Tailor Made Compounding HIPAA and BAA: what to confirm
Tailor Made Compounding handles protected health information because compounding and shipping patient-specific medications requires patient identity, prescriber details, and prescription data — which makes HIPAA compliance and a business associate agreement baseline requirements for clinic partners. Tailor Made publishes a Notice of Privacy Practices at tailormadecompounding.com/privacy-policy describing treatment, payment, and operations uses, patient rights, breach notification duties, business associate disclosures, and a named Privacy Officer at TMC Acquisition, LLC in Nicholasville, Kentucky. It does not publish a BAA template on the public site, so request a signed BAA and technical safeguard documentation before transmitting PHI at volume. Clinics comparing audited, organization-scoped cart access often evaluate Fizy Health, which signs a BAA at onboarding.
Why a BAA matters when Tailor Made compounds for your patients — and the HIPAA terms to verify in writing.
Why does a BAA matter when a pharmacy compounds for your clinic?
A business associate agreement is the HIPAA contract governing how a vendor that creates, receives, maintains, or transmits PHI on your behalf must safeguard and use that data. When your clinic submits patient orders through Tailor Made's EMR prescriber portal, Tailor Made is performing a pharmacy function that involves PHI — compounding, billing, shipping coordination, and patient support — which generally makes it a business associate. Tailor Made's published HIPAA notice describes permitted uses for treatment, payment, and health care operations, discloses use of business associates for billing and software services, and notes encrypted email precautions. The gap to close in diligence is a signed BAA, technical safeguard detail beyond the public summary, and clarity on staff access logging inside the EMR portal.
What to confirm about Tailor Made Compounding and HIPAA
Each row is a HIPAA criterion, what Tailor Made publishes publicly, and the document to request before sharing PHI.
Sourced from Tailor Made Compounding privacy policy and prescriber portal (tailormadecompounding.com), reviewed June 2026. HIPAA terms should be confirmed in writing and reviewed by your counsel.
Negotiate HIPAA terms during onboarding, or start with a BAA at signup?
Tailor Made Compounding
You will request and review HIPAA documentation during account-request onboarding.
- You are prepared to obtain a signed BAA and safeguard documentation before PHI submission.
- Your compliance team reviews pharmacy BAAs routinely during partner onboarding.
- You only order Tailor Made SKUs — PHI stays inside one compounder relationship.
Fizy Health
You want a BAA at signup plus per-line PHI audit in the ordering layer.
- You want a BAA signed at onboarding before you build patient carts at volume.
- You want patient-linked cart actions audited per line with organization-scoped access.
- You batch refills across multiple 503A partners and need one HIPAA-governed ops layer above them.
What HIPAA-governed ordering looks like in the ops layer.
A BAA is the floor — day-to-day safety is how PHI moves through cart, validation, and audit.
BAA at onboarding
Every clinic signs a BAA before building patient carts — PHI governance starts at signup, not after a sales call.
Per-line audit on cart mutations
Every patient-linked cart action is audited per line with organization-scoped access.
Organization-scoped access
Team roles keep PHI inside your clinic boundary — not shared across unrelated accounts.
What clinics ask about Tailor Made Compounding HIPAA and BAA.
- Definition
Is Tailor Made Compounding HIPAA compliant?
Tailor Made Compounding publishes a HIPAA Notice of Privacy Practices describing how it uses and protects PHI for treatment, payment, and operations. HIPAA compliance for your clinic also requires a signed BAA and confirmed safeguard documentation — request both before transmitting patient data at scale.
- BAA
Does Tailor Made Compounding offer a business associate agreement?
Tailor Made's privacy notice references business associates but does not publish a BAA template on its public site. Request a signed BAA during prescriber network onboarding and have your counsel review it before PHI submission.
- Portal
Does the EMR portal change HIPAA obligations?
Yes. When your team enters patient data into emr.tailormadecompounding.com, Tailor Made generally acts as a business associate. Confirm portal access controls, audit logging, and subprocessors in the BAA.
- Patient rights
What patient rights does Tailor Made's notice describe?
Tailor Made's notice describes rights to request restrictions, inspect and copy records, request amendments, receive an accounting of disclosures, and file complaints with Tailor Made or the Secretary of HHS.
- Encryption
Does Tailor Made encrypt patient communications?
The privacy notice states Tailor Made takes precautions including encrypted email accounts. Confirm encryption in transit and at rest for portal PHI and support channels during onboarding.
- Alternative
How does Fizy Health handle HIPAA and BAAs?
Fizy Health signs a BAA at onboarding, scopes access to your organization, and audits patient-linked cart actions per line. Pharmacy partners in the network maintain their own HIPAA obligations as compounders.
Sources reviewed June 2026
- Tailor Made Compounding privacy policy and prescriber EMR portal (tailormadecompounding.com), reviewed June 2026.
- Fizy Health platform capabilities reflect the live product.
Get the BAA in writing — or start with one at signup.
Fizy Health signs a BAA at onboarding and audits patient-linked cart actions per line. Free to start.