Product

How DTC Brands Add Prescription Treatments to Shopify (2026)

Add prescription treatments to Shopify the compliant way: intake, licensed provider review, e-prescribing, pharmacy fulfillment and PHI boundaries.

MyOrbitHealth Developer Relations TeamOctober 6, 202617 min read

You cannot list a prescription medication as a Shopify product, add it to cart and ship it. A prescription only exists after a licensed provider, licensed in the patient's state, evaluates that patient and decides to prescribe, and only a licensed pharmacy can dispense it. Shopify's own Acceptable Use Policy also says merchants cannot upload protected health information subject to HIPAA, which rules out running medical intake inside your store.

What a DTC brand can do is sell the program: a treatment subscription whose price covers the clinical evaluation and ongoing care, with the medication prescribed only if appropriate and dispensed by a pharmacy under the provider's order. The compliant flow is storefront, then intake, then licensed provider review, then e-prescribing, then pharmacy fulfillment, then subscription refills tied to the clinical plan. Shopify stays the catalog and brand front door; everything from intake onward runs on HIPAA-grade infrastructure under a business associate agreement. MyOrbitHealth supplies that layer three ways: a branded program storefront linked from your store, a REST API with signed webhooks into a custom or headless storefront, or a React SDK embedded in a page you own. There is no app to install; the integration runs through the storefront, API, webhooks or SDK. This guide covers the flow, the integration patterns, the PHI boundary, payments, LegitScript and the supplement-to-Rx upgrade path. It is general information, not legal advice.

Key takeaways

  • A prescription treatment cannot be a Shopify product; the brand sells a program that includes a licensed provider's evaluation, and the medication is dispensed by a pharmacy only if prescribed.
  • Shopify's Acceptable Use Policy prohibits uploading HIPAA-protected health information, so medical intake, provider review, prescriptions and clinical messaging must run on a separate platform under a BAA.
  • The compliant flow has six stages: storefront, intake, provider review, e-prescribing, pharmacy fulfillment and subscription refills, and the brand only ever needs non-PHI order and status events on the Shopify side.
  • Three integration patterns cover almost every brand: a branded program storefront linked from the store, an API-and-webhook integration into a custom storefront, or a React SDK embed on a page the brand owns.
  • Paid advertising for prescription programs on Google and most major platforms requires LegitScript certification, so certification belongs in the launch plan, not after it.

Who this is for

  • Supplement, nutrition and wellness brands on Shopify deciding whether to add GLP-1, TRT, hair, skin or sexual health treatments.
  • Fitness, creator and community brands with an audience that is asking for prescription programs.
  • Product and engineering leads who own a headless or custom Shopify storefront and need to integrate prescribing without moving PHI into the commerce stack.
  • Not for: pharmacies or licensed practices that already dispense; their constraint is different.

Why can't you sell prescription treatments as a Shopify product?

Three separate constraints stack on top of each other.

Medical. A prescription is the output of a clinical encounter. State law requires the prescriber to hold a license where the patient is located, to establish a provider-patient relationship, and in some states to conduct a video or in-person evaluation before a first prescription. A cart has none of that. Our telehealth prescribing rules guide covers the state rules.

Pharmacy. Dispensing is a licensed pharmacy function. The brand does not stock, pick or ship medication; a pharmacy licensed in the patient's state fills the provider's order. Compounded GLP-1s and hormones come from 503A pharmacies compounding for a named patient; commercial products come from retail or mail-order pharmacies.

Platform. Shopify's Acceptable Use Policy lists uploading protected health information subject to HIPAA among the things merchants cannot do, and Shopify does not sign business associate agreements with merchants. Shopify Payments defers prohibited and restricted business categories to its payment processors' lists, which commonly restrict prescription drug sales. So the clinical data cannot live in Shopify and the medication itself should not be the SKU.

Put together: Shopify can sell a membership or program; it cannot sell or evaluate for a drug. That division is the design principle for everything below.

What is the compliant flow for prescription treatments in a DTC brand?

Six stages, in order. The first lives on your store. The rest live on the clinical platform.

  1. Storefront. The customer learns about the program, sees eligibility basics (age, states served, what the program includes), and clicks start. The product page is marketing, not intake. No health questions here.
  2. Intake and identity. On the clinical platform, the customer becomes a patient: identity verification, state of residence, adaptive medical questionnaire with severity scoring and red-flag escalation, consents and state-specific disclosures. On MyOrbitHealth this is Orbit Intake, white-labeled to your brand.
  3. Licensed provider review. A provider licensed in the patient's state reviews the intake, asynchronously where state rules allow, or by video where they require it. The provider may approve, decline, request labs, or ask follow-up questions. MyOrbitHealth's Provider Network covers all 50 states with 2,400+ board-certified providers and an average response under six minutes during business hours.
  4. E-prescribing. If appropriate, the provider sends the prescription electronically over Surescripts to a licensed pharmacy. Controlled substances such as testosterone require EPCS with identity proofing and two-factor authentication under DEA rules. OrbitRx is EPCS-ready.
  5. Pharmacy fulfillment. A LegitScript-certified 503A compounding or retail pharmacy fills the order and ships it, cold chain where the medication needs it, to all 50 states. The patient gets tracking through the branded portal or app.
  6. Subscription refills. Refills follow the clinical plan, not just a billing calendar. The provider checks in on cadence, adjusts dosing, orders labs when indicated and authorizes the next fill; billing runs on the same cadence. Billing follows the same cadence.

What the Shopify side ever needs to know: that a customer started a program, that an order or refill was completed, and that a subscription is active, paused or cancelled. None of that is PHI if it is scoped correctly, which is the point of the next two sections.

How do you integrate telehealth prescribing into a Shopify store?

Three patterns. Most brands start with the first and move to the second or third when they have an engineering team.

Pattern What lives on Shopify What lives on the clinical platform Best for
Branded program storefront linked from the store Catalog, content, OTC and supplement SKUs, a prominent link or button to the program Program storefront, checkout and subscriptions, intake, provider review, Rx, pharmacy, portal and native app, all under your brand Brands without engineers; fastest launch; cleanest PHI boundary
API and webhooks into a custom or headless storefront Your own storefront UI, account area, CRM and analytics; program start handoff Patient, appointment and prescription lifecycle behind documented endpoints; signed webhooks back to your systems Brands with a headless front end (for example Hydrogen) and an engineering team
React SDK embed on a page you own The surrounding page and navigation The embedded clinical flow component: intake, scheduling, status, messaging, transmitted under the BAA Brands that want a native feel without building clinical screens

Pattern one: branded program storefront. Your Shopify store keeps selling what it sells. A nav item, product page or banner sends the customer to a program storefront on your domain or subdomain, white-labeled with your logo, colors and copy. That storefront runs checkout and subscriptions, intake, review, prescribing and the patient portal, and includes a native iOS and Android app under your brand. This is the MyOrbitHealth hosted path and the one most DTC brands launch on, typically in days.

Pattern two: API and webhooks. Your front end stays yours. When a customer starts a program, your server creates the patient and appointment through the product API at https://api.myorbithealth.com/v1 (bearer-token auth, test and live keys, documented endpoints for patients, appointments, prescriptions and webhook registration, 600 requests per minute per key with burst to 1,200). Signed webhooks tell your systems when things happen. An illustrative event payload, with example fields:

{
  "type": "prescription.dispensed",
  "data": {
    "patient_id": "pat_123",
    "prescription_id": "rx_456",
    "status": "dispensed"
  }
}

Your webhook handler verifies the signature, maps pat_123 to your customer record, and updates the subscription state or triggers a shipping-confirmation email. It does not need the medication name, the diagnosis or the chart to do that, so keep those out of your payload mapping. appointment.completed works the same way for the review stage. The telehealth API overview and /api-docs carry the contract; a sandbox is provisioned within a day after a short partner review.

Pattern three: React SDK. For brands that want the clinical flow to feel like a page of their own site rather than a handoff, the React SDK mounts the intake and care flow inside a page you control. The component handles the regulated data and transmits it to MyOrbitHealth under the BAA; your page handles layout, branding and what happens around it. Do not load Shopify's analytics, pixels or third-party apps on that page.

None of these patterns requires a Shopify app, and you should be skeptical of any vendor that proposes capturing health questions inside the Shopify checkout or a Shopify form.

What must never go into Shopify?

Draw the line at the first health question. Anything the customer tells you about their body, their medications or their goals in a clinical context is protected health information once it is tied to an identifiable person, and it belongs on the clinical platform under a BAA.

Never in Shopify Fine in Shopify
Intake answers, symptoms, medications, diagnoses Customer name, email, shipping address for OTC orders
Prescription details, dosing, pharmacy records A program SKU name and price
Lab orders and results Order and subscription status (active, paused, cancelled)
Provider messages and visit notes Marketing consent and preferences
Photos uploaded for clinical review Non-clinical support tickets

Pixels and ad data. This is where DTC brands get hurt. In December 2022, with an update in March 2024, HHS Office for Civil Rights issued guidance on tracking technologies stating that pixels and similar tools on pages that handle PHI can create HIPAA obligations, including a BAA with the tracking vendor, and that disclosures to ad platforms without authorization can be violations. A federal court vacated part of that guidance in June 2024, but the core position on authenticated pages and clinical data stands. Separately, the FTC's amended Health Breach Notification Rule, effective in 2024, treats unauthorized disclosure of health data by apps and similar services outside HIPAA as a breach, and the FTC has brought enforcement actions against health companies over ad-tech sharing. The practical rule: run your Meta, Google and TikTok pixels on the Shopify catalog and marketing pages, and keep them off intake, portal and clinical pages. Fire conversion events from a non-PHI signal, such as a program-started event with no health data attached. Our HIPAA for founders guide covers the full obligation set.

How do payments and merchant of record work?

The money question has two parts: what you charge, and whose merchant account takes it.

What you charge. Brands sell a program fee that includes the clinical evaluation and care, with medication cost handled transparently. The common approach is to collect the program or consult fee first, not charge for medication until a provider has prescribed, and refund or not charge the medication portion if the provider declines. Doing it the other way, charging for a specific drug before anyone has evaluated the patient, invites both regulatory and chargeback problems.

Merchant of record. On MyOrbitHealth the brand is merchant of record: payments settle to your account, the platform fee is flat and scoped at onboarding, medication cost passes through at 0% markup, and there is no revenue share. The hosted storefront includes checkout and subscriptions. If you run pattern two, your own billing stack charges the program and reacts to webhook events for refills. Confirm with your payment processor that your program is categorized correctly as a telehealth or membership product rather than a pharmacy sale, and check your processor's restricted-business list; this matters as much on Shopify Payments as on any other processor. Some vendors in this category take payment into their own merchant account and remit to the brand, which is a different and less favorable model.

Each step, who does it

Step MyOrbitHealth runs You run
Program design Clinical protocols, state eligibility rules, intake logic per vertical Choosing programs and states, pricing, positioning on the store
Store integration Branded program storefront, API and webhooks, React SDK, sandbox Linking from Shopify, your front end if headless, webhook handlers
Intake and identity Orbit Intake with severity scoring and red-flag escalation, identity verification Nothing; drive traffic to it
Provider review and prescribing 50-state Provider Network, encounter and chart in OrbitOS, OrbitRx e-prescribing with EPCS Nothing clinical
Pharmacy fulfillment LegitScript-certified 503A and retail network, cold-chain shipping to all 50 states, 0% markup Customer support expectations and shipping messaging
Labs (if in program) Provider-ordered labs by Quest or Labcorp walk-in, Tasso at-home kit or mobile phlebotomy Deciding whether labs are part of the offer
Payments and subscriptions Checkout and recurring billing in the hosted storefront; refill cadence tied to clinical plan Merchant account, refund policy, chargebacks, your own billing if headless
Patient portal and app White-label portal and native iOS/Android app Branding assets
Compliance BAA, HIPAA controls, SOC 2 Type II, EPCS identity proofing, audit trail Your own operating company policies, pixel placement, marketing claims
LegitScript certification Preparing, filing and managing the application through approval Supplying documents, keeping site claims compliant
Marketing Nothing Ads, content, creators, email, retention

Do you need LegitScript certification to advertise prescription programs?

For paid search and most major ad platforms, yes in practice. Google's healthcare and medicines policy requires certification for online pharmacy and telemedicine advertisers in the US, and LegitScript's healthcare merchant certification is the program Google recognizes. Meta and other platforms run similar prescription-drug advertising requirements that lean on the same certification. Without it, your ads will be disapproved or your account restricted, and organic growth alone is a slow way to launch a prescription program.

Certification reviews your corporate structure, the licensed providers and pharmacies behind your program, your website claims and your privacy practices. MyOrbitHealth manages the application for its brands, preparing, filing and managing it through approval; it is typically days once filed, not months, though LegitScript makes the decision and no one should promise an outcome. Our LegitScript certification guide explains what the reviewer looks for.

What rules apply when a Shopify brand sells prescription treatments?

A short map, because each item has its own guide.

  • Corporate practice of medicine. In many states a non-physician entity cannot employ physicians or direct clinical decisions. The brand contracts with a management services organization and the care is delivered by an affiliated professional entity. The brand owns marketing, customers and data; it does not direct care.
  • State licensure and modality. The provider must be licensed where the patient is; some states require a video visit before a first prescription for certain drugs. Check each launch state before enabling a program.
  • HIPAA and the BAA. Every vendor that touches PHI signs a BAA. Shopify will not, which is why PHI stays off Shopify.
  • FTC. Health Breach Notification Rule for non-HIPAA health data; truth-in-advertising rules for claims about results.
  • DEA and EPCS. Controlled substances need DEA-registered prescribers, EPCS with identity proofing, and attention to telemedicine prescribing flexibilities, which have been extended by rule rather than made permanent; check the current status before launching a controlled-substance program.
  • LegitScript. Required to advertise, as above.
  • Pharmacy law. Dispensing by licensed pharmacies only; compounding under 503A for a named patient.

How does a supplement brand upgrade to prescription treatments?

Supplement brands are the natural candidates because they already have the audience, the subscription habit and the Shopify store. The upgrade path, in practice:

  1. Keep the supplement catalog exactly as it is.
  2. Add a prescription program in an adjacent category: GLP-1 for a weight-management brand, TRT for a men's performance brand, hair loss for a grooming brand, hormone therapy for a women's wellness brand.
  3. Link the program from the store using pattern one; migrate to pattern two or three once there is an engineering case for it.
  4. Separate the data: supplements and OTC through Shopify, clinical program through the platform, with only status events crossing.
  5. Get LegitScript certified before turning on paid acquisition for the program.
  6. Market the program to the existing list with claims that stay inside what the provider actually does; no outcome guarantees.

Our supplement brand to Rx guide goes through category selection, margin structure and the first 90 days.

How should you choose a telehealth partner for a Shopify brand?

Ask these before you sign, in order of how often they break a launch.

  1. Where does intake run, and will you sign a BAA? If the answer involves a Shopify form, walk away.
  2. Who is merchant of record, and is there revenue share or medication markup?
  3. How many providers, in which states, and what is the measured response time?
  4. Is there a documented API with signed webhooks and a sandbox, so you can grow into a custom storefront later?
  5. Who runs LegitScript certification, and is it for your brand?
  6. Which pharmacies, 503A and retail, and is cold-chain shipping covered in every state you serve?
  7. Can you export your patients and data, and leave without a termination fee?

The guide to choosing a white-label telehealth partner turns this into a full diligence script, and the companion post on telehealth backend as a service explains the layers behind the integration.

Frequently asked questions

Can you sell prescription drugs on Shopify?

No. A prescription only exists after a licensed provider evaluates the patient, and only a licensed pharmacy can dispense it. A Shopify brand sells a treatment program that includes the clinical evaluation, and the medication is prescribed and shipped by a pharmacy only if the provider decides it is appropriate.

Is Shopify HIPAA compliant?

No. Shopify's Acceptable Use Policy prohibits uploading protected health information subject to HIPAA, and Shopify does not sign business associate agreements with merchants. Medical intake, provider review, prescriptions and clinical messaging must run on a separate HIPAA-grade platform under a BAA, with Shopify handling only the catalog, marketing and non-clinical orders.

How do I integrate telehealth into a Shopify store?

Three patterns cover most brands: link a branded program storefront from your store, integrate a REST API and signed webhooks into a custom or headless storefront, or embed a React SDK on a page you own. MyOrbitHealth supports all three; there is no Shopify app, and health data never passes through Shopify.

How do I add online doctor consultations to my supplement store?

Keep the supplement catalog on Shopify and add a prescription program in an adjacent category, linked from the store. The program storefront runs intake, licensed provider review, e-prescribing, pharmacy fulfillment and subscription refills under your brand. Get LegitScript certified before running paid ads for the program.

Do I need a medical license to add prescriptions to my brand?

No, but you cannot practice medicine or direct clinical decisions. The care is delivered by licensed providers through an affiliated professional entity under a management services organization structure, which is how non-clinician founders run telehealth brands in corporate-practice-of-medicine states. The brand owns the marketing, customers and data.

Do I need LegitScript certification to advertise prescription treatments?

For Google and most major ad platforms, yes in practice. Google's healthcare policy requires certification for US telemedicine and online pharmacy advertisers, and LegitScript's healthcare merchant certification is the recognized program. MyOrbitHealth manages the application for its brands; approval is typically days once filed, with LegitScript making the decision.

What is e-prescribing and how does the medication reach the patient?

E-prescribing sends the provider's prescription electronically over the Surescripts network to a licensed pharmacy, with EPCS identity proofing and two-factor authentication for controlled substances. The pharmacy fills the order and ships it, cold chain where needed, and the patient tracks it in the branded portal or app. On MyOrbitHealth this runs through OrbitRx into a LegitScript-certified 503A and retail pharmacy network at 0% medication markup.

Can I run my Meta and Google pixels on the prescription program pages?

Keep them on the Shopify catalog and marketing pages and off intake, portal and clinical pages. HHS guidance on tracking technologies and the FTC Health Breach Notification Rule both treat ad-tech sharing of health data as a potential violation, and enforcement has followed. Fire conversion events from a non-PHI signal such as a program-started event.

Sources

Add a prescription program next to your store

MyOrbitHealth gives DTC brands the clinical layer without touching Shopify: a branded program storefront with checkout, subscriptions, portal and native app, or a documented REST API with signed webhooks and a React SDK for custom storefronts. 2,400+ providers in all 50 states, OrbitRx e-prescribing into a LegitScript-certified pharmacy network at 0% markup, managed LegitScript certification, and you stay merchant of record. Book a demo or see the DTC brands solution.

Verify Approval for www.myorbithealth.com

LegitScript certified. MyOrbitHealth (myorbithealth.com) is LegitScript certified. Click the seal to verify.

Related reading

Launch your telehealth brand with MyOrbitHealth.

We power the medical, regulatory, and pharmacy layer. You own the brand and the customer.