VLS Pharmacy patient data handling

VLS Pharmacy patient data handling

VLS Pharmacy is a licensed 503A compounding pharmacy, and placing a compounded order routes patient information — the patient's identity, the prescriber, and the directions for use — directly to the pharmacy's compounding team. As a pharmacy covered entity, VLS Pharmacy is legally required to handle PHI under HIPAA as part of its pharmacy operations. What clinics should additionally verify is whether a formal prescriber data agreement or BAA is offered, how access to patient records is controlled within the compounding staff, and what happens to patient data if the prescriber relationship ends. None of these are published in detail on VLS Pharmacy's public site.

This page maps how patient data flows through the VLS Pharmacy compounding process and lists the data-handling questions every clinic should confirm before sending PHI.

Proudly Partnered With

What patient data does a 503A compounding order involve?

To compound a patient-specific medication, VLS Pharmacy needs the patient's identity, date of birth, and address for shipping; the prescriber's name, NPI, and state license; and the prescription with directions for use — all of which constitutes protected health information. That data is transmitted to the pharmacy by fax, EMR, or phone and enters the compounding team's workflow. As a HIPAA covered entity, VLS Pharmacy is required to safeguard this PHI under its own privacy and security practices. What is less clear from public materials is the specific access controls that limit which staff members see PHI, the technical safeguards for fax and EMR data in transit and at rest, and the data retention and deletion terms for prescriber relationships. These are the items to request before you begin transmitting patient information.

Data-handling checklist

How to evaluate VLS Pharmacy patient data handling

Each row is a data-handling criterion, what is publicly known about VLS Pharmacy, and what to confirm before sending PHI.

What PHI is collected
What is publicly knownOrdering requires patient identity (name, DOB, address), prescriber credentials (NPI, state license), and prescription SIG — all PHI under HIPAA.
What to verifyAsk what patient fields are collected and stored and which are shared with the compounding staff and sister pharmacy New Drug Loft.
Fax and EMR transmission security
What is publicly knownPrescriptions are submitted by fax, EMR, or phone. VLS Pharmacy does not publish technical safeguards for data in transit.
What to verifyAsk whether secure or encrypted fax is used, how EMR submissions are handled, and how phone orders are documented securely.
Access controls
What is publicly knownVLS Pharmacy does not publish which staff roles have access to patient records or whether access is role-restricted.
What to verifyAsk which compounding staff members can view patient data, whether access is role-based, and whether it is logged.
Data at rest
What is publicly knownVLS Pharmacy does not publish encryption or hosting details for stored patient records.
What to verifyAsk where patient data is stored, whether it is encrypted at rest, and who administers the storage system.
Retention and deletion
What is publicly knownPharmacies are required by law to maintain dispensing records for defined periods. VLS Pharmacy does not publish its data retention or deletion policy for prescriber relationships.
What to verifyAsk how long patient records are retained, whether they can be deleted on request, and what happens to records if you stop ordering.

Sourced from VLS Pharmacy and New Drug Loft public materials (vlspharmacy.com, newdrugloft.com), reviewed June 2026. Data-handling and privacy terms should be confirmed in writing and reviewed by your own counsel.

Confirm data terms with the pharmacy, or start with scoped access built in?

VLS Pharmacy fits if

VLS Pharmacy

You will request and review data-handling terms during account setup.

  • You are prepared to ask how PHI is stored, transmitted, and accessed before you start ordering.
  • Your compliance team reviews pharmacy data terms on a case-by-case basis.
  • Phone and email coordination of data questions fits your workflow.
Consider Fizy Health if

Fizy Health

You want PHI access scoped and audited from the first order.

  • You want patient records organization-scoped so only authorized users see PHI.
  • You want patient-linked cart actions audited per line — not just pharmacy dispensing records.
  • You want a BAA at onboarding rather than a separate negotiation.
FAQ

What clinics ask about VLS Pharmacy and patient data.

  • Definition

    How does VLS Pharmacy handle patient data?

    VLS Pharmacy handles protected health information as a licensed 503A compounding pharmacy and HIPAA covered entity. Patient identity, prescriber credentials, and prescription details are required to compound an order and are handled under the pharmacy's own HIPAA privacy and security practices. Clinics should additionally confirm access controls, BAA terms, and retention policy before transmitting patient information.

  • Flow

    Where does patient data go when I place a VLS Pharmacy order?

    Patient details submitted by fax, EMR, or phone are received by VLS Pharmacy's compounding team, who use them to prepare the medication. The New Drug Loft sister pharmacy in Manhattan operates under the same ownership; confirm whether any patient data is shared between locations for order routing.

  • Access

    Who can see patient data at VLS Pharmacy?

    VLS Pharmacy does not publish which staff roles have access to patient records or whether access is role-restricted. Ask who on the compounding team sees patient data and whether that access is logged.

  • Fax

    Is PHI on a fax cover sheet handled securely?

    Fax is a recognized transmission method under HIPAA when appropriate safeguards are in place. Ask VLS Pharmacy whether secure or encrypted fax is used and how fax submissions are stored after receipt.

  • Retention

    How long does VLS Pharmacy keep patient data?

    Pharmacies must retain dispensing records per state and federal law. Ask VLS Pharmacy how long patient records are kept beyond regulatory minimums, whether records can be deleted on request, and what happens to your data if you stop ordering.

  • Alternative

    How does Fizy Health handle patient data?

    Fizy Health keeps patient records organization-scoped so only authorized users see PHI, audits patient-linked cart actions per line, and signs a BAA at onboarding. Access controls are built into the product rather than coordinated separately with each pharmacy.

Sources reviewed June 2026

  • VLS Pharmacy public website (vlspharmacy.com) and New Drug Loft network pages (newdrugloft.com), reviewed June 2026.
  • Data-handling and privacy terms should be confirmed in writing with VLS Pharmacy and reviewed by your own counsel.
  • Fizy Health platform capabilities reflect the live product.
Evaluate with real numbers

Keep patient data scoped from the first order.

Fizy Health organization-scopes patient records, audits actions per line, and signs a BAA at onboarding. Free to start.