Promise Pharmacy HIPAA and BAA: what to confirm
Promise Pharmacy handles protected health information because compounding and shipping patient-specific medications requires patient identity, prescriber details, and prescription data — which makes HIPAA compliance and a business associate agreement baseline requirements for clinic partners. Promise publishes a Privacy Policy & Notice of Privacy Practices (HIPAA) effective March 27, 2026, describing treatment, payment, and operations uses, patient rights, and security safeguards at a high level. It does not publish a BAA template on the public site, so request a signed BAA and technical safeguard documentation before transmitting PHI at scale. Clinics comparing audited, organization-scoped cart access often evaluate Fizy Health, which signs a BAA at onboarding.
Why a BAA matters when Promise compounds for your patients — and the HIPAA terms to verify in writing.
Why does a BAA matter when a pharmacy compounds for your clinic?
A business associate agreement is the HIPAA contract governing how a vendor that creates, receives, maintains, or transmits PHI on your behalf must safeguard and use that data. When your clinic submits patient orders through Promise's provider portal, Promise is performing a pharmacy function that involves PHI — compounding, billing, shipping coordination, and patient support — which generally makes it a business associate. Promise's published HIPAA notice describes permitted uses for treatment, payment, and health care operations, plus patient rights to access and amend records. The gap to close in diligence is a signed BAA, technical safeguard detail beyond the public summary, and clarity on staff access logging inside the portal.
What to confirm about Promise Pharmacy and HIPAA
Each row is a HIPAA criterion, what Promise publishes publicly, and the document to request before sharing PHI.
Sourced from Promise Pharmacy privacy policy and provider pages (promisepharmacy.com), reviewed June 2026. HIPAA terms should be confirmed in writing and reviewed by your counsel.
Negotiate HIPAA terms during onboarding, or start with a BAA at signup?
Promise Pharmacy
You will request and review HIPAA documentation with your account manager.
- You are prepared to obtain a signed BAA and safeguard documentation before PHI submission.
- Your compliance team reviews pharmacy BAAs routinely during partner onboarding.
- Promise's patient-support SMS and call model fits how you communicate refill status.
Fizy Health
You want a BAA signed at onboarding and PHI access scoped from day one.
- You want a clinic BAA executed before your first cart mutation.
- You want patient-linked cart actions audited per line with organization-scoped access.
- You want PHI controls in the ordering product, not only in a pharmacy BAA PDF.
What HIPAA-aware ordering looks like in practice.
A strong HIPAA posture shows up as scoped access, audited actions, and less PHI scattered across support channels.
Patient data scoped to the right team
Patient records and cart lines stay organization-scoped, so only authorized users in your clinic see PHI.
An audit trail on every order line
Patient-linked cart actions are audited per line — a defensible record for compliance review.
Fewer rejections that scatter PHI over email
Cart validation catches issues before payment, reducing back-and-forth that spreads patient details across inboxes.
What clinics ask about Promise Pharmacy and HIPAA.
- Definition
Is Promise Pharmacy HIPAA-compliant?
Promise Pharmacy publishes a HIPAA Notice of Privacy Practices describing how health information may be used and safeguarded for pharmacy operations. Confirm the current notice, obtain a signed BAA, and request technical safeguard documentation before transmitting PHI at scale.
- BAA
Does Promise Pharmacy provide a business associate agreement?
Promise does not publish a BAA template on its public site. Because compounding orders involve PHI, request a signed BAA during provider onboarding and have your counsel review it before your first patient orders.
- Why
Why does a compounding pharmacy need a BAA with my clinic?
A BAA is required when a vendor handles PHI on a covered entity's behalf. Promise receives patient and prescription data to compound and ship medications, which generally makes it a business associate under HIPAA.
- Safeguards
What HIPAA safeguards should I verify with Promise?
Ask for documentation of administrative, physical, and technical safeguards: role-based portal access, encryption in transit and at rest, audit logging, breach notification procedures, and subprocessors such as payment and SMS vendors.
- Patients
How does Promise handle patient-facing communications under HIPAA?
Promise offers patient support via phone, SMS, and email and can notify patients about shipments. Confirm authorization workflows, opt-out handling, and whether patient-facing channels meet your clinic's HIPAA policies.
- Alternative
How does Fizy Health handle HIPAA and BAAs?
Fizy Health signs a clinic BAA at onboarding, keeps patient records organization-scoped, and audits patient-linked cart actions per line. PHI access controls are built into the ordering platform rather than negotiated only in a pharmacy contract.
Sources reviewed June 2026
- Promise Pharmacy privacy policy and provider pages (promisepharmacy.com), reviewed June 2026.
- HIPAA terms and any BAA should be confirmed in writing with Promise Pharmacy and reviewed by your counsel.
- Fizy Health platform capabilities reflect the live product.
Start with a BAA at onboarding — not after a compliance surprise.
Fizy Health signs a clinic BAA before your first order and keeps patient access audited and scoped. Free to start.