Patient records
Every patient record is PHI-safe, role-isolated, and audit-ready.
- RLS-enforced on every read and write
- Role-scoped admin and clinician access
- Patient-owned uploads via signed URLs
End-to-end pharmacy integration, signed prescriptions, and a patient onboarding flow you can build and test in weeks. Full compliance as standard.
Health data is special-category under UK GDPR Article 9. Lawful processing requires architectural safeguards that bolt-on plugins cannot deliver.
Shopify’s own guidance is unambiguous: only non-HIPAA data. SOC 2 and PCI DSS Level 1 are not PHI cover.
GDPR, PIPEDA, and UK DPA impose parallel constraints. Each jurisdiction carries full legal weight.
Operators lose deals, pharmacy partners, and investor conviction when compliance becomes a workaround. Sync-RX builds compliance into the architecture.
Patients, orders, prescriptions, and compliance. All in one place. Everything is audit-ready from day one.
Treatment tracking, questionnaires, and test results — all white-label. Test and optimise the onboarding flow like any conversion surface.
Every patient record is PHI-safe, role-isolated, and audit-ready.
Full order lifecycle from pending to delivered, synced with the dispensing partner in real time.
Generate, sign, and dispatch prescriptions with HMAC-SHA256 integrity in every PDF.
Build and test onboarding flows with branching logic and AI flagging. No back-end code.
Trigger follow-ups, repeat-prescription gates, and partner events without back-end code.
Every auth event, record change, and patient access logged and retained for seven years.
Every control in place, published and kept current. Live in production. Pen-tested. Seven-year retention.
Live prescription submission, order webhooks, and bidirectional status sync.
Headless storefront and order sync. PHI never crosses the Shopify boundary.
Recurring billing for repeat prescriptions, with subscription release gated on clinical sign-off rather than payment.
Configurable per product line. LexisNexis for standard journeys, Verif for selfie capture on GLP-1 and consultation flows.
NHS surgery notification with in-app GP search at the point of treatment selection. Datagraphic as fallback.
Questionnaire auditing, blood test interpretation, and compliance research — all in an audited, role-scoped frame.
GLP-1 supply with mandatory wellness check-ins gating each repeat dispense.
Bloods-driven protocols, clinician sign-off, and scheduled review cadences.
Discreet patient journeys with consent capture and identity verification baked in.
Hair, skin, mental health, and adjacent men’s health categories on the same chassis.
We take on a small number of UK operators each quarter. If you’re launching a new vertical, replatforming, or scoping a pharmacy integration, we should talk.
A member of the Sync-RX team will reach out shortly with next steps.