VS Digital Health (VSDH) HIPAA and BAA
VS Digital Health, commonly known as VSDH, handles health-related data across white-label apps, telemedicine, and pharmacy ordering, but its public terms take an explicit position on HIPAA: the company states it is not a covered entity or business associate under HIPAA and that its services are not tailored to comply with industry-specific regulations including HIPAA if your use would be subject to such laws. Marketing materials mention HIPAA-compliant architecture, but the published legal terms are what your counsel should read first. This page explains why a BAA matters for clinic ordering and exactly what to request before you transmit PHI through VSDH or ConnectRxCare.
This page separates VSDH's public HIPAA disclaimers from the BAAs and safeguards a clinic still needs across platform, medical practices, and pharmacies.
Why does a BAA matter for a white-label pharmacy platform?
A business associate agreement is the HIPAA contract that governs how a vendor handling protected health information on a covered entity's behalf must safeguard, use, and disclose that data. When a clinic places a compounded order, patient details flow through the ordering platform and to fulfilling pharmacies, which generally makes multiple parties in the chain potential business associates. VSDH's public terms state the company is not a covered entity or business associate under HIPAA and that services are not tailored to HIPAA-regulated use, while also saying it will protect personal health information under its privacy policy. Clinic operators should not treat marketing language as a substitute for written BAAs and safeguard documentation reviewed by their own counsel.
What to confirm about VSDH and HIPAA
Each row is a HIPAA criterion, what is publicly known about VSDH, and the document or commitment to request before sharing PHI.
Sourced from vsdigitalhealth.com terms and privacy policy, reviewed June 2026. HIPAA terms should be confirmed in writing with VSDH and reviewed by your own counsel.
Map HIPAA across a white-label chain, or start with a BAA at onboarding?
VSDH
You are launching a D2C brand and your compliance team will map BAAs across VSDH's medical and pharmacy network.
- Your counsel accepts reviewing VSDH's public HIPAA disclaimers alongside any partner-specific agreements.
- You need bundled telemedicine and branded pharmacy more than clinic batch ordering with a platform BAA on day one.
- You will request written safeguard documentation from VSDH, Medical Practices, and Pharmacies before go-live.
Fizy Health
You want a clinic BAA signed at onboarding and PHI access scoped from day one.
- You want a clinic BAA executed at onboarding before you place an order.
- You want patient-linked cart actions audited per line with organization-scoped access.
- You want PHI access controls built into the clinic ops product, not negotiated across a white-label stack.
What HIPAA-aware ordering looks like in practice.
A strong HIPAA posture shows up as scoped access, audited actions, and a clear trail of who did what, not just a clause buried in a white-label agreement.
Patient data scoped to the right team
Patient records and cart lines stay organization-scoped, so only authorized users in your clinic see PHI.
An audit trail on every cart mutation
Patient-linked cart actions are recorded per line so compliance review has a defensible record.
Certified partners named before checkout
Each cart line shows which LegitScript-certified 503A partner fulfills it before you pay.
What clinics ask about VSDH and HIPAA.
- Posture
Is VS Digital Health (VSDH) HIPAA compliant?
VSDH's public terms state the company is not a HIPAA covered entity or business associate and that services are not tailored to HIPAA-regulated use if your interactions would be subject to such laws. Marketing mentions HIPAA-compliant architecture, but clinics should rely on written agreements and counsel review, not homepage copy alone.
- BAA
Does VSDH offer a business associate agreement?
VSDH does not publish a BAA template publicly. Request whether VSDH will sign a BAA for your use case and obtain BAAs or equivalent agreements with Medical Practices and Pharmacies that receive PHI.
- Why
Why does a BAA matter for pharmacy ordering?
Placing a compounded order requires patient identity, prescriber, and SIG, which is protected health information. A BAA governs how each vendor in the chain may use, store, and disclose that data on your behalf.
- Chain
Who else in the VSDH stack may need a BAA?
VSDH contracts with third-party Medical Practices and Pharmacies. PHI may flow to those parties for telehealth, prescribing, compounding, and shipping. Map the full chain with counsel and confirm agreements with each party that touches PHI.
- Hosting
Where is VSDH patient data hosted?
VSDH terms state services are hosted in the United States. Confirm encryption, subprocessors, and retention details in writing before transmitting PHI.
- Alternative
How does Fizy Health handle HIPAA and BAAs?
Fizy Health signs a clinic BAA at onboarding, scopes access to your organization, and audits patient-linked cart actions per line. Pharmacy partners in the network are LegitScript-certified 503A compounders.
Sources reviewed June 2026
- VS Digital Health terms and privacy policy (vsdigitalhealth.com), reviewed June 2026.
- Victory Square Technologies public VSDH materials mentioning HIPAA-compliant architecture, reviewed June 2026.
- Fizy Health platform capabilities reflect the live product.
Start with a BAA and audited access, not disclaimers alone.
Fizy Health signs a clinic BAA at onboarding and audits patient-linked cart actions per line. Free to start.