---
url: "https://dfylegitscript.com/blog/telehealth-payment-processing-and-high-risk-mcc-codes"
title: "Telehealth payment processing, MCC codes and why your acquirer asks for certification"
description: "A telehealth clinic that dispenses medicines is coded into MCC 5122 or MCC 5912, both classified by the card networks as high integrity risk, and that classification is what obliges your acquiring bank to register and vet you rather than simply board you."
published: "2025-09-15T08:30:22+00:00"
modified: "2025-09-15T08:30:22+00:00"
---

# Telehealth payment processing, MCC codes and why your acquirer asks for certification

A telehealth clinic that dispenses medicines is coded into MCC 5122 or MCC 5912, both classified by the card networks as high integrity risk, and that classification is what obliges your acquiring bank to register and vet you rather than simply board you.

## Key takeaways

- A telehealth business that dispenses medicines is coded into MCC 5122 or MCC 5912, and both sit in the group the card networks treat as high integrity risk.
- That classification is what obliges your acquiring bank to register and vet you, so the demand for certification is a rule being passed on rather than invented.
- Coding the merchant into a gentler category breaches network rules and ends in termination, which leaves the business worse off than the problem it was avoiding.
- The underwriting file and the certification file ask for the same evidence, so assembling one and then rebuilding it for the other is the avoidable half of the work.

The conversation usually starts with a rejection nobody explains properly. The
application to a payment processor comes back asking for a certification you do
not hold, or an existing account is suddenly under review, and the reason given
is a merchant category code you have never looked at.

Understanding the mechanism is worth an hour, because it tells you which of your
problems are negotiable and which are not.

## The code decides the treatment

Every merchant is assigned a merchant category code that tells the card networks
what the business sells. For telehealth businesses that involve medicines, two
matter: MCC 5122, which covers drugs, drug proprietaries and druggist sundries,
and MCC 5912, which covers drug stores and pharmacies.

Both are classified by the card networks as high integrity risk. That phrase is
specific and it is not about chargebacks. It describes categories where the
network's concern is that the underlying transaction may be for something
unlawful, which is a different risk from a customer disputing a charge.

The consequences attach to your acquiring bank rather than to you. Under the
Visa Integrity Risk Program, acquirers must register merchants in these
categories, pay a registration fee for doing so, and answer for them. That is
why the certification requirement usually arrives from the acquirer rather than
from the gateway you signed up with.

## Why miscoding is not the workaround it looks like

Every operator eventually meets the suggestion, sometimes from a sales agent,
that the account could simply be coded as something less scrutinised. General
merchandise. Health and beauty. Professional services.

Do not.

Miscoding a merchant is a violation of the network rules the acquirer is bound
by, and the networks run programs specifically to detect it. Being found is not a
warning. It is termination, potential placement on the industry termination
list, and a subsequent boarding process that starts every conversation with an
explanation of why you were terminated.

It is also, practically, a trap in the other direction. A business coded
incorrectly and then found is in a much worse position with a certification
reviewer than a business that was never coded at all.

## What the acquirer is actually underwriting

Three questions, and certification only answers the first cleanly:

**Is this merchant legitimate for this category?** This is what the
certification answers, and why the acquirer wants it before boarding rather
than after.

**What is the chargeback and refund exposure?** Subscription telehealth has
structural chargeback risk: recurring billing, a product that arrives late or
not at all if a prescriber declines, and customers who do not recognise the
descriptor. Your descriptor, your cancellation flow and your refund policy are
underwriting material, and they are also certification material, which is
convenient.

**Who is behind it?** Ownership, principals, prior terminations, prior
enforcement. The same identity work a certification review does.

Preparing for one of these prepares you substantially for the other. The
documents overlap, the disclosures overlap, and the website review is nearly the
same review.

## Sequencing that does not waste a month

The order that works:

1. **Get the website into the state a reviewer would pass.** Claims, provider
   disclosure, terms, cancellation, privacy. This is the long pole and it blocks
   both processes.
2. **Assemble the corporate and clinical documentation once.** Entity documents,
   ownership, licences by state, the pharmacy relationship, the processing
   history if you have one.
3. **File the certification and open the processor conversation in parallel.**
   The acquirer will want to see the certification before going live, but the
   underwriting questions can be answered while the review runs.
4. **Do not launch ads until both are settled.** An ad account suspended while
   you sort out payments is a third problem you do not need.

What that costs in elapsed time is set out in
[how long certification takes](/how-long-does-legitscript-take). The part worth
noting here is that the two clocks overlap, so running them in sequence rather
than in parallel is the most common self-inflicted delay in this whole process.

## Multiple domains, multiple problems

If you operate more than one storefront, this is where the arithmetic gets
uncomfortable. Certification attaches to a website. Merchant accounts attach to a
business and a descriptor. A funnel domain that takes payment and is not
certified is a problem for the acquirer as well as for the certifier, and
consolidating before you apply is nearly always cheaper than certifying
everything.

[What actually drives certification cost](/legitscript-certification-cost) is
worth reading with your domain list in front of you rather than after you have
already filed.

## The failure mode to plan for

The expensive scenario is not rejection. It is a live business whose processing
is suspended pending certification, because at that point every day of the
review is a day of revenue that does not happen, and the file is being prepared
under time pressure by people who are also fielding customer support.

Expedited processing exists for exactly that situation and buys a review start
within two business days of submission, which is worth having when waiting is
what is costing you money. It buys nothing at all if the application is not
ready, because an incomplete file reaches a reviewer sooner and then stops in
the same place it would have stopped anyway.

## The underwriting file, assembled once

Your acquirer and your certification reviewer want overlapping evidence, so
assemble it once and use it twice.

- Entity documents, ownership and the identity of the principals.
- Processing history where you have it, including chargeback and refund rates by
  month.
- The provider roster with licences by state, and the dispensing pharmacy with
  its registration.
- The subscription mechanics: billing interval, renewal disclosure, cancellation
  path and the descriptor that appears on a statement.
- The complete domain list, with a note against each about whether it transacts.

Two of those are worth a second look before anybody sees them. Your chargeback
profile is the number an underwriter reads first, and the cheapest way to improve
it is a recognisable descriptor and a cancellation flow that works. Your domain
list is the one that changes the arithmetic on everything else.

## What to do when processing is already suspended

Triage in this order. Establish what the acquirer actually requires and by when,
in writing, because "we need certification" and "we need certification within
thirty days" are different problems. Find out whether settlement is being held
and how much, because that sets how long you can operate.

Then start on the website rather than on the application, since it is the long
pole and it blocks both processes. And be honest with the acquirer about the
timeline, because the one thing that reliably makes this worse is a merchant who
promises a date that belongs to somebody else's review queue.

## Frequently asked questions

### Can I use a lower-risk merchant category code to avoid this?

No. Miscoding violates the network rules your acquirer is bound by, the networks run detection programs for it, and being found generally means termination rather than a warning. It also badly damages a subsequent certification application.

### Why does my acquirer care about certification when I am the one taking the risk?

Because network integrity programs make the acquirer responsible for registering and vetting merchants in high integrity risk categories. Certification is how they discharge that obligation with a credential the network recognises.

### Can I process payments while my application is under review?

That depends entirely on your acquirer and on whether you are already boarded. A merchant already processing is usually given a window; a merchant being boarded normally waits. Neither decision belongs to the certifier.

## Disclaimer

LegitScript is a trademark of LegitScript LLC. VeriScripts is an independent application-preparation service. It is not affiliated with, endorsed by, or certified by LegitScript LLC, and claims no sponsorship or partnership with it. We prepare, submit, and manage the application; LegitScript alone decides whether certification is granted. "LegitScript" is used here only to name the certification these applications are for.
