VLS Pharmacy patient data handling
VLS Pharmacy is a licensed 503A compounding pharmacy, and placing a compounded order routes patient information — the patient's identity, the prescriber, and the directions for use — directly to the pharmacy's compounding team. As a pharmacy covered entity, VLS Pharmacy is legally required to handle PHI under HIPAA as part of its pharmacy operations. What clinics should additionally verify is whether a formal prescriber data agreement or BAA is offered, how access to patient records is controlled within the compounding staff, and what happens to patient data if the prescriber relationship ends. None of these are published in detail on VLS Pharmacy's public site.
This page maps how patient data flows through the VLS Pharmacy compounding process and lists the data-handling questions every clinic should confirm before sending PHI.
What patient data does a 503A compounding order involve?
To compound a patient-specific medication, VLS Pharmacy needs the patient's identity, date of birth, and address for shipping; the prescriber's name, NPI, and state license; and the prescription with directions for use — all of which constitutes protected health information. That data is transmitted to the pharmacy by fax, EMR, or phone and enters the compounding team's workflow. As a HIPAA covered entity, VLS Pharmacy is required to safeguard this PHI under its own privacy and security practices. What is less clear from public materials is the specific access controls that limit which staff members see PHI, the technical safeguards for fax and EMR data in transit and at rest, and the data retention and deletion terms for prescriber relationships. These are the items to request before you begin transmitting patient information.
How to evaluate VLS Pharmacy patient data handling
Each row is a data-handling criterion, what is publicly known about VLS Pharmacy, and what to confirm before sending PHI.
Sourced from VLS Pharmacy and New Drug Loft public materials (vlspharmacy.com, newdrugloft.com), reviewed June 2026. Data-handling and privacy terms should be confirmed in writing and reviewed by your own counsel.
Confirm data terms with the pharmacy, or start with scoped access built in?
VLS Pharmacy
You will request and review data-handling terms during account setup.
- You are prepared to ask how PHI is stored, transmitted, and accessed before you start ordering.
- Your compliance team reviews pharmacy data terms on a case-by-case basis.
- Phone and email coordination of data questions fits your workflow.
Fizy Health
You want PHI access scoped and audited from the first order.
- You want patient records organization-scoped so only authorized users see PHI.
- You want patient-linked cart actions audited per line — not just pharmacy dispensing records.
- You want a BAA at onboarding rather than a separate negotiation.
What disciplined patient-data handling looks like.
Good data handling shows up as scoped access, audited actions, and less PHI scattered across fax cover sheets and email threads.
Patient data scoped to the right team
Patient records and cart lines stay organization-scoped, so only authorized users in your clinic see PHI.
An audit trail on every order
Per-line order status and history give a defensible record of what happened to each patient's order.
Fewer rejections that scatter PHI over email
Cart validation catches issues before payment, reducing the back-and-forth that spreads patient details across inboxes.
What clinics ask about VLS Pharmacy and patient data.
- Definition
How does VLS Pharmacy handle patient data?
VLS Pharmacy handles protected health information as a licensed 503A compounding pharmacy and HIPAA covered entity. Patient identity, prescriber credentials, and prescription details are required to compound an order and are handled under the pharmacy's own HIPAA privacy and security practices. Clinics should additionally confirm access controls, BAA terms, and retention policy before transmitting patient information.
- Flow
Where does patient data go when I place a VLS Pharmacy order?
Patient details submitted by fax, EMR, or phone are received by VLS Pharmacy's compounding team, who use them to prepare the medication. The New Drug Loft sister pharmacy in Manhattan operates under the same ownership; confirm whether any patient data is shared between locations for order routing.
- Access
Who can see patient data at VLS Pharmacy?
VLS Pharmacy does not publish which staff roles have access to patient records or whether access is role-restricted. Ask who on the compounding team sees patient data and whether that access is logged.
- Fax
Is PHI on a fax cover sheet handled securely?
Fax is a recognized transmission method under HIPAA when appropriate safeguards are in place. Ask VLS Pharmacy whether secure or encrypted fax is used and how fax submissions are stored after receipt.
- Retention
How long does VLS Pharmacy keep patient data?
Pharmacies must retain dispensing records per state and federal law. Ask VLS Pharmacy how long patient records are kept beyond regulatory minimums, whether records can be deleted on request, and what happens to your data if you stop ordering.
- Alternative
How does Fizy Health handle patient data?
Fizy Health keeps patient records organization-scoped so only authorized users see PHI, audits patient-linked cart actions per line, and signs a BAA at onboarding. Access controls are built into the product rather than coordinated separately with each pharmacy.
Sources reviewed June 2026
- VLS Pharmacy public website (vlspharmacy.com) and New Drug Loft network pages (newdrugloft.com), reviewed June 2026.
- Data-handling and privacy terms should be confirmed in writing with VLS Pharmacy and reviewed by your own counsel.
- Fizy Health platform capabilities reflect the live product.
Keep patient data scoped from the first order.
Fizy Health organization-scopes patient records, audits actions per line, and signs a BAA at onboarding. Free to start.