Legal

HIPAA Notice of Privacy Practices

How ScriptExchange handles Protected Health Information under the Health Insurance Portability and Accountability Act.

Last updated: June 24, 2026

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

1. Our Role Under HIPAA

ScriptExchange, LLC ("ScriptExchange") operates as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act. We process Protected Health Information (PHI) on behalf of covered entities, including licensed prescribers, clinics, and healthcare organizations, that use our Platform to transmit electronic prescriptions and manage patient orders.

As a Business Associate, ScriptExchange is required to maintain the privacy and security of PHI in accordance with the HIPAA Privacy Rule (45 CFR Part 164) and Security Rule. We execute Business Associate Agreements (BAAs) with all covered entities and pharmacy partners in our network.

2. What Is Protected Health Information?

PHI is individually identifiable health information that relates to a patient's past, present, or future physical or mental health condition, the provision of healthcare, or payment for healthcare. PHI processed through ScriptExchange includes:

  • Patient name, date of birth, address, and contact information
  • Prescription details including medication name, strength, quantity, and directions
  • Prescriber name, NPI, and DEA number associated with a prescription
  • Order status and fulfillment records
  • Allergy and medication history entered into the Platform

3. How We Use and Disclose PHI

3.1 Permitted Uses and Disclosures

ScriptExchange uses and discloses PHI only as permitted or required by our Business Associate Agreements and applicable law, including:

  • Treatment: Transmitting prescriptions to pharmacy partners for compounding and dispensing
  • Healthcare Operations: Quality assurance, audit logging, and compliance monitoring
  • Payment: Processing order transactions and generating invoices
  • Legal Requirements: Disclosures required by law, including to the DEA, state pharmacy boards, or law enforcement as required by applicable regulations
  • Business Associate Functions: Performing services on behalf of covered entities as described in our BAAs

3.2 Uses Requiring Authorization

ScriptExchange will not use or disclose PHI for marketing purposes, sell PHI, or use PHI in ways not permitted by our BAAs without obtaining a valid HIPAA authorization from the patient, except as required by law.

Our HIPAA Marketing Authorization sets out what HIPAA treats as marketing, what a valid authorization must contain, and our current practice — which is that we do not use or disclose PHI for marketing at all.

3.3 Minimum Necessary Standard

ScriptExchange applies the minimum necessary standard to all uses and disclosures of PHI. We access, use, and disclose only the PHI reasonably necessary to accomplish the intended purpose.

4. How We Protect PHI

ScriptExchange implements comprehensive administrative, physical, and technical safeguards to protect PHI in accordance with the HIPAA Security Rule, including:

  • Administrative Safeguards: HIPAA workforce training, designated Privacy and Security Officers, risk analysis and management program, and sanction policies for workforce members who violate HIPAA
  • Physical Safeguards: Secure data center facilities with access controls, workstation security policies, and device and media controls
  • Technical Safeguards: AES-256-GCM authenticated encryption of PHI at rest, TLS 1.3 encryption in transit, unique user identification, role-based access controls, audit controls, and integrity controls (authenticated decryption that rejects tampered ciphertext, and fail-closed key handling that refuses to process PHI without a key)
  • Breach Notification: Procedures for detecting, investigating, and notifying covered entities of breaches of unsecured PHI within the timeframes required by HIPAA

5. Your Rights Regarding PHI

As a Business Associate, ScriptExchange supports covered entities in fulfilling patient rights under HIPAA. Patients who wish to exercise their rights regarding their PHI, including the right to access, amend, or request an accounting of disclosures, should contact the covered entity (prescriber or clinic) that submitted their information to the Platform.

Covered entities using ScriptExchange may contact us at privacy@scriptexchange.com to request assistance in fulfilling patient rights requests.

6. Breach Notification

In the event of a breach of unsecured PHI, ScriptExchange will notify affected covered entities without unreasonable delay and within 60 days of discovery, as required by the HITECH Act. Notification will include the nature of the breach, the PHI involved, steps taken to mitigate harm, and corrective actions implemented.

7. Subcontractors and Third Parties

ScriptExchange requires all subcontractors and agents that access PHI on our behalf to execute Business Associate Agreements and maintain HIPAA-compliant safeguards. Key subcontractors include:

  • Vercel: Application hosting
  • Supabase: Managed database and authentication
  • ScriptX transmission rail: Routing of prescription and order data to the selected pharmacy partner
  • LifeFile: Pharmacy fulfillment network integration
  • Resend: Transactional email delivery

8. Retention of PHI

ScriptExchange retains PHI for the period required by our BAAs and applicable law. Prescription records are retained for a minimum of seven (7) years from the date of the prescription, consistent with DEA record-keeping requirements. Upon termination of a BAA, PHI is returned or destroyed in accordance with the terms of the agreement.

9. Changes to This Notice

ScriptExchange reserves the right to modify this Notice at any time. Changes will be effective upon posting to the Platform. Material changes will be communicated to covered entities via email.

10. Complaints and Contact

If you believe ScriptExchange has violated your HIPAA privacy rights, you may file a complaint with:

ScriptExchange will not retaliate against any individual for filing a complaint in good faith.

Privacy Officer, ScriptExchange, LLC
Email: privacy@scriptexchange.com
Address: 1309 Coffeen Avenue STE 1200, Sheridan, WY 82801