---
url: "https://dfylegitscript.com/blog/patient-trust-signals-a-certified-telehealth-clinic-owes-its-patients"
title: "The patient disclosures a certified telehealth clinic owes its patients"
description: "A website privacy policy is not a Notice of Privacy Practices, and the gap between the two is one of several disclosure defects that a LegitScript reviewer, a state board and a hesitant patient all notice for exactly the same reason."
published: "2026-01-20T09:40:24+00:00"
modified: "2026-02-23T08:01:23+00:00"
---

# The patient disclosures a certified telehealth clinic owes its patients

A website privacy policy is not a Notice of Privacy Practices, and the gap between the two is one of several disclosure defects that a LegitScript reviewer, a state board and a hesitant patient all notice for exactly the same reason.

## Key takeaways

- A website privacy policy is not a Notice of Privacy Practices, and a clinic publishing only the first has a gap that a reviewer, a state board and a patient all read the same way.
- The disclosures that satisfy a reviewer are the ones that raise conversion, because both audiences are asking who is treating me and what am I actually buying.
- One sentence naming what appears on the card statement prevents disputes no refund policy recovers, and it belongs at the point of purchase rather than in a help centre.
- A disclosure that exists but cannot be found fails the test, so where each one lives matters as much as whether anybody wrote it.

There is a comfortable assumption in telehealth marketing that compliance work
and conversion work pull in opposite directions: that every disclosure added is
friction, and friction costs revenue. In this category the assumption is mostly
wrong. The things a certification reviewer wants to see are, with very few
exceptions, the things a cautious patient is looking for and cannot find.

## Who is treating me

The most valuable disclosure on a telehealth site is also the one most often
missing: a named clinician with credentials, and a plain description of the
relationship.

That means a named medical director, the licences held, and an honest statement
of the model. If prescribers are contracted through a professional entity rather
than employed, say so. If the intake is asynchronous and a prescriber reviews it
rather than meeting the patient, say that too. Patients who are told how it works
are less likely to churn than patients who find out at the point where a
prescriber declines.

Vagueness reads as evasion to a reviewer, and it reads as evasion to a patient
who is deciding whether a medicine that arrives in the post came from anything
resembling medical care.

## What the product actually is

If a product is compounded, the site should say so, and should not describe it
in terms that belong to an approved product. This is where most enforcement in
this sector lands, and it is the same language that stalls a certification
review.

The precision that keeps you safe is not legalistic, it is simply accurate. A
compounded preparation is not the brand-name drug. It has not been reviewed by
the FDA for safety, effectiveness or quality. Saying so plainly, once, in a
place a patient will actually read, is worth more than a wall of small print
underneath a headline that implies the opposite.

## What it costs and how to stop

Subscription telehealth attracts scrutiny here from every direction at once:
certification review, card network rules on recurring billing, consumer
protection regulators and the patient's own bank.

The disclosures that satisfy all of them are the same short list. What is
charged and when. What renews, at what interval, at what amount. How to cancel,
in a way that does not require a phone call at a specific hour. What happens to
an unshipped order if a prescriber declines. What the descriptor on the card
statement will say.

That last one prevents chargebacks, which is a payment problem before it is a
compliance problem, and it costs one sentence.

## Privacy, and the document people forget

A website privacy policy describes what the site collects and how it is used. A
Notice of Privacy Practices is the document a covered entity is required to
provide describing how it uses and discloses protected health information. They
are different documents with different content, and publishing one under both
names is a common defect.

Adjacent to this, and worth an audit of its own: what your marketing tools can
see. Analytics, session recording, advertising pixels and chat widgets on pages
where a patient discusses a condition are a live regulatory issue independent of
certification, and a pixel firing from an intake flow is exactly the kind of
thing a reviewer notices while reading your site with developer tools open.

## The complaint and adverse event path

Two contact routes that need to exist and be findable: how a patient raises a
clinical concern, and how a patient reports an adverse event.

Neither is a marketing asset and neither will convert anybody. Both are
questions a reviewer will ask, and a business that cannot answer them is
describing a model with no clinical governance behind it, whatever its
prescribers are licensed to do.

## Where the trust actually comes from

Strip out everything mandated and the disclosures that move a hesitant
healthcare buyer are unglamorous: a real address, a named human, a phone number
that is answered, a cancellation path that works, and a description of the
product that does not sound like it is hiding something.

Certification badges do not do this work. Patients do not know what the
certification is, and the ones who do are not the hesitant ones. The badge is
for your counterparties, as
[the seal and listing](/blog/what-the-legitscript-seal-and-listing-actually-signal)
sets out.

## An audit you can run this week

Open your own site as a patient. Try to find, in under a minute each: who
prescribes, what the product is, what it costs to keep receiving it, how to
stop, who to contact with a clinical problem, and what happens to your health
information.

Every one of those you cannot find in a minute is both a conversion leak and an
open question in your certification file. Fixing them before you submit is the
cheapest version of this work, which is the argument
[what disqualifies an application](/blog/what-disqualifies-a-legitscript-application)
makes at greater length.

## Where each disclosure should actually live

Having the document is half of it. Reviewers and patients both judge findability,
and burying a disclosure in a policy page nobody opens is close to not having it.

- **Who prescribes**: on the page describing the service, not only in an about
  section. A named medical director belongs somewhere a patient looking for
  reassurance will find in one click.
- **What the product is**: on the product page, above the fold if the product is
  compounded, in the same visual weight as the headline that describes it.
- **What it costs and how to stop**: at the point of purchase, not in a footer
  link. Renewal interval, amount and cancellation route, in the checkout.
- **The clinical contact route**: in the site footer and in the post-purchase
  email, because that is where a worried patient looks.
- **The privacy documents**: linked from the footer and from the intake form,
  with the two documents distinct and separately named.

## The pattern to watch for internally

Almost every disclosure defect in a growing telehealth business has the same
origin. A page was written by somebody who was measured on conversion and who
was never told that the page is also a compliance artefact.

The fix is not more review. It is a written standard for what each page type
must carry, given to the people writing the pages, plus one person who reads new
copy before it ships. That is cheaper than a legal review of every page and far
cheaper than reconstructing the reasoning during a certification review.

## Frequently asked questions

### Is a privacy policy the same as a Notice of Privacy Practices?

No. A privacy policy describes what a website collects and how it is used. A Notice of Privacy Practices is the HIPAA-mandated document describing how a covered entity uses and discloses protected health information. A covered entity needs both.

### Do I have to name my medical director publicly?

Nothing forces you to, but a named clinician with credentials is one of the strongest trust signals a telehealth site can carry, and vagueness about who prescribes generates questions in a certification review that a name would have answered.

### Are advertising pixels on intake pages a certification problem?

They are a privacy problem first, and an independent regulatory issue, but a reviewer reading your site closely will see them. Tracking that can observe a patient discussing a condition deserves an audit whether or not certification is in progress.

## Disclaimer

LegitScript is a trademark of LegitScript LLC. VeriScripts is an independent application-preparation service. It is not affiliated with, endorsed by, or certified by LegitScript LLC, and claims no sponsorship or partnership with it. We prepare, submit, and manage the application; LegitScript alone decides whether certification is granted. "LegitScript" is used here only to name the certification these applications are for.
