The patient disclosures a certified telehealth clinic owes its patients
A website privacy policy is not a Notice of Privacy Practices, and the gap between the two is one of several disclosure defects that a LegitScript reviewer, a state board and a hesitant patient all notice for exactly the same reason.
By VeriScripts · · Last updated · 5 min read
There is a comfortable assumption in telehealth marketing that compliance work and conversion work pull in opposite directions: that every disclosure added is friction, and friction costs revenue. In this category the assumption is mostly wrong. The things a certification reviewer wants to see are, with very few exceptions, the things a cautious patient is looking for and cannot find.
Who is treating me
The most valuable disclosure on a telehealth site is also the one most often missing: a named clinician with credentials, and a plain description of the relationship.
That means a named medical director, the licences held, and an honest statement of the model. If prescribers are contracted through a professional entity rather than employed, say so. If the intake is asynchronous and a prescriber reviews it rather than meeting the patient, say that too. Patients who are told how it works are less likely to churn than patients who find out at the point where a prescriber declines.
Vagueness reads as evasion to a reviewer, and it reads as evasion to a patient who is deciding whether a medicine that arrives in the post came from anything resembling medical care.
What the product actually is
If a product is compounded, the site should say so, and should not describe it in terms that belong to an approved product. This is where most enforcement in this sector lands, and it is the same language that stalls a certification review.
The precision that keeps you safe is not legalistic, it is simply accurate. A compounded preparation is not the brand-name drug. It has not been reviewed by the FDA for safety, effectiveness or quality. Saying so plainly, once, in a place a patient will actually read, is worth more than a wall of small print underneath a headline that implies the opposite.
What it costs and how to stop
Subscription telehealth attracts scrutiny here from every direction at once: certification review, card network rules on recurring billing, consumer protection regulators and the patient's own bank.
The disclosures that satisfy all of them are the same short list. What is charged and when. What renews, at what interval, at what amount. How to cancel, in a way that does not require a phone call at a specific hour. What happens to an unshipped order if a prescriber declines. What the descriptor on the card statement will say.
That last one prevents chargebacks, which is a payment problem before it is a compliance problem, and it costs one sentence.
Privacy, and the document people forget
A website privacy policy describes what the site collects and how it is used. A Notice of Privacy Practices is the document a covered entity is required to provide describing how it uses and discloses protected health information. They are different documents with different content, and publishing one under both names is a common defect.
Adjacent to this, and worth an audit of its own: what your marketing tools can see. Analytics, session recording, advertising pixels and chat widgets on pages where a patient discusses a condition are a live regulatory issue independent of certification, and a pixel firing from an intake flow is exactly the kind of thing a reviewer notices while reading your site with developer tools open.
The complaint and adverse event path
Two contact routes that need to exist and be findable: how a patient raises a clinical concern, and how a patient reports an adverse event.
Neither is a marketing asset and neither will convert anybody. Both are questions a reviewer will ask, and a business that cannot answer them is describing a model with no clinical governance behind it, whatever its prescribers are licensed to do.
Where the trust actually comes from
Strip out everything mandated and the disclosures that move a hesitant healthcare buyer are unglamorous: a real address, a named human, a phone number that is answered, a cancellation path that works, and a description of the product that does not sound like it is hiding something.
Certification badges do not do this work. Patients do not know what the certification is, and the ones who do are not the hesitant ones. The badge is for your counterparties, as the seal and listing sets out.
An audit you can run this week
Open your own site as a patient. Try to find, in under a minute each: who prescribes, what the product is, what it costs to keep receiving it, how to stop, who to contact with a clinical problem, and what happens to your health information.
Every one of those you cannot find in a minute is both a conversion leak and an open question in your certification file. Fixing them before you submit is the cheapest version of this work, which is the argument what disqualifies an application makes at greater length.
Where each disclosure should actually live
Having the document is half of it. Reviewers and patients both judge findability, and burying a disclosure in a policy page nobody opens is close to not having it.
- Who prescribes: on the page describing the service, not only in an about section. A named medical director belongs somewhere a patient looking for reassurance will find in one click.
- What the product is: on the product page, above the fold if the product is compounded, in the same visual weight as the headline that describes it.
- What it costs and how to stop: at the point of purchase, not in a footer link. Renewal interval, amount and cancellation route, in the checkout.
- The clinical contact route: in the site footer and in the post-purchase email, because that is where a worried patient looks.
- The privacy documents: linked from the footer and from the intake form, with the two documents distinct and separately named.
The pattern to watch for internally
Almost every disclosure defect in a growing telehealth business has the same origin. A page was written by somebody who was measured on conversion and who was never told that the page is also a compliance artefact.
The fix is not more review. It is a written standard for what each page type must carry, given to the people writing the pages, plus one person who reads new copy before it ships. That is cheaper than a legal review of every page and far cheaper than reconstructing the reasoning during a certification review.
Frequently asked questions
Is a privacy policy the same as a Notice of Privacy Practices?
No. A privacy policy describes what a website collects and how it is used. A Notice of Privacy Practices is the HIPAA-mandated document describing how a covered entity uses and discloses protected health information. A covered entity needs both.
Do I have to name my medical director publicly?
Nothing forces you to, but a named clinician with credentials is one of the strongest trust signals a telehealth site can carry, and vagueness about who prescribes generates questions in a certification review that a name would have answered.
Are advertising pixels on intake pages a certification problem?
They are a privacy problem first, and an independent regulatory issue, but a reviewer reading your site closely will see them. Tracking that can observe a patient discussing a condition deserves an audit whether or not certification is in progress.
More on Telehealth clinic compliance
General compliance information, not legal or medical advice.