Scripts HIPAA and BAA

Scripts HIPAA and BAA: what to confirm

Scripts is a fulfillment intermediary, and because placing orders requires patient name, prescriber, diagnosis context, and SIG, HIPAA considerations apply to how it handles that data. Scripts does not publish its HIPAA safeguard details, a BAA template, or encryption specifics on its public website — even though its network includes pharmacies that are deeply compliance-focused. The right move is to request Scripts's HIPAA documentation and a signed business associate agreement in writing before you transmit any protected health information. This page lists exactly what to ask for so you enter the relationship with compliance covered.

This page explains why a BAA matters for a fulfillment portal and what HIPAA terms to verify before you share PHI with Scripts.

Compare Fizy Health vs Scripts

Proudly Partnered With

Why does a BAA matter for a fulfillment intermediary like Scripts?

A business associate agreement is the HIPAA contract that governs how a vendor handling protected health information on a covered entity's behalf must safeguard, use, and disclose that data. When a clinic places a compounded order through Scripts, patient details — name, prescriber, medication, SIG — flow through the platform to partner pharmacies, which generally makes Scripts a business associate. That is why a signed BAA, plus documented administrative, physical, and technical safeguards, is the baseline a clinic should require before any PHI moves. Scripts markets a compliant ordering workflow and works with pharmacies that hold their own compliance credentials, but Scripts itself does not publish a BAA template or safeguard details on its public site, so a clinic should obtain both directly before sending any PHI.

HIPAA verification checklist

What to confirm about Scripts and HIPAA

Each row is a HIPAA criterion, what Scripts states publicly, and the document or commitment to request before sharing PHI.

Signed BAA
What Scripts states publiclyScripts does not publish a business associate agreement template on its public site, even though its ordering workflow handles patient information.
What to requestRequest a signed BAA before transmitting any patient information and have counsel review it.
Stated HIPAA posture
What Scripts states publiclyScripts markets a compliant ordering workflow and 503A/503B-compliant pharmacy partners, but does not detail its own platform-level administrative, physical, and technical safeguards publicly.
What to requestAsk for written documentation of its administrative, physical, and technical safeguards.
PHI access controls
What Scripts states publiclyScripts does not publish how access to patient data is restricted by role or organization on its public site.
What to requestAsk who can access patient data, whether access is role-based, and how it is logged.
Data in transit and at rest
What Scripts states publiclyScripts does not publish encryption details for stored or transmitted patient data on its public site.
What to requestConfirm encryption in transit and at rest, and where patient data is hosted.
Subcontractors and pharmacy partners
What Scripts states publiclyOrders route to 503A and 503B partner pharmacies, which also receive patient information to compound and ship. Scripts describes these partners as 'fully licensed, compliant, and verified.'
What to requestAsk how PHI is shared with fulfilling pharmacies and whether downstream subcontractor BAAs are in place.

Sourced from Scripts public website (scripts.co), reviewed June 2026. HIPAA terms should be confirmed in writing with Scripts and reviewed by your own counsel before you share patient data.

Negotiate HIPAA terms during the sales cycle, or start with a BAA at onboarding?

Scripts fits if

Scripts

You will request and review HIPAA documentation during the sales process.

  • You are prepared to ask for a BAA and safeguard documentation before sharing PHI.
  • Your compliance team is comfortable reviewing vendor terms case by case.
  • Email-based coordination of compliance questions fits your workflow.
Consider Fizy Health if

Fizy Health

You want a BAA signed at onboarding and PHI access scoped from day one.

  • You want a clinic BAA executed at onboarding before you place an order.
  • You want patient-linked cart actions audited per line with organization-scoped access.
  • You want PHI access controls built into the product, not negotiated after the fact.
FAQ

What clinics ask about Scripts and HIPAA.

  • Definition

    Is Scripts HIPAA-compliant?

    Scripts markets a compliant ordering workflow and works with 'fully licensed, compliant, and verified' pharmacy partners, but it does not publish the specifics of its own safeguards or a standard BAA on its site. Confirm its HIPAA posture and obtain a signed business associate agreement in writing before transmitting protected health information.

  • BAA

    Does Scripts provide a business associate agreement?

    Scripts does not publish a BAA template publicly. Because ordering involves patient information, request a signed BAA before sharing PHI and have your counsel review the terms.

  • Why

    Why does a fulfillment portal need a BAA?

    A BAA is the HIPAA contract required when a vendor handles protected health information on a covered entity's behalf. Placing compounded orders routes patient details — name, prescriber, SIG — through the platform, which generally makes it a business associate, so a BAA is the baseline.

  • Safeguards

    What HIPAA safeguards should I verify with Scripts?

    Ask for documentation of administrative, physical, and technical safeguards: role-based access controls, encryption in transit and at rest, hosting location, audit logging, and how PHI is shared with fulfilling 503A and 503B pharmacy partners.

  • Partners

    How is patient data shared with the pharmacies?

    Orders route to Scripts's pharmacy partners — which it describes as 'fully licensed, compliant, and verified' — that receive patient information to compound and ship medications. Ask Scripts how PHI is transmitted to partners and whether downstream business associate agreements are in place.

  • Alternative

    How does Fizy Health handle HIPAA and BAAs?

    Fizy Health signs a clinic BAA at onboarding, keeps patient records organization-scoped, and audits patient-linked cart actions per line. PHI access controls are built into the product rather than negotiated after signing.

Sources reviewed June 2026

  • Scripts public website and FAQ (scripts.co), reviewed June 2026.
  • HIPAA terms and any BAA should be confirmed in writing with Scripts and reviewed by your own counsel.
  • Fizy Health platform capabilities reflect the live product.
Evaluate with real numbers

Start with a BAA at onboarding — not after a contract fight.

Fizy Health signs a clinic BAA before your first order and keeps patient access audited and scoped. Free to start.