Promise Pharmacy patient data handling

Promise Pharmacy patient data handling

Promise Pharmacy receives protected health information because 503A compounding is patient-specific: identity, prescription details, shipping address, and prescriber information flow from your clinic through Promise's provider portal into pharmacy operations, billing, and patient support channels. Promise publishes a HIPAA Notice of Privacy Practices describing treatment, payment, and operations uses, retention, and security safeguards. Public materials also describe patient notifications via phone, SMS, and email when partners configure shipment alerts. Confirm a signed BAA, portal access controls, and subprocessors such as payment and SMS vendors before high-volume PHI submission — and compare Fizy Health if you need organization-scoped cart audit across multiple compounders.

Where patient data goes in Promise's compounding workflow — and what to confirm about access, retention, and patient communications.

Proudly Partnered With

What patient data does a compounding pharmacy handle?

Patient-specific compounding requires enough PHI to prepare, label, ship, and support a prescription: demographics, medication and SIG, prescriber credentials, shipping destination, and often payment or billing details. Promise's privacy notice describes collecting information through portal submissions, onboarding forms, support requests, and patient communications, plus automatic technical data such as IP addresses. Data may be shared with payment processors (Authorize.net cited in terms), communication vendors, and service providers supporting hosting and operations. Your diligence checklist: inventory what your team enters in the portal, confirm role-based access for staff, understand retention periods, and align patient-facing SMS with your clinic's authorization workflow.

Data-handling checklist

How to evaluate Promise Pharmacy patient data handling

Each row is a data-handling criterion, what Promise publishes, and what to confirm before sending PHI.

PHI collected for compounding
What is publicly knownPrivacy notice covers prescription-related and patient-support information submitted by clinics and providers through portal and communication channels.
What to verifyAsk for a data inventory: required fields per order, optional fields, and what Promise stores after shipment.
Portal access controls
What is publicly knownProvider portal supports team login after credential verification; public pages do not detail role-based PHI restrictions.
What to verifyConfirm staff roles, least-privilege access, and whether patient-order views are logged with user identity.
Subprocessors
What is publicly knownPrivacy notice lists payment processors, hosting, analytics, CRM, and communication vendors; terms cite Authorize.net for payments.
What to verifyRequest a subprocessor list and confirm BAAs or equivalent agreements cover vendors touching PHI.
Patient-facing channels
What is publicly knownFAQ describes patient care via phone, SMS, and email with configurable shipment notifications to patients.
What to verifyConfirm how your clinic authorizes patient contact, opt-out handling, and whether Promise or your staff owns the patient relationship on support tickets.
Retention and deletion
What is publicly knownPrivacy notice states information is retained as needed for services, legal obligations, disputes, and operational records; patient HIPAA rights include access and amendment requests.
What to verifyAsk retention periods for portal order history, export options if you leave, and deletion timelines after account closure.

Sourced from Promise Pharmacy privacy policy, terms, FAQ, and provider pages (promisepharmacy.com), reviewed June 2026.

PHI in one compounder portal, or audited cart lines across partners?

Promise Pharmacy fits if

Promise Pharmacy

You will confirm BAA and portal access during partner onboarding.

  • All compounded orders flow through Promise and its patient-support model fits your clinic.
  • You will review Promise's HIPAA notice, BAA, and subprocessor list with compliance before scale.
  • Configurable patient shipment notifications reduce your team's status-call volume.
Consider Fizy Health if

Fizy Health

You want PHI scoped and audited on every cart line across partners.

  • You batch patient-linked orders across multiple 503A partners and need one audited cart.
  • You want organization-scoped patient records with per-line HIPAA audit at onboarding.
  • You want validation before payment to reduce PHI-heavy rejection threads over email.
FAQ

What clinics ask about Promise Pharmacy and patient data.

  • Definition

    How does Promise Pharmacy handle patient data?

    Promise receives PHI to compound and ship patient-specific medications and support patients through phone, SMS, and email. Its published HIPAA notice describes permitted uses for treatment, payment, and operations — confirm a signed BAA and technical safeguards before scale.

  • Flow

    Where does patient data go when I place a Promise order?

    Patient and prescription details flow from your clinic through the provider portal into Promise's pharmacy operations, billing systems, and — when configured — patient shipment notifications. Subprocessors such as payment and communication vendors may also process limited data.

  • Access

    Who can see patient data on Promise Pharmacy?

    Public materials describe team portal access after verification but do not detail role-based restrictions. Ask who in your clinic and at Promise can view orders, whether access is logged, and how offboarding staff are removed.

  • Patients

    Does Promise contact patients directly?

    Yes — Promise's FAQ describes a patient care team reachable by phone, SMS, and email, and partners can configure shipment notifications to patients. Confirm authorization and opt-out workflows align with your clinic policies.

  • Retention

    How long does Promise Pharmacy keep patient data?

    Promise's privacy notice states retention for as long as needed to provide services and meet legal and operational obligations. Ask specific retention periods, export options, and deletion after account closure.

  • Alternative

    How does Fizy Health handle patient data?

    Fizy Health keeps patient records organization-scoped, audits patient-linked cart actions per line, and signs a BAA at onboarding — designed for clinics batching orders across multiple LegitScript-certified 503A partners in one cart.

Sources reviewed June 2026

  • Promise Pharmacy privacy policy, terms, FAQ, and provider pages (promisepharmacy.com), reviewed June 2026.
  • Data-handling terms should be confirmed in writing with Promise Pharmacy and reviewed by your counsel.
  • Fizy Health platform capabilities reflect the live product.
Evaluate with real numbers

Keep patient data scoped from the first order.

Fizy Health organization-scopes patient records, audits actions per line, and signs a BAA at onboarding. Free to start.