Shipping medicine to patients in fifty states is a licensing problem, a floor problem and a carrier problem before it is a dispensing problem. Pharmacy Flow gates every order on licensure, runs the floor with scan interlocks, and keeps every carrier event.
A mail-order pharmacy's exposure is measured in parcels: the one that went to a state where the licence lapsed last month, the one that shipped without a verify scan, the cold one that sat on an ambient bench, the one the carrier marked delivered twice. Each of those is a rule the system can apply before the parcel exists. This page describes the rules Pharmacy Flow applies, the floor it runs, and the record it keeps for each shipment.
Nonresident licensure: the gate that fails closed
Every state licenses pharmacies located outside it that ship prescriptions to its residents, and the rules for controlled substances and compounded products differ state by state. In Pharmacy Flow the licensing master holds one record per state with status, validity dates and whether compounded controlled substances are permitted. Every order — from staff entry, the partner portal or the ordering API — is evaluated against the ship-to state before it is accepted, and the evaluation fails closed: no licence on file for the state, a licence that is expired or not in active or expiring status, or a controlled product into a state whose record says controlled is not permitted all place the order on hold with the reason shown. A licence renewal is a data change. The check is one function called by every intake path, so a brand's API order and a walk-in order get the same answer.
An order lifecycle enforced in the database
Orders move Received → Eligibility → Clinical Review → In Production or line fill → Packed → Shipped → Delivered, with On Hold and Cancelled reachable from working states. The allowed transitions are a table in Postgres and a trigger rejects any update not in it. The database also checks two interlocks: an order cannot be Packed without a finished lot, and cannot be Shipped without a recorded pack verification. An order tied to a prescription cannot be Packed or Shipped unless the prescription is Filled. Every change writes a status-history row with actor and time, which feeds cycle-time and hold-reason reporting per stage, brand and facility.
Orders by stage, brand and facility: the hold reason is on the row, not in someone's inbox.
The floor: fill, pack, verify, ship
The production line is a scan-driven shell built for a touch screen. At fill, scanning a unit against an order checks that the serial exists, belongs to this order, is not recalled and is not past BUD, and refuses the fill with the reason otherwise. Each unit carries a GS1 DataMatrix label with GTIN, lot and serial; parcels are aggregated into cartons and pallets with an SSCC on a GS1-128 label, and every step writes an EPCIS-style event with read point, business step and disposition. Pack verification is a separate scan by a separate step and is the ship interlock — a unit that has not passed verify cannot be shipped, and the database rejects the transition. A failed verify sends the order to On Hold; re-verification brings it back to Packed. Labels print as ZPL to networked printers, with print jobs recorded against the serial.
The line: units queued at fill, pack, verify and ship, with the verify interlock's pass/fail on each.
Carriers: scans stored once, delivery that honours holds
Carrier tracking events arrive by webhook and are stored one row per event, keyed on the carrier's event id when one is sent and otherwise on parcel, timestamp and raw status. A carrier retry therefore never creates a duplicate scan, and a long journey keeps its early history. A delivered scan cascades to the order — but not if the order is under a QA hold, which is the difference between a system that records what the carrier said and one that also records what the pharmacy decided. Outbound notifications to partners go through an outbox with retries, so a partner's endpoint being down does not lose the event. Returns carry structured reasons — damaged in transit, cold-chain breach, undeliverable, patient return, wrong item, recalled — so return analysis is a query.
Shipping: every parcel with its carrier, service, cold-chain flag and last scan.
Cold chain and packout
Packout is a field on the order — standard, cold-chain (insulated with gel packs), frozen (dry ice) or hazardous (segregated) — derived from the product's storage requirement, and the cold-chain flag travels on the parcel to the carton and the carrier record. Refrigerated and frozen materials are routed to matching storage on receipt by the putaway rule. Temperature excursion is a deviation category with investigation and CAPA. Which insulated configuration and service level you validate for each lane and season is your procedure; the cold-chain guide covers it, and the GLP-1 fulfilment page covers the product category where it matters most.
Ship one parcel with us, start to finish
Intake from a brand API, the licence gate, fill and verify scans, an SSCC carton, carrier scans arriving, delivered — on live software.
Subscriptions generate orders on a 28-, 30- or 90-day cadence. Each generated order runs the same eligibility, licence and refill checks as a new one: Schedule II refills are refused, Schedule III–V refills are refused beyond five or beyond six months from the written date, and a controlled material without a parseable schedule holds the refill for manual verification. The pharmacist's DUR screen at verification raises duplicate therapy, GLP-1 class duplication, controlled-with-refills, quantity-versus-days-supply and a counselling reminder, and states explicitly that no allergies are on file. The 503A page lists the compliance rules in full.
Intake: brands, portal and API
Mail-order volume comes from telehealth brands and B2B partners. Each brand is a first-class record with its own API key and its own view of orders, so a pharmacy can fulfil for several brands with separate reporting. The ordering API is idempotent on a client order id — a retried request returns the existing order — and runs the licence gate before accepting. The partner portal gives a brand or clinic order status with carrier scans, subscriptions, invoices and support. Details are on the ordering API page and the partners page.
A brand's portal view of its orders and their shipment status.
Scale: Control Tower and multi-facility
The Control Tower is the floor's live view: orders by stage, holds by reason, throughput, and the queue at each station. Facilities are first-class with their own locations, capacity and qualified product families; orders route to a facility by capability and ship-to state, with contractual pinning where a brand must be served from one site, and inter-site transfers are two-sided (the sender releases the lot, the receiver counts what arrived). Finance follows the same records — receivables by brand, income statement, weekly review — and analytics run on the status history and carrier events rather than on estimates. See the Control Tower page, the fulfilment automation page for the path to robotics, and the automation guide.
The dashboard: orders by stage, holds by reason, parcels in transit and exceptions needing a person.
Who this is for
Direct-to-patient pharmacy
Fulfilling for one or many telehealth brands into most states, with licence exposure as the main risk.
Central fill for a group
One facility filling for several dispensing sites, with transfers and per-site reporting.
The lists and dashboards are paged in SQL rather than loaded whole, the floor is scan-driven with per-station queues, carrier events are stored as rows, and facilities route by capability. We do not publish a throughput figure because it depends on your stations, staff and carriers; on the demo we will show the floor and the Control Tower on realistic volume.
Does it handle subscriptions and cold-chain?+
Subscriptions generate orders on a 28-, 30- or 90-day cadence with the same checks as new orders. Packout is a field on the order and the cold-chain flag travels to the parcel, carton and carrier record; refrigerated and frozen materials are routed to matching storage on receipt.
What happens if we ship to a state where our licence expired?+
The order is held at eligibility with the reason before it reaches the floor. The gate fails closed: missing, expired or inactive licences block, and a controlled product into a state that does not permit compounded controlled substances blocks.
Which carriers are integrated?+
Carrier tracking is ingested by webhook into a per-event scan table and labels print as ZPL. Carrier label purchasing inside the platform is on the roadmap rather than in the product today; ask on the demo call which carriers you use and we will tell you the current state plainly.
Can we run several brands on one account?+
Yes. Each brand has its own API key, portal view and reporting; orders carry the brand through fulfilment and finance.
How is a duplicate delivery scan prevented?+
Scans are stored one row per carrier event with a unique index on parcel and carrier event id (or parcel, timestamp and raw status when the carrier sends no id). A retry matches the existing row and is ignored.
Is patient data secure?+
Tenants are isolated by Postgres row-level security, permissions are rows in the database checked by the status functions, and events, approvals and the audit log are append-only for application users. See security and compliance.
A working platform, not a slide deck. Book a walkthrough and we'll run a real order from intake to carrier lane — or explore the public directory first, no account needed.