olympia Pharmacy patient data handling
Each row is a data-handling criterion, what is publicly known about Olympia Pharmacy, and what to confirm before transmitting patient PHI.
Sourced from Olympia Pharmacy public website (olympiapharmacy.com), reviewed June 2026. Confirm data-handling terms in writing with Olympia and review with your own counsel.
Negotiate data terms per compounder, or start with scoped access built in?
Olympia Pharmacy
You will request and review data-handling documentation during onboarding.
- You are prepared to request a BAA, encryption details, and access control documentation before sharing PHI.
- Your compliance team reviews vendor data terms with each compounder you use.
- A direct relationship with a single compounder simplifies your PHI flow and audit trail.
Fizy Health
You want PHI access scoped and audited from the first order.
- You want patient records organization-scoped so only authorized users see PHI.
- You want patient-linked cart actions audited per line.
- You want a BAA at onboarding rather than a separate compliance negotiation.
What disciplined patient-data handling looks like.
Good data handling shows up as scoped access, audited actions, and less PHI scattered across email threads.
Patient data scoped to the right team
Patient records and cart lines stay organization-scoped, so only authorized users in your clinic see PHI.
An audit trail on every order
Per-line order status and history give a defensible record of what happened to each patient's order.
Fewer rejections that scatter PHI over email
Cart validation catches issues before payment, reducing the back-and-forth that spreads patient details across inboxes.
What clinics ask about Olympia Pharmacy and patient data.
- Definition
How does Olympia Pharmacy handle patient data?
Patient information flows directly from your clinic through Olympia's DrScript portal to Olympia Pharmacy, which compounds and ships the medication. Olympia is the compounder and the single recipient of patient PHI in their model. Confirm their HIPAA safeguards and obtain a signed BAA before transmitting patient data.
- Flow
Where does patient data go when I place an Olympia Pharmacy order?
Patient details are entered at the clinic through the DrScript prescriber portal and transmitted directly to Olympia Pharmacy. Because Olympia is the pharmacy rather than a routing intermediary, the PHI goes to Olympia — not to third-party pharmacies.
- Access
Who can see patient data on Olympia Pharmacy?
Olympia does not publish access control specifics for DrScript. Ask who within Olympia and your clinic can access patient data, whether access is role-based and logged, and how the BAA governs internal access.
- BAA
Does Olympia Pharmacy provide a BAA?
Olympia does not publish a BAA template. Because they receive and process PHI as the compounding pharmacy, request a signed BAA before placing any patient-specific orders.
- Retention
How long does Olympia Pharmacy keep patient data?
Olympia does not publish retention or deletion policies publicly. Ask how long patient data is retained, whether it can be deleted or exported on request, and what happens to your records if you leave.
- Alternative
How does Fizy Health handle patient data?
Fizy Health keeps patient records organization-scoped so only authorized users see PHI, audits patient-linked cart actions per line, and signs a BAA at onboarding. Access controls are built into the product rather than negotiated separately.
Sources reviewed June 2026
- Olympia Pharmacy public website (olympiapharmacy.com), reviewed June 2026.
- HIPAA Business Associate Agreement requirements from HHS.gov.
- Data-handling and privacy terms should be confirmed in writing with Olympia Pharmacy and reviewed by your own counsel.
- Fizy Health platform capabilities reflect the live product.
Keep patient data scoped from the first order.
Fizy Health organization-scopes patient records, audits actions per line, and signs a BAA at onboarding. Free to start.