Product

Pharmacy API for Telehealth: E-Prescribing Explained

Pharmacy API for telehealth: how e-prescribing, EPCS and NCPDP SCRIPT work, 503A vs retail routing, cold chain, refills, and what OrbitRx exposes.

MyOrbitHealth Developer Relations TeamOctober 6, 202616 min read

A telehealth brand cannot call Surescripts directly, cannot write prescriptions in its own software without DEA-compliant certification, and cannot ship medication without a licensed pharmacy. A pharmacy API is how a brand gets the outcome anyway: a licensed provider prescribes inside a certified e-prescribing application, the prescription travels over the Surescripts network in the NCPDP SCRIPT standard to a pharmacy that is licensed to fill it, the pharmacy dispenses and ships, and your software sees status, dispense and shipment events through a vendor's API. The regulated parts (prescriber identity proofing and two-factor signing under 21 CFR Part 1311, network certification, pharmacy licensing, 503A compounding rules, cold chain) stay with the vendor. The part you build is the patient experience around them. This guide explains how e-prescribing actually works, what a pharmacy API should expose, what OrbitRx does, and how to evaluate any vendor's pharmacy layer. This is general information, not legal or medical advice.

Key takeaways

  • E-prescribing is a prescriber-to-pharmacy transaction over the Surescripts network in the NCPDP SCRIPT standard; brands integrate with a vendor whose certified software and licensed providers sit on that network rather than connecting themselves.
  • Controlled-substance prescriptions require EPCS under 21 CFR Part 1311: prescriber identity proofing, two-factor signing and a third-party-audited or certified application.
  • A pharmacy API should expose prescription status, dispense events and shipment tracking to the brand, and should handle 503A compounding versus retail routing, cold chain and refill cycles underneath.
  • OrbitRx is MyOrbitHealth's EPCS-ready e-prescribing layer, routed via Surescripts to a LegitScript-certified pharmacy network of 503A compounding and retail partners, with cold-chain shipping to all 50 states and 0% medication markup; the product API exposes a prescriptions endpoint and a prescription.dispensed webhook event.
  • Evaluate a vendor's pharmacy layer on who prescribes, which pharmacies fill, how routing decides, what events you receive, and what you pay per fill.

Who this is for

  • Founders and operators of GLP-1, TRT, HRT, hair-loss, sexual-health and peptide brands who need medication shipped to patients and want to know what happens between the provider's decision and the doorstep.
  • Engineering leads integrating a telehealth vendor and deciding what pharmacy events their backend should handle.
  • Supplement and e-commerce brands moving into prescription products who have never dealt with Surescripts, EPCS or a compounding pharmacy.
  • Operators comparing vendors' pharmacy layers on routing, cold chain, markup and event visibility.

What does a pharmacy API for telehealth include?

The phrase covers three layers that different companies often run separately. A useful pharmacy API gives your brand all three behind one integration.

Layer What has to happen Who is allowed to do it What your software sees
Clinical decision A licensed provider reviews the case and decides whether to prescribe, what, and at what dose A prescriber licensed in the patient's state, with DEA registration for controlled substances Appointment or case status; the prescription record
Prescribing network The prescription is created in certified e-prescribing software and transmitted to the pharmacy in NCPDP SCRIPT over Surescripts A Surescripts-certified e-prescribing application used by the prescriber Prescription status
Pharmacy fulfillment A licensed pharmacy receives the order, compounds or dispenses, packages (cold chain where needed) and ships A state-licensed pharmacy (503A for patient-specific compounding) or retail pharmacy Dispense and shipment events, tracking

A "pharmacy API" that only covers the third layer is a fulfillment API; you still need a prescriber and a prescribing network. One that only covers the second is an e-prescribing vendor; you still need providers and pharmacies. Our white-label pharmacy post covers the fulfillment layer in detail; this post follows a prescription from decision to doorstep.

How does e-prescribing work?

Federal law at 21 U.S.C. 353(b) allows a prescription drug to be dispensed only on the prescription of a practitioner licensed to administer it. Electronic prescribing moves that prescription from the practitioner's software to the pharmacy's software as a structured message instead of paper or fax.

The standard. The message format is NCPDP SCRIPT, maintained by the National Council for Prescription Drug Programs, an ANSI-accredited standards developer. SCRIPT defines transaction types such as NewRx (a new prescription), RxRenewal (a refill request and response), RxChange (the pharmacy asks the prescriber to change something), CancelRx and RxFill (a fill-status notification back to the prescriber). Medicare Part D's e-prescribing program at 42 CFR 423.160 requires SCRIPT for Part D prescriptions, and HHS's adopted content-exchange standards at 45 CFR 170.205 name the SCRIPT versions certified health IT must support.

The network. Surescripts is the dominant US e-prescribing network. It connects prescribing software, pharmacies and pharmacy benefit managers, and processes billions of e-prescriptions a year per its published reports. Prescribing applications and pharmacy systems are certified by Surescripts for each transaction type they support, and Surescripts applies its own business rules and verification to messages that cross the network.

The participants. Surescripts onboards software vendors and pharmacies, not brands. A telehealth company does not get a Surescripts API key. Its providers use a certified e-prescribing application, and that application is what talks to the network. This is why "we built our own pharmacy integration" is almost never literally true for a brand; what it has is a vendor relationship with someone who did.

Can a telehealth brand connect to Surescripts directly?

Only by becoming a certified e-prescribing vendor, which is a software-certification project with Surescripts, plus, for controlled substances, a DEA-compliant audit or certification of the application. That is a multi-quarter effort with ongoing recertification obligations, and it does not come with providers or pharmacies. For nearly every brand the answer is to use a platform whose prescribing application is already on the network. The telehealth prescribing rules post covers the clinical and state-law side of what those providers can prescribe remotely.

What does EPCS require?

Electronic prescribing of controlled substances is governed by DEA's rules at 21 CFR Part 1311, issued as an interim final rule at 75 FR 16236 on March 31, 2010 and effective June 1, 2010. Testosterone is Schedule III, which pulls every TRT program under these rules; some sleep and mental health medications are scheduled as well. The requirements fall on the prescriber and the application, and a brand should know what they are because they explain why a vendor cannot just "turn on" controlled prescribing.

Requirement Where in Part 1311 What it means in practice
Identity proofing 1311.105 Each individual prescriber's identity is verified to a NIST SP 800-63 assurance level before credentials are issued
Two-factor authentication 1311.115 Signing a controlled-substance prescription requires two of three factors: something you know, a hard token meeting FIPS 140-2 Level 1 or better, or a biometric
Logical access controls 1311.120 and 1311.125 The application restricts signing to approved prescribers, and setting those permissions requires two individuals, one of whom is a DEA registrant
Application audit or certification 1311.300 A third-party audit or certification before the application is first used for EPCS, whenever EPCS functionality changes, and at least every two years
Record retention and reporting Subpart C generally Signed prescription records retained; security incidents reported

Surescripts adds its own gate on top: an application has to be EPCS-enabled on the network, not just DEA-compliant on paper. MyOrbitHealth's OrbitRx is EPCS-ready with two-factor identity proofing and uses DEA-registered partner pharmacies where applicable. Beyond federal EPCS, state telemedicine prescribing rules and the federal rules on prescribing controlled substances without an in-person exam decide whether a given controlled medication can be prescribed by telehealth at all; that is a clinical and legal question, not an API question.

503A compounding or retail: how does routing decide?

Once a provider has signed, the prescription has to go to a pharmacy that is legally and practically able to fill it. This is the part of the pharmacy layer that most distinguishes a telehealth vendor from a clinic EHR, which simply sends the script to whichever pharmacy the patient names.

Retail and mail-order fulfillment covers FDA-approved commercial products: finasteride, oral minoxidil, sildenafil, tadalafil, branded GLP-1 pens where prescribed, many hormonal contraceptives. The pharmacy dispenses a manufactured product.

503A compounding covers patient-specific preparations made by a state-licensed pharmacy on a prescription for an individual patient, under section 503A of the Federal Food, Drug, and Cosmetic Act (21 U.S.C. 353a). Compounded medications are not FDA-approved. Compounding a copy of a commercially available drug is restricted under 503A except in limited circumstances, and FDA's position on compounding GLP-1 drugs has shifted as shortages were declared resolved, so routing rules have to track current FDA guidance and state board positions. 503B outsourcing facilities (21 U.S.C. 353b) compound in bulk under cGMP and are FDA-registered; they supply office stock rather than patient-specific prescriptions. Our 503A vs 503B explainer covers the distinctions and the current GLP-1 picture.

A routing engine has to answer, for each prescription: Is the product commercial or compounded? Which partner pharmacy is licensed to ship into this patient's state (pharmacies are state-licensed, and non-resident pharmacy licensure is required to ship across state lines)? Does that pharmacy stock this formulation and strength? Does the product need cold chain? What is the current turnaround? OrbitRx routes to a LegitScript-certified pharmacy network of 503A compounding and retail partners, with cold-chain shipping to all 50 states, and passes pharmacy cost through at 0% markup. The compounding pharmacy partnerships post explains what a good pharmacy relationship looks like underneath that routing.

What does cold chain mean for an injectable program?

Semaglutide, tirzepatide and many peptides are refrigerated products. The standard refrigerated range is 2 to 8 degrees C, and compounded vials carry a beyond-use date set by the pharmacy. Cold chain in a telehealth context means insulated packaging with gel packs or phase-change material, carrier selection and transit-time limits appropriate to the destination and season, ship-day rules so a package is not sitting in a depot over a weekend, and lot and beyond-use-date tracking on every dispense so a recall or a complaint can be traced. The brand does not run any of this, but it does see the consequences: a shipment delayed by a heat wave or a wrong address is a support ticket and a churn risk. That is why shipment events in the API matter as much as dispense events.

How does refill automation work?

Most telehealth programs are subscriptions, and most of the pharmacy traffic after month one is refills, not new prescriptions. Three things have to line up: the prescription must still be valid (prescriptions carry refill counts and expiration, and controlled substances have tighter limits), the provider must have re-reviewed the patient where the protocol requires it (dose escalation on GLP-1s, labs on TRT), and the subscription must be paid. A vendor's pharmacy layer should expose enough state that your app can prompt the patient at the right time, trigger the provider check-in, and show the patient when the next shipment is leaving. On MyOrbitHealth, provider review before a refill is handled inside the clinical flow, and dispense events notify your backend when the pharmacy ships.

What does a pharmacy API expose to the brand?

Your software never writes a prescription. What it needs is read access to the state of the prescription and events when that state changes.

What the brand needs Why On MyOrbitHealth, per /api-docs as of October 2026
Prescription status Show the patient the decision and what was prescribed GET /v1/prescriptions/:id
Dispense events Trigger shipment tracking, refill scheduling and lifecycle messaging prescription.dispensed webhook event
Visit completion Know when the provider has finished the case appointment.completed webhook event
Webhook registration Subscribe your backend to events POST /v1/webhooks
Signed payloads Verify events before acting on PHI HMAC-SHA256 signed webhooks
Errors Handle rejections cleanly { error: { code, message, details } }

An illustrative example of reading a prescription and subscribing to dispense events on the documented endpoints (field names beyond the documented ones are examples):

# Example: subscribe to dispense events
curl -X POST https://api.myorbithealth.com/v1/webhooks \
  -H "Authorization: Bearer $MYORBIT_TEST_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://api.yourbrand.example/hooks/myorbit","events":["prescription.dispensed"]}'

# Example: fetch current prescription state when an event arrives
curl https://api.myorbithealth.com/v1/prescriptions/rx_example \
  -H "Authorization: Bearer $MYORBIT_TEST_KEY"
// Example event payload shape, illustrative
{
  "type": "prescription.dispensed",
  "data": { "prescription_id": "rx_example", "patient_id": "pat_example" }
}

Treat the event as a signal to fetch the record. Verify the HMAC-SHA256 signature, deduplicate on the event, then call the prescriptions endpoint for the current state. The API is versioned in the path and returns X-RateLimit-* headers at 600 requests per minute per key with burst to 1,200, so a burst of dispense events on a busy ship day stays comfortably inside the limit. Sandbox keys are provisioned within a day after a short partner review, and the API docs carry the current endpoint list.

What the API deliberately does not expose: a way for the brand to create, change or cancel a prescription, choose a pharmacy for a controlled substance, or see clinical notes beyond what the patient's record and role permit. Those boundaries are what keep the brand out of the practice of medicine and pharmacy.

What does OrbitRx do?

OrbitRx is the e-prescribing and pharmacy layer inside MyOrbitHealth's platform. Per the company's published description as of October 2026:

  • EPCS-ready e-prescribing with two-factor identity proofing, so controlled-substance verticals such as TRT are in scope.
  • Routing via Surescripts to a LegitScript-certified pharmacy network of 503A compounding and retail partners, with DEA-registered partner pharmacies where applicable.
  • Cold-chain shipping to all 50 states for refrigerated products.
  • 0% medication markup: pharmacy cost passes through to the brand, and the brand sets its retail price as merchant of record.
  • Integration with OrbitOS, the clinical console where providers write prescriptions, with the full HIPAA audit trail, and with the product API's prescriptions endpoint and prescription.dispensed event.

MyOrbitHealth does not publish a count of partner pharmacies, and we will not invent one. Formulary coverage for a specific vertical and state set is scoped at onboarding, along with the flat platform fee. There is no revenue share and no exit fee.

Should you build e-prescribing, buy a single layer, or use a platform?

Option What you build and run Prescribers and pharmacies What it means
Build your own e-prescribing Certified application, Surescripts certification, DEA Part 1311 audit, ongoing recertification You still need both Multi-quarter software and compliance project before the first script; only sensible if e-prescribing is your product
Buy an e-prescribing vendor Integration with a certified application; providers use its UI You need providers and pharmacy contracts separately Solves transport, not the clinic or the fulfillment
Buy a single pharmacy's fulfillment API Integration with one pharmacy's order and shipment events You need providers and a prescribing application; one pharmacy's state coverage and formulary Solves shipping for the states and products that pharmacy covers
Use a white-label platform (MyOrbitHealth) Your app, intake embed or API calls, event handlers 2,400+ providers in 50 states; OrbitRx via Surescripts to a LegitScript-certified 503A and retail network One BAA, one integration, prescriptions and dispense events through one API

For comparison, as of October 2026 Cuvo Health reports 17 partner pharmacies (503A and 503B) with bring-your-own-pharmacy allowed, routes via Surescripts, charges 0% medication markup and $25 per completed consult, and gates its API to its Grow plan ($15,000 setup plus $2,500 per month) and above, per its site. The MyOrbitHealth vs Cuvo page sets the two side by side, and the 9-platform API comparison covers what each vendor documents.

Best for

  • Build your own e-prescribing: companies whose product is prescribing software and who are funded for Surescripts and DEA certification.
  • E-prescribing vendor only: existing medical practices with their own providers and pharmacy relationships that need transport.
  • Single pharmacy fulfillment API: brands with one product in a handful of states and an existing clinical partner.
  • MyOrbitHealth with OrbitRx: brands that want providers, EPCS-ready prescribing, 503A and retail routing, cold chain and dispense events through one API at 0% markup.

How do you evaluate a vendor's pharmacy layer?

Ask these in order and get the answers in writing. A good vendor answers all of them without a contract.

  1. Who prescribes? Which entity employs or contracts the providers, in how many states, and are they DEA-registered where your formulary needs it?
  2. Which application and is it EPCS-certified? Ask for the Part 1311 audit or certification status if you prescribe anything scheduled.
  3. Which pharmacies fill, and under what license? 503A, retail, or both; state licensure for each state you sell into; LegitScript status of the network.
  4. How does routing decide? By state, product, cold chain, turnaround. Can you see which pharmacy filled a given order?
  5. What is the markup? 0% pass-through or a margin on medication, and who sets retail price.
  6. What events do you receive? Prescription status, dispense, shipment, and how they are signed.
  7. What is the refill model? Provider re-review rules, how the brand is notified, how controlled-substance limits are handled.
  8. What happens when a product's regulatory status changes? Who decides to stop compounding a drug when FDA guidance shifts, and how fast.

Our guide to choosing a white-label telehealth partner extends this list to the rest of the stack.

Frequently asked questions

Is there a pharmacy API for telehealth?

Yes, in the sense of an API that exposes prescription status, dispense events and shipment tracking to a brand while a vendor's licensed providers prescribe and licensed pharmacies fill. MyOrbitHealth exposes a prescriptions endpoint and a prescription.dispensed webhook event on its product API, with OrbitRx handling prescribing and routing underneath.

How do I get access to the Surescripts API?

Brands do not. Surescripts certifies e-prescribing software vendors and pharmacies, and for controlled substances the application also needs a DEA-compliant audit or certification. A telehealth brand gets on the network by using a platform whose certified prescribing application its providers use.

What is an e-prescribing API?

An interface a certified e-prescribing application exposes so that a prescriber's workflow or an integrated system can create and track prescriptions that travel over Surescripts in NCPDP SCRIPT. Brands do not write prescriptions, so what a brand consumes is a telehealth or pharmacy API that reports prescription state rather than an e-prescribing API itself.

Can a telehealth company send prescriptions to any pharmacy?

A prescriber can generally transmit a prescription to any pharmacy the patient chooses, but a telehealth program that ships medication routes to partner pharmacies licensed in the patient's state that stock the formulation and can meet cold-chain requirements. Compounded products must come from a 503A pharmacy on a patient-specific prescription.

What is EPCS?

Electronic prescribing of controlled substances under DEA rules at 21 CFR Part 1311. It requires identity proofing of each prescriber, two-factor authentication when signing, logical access controls set by two individuals, and a third-party audit or certification of the application before first use, when EPCS functionality changes, and at least every two years.

How do telehealth companies send prescriptions to compounding pharmacies?

The same way as to any pharmacy: the provider signs in a certified application and the prescription travels over Surescripts to the compounding pharmacy's system. The difference is routing, since the pharmacy must be a 503A facility licensed to ship into the patient's state and able to prepare the specific formulation.

What is the difference between 503A and 503B?

A 503A pharmacy compounds patient-specific preparations on individual prescriptions under state pharmacy licensure. A 503B outsourcing facility is FDA-registered, compounds in bulk under cGMP, and supplies office stock rather than individual prescriptions. Telehealth programs that ship to patients use 503A pharmacies for compounded products.

What does OrbitRx cost?

MyOrbitHealth does not publish a price list. OrbitRx is part of the platform, scoped into a flat platform fee at onboarding, and medication is passed through at 0% markup with no revenue share; the brand is merchant of record and sets its own retail price.

Sources

See OrbitRx route a prescription for your vertical

MyOrbitHealth's OrbitRx is EPCS-ready, routed via Surescripts to a LegitScript-certified 503A and retail pharmacy network with cold-chain shipping to all 50 states at 0% medication markup, behind 2,400+ board-certified providers and a documented telehealth API. Book a demo to walk through routing, dispense events and refill handling for your formulary.

Verify Approval for www.myorbithealth.com

LegitScript certified. MyOrbitHealth (myorbithealth.com) is LegitScript certified. Click the seal to verify.

Related reading

Launch your telehealth brand with MyOrbitHealth.

We power the medical, regulatory, and pharmacy layer. You own the brand and the customer.