Security & compliance

Patient data protected.Your team stays focused on care.

Cash-pay clinics should not have to guess whether their ordering platform meets healthcare standards. Fizy Health is built HIPAA-aligned from day one: BAA at onboarding, tenant-scoped access, audit trails on every patient-linked line, and SOC 2 Type II control frameworks implemented across the platform.

Proudly Partnered With

How we protect clinic data

Five layers between your patients and the wrong eyes.

Security on Fizy Health is not a marketing slide. It is how the product is wired: isolation by organization and clinic, least-privilege roles, encrypted transport, and an audit record every time staff touch patient-linked orders.

  1. BAA before production data

    Every clinic organization signs a Business Associate Agreement during onboarding before patient records are stored in production. Multi-location groups operate under one org with clinic-scoped staff access.

    • BAA executed before live PHI is stored
    • One org can span multiple clinic locations
    • Subprocessor protections aligned to HIPAA expectations
  2. Tenant isolation in the database

    Patient, cart, and order data live in Postgres with row-level security keyed on organization and clinic assignment. Staff only see patients and orders for sites they are assigned to. Nothing crosses between unrelated clinic accounts.

    • Row-level security on tenant-scoped tables
    • Clinic assignment gates what each user can open
    • Platform admin access is separate and audited
  3. Audit trail on every PHI touch

    Cart reads and mutations that include patient identifiers write an audit record with actor, organization, patient, and action. Application logs use structured fields and identifiers only, not prescription contents or demographics. That supports HIPAA Security Rule access review expectations.

    • Per-line audit on patient-linked cart actions
    • Domain-level PHI access records for compliance review
    • No patient names or chart contents in routine logs
  4. Encryption and least-privilege access

    Traffic between browser, API, and database uses TLS. Sensitive patient fields that need extra protection are stored with application-level encryption. Role-based access separates prescribers, staff, and admins so permissions match clinic workflow.

    • TLS everywhere in transit
    • Encrypted storage for designated high-sensitivity fields
    • NPI, DEA, and role gates on prescriber workflows
  5. Operational controls clinics can ask about

    Auth endpoints and webhooks are rate-limited. Incoming payment and vendor webhooks are signature-verified before any side effect. We align internal operations to SOC 2 Type II control frameworks and can share our security posture on request under NDA.

    • Rate limits on auth and webhook surfaces
    • Webhook signature verification before processing
    • SOC 2 Type II frameworks implemented (not a certification claim)

What your clinic gets from a security-first ops platform.

You are evaluating vendors on whether patient data stays where it belongs and whether you can answer an auditor without a spreadsheet hunt. These are the outcomes compliance-minded clinic teams care about on Fizy Health.

  • A signed BAA before you go live

    Onboarding includes executing a Business Associate Agreement with your organization before production patient data is stored. Legal and ops can check the box before the first real order, not after a surprise questionnaire.

  • Answers when patients ask who sees their data

    Staff access is scoped by clinic and role. Patient-linked cart and order actions leave an audit trail per line. You can explain who touched an order and when without reconstructing events from email threads.

  • Isolation that matches how you actually operate

    Multi-location groups run under one login with clinic switchers, but data does not bleed across sites. Row-level security enforces boundaries even when your team shares one Fizy Health account.

  • LegitScript-certified pharmacy partners

    Fulfillment routes to LegitScript-certified 503A compounding pharmacies in the network. That partner verification is part of how cash-pay clinics reduce compounding compliance risk alongside platform controls.

  • Logging discipline, not log noise

    Engineering standards prohibit patient names, DOB, addresses, and prescription contents in application logs. When something needs investigation, teams work from identifiers and audit rows, not exported chart dumps.

  • A vendor that expects diligence questions

    We implement SOC 2 Type II control frameworks across access, change management, monitoring, and incident response. Enterprise prospects can request security documentation under NDA. We do not overstate certification status.

Security posture

What is Fizy Health's approach to security?

Fizy Health is a HIPAA-aligned pharmacy operations platform for cash-pay clinics and telehealth brands. Security means tenant isolation, auditable PHI access, encrypted transport, verified pharmacy partners, and operational controls mapped to SOC 2 Type II frameworks. It is designed so clinic leaders can place orders with confidence, not hope.

  • HIPAA

    HIPAA-aligned by design

    BAA at onboarding, minimum-necessary access patterns, breach-notification commitments in contract, and PHI handling rules baked into engineering standards. We build for covered entities aligned with the HIPAA Security Rule, not generic SaaS defaults.

  • Isolation

    Organization and clinic scoping

    Postgres row-level security and role-based access keep each clinic's patients and orders inside their boundary. Team invites carry NPI, DEA, and role requirements where prescribing workflows demand them.

  • Audit

    Defensible access records

    Patient-linked reads and writes in cart, checkout, and order flows record who accessed what and when. That supports HIPAA access review and internal ops accountability without exposing chart contents in logs.

  • Operations

    SOC 2 Type II frameworks implemented

    We align policies and technical controls to SOC 2 Type II trust criteria: access control, encryption, monitoring, vendor management, and incident response. We describe this as frameworks implemented, not a certification badge we have not earned.

FAQ

Security questions clinics ask before they switch.

Is Fizy Health HIPAA compliant?

Fizy Health is built as a HIPAA-aligned platform for covered entities. Every clinic organization signs a Business Associate Agreement during onboarding before production patient data is stored. Patient-linked cart and order actions are audited, access is scoped by organization and clinic, and engineering standards prohibit PHI in routine application logs. See the HIPAA Security Rule for federal requirements on audit controls and access review.

When does Fizy Health sign a BAA with our clinic?

The Business Associate Agreement is part of onboarding before your organization stores live patient data in production. Multi-location groups can manage several clinics under one org while keeping staff access scoped to assigned sites.

How is clinic data isolated on Fizy Health?

Fizy Health scopes patient, cart, and order data per organization and clinic using row-level security in Postgres plus role-based access in the application layer. Staff only see patients and orders for clinics they are assigned to, and unrelated clinic accounts cannot read each other's data.

Are patient-linked actions audited?

Yes. Cart and order flows that include patient identifiers write audit records with actor, organization, patient, and action. That gives clinics a trail for HIPAA access review. Audit details use identifiers and counts, not prescription contents or demographics.

Is Fizy Health SOC 2 certified?

Fizy Health implements SOC 2 Type II control frameworks across access management, encryption, monitoring, change control, and incident response. We do not claim SOC 2 Type II certification unless and until an independent auditor issues a report. Prospects evaluating enterprise risk can request our security documentation under NDA.

Are Fizy Health pharmacy partners verified?

Yes. Fulfillment routes to LegitScript-certified 503A compounding pharmacies in the network. Partner verification complements platform controls so clinics can order compounded medications with both pharmacy legitimacy and software safeguards in place.

Order with confidence. Protect patients by default.

Start free, sign your BAA during onboarding, and run daily pharmacy ops on a platform built for HIPAA-aligned clinics. Pass-through pricing, one cart, and security controls that match how you are evaluated.