Scripts patient data handling

Scripts patient data handling

Scripts handles patient information because placing a compounded order requires the patient's identity, prescriber, and directions for use — all protected health information — and that information must reach the fulfilling pharmacy partner to compound and ship the medication. Scripts's pharmacy partners are described as 'fully licensed, compliant, and verified,' and Scripts itself markets a compliant ordering workflow. What Scripts does not publish on its public site is how patient data is stored at the platform level, what role-based access controls govern who can see PHI, how PHI is transmitted to pharmacy partners, and what retention or deletion terms apply. This page maps the PHI flow and lists the data-handling questions a clinic should verify before routing patient information through the platform.

This page explains where patient data goes in the Scripts ordering flow and what to confirm about access, encryption, and partner sharing.

Compare Fizy Health vs Scripts

Proudly Partnered With

What patient data does a fulfillment portal handle?

To place a compounded order through Scripts, the platform needs the patient's identity tied to the medication, the prescriber's information, and the directions for use — all of which is protected health information. That data is entered or imported at the clinic, stored and processed by the Scripts platform, and transmitted to the pharmacy partner that fills the order. Each hop is a place where PHI must be safeguarded: access should be limited to authorized users, data should be encrypted in transit and at rest, and sharing with fulfilling pharmacies should be governed by appropriate agreements. Scripts markets compliant operations but does not publish these specifics, so a clinic should confirm them in writing before transmitting any patient information.

Data-handling checklist

How to evaluate Scripts patient data handling

Each row is a data-handling criterion, what Scripts states publicly, and what to confirm before sending PHI.

What PHI is collected
What Scripts states publiclyOrdering requires patient identity, prescriber, and SIG. Scripts also sends automated patient text alerts about order status, which requires patient contact information.
What to verifyAsk what patient fields are collected and stored, which are required to place an order, and how contact data is used.
Access controls
What Scripts states publiclyScripts does not publish whether patient-data access is restricted by role or organization on its public site.
What to verifyAsk who can access patient data, whether access is role-based, and how access is logged.
Encryption
What Scripts states publiclyScripts does not publish encryption details for data in transit or at rest on its public site.
What to verifyConfirm encryption in transit and at rest and where patient data is hosted.
Sharing with pharmacy partners
What Scripts states publiclyOrders route to Scripts's 503A and 503B pharmacy partners that must receive patient information to compound and ship. Partners are described as 'fully licensed, compliant, and verified.'
What to verifyAsk how PHI is transmitted to partner pharmacies and whether downstream subcontractor agreements govern that sharing.
Retention and deletion
What Scripts states publiclyScripts does not publish how long patient data is retained or whether it can be deleted on request or after cancellation.
What to verifyAsk about retention periods, deletion on cancellation, and how to export patient records before you leave.

Sourced from Scripts public website (scripts.co), reviewed June 2026. Confirm data-handling terms in writing and review with your own counsel.

Negotiate data terms per vendor, or start with scoped access built in?

Scripts fits if

Scripts

You will request and review data-handling documentation during onboarding.

  • You are prepared to ask how PHI is stored, transmitted, and accessed before sharing it.
  • Your compliance team reviews vendor data terms case by case.
  • Concierge email coordination of data and privacy questions fits your process.
Consider Fizy Health if

Fizy Health

You want PHI access scoped and audited from the first order.

  • You want patient records organization-scoped so only authorized users see PHI.
  • You want patient-linked cart actions audited per line.
  • You want a BAA at onboarding rather than a separate negotiation.
FAQ

What clinics ask about Scripts and patient data.

  • Definition

    How does Scripts handle patient data?

    Scripts handles protected health information because placing a compounded order requires patient identity, a prescriber, and a SIG, which flow from the clinic through the platform to the fulfilling pharmacy partner. Scripts markets a compliant workflow but does not publish its PHI safeguard specifics, so confirm storage, access, and transmission terms directly.

  • Flow

    Where does patient data go when I place a Scripts order?

    Patient details are entered or imported at the clinic, stored and processed by Scripts, and transmitted to the 503A or 503B pharmacy partner that compounds and ships the order. Scripts also uses patient contact information to send automated text status updates. Each step should safeguard PHI with access controls and encryption.

  • Access

    Who can see patient data on Scripts?

    Scripts does not publish whether access to patient data is restricted by role or organization. Ask who can access patient records, whether access is role-based, and whether that access is logged.

  • Partners

    Do the pharmacies receive patient information?

    Yes. The pharmacy partners must receive patient information to compound and ship medications. Scripts describes its partners as 'fully licensed, compliant, and verified.' Ask how PHI is transmitted to partners and whether subcontractor agreements govern that sharing.

  • Retention

    How long does Scripts keep patient data?

    Scripts does not publish its retention or deletion policy. Ask how long patient data is retained, whether it can be deleted on request, and whether you can export patient records if you leave.

  • Alternative

    How does Fizy Health handle patient data?

    Fizy Health keeps patient records organization-scoped so only authorized users see PHI, audits patient-linked cart actions per line, and signs a BAA at onboarding. Access controls are built into the product rather than negotiated separately.

Sources reviewed June 2026

  • Scripts public website and FAQ (scripts.co), reviewed June 2026.
  • Data-handling and privacy terms should be confirmed in writing with Scripts and reviewed by your own counsel.
  • Fizy Health platform capabilities reflect the live product.
Evaluate with real numbers

Keep patient data scoped from the first order.

Fizy Health organization-scopes patient records, audits actions per line, and signs a BAA at onboarding. Free to start.