RxFul HIPAA and BAA: what to confirm
RxFul handles protected health information because white-label patient checkout requires patient identity, prescriber details, and medication directions to reach a licensed 503A pharmacy. RxFul publicly positions itself as HIPAA-first with encrypted PHI storage, role-based access controls, and full BAA coverage. That is more specific than many vendors publish, but marketing claims are not a signed agreement. Request the executed business associate agreement and written safeguard documentation before transmitting PHI, and confirm how data is shared with fulfilling pharmacies and the 3PL agent. Clinics that batch prescriber-side orders often compare Fizy Health for a BAA signed at self-serve onboarding.
This page maps what RxFul publishes about HIPAA against what your compliance team should still request in writing.
Why does a BAA matter for white-label pharmacy infrastructure?
A business associate agreement is the HIPAA contract governing how a vendor that handles protected health information on a clinic's behalf must safeguard, use, and disclose that data. When patient details flow through RxFul to a 503A partner pharmacy and its 3PL agent, multiple parties touch PHI. RxFul publicly states full BAA coverage and encrypted PHI storage with role-based access, which signals HIPAA awareness, but your covered entity still needs the signed BAA, subcontractor chain clarity, and written safeguards before any patient record enters the platform.
What to confirm about RxFul and HIPAA
Each row is a HIPAA criterion, what RxFul publishes, and the document to request before sharing PHI.
Sourced from RxFul public website (rxful.com), reviewed June 2026. HIPAA terms should be confirmed in writing and reviewed by your own counsel.
Negotiate HIPAA terms during tier selection, or sign a BAA at self-serve onboarding?
RxFul
White-label patient checkout is the priority and you will review the BAA during onboarding.
- You are building a clinic-branded patient portal and will request the signed BAA before go-live.
- Your compliance team is comfortable reviewing vendor HIPAA terms during the tier-selection process.
- Patient-facing branded checkout matters more than prescriber-side batch carts.
Fizy Health
You want a BAA and audited PHI handling from day one on the prescriber side.
- Every clinic signs a BAA at onboarding before patient data enters the system.
- Patient-linked cart actions are audited per line with organization-scoped access.
- You want to evaluate HIPAA posture alongside pass-through pricing before any monthly platform tier.
What HIPAA-ready ordering looks like in practice.
A BAA is the contract; audited, patient-scoped access is what your team feels every refill day.
Every cart line tied to a patient
Patient-linked checkout means PHI stays scoped to the right record and organization.
An audit trail on every mutation
Cart additions, edits, and checkouts are audited per line so compliance reviews have a defensible record.
Validation before PHI-backed payment
Cart validation catches SIG and licensure issues before you pay, reducing rejected orders that scatter PHI over email.
What clinics ask about RxFul and HIPAA.
- Definition
Is RxFul HIPAA compliant?
RxFul publicly positions itself as HIPAA-first with encrypted PHI storage, role-based access controls, and full BAA coverage. Because ordering involves patient information, request the signed BAA and written safeguard documentation before transmitting PHI rather than relying on marketing copy alone.
- BAA
Does RxFul offer a business associate agreement?
RxFul publicly states full BAA coverage for clinics on the platform. Request the executed agreement before go-live and have your counsel review permitted uses, subcontractor flow, and breach notification terms.
- Storage
How does RxFul store patient data?
RxFul describes encrypted PHI storage with role-based access controls. Confirm in writing where data is hosted, encryption in transit and at rest, and retention and deletion policies.
- Partners
Do RxFul's pharmacy partners also receive PHI?
Yes. Licensed 503A partner pharmacies and the regulated 3PL agent must receive patient information to compound, authorize, and ship orders. Ask how PHI is transmitted and whether downstream business associate agreements are in place.
- Portal
Does the white-label patient portal change HIPAA obligations?
A clinic-branded patient portal still handles PHI when patients check out and receive tracking communications. Confirm which portal features touch PHI, how access is logged, and whether patient-facing messages are covered under the BAA.
- Alternative
How does Fizy Health handle HIPAA?
Fizy Health signs a BAA at onboarding, keeps patient records organization-scoped, audits patient-linked cart actions per line, and validates orders before payment on the prescriber-side workflow.
Sources reviewed June 2026
- RxFul public website (rxful.com), reviewed June 2026.
- HIPAA terms should be confirmed in writing with RxFul and reviewed by your own counsel.
- Fizy Health platform capabilities reflect the live product.
Get the BAA and see prescriber-side audit in one place.
Fizy Health signs a BAA at onboarding and audits patient-linked actions per line. Free to start.