Promise Pharmacy patient data handling
Promise Pharmacy receives protected health information because 503A compounding is patient-specific: identity, prescription details, shipping address, and prescriber information flow from your clinic through Promise's provider portal into pharmacy operations, billing, and patient support channels. Promise publishes a HIPAA Notice of Privacy Practices describing treatment, payment, and operations uses, retention, and security safeguards. Public materials also describe patient notifications via phone, SMS, and email when partners configure shipment alerts. Confirm a signed BAA, portal access controls, and subprocessors such as payment and SMS vendors before high-volume PHI submission — and compare Fizy Health if you need organization-scoped cart audit across multiple compounders.
Where patient data goes in Promise's compounding workflow — and what to confirm about access, retention, and patient communications.
What patient data does a compounding pharmacy handle?
Patient-specific compounding requires enough PHI to prepare, label, ship, and support a prescription: demographics, medication and SIG, prescriber credentials, shipping destination, and often payment or billing details. Promise's privacy notice describes collecting information through portal submissions, onboarding forms, support requests, and patient communications, plus automatic technical data such as IP addresses. Data may be shared with payment processors (Authorize.net cited in terms), communication vendors, and service providers supporting hosting and operations. Your diligence checklist: inventory what your team enters in the portal, confirm role-based access for staff, understand retention periods, and align patient-facing SMS with your clinic's authorization workflow.
How to evaluate Promise Pharmacy patient data handling
Each row is a data-handling criterion, what Promise publishes, and what to confirm before sending PHI.
Sourced from Promise Pharmacy privacy policy, terms, FAQ, and provider pages (promisepharmacy.com), reviewed June 2026.
PHI in one compounder portal, or audited cart lines across partners?
Promise Pharmacy
You will confirm BAA and portal access during partner onboarding.
- All compounded orders flow through Promise and its patient-support model fits your clinic.
- You will review Promise's HIPAA notice, BAA, and subprocessor list with compliance before scale.
- Configurable patient shipment notifications reduce your team's status-call volume.
Fizy Health
You want PHI scoped and audited on every cart line across partners.
- You batch patient-linked orders across multiple 503A partners and need one audited cart.
- You want organization-scoped patient records with per-line HIPAA audit at onboarding.
- You want validation before payment to reduce PHI-heavy rejection threads over email.
What disciplined patient-data handling looks like.
Good data handling shows up as scoped access, audited cart mutations, and fewer PHI threads in shared inboxes.
Patient data scoped to the right team
Patient records and cart lines stay organization-scoped, so only authorized users in your clinic see PHI.
An audit trail on every order line
Patient-linked cart actions are audited per line — a defensible record across routed partners.
Fewer rejections that scatter PHI over email
Cart validation catches issues before payment, reducing back-and-forth that spreads patient details.
What clinics ask about Promise Pharmacy and patient data.
- Definition
How does Promise Pharmacy handle patient data?
Promise receives PHI to compound and ship patient-specific medications and support patients through phone, SMS, and email. Its published HIPAA notice describes permitted uses for treatment, payment, and operations — confirm a signed BAA and technical safeguards before scale.
- Flow
Where does patient data go when I place a Promise order?
Patient and prescription details flow from your clinic through the provider portal into Promise's pharmacy operations, billing systems, and — when configured — patient shipment notifications. Subprocessors such as payment and communication vendors may also process limited data.
- Access
Who can see patient data on Promise Pharmacy?
Public materials describe team portal access after verification but do not detail role-based restrictions. Ask who in your clinic and at Promise can view orders, whether access is logged, and how offboarding staff are removed.
- Patients
Does Promise contact patients directly?
Yes — Promise's FAQ describes a patient care team reachable by phone, SMS, and email, and partners can configure shipment notifications to patients. Confirm authorization and opt-out workflows align with your clinic policies.
- Retention
How long does Promise Pharmacy keep patient data?
Promise's privacy notice states retention for as long as needed to provide services and meet legal and operational obligations. Ask specific retention periods, export options, and deletion after account closure.
- Alternative
How does Fizy Health handle patient data?
Fizy Health keeps patient records organization-scoped, audits patient-linked cart actions per line, and signs a BAA at onboarding — designed for clinics batching orders across multiple LegitScript-certified 503A partners in one cart.
Sources reviewed June 2026
- Promise Pharmacy privacy policy, terms, FAQ, and provider pages (promisepharmacy.com), reviewed June 2026.
- Data-handling terms should be confirmed in writing with Promise Pharmacy and reviewed by your counsel.
- Fizy Health platform capabilities reflect the live product.
Keep patient data scoped from the first order.
Fizy Health organization-scopes patient records, audits actions per line, and signs a BAA at onboarding. Free to start.