RxFul user roles and permissions

RxFul user roles and permissions

RxFul user roles and permissions separate at least three account types: clinic users registered at /clinic-login with a clinic role in the platform's user_roles system, affiliate partners at /affiliate-login with an affiliate role, and admin users who sign in at /admin-login for internal administration. RxFul advertises HIPAA-compliant storage with role-based access controls and BAA coverage, but does not publish a detailed prescriber-versus-staff permission matrix for the clinic dashboard. Multi-person clinics should confirm who can place orders, manage users, and access patient data during onboarding.

This page frames the role distinctions RxFul's public materials support, the permission questions to ask, and how Fizy Health implements role-based prescriber access.

Compare Fizy Health vs RxFul

Proudly Partnered With

How roles work

RxFul separates account types — confirm clinic permissions inside.

The clearest public role boundary is between clinic, affiliate, and admin login paths. Within the clinic dashboard, separation of duties between prescribers and operations staff is implied by the onboarding application's prescriber and attestation steps but not documented as a granular permission matrix.

What you need first

  • Clinic role for dashboard accessOnly accounts registered at /clinic-login with the clinic role can access /clinic-dashboard. Affiliate accounts are rejected.
  • Prescriber attestation boundaryPrescribers complete credential verification and a signed attestation in onboarding. Confirm whether only attested prescribers can sign orders.
  • Admin approval as a gateUntil admin approval completes, clinic-role users may have dashboard access without full ordering permissions.

How access works

  1. 01
    Register the right account typeClinic staff use /clinic-login. Affiliate partners use /affiliate-login. These roles do not interchange.
  2. 02
    Complete prescriber verificationAdd each prescriber in the onboarding application with NPI verification and attestation.
  3. 03
    Confirm the permission matrixAsk RxFul during onboarding which actions require a prescriber versus clinic staff, and who can invite users.

Common access issues

  • Shared clinic logins

    Shared credentials break the audit trail RxFul's HIPAA framing implies. Each person should have an individual account with a defined role.

  • Unclear order submission rights

    If staff and prescribers have the same submit permissions, separation of duties is weak. Document the matrix in writing.

Evaluating RxFul roles — or comparing role-based access?

RxFul fits if

RxFul

You will confirm clinic permissions during white-label onboarding.

  • You need clinic-branded patient portal infrastructure and will verify role boundaries during Schedule a Demo.
  • Built-in prescriber attestation and NPI verification in onboarding match your compliance model.
  • Your clinic is small enough that a single clinic-role dashboard suffices today.
Consider Fizy Health if

Fizy Health

You want explicit admin, prescriber, and staff roles out of the box.

  • You want admins, prescribers, and staff provisioned by clearly defined roles from day one.
  • You want NPI and DEA validated by role so only verified prescribers can sign off.
  • You want individual accounts and per-line HIPAA audit across every clinic you manage.
FAQ

What clinics ask about RxFul roles.

  • Definition

    What user roles does RxFul have?

    RxFul publicly supports at least clinic, affiliate, and admin account types with separate login paths at /clinic-login, /affiliate-login, and /admin-login. Clinic dashboard access requires the clinic role.

  • Clinic

    What can a clinic-role user do on RxFul?

    Clinic-role users access /clinic-dashboard for onboarding, orders, inventory, shipments, and education. Full ordering permissions depend on admin approval of the onboarding application and SaaS tier.

  • Prescriber

    How are prescriber permissions handled?

    Prescribers are verified in the onboarding application with NPI, license, and attestation. RxFul does not publish a detailed prescriber-versus-staff permission matrix on its public site.

  • Affiliate

    Can an affiliate account use the clinic dashboard?

    No. RxFul rejects affiliate-role accounts from the clinic dashboard with a not-registered-as-a-clinic error. Affiliates use /affiliate-login and /affiliate-dashboard.

  • Compliance

    Does RxFul support role-based access controls?

    RxFul advertises HIPAA-compliant encrypted PHI storage with role-based access controls and BAA coverage. Confirm the specific permission model for your clinic during onboarding.

  • Alternative

    How does Fizy Health handle roles?

    Fizy Health provisions admins, prescribers, and staff with explicitly defined roles, validates NPI and DEA by role at onboarding, and audits patient-linked cart actions per line with organization-scoped access.

Sources reviewed June 2026

  • RxFul public website and clinic login flows (rxful.com), reviewed June 2026.
  • Fizy Health platform capabilities reflect the live product.
Evaluate with real numbers

Roles that keep sign-off fast and auditable.

Provision admins, prescribers, and staff by role at app.fizy.health. Free to start.