Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that information submitted through a pharmacy account login, including prescription order data, is governed by HIPAA's Notice of Privacy Practices rather than this privacy policy, creating a distinct legal framework for pharmacy interactions separate from general retail data practices.
This analysis describes what Walgreens's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a structural data governance boundary between HIPAA-covered pharmacy data and general retail personal information, which determines which consumer rights framework and which notice and consent mechanisms apply depending on the nature of the customer interaction.
Under this provision, customers who submit prescription information through their pharmacy account operate under the Walgreens Notice of Privacy Practices governed by HIPAA rather than this privacy policy, which means the rights and protections described in this document do not apply to that data. Customers with questions about which policy applies to their data are directed to contact Walgreens customer service.
Cross-platform context
See how other platforms handle HIPAA Carve-Out for Pharmacy Account Data and similar clauses.
Compare across platforms →Monitoring
Walgreens has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"In some circumstances, Walgreens' use of your information will be subject to the requirements of the Health Insurance Portability and Accountability Act (commonly known as 'HIPAA'). For example, if you log in to your pharmacy account and submit information regarding a prescription order, that information is subject to HIPAA's requirements. In those circumstances, the Walgreens Notice of Privacy Practices and not this Privacy Policy will apply.Excerpt from Walgreens's Privacy Policy
1. REGULATORY LANDSCAPE: This provision directly engages HIPAA's Privacy Rule, enforced by HHS Office for Civil Rights. HIPAA's Notice of Privacy Practices requirements govern the use and disclosure of protected health information by covered entities and their business associates. The boundary between HIPAA-covered data and non-HIPAA retail data is a recognized compliance challenge in pharmacy retail contexts, and HHS guidance addresses the treatment of health information collected outside of a covered entity transaction. 2. GOVERNANCE EXPOSURE: High. The operational distinction between pharmacy account data and general retail data requires that Walgreens accurately identify and segregate data collected in each context, ensure that the correct notice is presented to users at each interaction point, and that data systems do not commingle HIPAA-covered information with general retail personal information used for advertising or marketing purposes. 3. JURISDICTION FLAGS: HIPAA applies nationally to covered entities and their business associates regardless of state. However, several states including California impose additional health data protections that may apply to health information collected outside of a HIPAA-covered transaction, including health-related retail purchases not covered by this carve-out. Washington's My Health MY Data Act and other state health data statutes may create additional obligations for retail health data outside the HIPAA boundary. 4. CONTRACT AND VENDOR IMPLICATIONS: Business associate agreements must be in place with any vendor that processes HIPAA-covered pharmacy data. Vendors receiving general retail data that also includes health-related retail purchase data must be governed by appropriate contractual data use restrictions distinct from HIPAA BAA requirements. Procurement teams should assess whether any vendor touches both data categories and ensure segregation or dual agreement structures are in place. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should audit the user interface and data collection workflows to confirm that the applicable notice is clearly presented at the point where the user transitions between a retail interaction and a pharmacy account interaction. Data mapping should verify that prescription and pharmacy data is not accessible by marketing, analytics, or advertising systems governed by the general retail privacy policy. Records management policies should separately address HIPAA and non-HIPAA health data retention and destruction obligations.
This provision establishes a structural data governance boundary between HIPAA-covered pharmacy data and general retail personal information, which determines which consumer rights framework and which notice and consent mechanisms apply depending on the nature of the customer interaction.
Under this provision, customers who submit prescription information through their pharmacy account operate under the Walgreens Notice of Privacy Practices governed by HIPAA rather than this privacy policy, which means the rights and protections described in this document do not apply to that data. Customers with questions about which policy applies to their data are directed to contact Walgreens customer …
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Walgreens.