Resources / Start a digital clinic

Telehealth Compliance Checklist for New Founders

Short answer: A telehealth compliance checklist for new founders covers provider licensure in each patient’s state, corporate practice of medicine rules, HIPAA and business associate agreements, LegitScript certification, FTC rules on health claims and breach notification, FDA marketing rules for compounded drugs, ad platform policies, controlled substance rules, TCPA consent for texts, state health data privacy laws and record keeping.

Compliance is the part of launching a telehealth brand that founders most often underestimate, and it is the part that is most expensive to fix later. This telehealth compliance checklist gives you the full map in one place: what each rule is, who enforces it, and what to confirm before you launch. It will not replace a healthcare attorney, but it will help you ask better questions and avoid the mistakes we see most often.

Work through each section, mark what applies to your digital clinic, and bring the list to your legal and platform partners.

Why a telehealth compliance checklist matters

A telehealth brand sits at the intersection of healthcare, pharmacy, advertising, data privacy and telecommunications law. Each area has its own regulators. A single landing page can touch the FDA (drug claims), the FTC (health claims and data), state medical and pharmacy boards (licensure) and ad platform policy teams at the same time. Missing one piece can mean a rejected ad account, a paused merchant account or a regulatory letter.

The good news: most requirements are knowable in advance. Build them into your launch plan from week one, not after your first ad gets rejected.

The telehealth compliance checklist at a glance

Area Main regulator or authority What to confirm
Provider licensure State medical and nursing boards Providers licensed where each patient is located
Corporate practice of medicine State law and medical boards Ownership structure reviewed by a healthcare attorney
HIPAA and BAAs HHS Office for Civil Rights Signed BAAs with every vendor handling protected health information
LegitScript LegitScript (recognized by ad platforms and card networks) Certification plan for each website
Health claims Federal Trade Commission Substantiation for every objective claim
Health Breach Notification Rule Federal Trade Commission Breach response plan for health data outside HIPAA
Compounded drug marketing U.S. Food and Drug Administration No FDA-approved, generic or sameness claims
Ad platforms Meta and Google policy teams Certification and platform authorization before running ads
Controlled substances DEA and HHS Current telemedicine prescribing rules, if applicable
SMS marketing Federal Communications Commission (TCPA) Documented consent and working opt-out
State health data privacy State attorneys general Consent flows and consumer health data policy
Record keeping HHS and state law Retention schedule for records and documentation

1. State licensure

According to Telehealth.HHS.gov, health professionals must meet the licensure requirements of the state where they are located and be licensed or legally permitted to practice in the state where the patient is located. For your brand, that means the providers reviewing intakes must be licensed in every state you serve.

Interstate compacts, such as the Interstate Medical Licensure Compact for physicians and the Nurse Licensure Compact for nurses, can make multistate licensing faster, and some states offer telehealth registrations for out-of-state providers. Each state sets its own rules, so confirm coverage state by state before you open intake there.

2. Corporate practice of medicine

Many states have corporate practice of medicine (CPOM) rules that limit how non-clinicians can own or control a medical practice or influence clinical decisions. The American Medical Association has publicly strengthened its opposition to corporate control of medicine, and state enforcement varies. Some founders use a management services organization (MSO) and professional corporation (PC) structure to separate the business side from clinical decision-making. Whether that is needed depends on your state and model. We cover this in depth in How to Start a Telehealth Business Without Being a Doctor.

3. HIPAA and business associate agreements

If your business handles protected health information (PHI) as a covered entity or business associate, HIPAA’s Privacy, Security and Breach Notification Rules apply. HHS explains that a written contract between a covered entity and a business associate must establish the permitted uses and disclosures of PHI, require appropriate safeguards (including the Security Rule for electronic PHI) and require reporting of uses or disclosures not allowed by the contract, including breaches.

In practice, list every vendor that touches patient data: your platform, pharmacy, lab partner, email and SMS tools, support desk and analytics. Confirm each one will sign a BAA if required, and do not send PHI to tools that will not. Tracking pixels and analytics on intake pages deserve special attention, since they can transmit health information to third parties.

4. LegitScript certification

LegitScript Healthcare Certification verifies that telehealth providers and online pharmacies meet standards for licensure, legal compliance and transparency. LegitScript notes that without certification, telehealth providers are limited in their ability to advertise on major platforms including Google, Microsoft, Meta and TikTok, and certification also supports payment processing with Visa and Mastercard. Plan for certification early, since your website, policies and pharmacy relationships all need to be in order before you apply. Our startup cost guide lists LegitScript’s published fees.

5. FTC health claims and the Health Breach Notification Rule

Health claims

The FTC’s Health Products Compliance Guidance explains that advertisers need competent and reliable scientific evidence to support objective health claims before an ad runs. That applies to your website, ads, emails, influencer content and user-generated videos. Testimonials do not replace substantiation, and results that are not typical cannot be presented as if they are.

Health Breach Notification Rule

The FTC’s Health Breach Notification Rule applies to vendors of personal health records and related entities that are not covered by HIPAA. The FTC finalized updates in April 2024, effective July 29, 2024, clarifying that the rule applies to health apps and similar technologies. Covered businesses must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering a breach, and for breaches involving 500 or more people, notify the FTC at the same time. Under the rule, an unauthorized disclosure, such as sharing health data with an ad platform without authorization, can count as a breach. Ask your attorney whether any part of your stack falls under this rule instead of HIPAA.

6. FDA marketing rules for compounded drugs

If your digital clinic offers compounded medications, FDA rules shape your marketing. The FDA states that compounded drugs are not FDA-approved. In its guidance for telehealth companies, the FDA identifies claims it considers false or misleading, including:

  • Stating or implying a compounded drug is FDA-approved or was evaluated by the FDA for safety or effectiveness.
  • Describing compounded drugs as generic versions of, or the same as, FDA-approved drugs.
  • Claiming compounded drugs produce the same results as approved products.
  • Implying your brand manufactures or compounds the drug.
  • Claiming drugs come from “FDA-approved” or “FDA-licensed” facilities.

The FDA has issued warning letters to telehealth companies over these kinds of claims. Read every product page, ad and email against this list. Our guide What Is a 503A Pharmacy? explains the pharmacy side.

7. Ad platform policies

Meta requires online pharmacies and telehealth providers promoting prescription drugs to be actively certified with LegitScript and to request authorization from Meta, target only eligible countries and never target people under 18. Google restricts promotion of online prescribing and dispensing services, including telemedicine providers, and requires certification through LegitScript or an NABP program plus Google’s own application. Google treats violations of its prescription drug policies as egregious and may suspend accounts without prior warning.

Beyond certification, both platforms have rules on health claims, before and after imagery, personal attributes (“Are you struggling with…”) and sensitive targeting. Review current policies before every campaign, since they change.

8. Controlled substances

Prescribing controlled substances through telemedicine is governed by the DEA as well as state law. At the time of writing, the DEA and HHS have extended COVID-era telemedicine prescribing flexibilities through December 31, 2026, while permanent rules are being finalized. If any medication you plan to offer is a controlled substance, get specific legal advice, confirm your providers hold the right DEA registrations and plan for the rules to change after that date.

9. TCPA and SMS marketing

The Telephone Consumer Protection Act, enforced by the FCC, requires consent before sending autodialed or prerecorded calls and texts to wireless numbers, and prior express written consent for telemarketing messages. For a telehealth brand, that means clear, documented opt-in language at the point of capture, separate from your terms, plus a working opt-out that is honored promptly. Keep consent records. Also avoid including sensitive health details in text messages, since SMS is not a secure channel for PHI.

10. State health data privacy laws

States are adding privacy laws that reach beyond HIPAA. Washington’s My Health My Data Act, described by the Washington Attorney General as the first privacy-focused law in the country to protect personal health data that falls outside HIPAA, requires entities to publish a consumer health data privacy policy, get consent before collecting and sharing health data, not sell it without authorization, honor deletion requests and avoid geofencing around health care facilities. Violations are enforceable by the Attorney General and through private lawsuits. Other states have passed their own consumer health data laws, so check each state you serve.

11. Record keeping

HIPAA requires covered entities and business associates to retain required policies, procedures and documentation for six years from creation or last effective date. Medical record retention periods are set by state law and vary. Keep intake records, prescriptions, patient communications, consent records, marketing approvals and BAAs organized and retrievable. Good records make LegitScript applications, merchant reviews and regulatory questions far easier to answer.

How to work through this checklist before launch

  1. Map your model. List your products, target states and whether any medication is compounded or controlled.
  2. Engage a healthcare attorney. Scope entity structure, CPOM, state licensure and privacy obligations.
  3. Inventory your data flows. Identify every tool that touches patient data and collect BAAs where required.
  4. Confirm provider and pharmacy licensing. Verify coverage in every state before opening intake there.
  5. Draft compliant copy. Review every claim against FTC substantiation rules and FDA compounding guidance.
  6. Set up consent flows. Build TCPA opt-in, state health data consent and privacy policy links into intake.
  7. Prepare for certification. Assemble what LegitScript needs and apply once your site and policies are ready.
  8. Apply for ad platform authorization. Request authorization from Meta and Google after certification.
  9. Write a breach response plan. Know who does what under HIPAA or the FTC rule if something goes wrong.
  10. Schedule recurring reviews. Recheck licenses, policies and ad rules on a set calendar, not only at launch.

How WellieMD helps

WellieMD is a white-label telehealth platform, often described as a digital clinic platform, built with compliance infrastructure in mind. It includes branded intake, licensed provider review, e-prescribing, licensed 503A compounding pharmacies and brand-name pharmacy pathways, subscriptions, refills and labs. The platform is HIPAA-ready with a business associate agreement and is LegitScript certified. Your own brand, website and marketing still need their own legal review and certification steps, and we help you plan for them.

WellieMD was founded by Jessica Lynne White, BS, MSPT, a licensed physical therapist for 27 years, and the team includes a licensed pharmacist and five registered nurses. Explore the white-label telehealth platform, or if you want a done-for-you launch team, GrowPro has launched 80+ telehealth brands. Planning a hormone health brand? See our perimenopause and menopause telehealth platform.

Frequently asked questions

Do I need a lawyer to launch a telehealth business?

For most founders, yes. Ownership structure, corporate practice of medicine, state licensure and privacy obligations depend on your state and model. A healthcare attorney can tell you what applies, and this checklist helps you use that time well.

Does HIPAA apply to my telehealth brand?

It depends on your role. Covered entities and their business associates must follow HIPAA, and vendors handling PHI for them need BAAs. If some of your health data falls outside HIPAA, the FTC Health Breach Notification Rule and state health data laws may apply instead.

Is LegitScript certification required?

No law requires it in general, but Meta requires LegitScript certification for telehealth providers promoting prescription drugs, Google requires LegitScript or NABP certification, and many payment processors look for it. If you plan to advertise, expect to need it.

Can I say my compounded medication is FDA-approved?

No. The FDA states that compounded drugs are not FDA-approved. You also cannot call them generic versions of, or the same as, FDA-approved drugs, or imply your brand makes them. The FDA has sent warning letters to telehealth companies over these claims.

Do I need consent to send marketing texts?

Yes. Under the TCPA, autodialed marketing texts require prior express written consent, and consumers can revoke consent at any time. Document opt-ins, honor opt-outs promptly and keep health details out of text messages.

Use this telehealth compliance checklist before every launch

A telehealth compliance checklist is not a one-time task. Licensure, HIPAA and BAAs, LegitScript, FTC and FDA marketing rules, ad platform policies, controlled substance rules, TCPA consent, state health data laws and record keeping all evolve. Review them before launch, then on a regular schedule, and your digital clinic will be ready for ad reviews, merchant reviews and regulator questions. When you want to see how the platform side fits into your plan, book a demo with WellieMD.

This guide is general information, not legal or medical advice. Prescription products require evaluation by a licensed provider. Compounded medications are not FDA-approved.

Sources

See How a Digital Clinic Runs on WellieMD

Intake to refill, live, in 30 minutes.

Book A Demo