Privacy Policy

Total Script Solutions (“Total Script,” “we,” “us,” or “our”) operates totalscriptsolutions.com, the clinic ordering portal, and related operations software (together, the “Service”). This Privacy Policy explains how we collect, use, disclose, and protect personal information and Protected Health Information (“PHI”) as defined by the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”).

Total Script is a pharmaceutical sourcing and fulfillment-coordination partner for licensed clinics and pharmacies. We are not a 503A compounding pharmacy or a 503B outsourcing facility, and we do not ourselves compound, dispense, or practice medicine. Partner pharmacies that fill named-patient prescriptions are independently responsible for their own HIPAA notices and dispensing records.

1. Definitions

When personal information and PHI overlap, we treat that information with the protections HIPAA requires.

2. Information we collect

We may collect information from you, from authorized clinic staff, from partner pharmacies, from Google when you connect a Google account, and automatically when you use the Service:

Patient information is collected only as needed to fulfill a named-patient prescription through a partner pharmacy, or as otherwise permitted by law.

3. How we use information

4. Google Calendar and Google user data

Staff users of the operations software may connect a personal or work Google account so the Service can display that user’s Google Calendar. This is a per-user connection. We do not use a company-wide Google key. Other staff users do not receive your Google Calendar events.

Connecting a Google account is voluntary. The Service works without it. If you connect, we request only these Google API scopes:

What we access

When you open the calendar in the Service, we read the month currently on screen:

We use the title and attendee emails only to match the event to a clinic or lead already stored in the Service, so you can open that record from the meeting. When you create an event from the Service, we also write a private tag on that Google event (meeting vs follow-up, and the clinic or lead you picked) so it stays classified after you reload. We do not import Google contacts, Gmail, Drive, or any other Google product.

Clinic booking against a designated specialist

Authenticated clinic users of the ordering portal can book a product call with one designated specialist (the staff user whose email is configured for that feature). If that specialist has connected Google Calendar, we read occupied start and end times from that calendar so the clinic can see when the specialist is free. We do not show clinics event titles, descriptions, locations, attendee lists, or other calendar content belonging to the specialist. Booking writes a new event on the specialist’s calendar, adds a Google Meet link, and emails a calendar invite to the clinic user who booked.

Meetings a clinic has booked (or been invited to) may be shown back to that clinic with the title and Meet link they already received as an invitee. Disconnecting Google Calendar from the calendar page stops clinic booking against that account.

What we store

We persist only what is required to keep the connection:

We do not keep a copy of your calendar. Event details are requested from Google when you view the calendar in the Service, or when a clinic loads the booking page against a designated specialist’s calendar, and are not archived as a second calendar. We request at most the month currently on screen (six weeks).

How we use Google user data

Google user data is used only to provide and improve the user-facing calendar features: show staff their meetings, let them schedule a meeting or follow-up, link those events to clinics and leads in the Total Script workspace, and let authenticated clinic users book a product call against a designated specialist’s busy/free times. We do not use Google user data to serve advertisements, to train generalized AI or machine-learning models, or for any purpose other than those features.

Sharing, transfer, and sale

We do not sell Google user data. We do not transfer Google user data to third parties except as needed to operate the Service (our hosting and database providers, acting as processors under our instructions), to comply with law, or with your direction. Other staff users do not receive your Google Calendar events through this feature. Authenticated clinic users see only busy/free times from a designated specialist’s connected calendar, plus meetings they are a party to.

How to disconnect

You can disconnect Google Calendar at any time from the calendar page in the Service. That deletes the stored tokens and email from our systems and asks Google to revoke the grant. You can also revoke access in your Google Account under Google Account → Third-party apps & services. After revoke, we can no longer read your calendar or create events on it until you connect again.

Google’s use of information it receives from this integration is governed by the Google Privacy Policy.

5. Google API Services User Data Policy (Limited Use)

Our use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. In particular:

6. How we disclose information

We disclose PHI and personal information only as permitted or required by HIPAA and other applicable law, including:

We do not sell PHI. We do not use or disclose PHI for marketing without the authorization HIPAA requires.

7. Your rights regarding PHI

Depending on your relationship to the information, HIPAA may give you the right to:

To exercise these rights, contact us using the information below. If a partner pharmacy holds the dispensing record, we may need to direct you to that pharmacy.

8. Other requests about your information

Staff users may disconnect Google Calendar as described in Section 4. You may also email us to ask what personal information we hold about your staff account, to correct it, or to request deletion of the Google connection records associated with your user. We will honor those requests except where we must retain information for legal, security, or accounting purposes, or where the information is PHI subject to the process in Section 7.

9. Our duties

10. Security

We use administrative, technical, and physical safeguards, including encryption in transit (TLS), access controls, host-only session cookies, and encryption of stored Google OAuth tokens, to protect the confidentiality, integrity, and security of information on the Service. No method of transmission or storage is completely secure. We cannot guarantee absolute security.

11. Retention

We keep account, order, and PHI records for as long as needed to provide the Service, meet legal and pharmacy-coordination obligations, and resolve disputes. Google OAuth tokens and the connected Google email are kept only while the calendar remains connected, and are deleted when you disconnect or when the staff account is removed.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will post the revised notice on this page and update the effective date. Continued use of the Service after a change is posted constitutes acceptance of the revised policy, except where applicable law requires a different process for PHI.

13. Contact

Privacy questions, HIPAA requests, Google data requests, and complaints about this policy can be sent to:

Total Script Solutions
Email: juan@totalscriptsolutions.com
Phone: 305-331-5120

You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights, 200 Independence Avenue S.W., Washington, D.C. 20201, 1-877-696-6775, hhs.gov/ocr/privacy/hipaa/complaints. We will not retaliate against you for filing a complaint.

Related: Terms of Use and FAQ.