Skip to content

LegitScript certification explained

Who actually requires LegitScript certification, and why they do

Nobody is legally required to hold LegitScript certification, but the card networks, acquiring banks, advertising platforms and marketplaces that a telehealth business depends on have each independently adopted it as an entry condition, which is why the requirement reaches you through four different counterparties at once.

By VeriScripts · · 5 min read

The requirement never arrives from one place. It arrives from a payment processor, then from an ad platform, then from a fulfilment partner, each in slightly different language, and it is easy to conclude that some regulator somewhere has mandated it. None has. Four separate commercial ecosystems reached the same conclusion about healthcare merchants, and certification is the credential they all settled on.

Knowing which of them is asking, and why, changes what you do about it.

The card networks and the banks that acquire for them

Card-not-present healthcare transactions sit in merchant categories the networks treat as high integrity risk. That designation is not about fraud rates, it is about the risk that the underlying transaction is for something unlawful, and it brings registration obligations for the acquiring bank rather than for you.

Under the Visa Integrity Risk Program, an acquirer must register merchants in those categories and is answerable for them. That is the mechanism. Your acquirer requires certification because their obligation to the network is easier to discharge if every healthcare merchant on their book has been vetted by a third party the network recognises.

Which is why the requirement is usually non-negotiable at the processor level, and why the answer to "can I find a processor who does not ask" is generally yes, briefly, and then no.

The advertising platforms

Google and the other major platforms restrict healthcare and medicines advertising, and certification is the gate into the restricted categories. It is worth being precise about the sequence, because the two applications get conflated constantly:

  1. The certification comes first. It certifies the website.
  2. The platform approval comes second. It is filed per advertising account, it references the public certification listing, and it is reviewed by the platform on its own timetable.

Holding the first does not automatically deliver the second. Merchants routinely finish certification, assume ads will now serve, and discover a further review in the way. Building the platform approval into the plan from the start is covered in Google Ads healthcare certification for telehealth.

The pharmacy and fulfilment side

Compounding pharmacies and fulfilment partners screen the telehealth brands they work with, and they screen hard, because their own registration and their own liability are attached to who they dispense for. Certification is a cheap first filter for them.

This one runs in both directions, and operators miss that. Your pharmacy partner is checking you, and the certification reviewer is checking your pharmacy partner. A relationship with a compounder that cannot survive scrutiny is a problem in your application, not just in theirs.

Marketplaces, affiliates and enterprise buyers

The fourth ring is the one nobody plans for. Affiliate networks in the health vertical increasingly require it before they will approve an offer. Marketplaces require it for healthcare listings. Employer and benefits buyers ask for it in diligence questionnaires because it is a single credential that answers a page of questions.

None of these will shut you down. They will just quietly not work with you, and you will read it as poor conversion on partnership outreach rather than as a missing credential.

Why they all landed on the same standard

Because the alternative is each of them building a healthcare diligence function of their own. A network cannot audit every telemedicine site that wants to accept cards. A platform cannot verify every pharmacy that wants to advertise. Outsourcing the vetting to a specialist certifier, and requiring the credential as a condition of access, is cheaper for all of them and produces a consistent standard for the merchant.

Accreditation from the National Association of Boards of Pharmacy is accepted by some platforms as an alternative for the businesses it covers, and state boards and payers recognise it more directly. It is not a general substitute, and for most telehealth models it does not answer the question the acquirer is asking.

What this means for sequencing

The four requirements do not arrive at once, but they do arrive in a predictable order, and the expensive mistake is treating each as a separate fire.

Certification is upstream of all of them. Whatever forced the issue first, usually a processor, the same credential unlocks the others, and the work you do on your website to pass it is the same work the ad platform review will look at. Doing it once, properly, for every domain you intend to operate is materially cheaper than doing it three times reactively as each counterparty notices.

What that sequencing costs in time is covered in how long certification takes, and what it costs when it goes wrong in what a denied application actually costs.

Working out which ring is actually blocking you

Businesses usually arrive with one symptom and assume it is the whole problem. It is worth mapping all four before you act, because the fix is the same credential and the sequencing is different depending on what is at risk.

  • Payments. Are you boarded? Is settlement being held? Has your acquirer asked for documentation? Anything here is urgent, because it is revenue rather than margin.
  • Advertising. Are the accounts serving? Have you been asked for a healthcare certification at the account level? A suspended account is worse than a paused one, because the history goes with it.
  • Partners. Are affiliate or marketplace conversations stalling without an explanation? This is the silent one, and it reads as a business development problem rather than a credential problem.
  • Buyers. Has a diligence questionnaire asked for it? That usually gives you the longest runway of the four.

The order that wastes the least time

Certification is upstream of all four, and the preparation work is the same work regardless of which one forced the issue. So the sequence that wastes least is: settle the domain architecture, fix the website, assemble the documentation, file once for every domain that needs it, and only then work the downstream approvals.

The expensive alternative is reactive: certify one domain because a processor asked, then discover the advertised domain needs its own, then discover a partner wants a third. Same work, three times, with a gap between each.

Frequently asked questions

Can I find a payment processor that does not require certification?

Occasionally, and rarely for long. The requirement usually originates with the acquiring bank rather than the processor, because network programs make the acquirer answerable for merchants in high integrity risk categories, so a processor who waives it is generally between acquirers rather than exempt.

Is NABP accreditation an alternative?

For some businesses and some platforms, yes. Accreditation from the National Association of Boards of Pharmacy is accepted by certain advertising platforms and is recognised more directly by state boards and payers, but it is not a general substitute and does not usually answer what an acquirer is asking.

Do I need certification before I have a payment processor?

You need it before the processor will go live, and certification requires a website that is substantially complete. Most operators build the site, prepare the application against it, and run the processor application in parallel rather than in sequence.

General compliance information, not legal or medical advice.