Privacy Policy
Effective date: August 25, 2026
Total Script Solutions (“Total Script,” “we,” “us,” or “our”) operates totalscriptsolutions.com, the clinic ordering portal, and related operations software (together, the “Service”). This Privacy Policy explains how we collect, use, disclose, and protect personal information and Protected Health Information (“PHI”) as defined by the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”).
Total Script is a pharmaceutical sourcing and fulfillment-coordination partner for licensed clinics and pharmacies. We are not a 503A compounding pharmacy or a 503B outsourcing facility, and we do not ourselves compound, dispense, or practice medicine. Partner pharmacies that fill named-patient prescriptions are independently responsible for their own HIPAA notices and dispensing records.
1. Definitions
- Protected Health Information (PHI) means individually identifiable health information we maintain or transmit (electronic, oral, or written) that relates to a person’s past, present, or future physical or mental health, the care they receive, or payment for that care.
- Personal information includes name, email, phone number, clinic or pharmacy identifiers (including NPI), account credentials, and similar data you provide when you use the Service.
- Google user data means information we receive from Google APIs when a staff user of the Service chooses to connect their Google account, including the Google account email and Calendar event information described in Section 4.
When personal information and PHI overlap, we treat that information with the protections HIPAA requires.
2. Information we collect
We may collect information from you, from authorized clinic staff, from partner pharmacies, from Google when you connect a Google account, and automatically when you use the Service:
- Account and clinic information: name, practice name, email, phone, NPI, and related onboarding details.
- Prescription and patient information (PHI): the patient, prescriber, and product data required to route a named-patient order to a licensed partner pharmacy.
- Google Calendar information: if a staff user connects Google Calendar, the Google account email and the calendar event fields listed in Section 4. Connecting Google is optional. Clinic portal users are not asked to connect a Google account.
- Usage data: IP address, browser type, pages viewed, and similar logs used to operate and secure the Service.
- Cookies and similar technologies: used to keep you signed in, remember preferences, and understand how the Site is used.
Patient information is collected only as needed to fulfill a named-patient prescription through a partner pharmacy, or as otherwise permitted by law.
3. How we use information
- To provide the Service: open clinic accounts, process orders, route prescriptions to partner pharmacies, coordinate shipping, and support billing.
- Staff calendar: show a connected staff user their own upcoming meetings inside the Service, let them create a meeting or follow-up on their Google Calendar (including an optional Google Meet link), and match those events to clinics and leads already in the Service. See Section 4.
- Payment and operations: invoicing, payment processing, quality review, and improving how the Service works.
- Communications: respond to inquiries, send service updates, and provide support.
- Legal and compliance: meet applicable laws, licensing rules, and certification-program requirements.
- Security: detect, prevent, and investigate fraud, abuse, and technical issues.
4. Google Calendar and Google user data
Staff users of the operations software may connect a personal or work Google account so the Service can display that user’s Google Calendar. This is a per-user connection. We do not use a company-wide Google key. Other staff users do not receive your Google Calendar events.
Connecting a Google account is voluntary. The Service works without it. If you connect, we request only these Google API scopes:
- calendar.events — read events on the connected calendar, and create a new event when you schedule a meeting or follow-up from the Service. Creating an event can include a Google Meet link and optional email invites to guests. We do not edit or delete events you created in Google Calendar. Google Calendar remains the system of record.
- userinfo.email — read the Google account email so we can show which account is connected and so you can confirm it is the right one.
What we access
When you open the calendar in the Service, we read the month currently on screen:
- event title, start and end time (or all-day date), and status;
- location, Google Meet or other conference link, and the event’s Google Calendar URL;
- attendee email addresses and display names (other than your own).
We use the title and attendee emails only to match the event to a clinic or lead already stored in the Service, so you can open that record from the meeting. When you create an event from the Service, we also write a private tag on that Google event (meeting vs follow-up, and the clinic or lead you picked) so it stays classified after you reload. We do not import Google contacts, Gmail, Drive, or any other Google product.
Clinic booking against a designated specialist
Authenticated clinic users of the ordering portal can book a product call with one designated specialist (the staff user whose email is configured for that feature). If that specialist has connected Google Calendar, we read occupied start and end times from that calendar so the clinic can see when the specialist is free. We do not show clinics event titles, descriptions, locations, attendee lists, or other calendar content belonging to the specialist. Booking writes a new event on the specialist’s calendar, adds a Google Meet link, and emails a calendar invite to the clinic user who booked.
Meetings a clinic has booked (or been invited to) may be shown back to that clinic with the title and Meet link they already received as an invitee. Disconnecting Google Calendar from the calendar page stops clinic booking against that account.
What we store
We persist only what is required to keep the connection:
- the Google account email;
- OAuth access and refresh tokens, encrypted at rest, used solely to call Google Calendar on your behalf;
- the calendar identifier (your primary calendar) and the time you connected.
We do not keep a copy of your calendar. Event details are requested from Google when you view the calendar in the Service, or when a clinic loads the booking page against a designated specialist’s calendar, and are not archived as a second calendar. We request at most the month currently on screen (six weeks).
How we use Google user data
Google user data is used only to provide and improve the user-facing calendar features: show staff their meetings, let them schedule a meeting or follow-up, link those events to clinics and leads in the Total Script workspace, and let authenticated clinic users book a product call against a designated specialist’s busy/free times. We do not use Google user data to serve advertisements, to train generalized AI or machine-learning models, or for any purpose other than those features.
Sharing, transfer, and sale
We do not sell Google user data. We do not transfer Google user data to third parties except as needed to operate the Service (our hosting and database providers, acting as processors under our instructions), to comply with law, or with your direction. Other staff users do not receive your Google Calendar events through this feature. Authenticated clinic users see only busy/free times from a designated specialist’s connected calendar, plus meetings they are a party to.
How to disconnect
You can disconnect Google Calendar at any time from the calendar page in the Service. That deletes the stored tokens and email from our systems and asks Google to revoke the grant. You can also revoke access in your Google Account under Google Account → Third-party apps & services. After revoke, we can no longer read your calendar or create events on it until you connect again.
Google’s use of information it receives from this integration is governed by the Google Privacy Policy.
5. Google API Services User Data Policy (Limited Use)
Our use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We use Google user data only to provide or improve user-facing features that are prominent in the Service’s user interface (the staff calendar, and clinic booking of a product call against a designated specialist’s busy/free times).
- We do not use Google user data for serving advertisements.
- We do not allow humans to read Google user data unless you give us permission, it is necessary for security purposes (investigating abuse), we are complying with applicable law, or the data is aggregated and no longer associated with you.
- We do not transfer Google user data to others except as necessary to provide or improve those features, for security, to comply with law, or as part of a merger, acquisition, or sale of assets with notice to you.
6. How we disclose information
We disclose PHI and personal information only as permitted or required by HIPAA and other applicable law, including:
- To you or your authorized representative, upon request.
- To partner pharmacies and other healthcare professionals involved in filling or coordinating an order.
- To payment processors, email providers, cloud hosts, and other service providers who help us operate the Service, under appropriate agreements. Google receives OAuth credentials when you connect a Google account, as described in Section 4.
- As required by law, including in response to a valid legal process.
- To prevent a serious and imminent threat to health or safety, when permitted.
- With your written authorization, for uses not otherwise described here.
We do not sell PHI. We do not use or disclose PHI for marketing without the authorization HIPAA requires.
7. Your rights regarding PHI
Depending on your relationship to the information, HIPAA may give you the right to:
- Inspect and obtain a copy of PHI we maintain, usually within 30 days of a request.
- Request an amendment if you believe PHI is incorrect or incomplete.
- Request restrictions on certain uses or disclosures. We will consider reasonable requests; we are not always required to agree.
- Request confidential communications at an alternative address or by an alternative method.
- Request an accounting of certain disclosures of PHI for the prior six years.
- Request a paper copy of this notice at any time.
- File a complaint with us or with the U.S. Department of Health and Human Services if you believe your privacy rights have been violated.
To exercise these rights, contact us using the information below. If a partner pharmacy holds the dispensing record, we may need to direct you to that pharmacy.
8. Other requests about your information
Staff users may disconnect Google Calendar as described in Section 4. You may also email us to ask what personal information we hold about your staff account, to correct it, or to request deletion of the Google connection records associated with your user. We will honor those requests except where we must retain information for legal, security, or accounting purposes, or where the information is PHI subject to the process in Section 7.
9. Our duties
- We are required by law to maintain the privacy and security of PHI and to follow the practices described in this notice.
- We will notify affected individuals as required if a breach compromises the privacy or security of unsecured PHI.
- We will not retaliate against you for filing a complaint or exercising HIPAA rights.
10. Security
We use administrative, technical, and physical safeguards, including encryption in transit (TLS), access controls, host-only session cookies, and encryption of stored Google OAuth tokens, to protect the confidentiality, integrity, and security of information on the Service. No method of transmission or storage is completely secure. We cannot guarantee absolute security.
11. Retention
We keep account, order, and PHI records for as long as needed to provide the Service, meet legal and pharmacy-coordination obligations, and resolve disputes. Google OAuth tokens and the connected Google email are kept only while the calendar remains connected, and are deleted when you disconnect or when the staff account is removed.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will post the revised notice on this page and update the effective date. Continued use of the Service after a change is posted constitutes acceptance of the revised policy, except where applicable law requires a different process for PHI.
13. Contact
Privacy questions, HIPAA requests, Google data requests, and complaints about this policy can be sent to:
Total Script Solutions
Email: juan@totalscriptsolutions.com
Phone: 305-331-5120
You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights, 200 Independence Avenue S.W., Washington, D.C. 20201, 1-877-696-6775, hhs.gov/ocr/privacy/hipaa/complaints. We will not retaliate against you for filing a complaint.
Related: Terms of Use and FAQ.