Legal
How ScriptXchange handles Protected Health Information under the Health Insurance Portability and Accountability Act.
Last updated: June 24, 2026
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
ScriptXchange, LLC ("ScriptXchange") operates as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act. We process Protected Health Information (PHI) on behalf of covered entities, including licensed prescribers, clinics, and healthcare organizations, that use our Platform to transmit electronic prescriptions and manage patient orders.
As a Business Associate, ScriptXchange is required to maintain the privacy and security of PHI in accordance with the HIPAA Privacy Rule (45 CFR Part 164) and Security Rule. We execute Business Associate Agreements (BAAs) with all covered entities and pharmacy partners in our network.
PHI is individually identifiable health information that relates to a patient's past, present, or future physical or mental health condition, the provision of healthcare, or payment for healthcare. PHI processed through ScriptXchange includes:
ScriptXchange uses and discloses PHI only as permitted or required by our Business Associate Agreements and applicable law, including:
ScriptXchange will not use or disclose PHI for marketing purposes, sell PHI, or use PHI in ways not permitted by our BAAs without obtaining a valid HIPAA authorization from the patient, except as required by law.
ScriptXchange applies the minimum necessary standard to all uses and disclosures of PHI. We access, use, and disclose only the PHI reasonably necessary to accomplish the intended purpose.
ScriptXchange implements comprehensive administrative, physical, and technical safeguards to protect PHI in accordance with the HIPAA Security Rule, including:
As a Business Associate, ScriptXchange supports covered entities in fulfilling patient rights under HIPAA. Patients who wish to exercise their rights regarding their PHI, including the right to access, amend, or request an accounting of disclosures, should contact the covered entity (prescriber or clinic) that submitted their information to the Platform.
Covered entities using ScriptXchange may contact us at privacy@pharmaxis.health to request assistance in fulfilling patient rights requests.
In the event of a breach of unsecured PHI, ScriptXchange will notify affected covered entities without unreasonable delay and within 60 days of discovery, as required by the HITECH Act. Notification will include the nature of the breach, the PHI involved, steps taken to mitigate harm, and corrective actions implemented.
ScriptXchange requires all subcontractors and agents that access PHI on our behalf to execute Business Associate Agreements and maintain HIPAA-compliant safeguards. Key subcontractors include:
ScriptXchange retains PHI for the period required by our BAAs and applicable law. Prescription records are retained for a minimum of seven (7) years from the date of the prescription, consistent with DEA record-keeping requirements. Upon termination of a BAA, PHI is returned or destroyed in accordance with the terms of the agreement.
ScriptXchange reserves the right to modify this Notice at any time. Changes will be effective upon posting to the Platform. Material changes will be communicated to covered entities via email.
If you believe ScriptXchange has violated your HIPAA privacy rights, you may file a complaint with:
ScriptXchange will not retaliate against any individual for filing a complaint in good faith.
Privacy Officer, ScriptXchange, LLC
Email: privacy@pharmaxis.health
Address: 1330 Pin Oak Rd, Katy, TX 77494