Tailor Made Compounding HIPAA and BAA

Tailor Made Compounding HIPAA and BAA: what to confirm

Tailor Made Compounding handles protected health information because compounding and shipping patient-specific medications requires patient identity, prescriber details, and prescription data — which makes HIPAA compliance and a business associate agreement baseline requirements for clinic partners. Tailor Made publishes a Notice of Privacy Practices at tailormadecompounding.com/privacy-policy describing treatment, payment, and operations uses, patient rights, breach notification duties, business associate disclosures, and a named Privacy Officer at TMC Acquisition, LLC in Nicholasville, Kentucky. It does not publish a BAA template on the public site, so request a signed BAA and technical safeguard documentation before transmitting PHI at volume. Clinics comparing audited, organization-scoped cart access often evaluate Fizy Health, which signs a BAA at onboarding.

Why a BAA matters when Tailor Made compounds for your patients — and the HIPAA terms to verify in writing.

Proudly Partnered With

Why does a BAA matter when a pharmacy compounds for your clinic?

A business associate agreement is the HIPAA contract governing how a vendor that creates, receives, maintains, or transmits PHI on your behalf must safeguard and use that data. When your clinic submits patient orders through Tailor Made's EMR prescriber portal, Tailor Made is performing a pharmacy function that involves PHI — compounding, billing, shipping coordination, and patient support — which generally makes it a business associate. Tailor Made's published HIPAA notice describes permitted uses for treatment, payment, and health care operations, discloses use of business associates for billing and software services, and notes encrypted email precautions. The gap to close in diligence is a signed BAA, technical safeguard detail beyond the public summary, and clarity on staff access logging inside the EMR portal.

HIPAA verification checklist

What to confirm about Tailor Made Compounding and HIPAA

Each row is a HIPAA criterion, what Tailor Made publishes publicly, and the document to request before sharing PHI.

Notice of Privacy Practices
What is publicly knownTailor Made publishes a combined Privacy Policy and HIPAA Notice of Privacy Practices with treatment, payment, operations uses, patient rights, breach complaint procedures, and a Privacy Officer contact.
What to requestConfirm the notice version in effect at signing and whether clinic-specific terms supplement it.
Signed BAA
What is publicly knownNo BAA template appears on the public website; prescriber network onboarding likely includes a separate agreement.
What to requestRequest a signed BAA before transmitting PHI and have counsel review permitted uses, subprocessors, and breach notification timelines.
PHI access controls
What is publicly knownTailor Made uses an EMR prescriber portal at emr.tailormadecompounding.com; public materials do not detail role-based PHI restrictions.
What to requestAsk who can view patient orders, whether access is role-scoped, and whether views and edits are audit-logged.
Data in transit and at rest
What is publicly knownThe privacy notice states Tailor Made takes precautions to prevent unauthorized disclosure, including using encrypted email accounts for communications.
What to requestConfirm encryption in transit and at rest for portal PHI, hosting location, and backup retention for order data.
Business associates and subprocessors
What is publicly knownThe notice discloses sharing PHI with business associates performing billing, collections, and network or software services on Tailor Made's behalf.
What to requestRequest a subprocessors list with BAAs or equivalent assurances for every vendor touching PHI.

Sourced from Tailor Made Compounding privacy policy and prescriber portal (tailormadecompounding.com), reviewed June 2026. HIPAA terms should be confirmed in writing and reviewed by your counsel.

Negotiate HIPAA terms during onboarding, or start with a BAA at signup?

Tailor Made Compounding fits if

Tailor Made Compounding

You will request and review HIPAA documentation during account-request onboarding.

  • You are prepared to obtain a signed BAA and safeguard documentation before PHI submission.
  • Your compliance team reviews pharmacy BAAs routinely during partner onboarding.
  • You only order Tailor Made SKUs — PHI stays inside one compounder relationship.
Consider Fizy Health if

Fizy Health

You want a BAA at signup plus per-line PHI audit in the ordering layer.

  • You want a BAA signed at onboarding before you build patient carts at volume.
  • You want patient-linked cart actions audited per line with organization-scoped access.
  • You batch refills across multiple 503A partners and need one HIPAA-governed ops layer above them.
FAQ

What clinics ask about Tailor Made Compounding HIPAA and BAA.

  • Definition

    Is Tailor Made Compounding HIPAA compliant?

    Tailor Made Compounding publishes a HIPAA Notice of Privacy Practices describing how it uses and protects PHI for treatment, payment, and operations. HIPAA compliance for your clinic also requires a signed BAA and confirmed safeguard documentation — request both before transmitting patient data at scale.

  • BAA

    Does Tailor Made Compounding offer a business associate agreement?

    Tailor Made's privacy notice references business associates but does not publish a BAA template on its public site. Request a signed BAA during prescriber network onboarding and have your counsel review it before PHI submission.

  • Portal

    Does the EMR portal change HIPAA obligations?

    Yes. When your team enters patient data into emr.tailormadecompounding.com, Tailor Made generally acts as a business associate. Confirm portal access controls, audit logging, and subprocessors in the BAA.

  • Patient rights

    What patient rights does Tailor Made's notice describe?

    Tailor Made's notice describes rights to request restrictions, inspect and copy records, request amendments, receive an accounting of disclosures, and file complaints with Tailor Made or the Secretary of HHS.

  • Encryption

    Does Tailor Made encrypt patient communications?

    The privacy notice states Tailor Made takes precautions including encrypted email accounts. Confirm encryption in transit and at rest for portal PHI and support channels during onboarding.

  • Alternative

    How does Fizy Health handle HIPAA and BAAs?

    Fizy Health signs a BAA at onboarding, scopes access to your organization, and audits patient-linked cart actions per line. Pharmacy partners in the network maintain their own HIPAA obligations as compounders.

Sources reviewed June 2026

  • Tailor Made Compounding privacy policy and prescriber EMR portal (tailormadecompounding.com), reviewed June 2026.
  • Fizy Health platform capabilities reflect the live product.
Evaluate with real numbers

Get the BAA in writing — or start with one at signup.

Fizy Health signs a BAA at onboarding and audits patient-linked cart actions per line. Free to start.