---
url: "https://dfylegitscript.com/blog/legitscript-certification-versus-other-healthcare-credentials"
title: "How LegitScript certification differs from the credentials it gets confused with"
description: "Telehealth operators routinely offer NABP accreditation, a HIPAA attestation, a SOC 2 report or a state licence when an acquirer asks for LegitScript certification, and none of the four answers the question, because each was designed to satisfy a different party about a different risk."
published: "2026-05-28T09:39:07+00:00"
modified: "2026-05-28T09:39:07+00:00"
---

# How LegitScript certification differs from the credentials it gets confused with

Telehealth operators routinely offer NABP accreditation, a HIPAA attestation, a SOC 2 report or a state licence when an acquirer asks for LegitScript certification, and none of the four answers the question, because each was designed to satisfy a different party about a different risk.

## Key takeaways

- Each credential in this space was designed to satisfy a different party about a different risk, which is why offering a state licence to an acquirer never lands.
- No third party issues a HIPAA certificate, so an attestation or a purchased badge answers a question nobody in this chain actually asked.
- Platform advertising approvals run in the opposite direction: they depend on the credential rather than substituting for it, and they are filed per advertising account.
- SOC 2, ISO 27001 and PCI DSS describe how you run systems and handle card data, not how you present medicines to patients, which is the thing being assessed.
- NABP accreditation is scoped to pharmacy practice, so a clinic that dispenses nothing cannot hold it and a brand whose partner does still needs its own application.

"We are already compliant" is the most common answer to a request for
certification, and it is usually true and always beside the point. A telehealth
business of any size accumulates credentials, attestations and licences, and
they are not interchangeable. Each exists because a specific counterparty wanted
assurance about a specific risk, and offering the wrong one reads as an attempt
to change the subject.

Here is what each of them actually answers.

## State licensure

**Who wants it:** state boards, and by extension anybody who cares whether your
practice is lawful.

**What it says:** that a named individual or entity is permitted to practise or
to dispense in a named jurisdiction.

**Why it is not a substitute:** it says nothing about how the business presents
itself. A clinic with impeccable licensure across forty states can still be
declined for a landing page describing a compounded preparation as though it
were an approved product. Licensure is necessary and it is not sufficient, which
is the distinction
[what the certification actually is](/blog/what-is-legitscript-healthcare-certification)
opens with.

## NABP accreditation

**Who wants it:** state boards and payers recognise it directly, and some
advertising platforms accept it as an alternative for the businesses it covers.

**What it says:** that a pharmacy practice has been assessed against
pharmacy-specific standards by an accreditor the profession recognises.

**Why it is not a general substitute:** it is scoped to pharmacy practice, and
most telehealth models involve a clinical layer, a marketing layer and a
fulfilment relationship that sit outside it. It is a genuine alternative in
specific places and it does not usually answer the question an acquiring bank is
asking, which is a question about the merchant rather than about the pharmacy.

## HIPAA compliance

**Who wants it:** patients, business associates, and any enterprise buyer with a
procurement function.

**What it says:** in strict terms, nothing that a third party has certified.
There is no government-issued HIPAA certificate. What exists is your own
compliance programme and, optionally, an assessment by a consultancy against its
own methodology.

**Why it is not a substitute:** it addresses the handling of protected health
information rather than the legitimacy of the commerce. It is also frequently
overstated: a website privacy policy is not a Notice of Privacy Practices, and a
business publishing one document under both names has a gap that a certification
reviewer reading the site will see, as
[the disclosures a clinic owes its patients](/blog/patient-trust-signals-a-certified-telehealth-clinic-owes-its-patients)
explains.

## SOC 2 and ISO 27001

**Who wants them:** enterprise buyers, health systems and platform partners.

**What they say:** that an organisation's security and process controls have
been examined against a defined framework.

**Why they are not a substitute:** they are about how you run systems, not about
what you sell or how you describe it. A brand with a clean SOC 2 report and a
product page comparing its compounded preparation to a brand-name drug has
demonstrated exactly nothing about the risk an acquirer is worried about.

## PCI DSS

**Who wants it:** the card networks and your acquirer.

**What it says:** that cardholder data is handled to the networks' security
standard.

**Why it is not a substitute:** it is about protecting card data, not about
whether the transaction should exist. Both requirements come at you through the
same channel, which is why they get conflated, and satisfying one has no bearing
on the other.

## Platform advertising approvals

**Who wants them:** the advertising platform, and only the advertising platform.

**What they say:** that a specific advertising account has been approved to run
in a restricted healthcare category, usually by reference to a certification
listing the platform has checked.

**Why they are not a substitute:** they run in the opposite direction. The
platform approval depends on the certification rather than replacing it, it is
filed per advertising account rather than per website, and it is reviewed
against policies that are stricter than the certification standard in places.
Operators conflate the two constantly, and the consequence is a campaign
calendar built on the assumption that one credential delivers the other, which
[the second application nobody plans for](/blog/google-ads-healthcare-certification-for-telehealth)
sets out in detail.

## Accreditation bodies and trust marks

**Who wants them:** patients, occasionally partners.

**What they say:** varies enormously, from serious clinical accreditation to a
paid directory listing with a badge.

**Why they are not a substitute:** the counterparties who require certification
name it specifically. A different badge in the footer does not answer a
requirement that names a credential.

## Why the requirement is so specific

Because the parties asking are not trying to establish that you are a good
business. They are discharging an obligation of their own. An acquiring bank
carries registration duties for merchants in high integrity risk categories, and
an advertising platform carries policy exposure for the medicines it lets
people promote.

Both want a credential that a specialist assessor issues against a standard they
recognise, so that the vetting is somebody else's work product rather than their
own. That is exactly what
[the four counterparties who require it](/blog/who-requires-legitscript-certification)
have in common, and it is why "we hold something similar" does not travel.

## The practical version

Keep a one-page credential inventory: what you hold, who issues it, what it
covers, when it renews, and which counterparty asks for it. Most businesses
discover two things when they build it.

The first is that they are answering questions with the wrong document, usually
because that document was the one to hand.

The second is that the credentials overlap far less than expected, and the
evidence behind them overlaps far more. The corporate documents, the provider
roster, the pharmacy registration and the state coverage matrix feed almost all
of them, which is the argument for assembling that evidence once and properly,
as
[a complete application file](/blog/what-a-complete-legitscript-application-file-looks-like)
sets out.

## Frequently asked questions

### Is there such a thing as a HIPAA certification?

Not one issued by a government body. A business can commission an assessment against a consultancy's methodology, and that is a useful internal exercise, but it is not a credential a card network or an advertising platform is asking for when it names a certification requirement.

### Can NABP accreditation replace LegitScript certification?

For some businesses and some advertising platforms it is accepted as an alternative, and state boards and payers recognise it more directly. It is scoped to pharmacy practice, so it does not usually answer what an acquiring bank is asking about a telehealth merchant.

### Does a SOC 2 report help my application?

Not directly. It describes how you run systems rather than what you sell or how it is described, and certification reviews turn on the second. It is worth having for enterprise buyers, and it is not an answer to a certification requirement.

## Disclaimer

LegitScript is a trademark of LegitScript LLC. VeriScripts is an independent application-preparation service. It is not affiliated with, endorsed by, or certified by LegitScript LLC, and claims no sponsorship or partnership with it. We prepare, submit, and manage the application; LegitScript alone decides whether certification is granted. "LegitScript" is used here only to name the certification these applications are for.
