Home / Resources / Operations
Operations

How to scale a compounding pharmacy

Growth does not fail in the cleanroom. It fails at six seams in operations, and they open in a predictable order. Here is each one, the signal that it is opening, and what closes it.

A compounding pharmacy at a hundred orders a day runs on a few good people who know where everything is. At a thousand, the same people are the bottleneck, and the systems that let them cope (a fax queue, a whiteboard, a spreadsheet of lots) turn into the reasons the pharmacy cannot take the next contract. The seams open in a roughly fixed order. Knowing the order lets you close each one a quarter before it costs you a partner.

Seam 1: intake becomes data entry

The signal: a new telehealth contract means hiring for intake, and errors on ship-to state or strength start appearing in the hold queue. Faxes, emails and portal downloads do not scale; every order is re-keyed and every rule (is this state licensed, is this product controlled there) is applied by a person after the fact. What closes it: programmatic intake with the rules at the door. In Pharmacy Flow, a partner posts an order with a variant SKU, quantity, ship-to state and its own order id; the licence gate fails closed and creates the order On Hold with the reason if the state is not covered; routing picks a facility; a retried call is idempotent; and the partner gets a signed webhook. Partners who are not ready for an API submit through the portal, which runs the same gate. Everything about the request and response is on the telehealth API page.
Orders workbench with channel, brand, facility, status and eligibility columns
When intake is programmatic, the workbench shows channel, eligibility and routing on every order instead of a queue of faxes.

Seam 2: the floor runs on memory

The signal: throughput depends on which lead is on shift, and a missed cold pack or a wrong-strength parcel gets caught by the patient. What closes it: work modelled as tasks and stations gated by scans. Plan open orders into waves of pick, pack and sort tasks with cold-chain and controlled flags; dispatch them by capability; put the board where the floor can see it. Make Fill, Pack, Verify and Ship scan-gated transitions with checks behind them, so a unit that does not belong to the order, is not packed, is recalled or is past BUD cannot ship, and so the database itself refuses to mark an order shipped without a verification stamp. The Control Tower page shows the board; the automation guide explains why this comes before any robot.

The scan that replaces the lead's memory

Verify checks four things server-side on every parcel. At a hundred orders a day a good lead catches most of the errors it would catch. At a thousand, the scan is the only thing that does.

Pack verify station with order and serial scans and result

Seam 3: inventory and API supply

The signal: a batch cannot start because one excipient is out; an API lot expires on the shelf while a later one is used; a cycle count consumes a Saturday. What closes it: a lot record with rules and a forecast that buys ahead. Lots need a status that the system enforces (quarantine on receipt, release by QA, available, consumed) and consumption that is first-expiry-first by construction, not by memory. Demand should be read from actual fills, exploded through each variant's bill of materials into material requirements, compared to stock and turned into draft purchase orders by supplier. In Pharmacy Flow the forecast does this at 30, 60 or 90 days, projects weekly buckets with Holt-Winters once there is history, and the anomaly scan raises expiring lots, expired stock still available, materials below reorder and shortfalls against forecast, with one-click remediations for two of them. The inventory page covers the mechanics.
Lots list with expiry bands, status, facility and location
Lots with expiry bands and enforced status: the record that makes FEFO and forecasting possible.

Seam 4: the batch record cannot keep up

The signal: batch records are completed after the fact, component lots are copied from a label, and a question about which lots went into a batch takes a morning. What closes it: a batch that cannot exist without its lots. Creating a batch should be one transaction that inserts the finished lot in quarantine, marks the batch in process, consumes raw lots first-expiry-first with the quantity per lot recorded, floors the beyond-use date by the soonest component expiry and creates the QC tests pending; release should be a separate permission-gated action a technician cannot perform. That is how Pharmacy Flow's batch action works, and it is why a recall on a lot can trace every dispensed unit to its parcel in seconds. The compounding software page and the 503B page cover the record; the serialisation guide covers the identifiers.
Find your next seam on a demo tenant

Tell us your order volume, partners and states. We will show which seam opens next and the mechanism that closes it, using your own numbers.

Seam 5: nobody knows how today went

The signal: the answer to how are we doing is a spreadsheet that takes a day to build and is wrong by the time it is read. Margin per product is a guess; churn is discovered from a partner's email. What closes it: operational and financial views computed from the same tables the floor writes to, and a scan that finds problems before you look for them. In Pharmacy Flow the dashboard, finance views and analytics read tenant-wide SQL views; cost per fill comes from the lots actually drawn and the labour rates in settings, and is compared with the blended contracted rate per family so negative-margin variants are visible; the anomaly scan runs ten rules and links each finding to its records; and when configured, a short written briefing is produced from a numeric snapshot and cached hourly. Every order status change is in a history table with the actor, which is where stage cycle times come from. See the finance and insights section.
Financial dashboard with revenue, gross and operating margin, receivables and payables
Finance computed from orders, rate cards, lots and labour, not from a monthly export.

Seam 6: the second site

The signal: a partner wants coverage in a state your licence and shipping lanes cannot reach cheaply, or your cleanroom is at capacity. What closes it: a system that was multi-site before you needed it. Facilities should declare the families they compound and a daily capacity; orders should route by capability, brand pin, ship-to state and load with the reason on the order; lots should belong to a facility and move between sites through an approved, counted transfer; and environmental readings and line work should be scoped to the active site while finance and insights roll up. That is the model on the local manufacturing page. Opening a second site on a single-site system is the most expensive seam to discover late.
SeamSignalMechanism
IntakeHiring for data entry; state errors in the hold queueAPI and portal with a fail-closed gate and idempotency
FloorThroughput depends on who is on shiftWaves, tasks, scan-gated stations, ship interlock
InventoryStock-outs and expired lotsEnforced lot status, FEFO by construction, forecast to draft POs
Batch recordRecords completed after the factAtomic batch with consumption quantities and QC gating
VisibilityA spreadsheet that takes a daySQL views, cost per fill, anomaly scan, status history
Second siteA state you cannot serveFacilities, routing rules, transfers, per-site scoping

People, roles and permissions

Growth also changes who may do what. At a hundred orders the pharmacist releases QA, signs approvals and manages orders. At a thousand, those must be separable so that a technician can run the line without being able to release a lot, a buyer can raise purchase orders without touching quality, a finance user can see margin without seeing patients, and a partner can see only their brand. Pharmacy Flow holds eight roles with permissions in Postgres and re-checks them in every server action; approvals require the signer's own password again at the moment of signing. Segregation of duties is easier to establish before the audit that asks for it. See security & compliance and the Part 11 article.

The order to do it in

  1. 1
    Close intake first

    It is the seam that brings partners, and the gate at the door removes the largest class of rework.

  2. 2
    Then the floor and the batch record together

    Scan-gated stations and an atomic batch record share the lot and serial model; do them in the same quarter.

  3. 3
    Then inventory and forecast

    Once fills are recorded properly, the forecast has real demand to read.

  4. 4
    Then visibility

    With the record complete, the views and the anomaly scan are true rather than estimated.

  5. 5
    Then the second site

    On a system that was multi-site from the start, this is configuration, not a migration.

If you are earlier than all of this, read how to start a compounding pharmacy. If the growth is GLP-1 driven, the GLP-1 operations playbook is the specific version of this article. If you are choosing between 503A and 503B as part of scaling, 503A vs 503B sets out the difference, and the 503B launch playbook the sequence.

Frequently asked questions

What breaks first when a compounding pharmacy grows?+
Intake. A new partner contract turns into data-entry hiring and state-licence errors in the hold queue. Programmatic intake with a fail-closed licence gate closes it, and partners who are not ready for an API use a portal that runs the same gate.
Do we need automation to scale?+
Not machines. You need work modelled as tasks, dispatched and tracked, and stations gated by scans. That raises the ceiling with human labour; machines join the same queue later if the numbers justify them.
How do we stop expired lots being used?+
Enforce lot status in the database, consume first-expiry-first by construction, and run an expiry sweep that quarantines anything past its date. The anomaly scan should flag expired stock still available and offer the sweep.
Why does the batch record matter for scale?+
Because at volume you cannot reconstruct it afterwards. An atomic batch that consumes real lots with quantities and gates release on QC is what makes recall a query and audits a report.
When should we open a second site?+
When a partner needs a state you cannot serve cheaply or your cleanroom is at capacity. Do it on a system where facilities, routing and transfers already exist, so it is configuration rather than a migration.
How do roles change with scale?+
They must separate: technicians who cannot release QA, buyers who cannot touch quality, finance users who cannot see patients, partners who see only their brand. Establish segregation before the audit that asks for it.
What visibility should we expect?+
Operational and financial views computed from the same tables the floor writes to, cost per fill from real lots and labour, and a scan that finds anomalies before you look. Anything that takes a day to build is already wrong.
Keep reading

See Pharmacy Flow on your own workflow

A working platform, not a slide deck. Book a walkthrough and we'll run a real order from intake to carrier lane — or explore the public directory first, no account needed.

Free 14-day trial on signup · Free to claim a directory listing · Log in