Legal informationPrivacy Policy

Privacy Policy

The short answer

Effective August 12, 2026. PharmaFix LLC operates PharmaFix. Authorized reports are transmitted to the hosted analyzer for transient processing, while limited credit, payment-reference, restore, session, contact, and technical metadata may be retained to operate the service.

Who operates PharmaFix

PharmaFix is operated by PharmaFix LLC, 166 Industrial Loop Bay 3, Staten Island, NY 10309. For privacy and support questions, use the Contact form.

Scope

This Policy applies to the PharmaFix website, analyzer, credit purchase and restoration features, and contact or lead forms operated through this site. It does not govern third-party providers' independent services and notices.

Report data you submit

No PHI or BAA-required reports

Do not upload protected health information (PHI). If a business associate agreement (BAA) is required for your report, do not upload it to the current service. Using PharmaFix or accepting these Terms does not create a BAA. Only use lawfully de-identified reports that you are authorized to submit, or fictional test data. If you are unsure, do not upload the report.

  • Supported report fields may include fill date, BIN, group, NDC, and amount paid.
  • The report is transmitted over HTTPS to the hosted analyzer and processed transiently to return the requested result.
  • The app is designed not to persist the raw report, claim rows, report NDCs and amounts, generated PDF, or analysis result in its application database or saved-report history.
  • Do not upload patient names, member IDs, prescription numbers, full dates of birth, addresses, Social Security numbers, or other direct patient identifiers.
  • PharmaFix automatically rejects reports when it detects a patient-name column. This check examines column headings, not every value in the report, and may miss names elsewhere. Passing this check does not establish that a report is de-identified, HIPAA compliant, or free of sensitive information.
  • The report is transmitted to the hosted analyzer before this check runs. Rejection does not mean that the report was never received. Review your report before uploading; do not rely on this check to remove sensitive information.

Other information we process

  • Purchase email, credit balance, credit-ledger entries, payment-event and checkout references, and transaction status.
  • Restore-request email and hashed, single-use restore-token metadata. Restore links currently expire after 30 minutes.
  • An essential signed browser-session cookie used to reconnect the browser to credit access. The current cookie lifetime is up to 180 days unless it is cleared sooner.
  • Theme preference stored locally in the browser.
  • Name, pharmacy name, email address, optional phone number, and optional message voluntarily submitted through a contact or lead form. Do not submit pharmacy reports, report rows, or patient information through these forms.
  • For a submitted website lead, our backend database service provider stores the submitted business-contact record and the fixed record prepared for delivery. Our business-contact service provider receives name, normalized email, optional phone and optional message when provided, website-lead source, disclosure version, and capture timestamp. Pharmacy name stays with the backend database service provider and is not sent to the business-contact service provider. Providing a phone is contact-only and does not consent to calls or texts.
  • Technical request information that hosting and security systems may process, such as IP address, user agent, timestamps, route, response status, and diagnostic logs. The app is designed not to log report rows or detected patient names.

Why we process this information

  • Provide the requested analysis and browser-generated exports.
  • Process checkout, grant and consume credits, prevent duplicate grants, and maintain the credit ledger.
  • Send a requested one-time credit-restore link and respond to support requests.
  • Record and manage a requested contact-form follow-up without enrolling the person in customer-facing messages or workflows. A Draft internal-only operator notification may alert staff; it sends no customer message.
  • Maintain availability, diagnose errors, prevent abuse, and comply with applicable legal obligations.

Service providers

Current product data flow

Provider categoryRoleReport data
Hosting and security providersHost the website and analysis endpointReceive the uploaded request for transient processing and may process technical infrastructure logs
Payment processorCheckout and payment processingDoes not receive the uploaded report; processes payment, email, amount, and payment references
Database and account providersCredit source of truth, ledger, restore-token metadata, and submitted contact metadataThe app is designed not to store report rows or analysis results there
Email-delivery providerTransactional credit-restore emailDoes not receive uploaded report rows or generated results
Business-contact providersProcess contact information voluntarily submitted through website formsDo not receive report data, payment data, credit balances, authentication data, or restore links

Retention and deletion

Uploaded report content is intended to exist only for the analysis request and is not intentionally retained by the app after the response. Restore tokens expire after 30 minutes, although security and audit metadata may remain for a limited period. Credit-account and ledger records may be retained while credits remain available and as reasonably necessary for payment records, dispute handling, fraud prevention, and legal obligations.

Your choices and requests

You may clear the essential session cookie or local theme setting in your browser, but clearing the session cookie can disconnect local credit access until you use restore by email. To request access, correction, or deletion of retained personal information, use the Contact form. Requests will be handled subject to identity verification and legal recordkeeping requirements.

HIPAA and sensitive report information

PharmaFix is not intended to receive protected health information (PHI) and does not represent that removing patient names alone makes a report de-identified or HIPAA compliant. Exact fill dates and other claim details may still be identifying. Authorization to access a pharmacy report does not by itself establish permission to send it to this service. Whether HIPAA, a business associate agreement, state law, or other requirements apply depends on the parties, data, contracts, and use. Do not submit a report unless its use satisfies the no-PHI upload requirements; obtain qualified legal and compliance advice if you are unsure. PharmaFix does not de-identify reports for you or certify their legal status.

Changes

Material changes will be posted here with a revised review or effective date. If the product begins storing report history, adds analytics, changes providers, or enables live payments, this Policy must be updated before that change is released.

Related reading