LegitScript certification explained
How LegitScript certification differs from the credentials it gets confused with
Telehealth operators routinely offer NABP accreditation, a HIPAA attestation, a SOC 2 report or a state licence when an acquirer asks for LegitScript certification, and none of the four answers the question, because each was designed to satisfy a different party about a different risk.
By VeriScripts · · 5 min read
"We are already compliant" is the most common answer to a request for certification, and it is usually true and always beside the point. A telehealth business of any size accumulates credentials, attestations and licences, and they are not interchangeable. Each exists because a specific counterparty wanted assurance about a specific risk, and offering the wrong one reads as an attempt to change the subject.
Here is what each of them actually answers.
State licensure
Who wants it: state boards, and by extension anybody who cares whether your practice is lawful.
What it says: that a named individual or entity is permitted to practise or to dispense in a named jurisdiction.
Why it is not a substitute: it says nothing about how the business presents itself. A clinic with impeccable licensure across forty states can still be declined for a landing page describing a compounded preparation as though it were an approved product. Licensure is necessary and it is not sufficient, which is the distinction what the certification actually is opens with.
NABP accreditation
Who wants it: state boards and payers recognise it directly, and some advertising platforms accept it as an alternative for the businesses it covers.
What it says: that a pharmacy practice has been assessed against pharmacy-specific standards by an accreditor the profession recognises.
Why it is not a general substitute: it is scoped to pharmacy practice, and most telehealth models involve a clinical layer, a marketing layer and a fulfilment relationship that sit outside it. It is a genuine alternative in specific places and it does not usually answer the question an acquiring bank is asking, which is a question about the merchant rather than about the pharmacy.
HIPAA compliance
Who wants it: patients, business associates, and any enterprise buyer with a procurement function.
What it says: in strict terms, nothing that a third party has certified. There is no government-issued HIPAA certificate. What exists is your own compliance programme and, optionally, an assessment by a consultancy against its own methodology.
Why it is not a substitute: it addresses the handling of protected health information rather than the legitimacy of the commerce. It is also frequently overstated: a website privacy policy is not a Notice of Privacy Practices, and a business publishing one document under both names has a gap that a certification reviewer reading the site will see, as the disclosures a clinic owes its patients explains.
SOC 2 and ISO 27001
Who wants them: enterprise buyers, health systems and platform partners.
What they say: that an organisation's security and process controls have been examined against a defined framework.
Why they are not a substitute: they are about how you run systems, not about what you sell or how you describe it. A brand with a clean SOC 2 report and a product page comparing its compounded preparation to a brand-name drug has demonstrated exactly nothing about the risk an acquirer is worried about.
PCI DSS
Who wants it: the card networks and your acquirer.
What it says: that cardholder data is handled to the networks' security standard.
Why it is not a substitute: it is about protecting card data, not about whether the transaction should exist. Both requirements come at you through the same channel, which is why they get conflated, and satisfying one has no bearing on the other.
Platform advertising approvals
Who wants them: the advertising platform, and only the advertising platform.
What they say: that a specific advertising account has been approved to run in a restricted healthcare category, usually by reference to a certification listing the platform has checked.
Why they are not a substitute: they run in the opposite direction. The platform approval depends on the certification rather than replacing it, it is filed per advertising account rather than per website, and it is reviewed against policies that are stricter than the certification standard in places. Operators conflate the two constantly, and the consequence is a campaign calendar built on the assumption that one credential delivers the other, which the second application nobody plans for sets out in detail.
Accreditation bodies and trust marks
Who wants them: patients, occasionally partners.
What they say: varies enormously, from serious clinical accreditation to a paid directory listing with a badge.
Why they are not a substitute: the counterparties who require certification name it specifically. A different badge in the footer does not answer a requirement that names a credential.
Why the requirement is so specific
Because the parties asking are not trying to establish that you are a good business. They are discharging an obligation of their own. An acquiring bank carries registration duties for merchants in high integrity risk categories, and an advertising platform carries policy exposure for the medicines it lets people promote.
Both want a credential that a specialist assessor issues against a standard they recognise, so that the vetting is somebody else's work product rather than their own. That is exactly what the four counterparties who require it have in common, and it is why "we hold something similar" does not travel.
The practical version
Keep a one-page credential inventory: what you hold, who issues it, what it covers, when it renews, and which counterparty asks for it. Most businesses discover two things when they build it.
The first is that they are answering questions with the wrong document, usually because that document was the one to hand.
The second is that the credentials overlap far less than expected, and the evidence behind them overlaps far more. The corporate documents, the provider roster, the pharmacy registration and the state coverage matrix feed almost all of them, which is the argument for assembling that evidence once and properly, as a complete application file sets out.
Frequently asked questions
Is there such a thing as a HIPAA certification?
Not one issued by a government body. A business can commission an assessment against a consultancy's methodology, and that is a useful internal exercise, but it is not a credential a card network or an advertising platform is asking for when it names a certification requirement.
Can NABP accreditation replace LegitScript certification?
For some businesses and some advertising platforms it is accepted as an alternative, and state boards and payers recognise it more directly. It is scoped to pharmacy practice, so it does not usually answer what an acquiring bank is asking about a telehealth merchant.
Does a SOC 2 report help my application?
Not directly. It describes how you run systems rather than what you sell or how it is described, and certification reviews turn on the second. It is worth having for enterprise buyers, and it is not an answer to a certification requirement.
More on LegitScript certification explained
General compliance information, not legal or medical advice.