The MSO Model Explained: How Non-Clinicians Legally Run Telehealth Brands
Can a non-doctor own a telehealth company? Yes, but not by owning the medical practice itself. In most US states, the corporate practice of medicine (CPOM) doctrine bars unlicensed people and corporations from owning a medical practice or employing physicians to deliver care. The structure the entire telehealth industry runs on is the MSO model: your company operates as a management services organization (MSO) that owns the brand, technology, and business operations, while a separate professional corporation (PC), owned by a licensed physician, owns the clinical practice and employs the providers. The two entities are tied together by a management services agreement under which the PC pays the MSO a fair-market-value fee for non-clinical services. Done correctly, this is legal in every state, including strict CPOM states like California, Texas, and New York. Done sloppily, it exposes you to fee-splitting violations, unlicensed practice claims, and unwound contracts. This guide explains how the structure works and where founders get it wrong.
This article is general information, not legal advice. Engage a healthcare attorney before forming entities or signing agreements.
Key takeaways
- The corporate practice of medicine doctrine prohibits non-physicians from owning medical practices in most states, which is why telehealth brands use the MSO plus friendly PC structure.
- In the MSO model, a physician-owned professional corporation delivers all clinical care while the founder's management services organization owns the brand, technology, marketing, and business operations.
- Management fees paid by the PC to the MSO must reflect fair market value for actual services rendered; percentage-of-revenue fees can be treated as illegal fee-splitting in strict states.
- The most common structuring mistake is the MSO exerting control over clinical decisions such as protocols, prescribing, or provider hiring, which can void the entire arrangement.
- Reputable white-label telehealth infrastructure partners ship a pre-built MSO/PC structure, so founders inherit a compliant framework instead of building one from scratch.
What is the corporate practice of medicine doctrine?
The corporate practice of medicine doctrine is a body of state law, some of it statute, much of it case law and attorney general opinions, holding that only licensed physicians (or physician-owned entities) may own a medical practice, employ physicians, or receive fees for medical services.
The policy logic is older than telehealth by about a century. Regulators worried that if a corporation owned the doctor's practice, commercial pressure would corrupt clinical judgment: push volume, cut corners, prescribe what sells. CPOM keeps the person making medical decisions accountable to a medical board, not a shareholder.
For a founder, the practical consequence is blunt. You cannot form an LLC, hire doctors as its W-2 employees, and bill patients for their medical services. In a strict CPOM state, that is unlicensed practice of medicine at the entity level, and contracts built on it can be declared void and unenforceable.
Which states enforce CPOM strictly?
CPOM is state law, so enforcement varies widely. There is no federal CPOM statute. A 50-state telehealth brand has to be structured for the strictest states it operates in, which in practice means structuring for California, Texas, and New York from day one.
| Enforcement tier | Representative states | What it means in practice |
|---|---|---|
| Strict | California, Texas, New York, New Jersey, Colorado | Active enforcement, detailed rules on MSO conduct and fee arrangements; percentage fees and MSO control over clinical matters draw scrutiny |
| Moderate | Illinois, Michigan, Georgia, Pennsylvania and many others | CPOM recognized but enforcement is less aggressive; standard MSO structures are routine |
| Permissive | Florida (for most physician practices), Missouri, and a handful of others | Corporations have more latitude to employ physicians directly, though other rules (fee-splitting, kickbacks) still apply |
Two cautions. First, "permissive" never means "unregulated": Florida is lenient on CPOM but has its own fee-splitting statute with teeth. Second, states move, and several strict states have tightened MSO scrutiny in recent years. Structure for the strict end of the spectrum and the rest of the map takes care of itself.
How does the MSO and friendly PC structure work?
The MSO model separates the clinical enterprise from the business enterprise into two legal entities with a contract between them.
The professional corporation (PC, or PLLC in some states) is owned by a licensed physician, often called the "friendly physician" because the PC's governing documents and a stock transfer restriction agreement keep the entity aligned with the MSO relationship. The PC is the medical practice: it holds the clinical relationships, employs or contracts the providers, and legally delivers the care.
The management services organization (MSO) is your company. Founders, investors, anyone can own it, no license required. It sells non-clinical services to the PC under a long-term management services agreement (MSA), and it owns everything that is not the practice of medicine.
Here is the division of labor:
| Friendly PC (physician-owned) | MSO (founder-owned) | |
|---|---|---|
| Ownership | Licensed physician(s) | Anyone: founders, investors |
| Clinical decisions | All of them: diagnosis, prescribing, protocols, standards of care | None |
| Provider hiring and supervision | Hires, credentials, supervises clinicians | May recruit candidates; PC decides |
| Patient relationship | Owns the medical record and the treatment relationship | Owns the customer/brand relationship |
| Brand and marketing | Approves clinical claims in ads | Owns the brand, runs all marketing |
| Technology | Uses it | Owns/licenses the platform, EMR, portal |
| Billing and collections | Fees are earned by the PC | Bills and collects as the PC's agent |
| Payroll, HR, admin, legal, facilities | Consumes these services | Provides them for a management fee |
| Revenue | Collects medical fees | Collects the management fee from the PC |
Money flows in a loop: patients pay the PC for medical care, and the PC pays the MSO a management fee for everything in the right-hand column. Your equity value as a founder lives in the MSO, which owns the brand, the customer list, the technology, and the MSA itself.
This is the structure that lets founders launch in regulated verticals at all. Our guides to launching a GLP-1 weight loss brand and starting an online TRT clinic show how it applies vertical by vertical.
How do management fees work, and what is fair market value?
The management fee is where good structures go bad, because it is where regulators look first for disguised profit-sharing.
The core rule: the fee must be fair market value (FMV) for the services actually provided, set in advance, and commercially reasonable. If the PC pays roughly what those services would cost from an independent vendor, the arrangement looks like a genuine service contract. If the fee is calibrated to sweep all of the PC's profit to the MSO regardless of services rendered, it looks like the MSO owns the practice in everything but name.
Fee structures, from safest to riskiest:
- Flat fee (fixed monthly amount, adjusted periodically to FMV). Cleanest in strict states.
- Cost-plus (MSO's documented costs plus a reasonable margin). Also well accepted.
- Per-unit fees (per visit, per patient) can work but need FMV support, and per-patient fees can raise anti-kickback issues if tied to referrals.
- Percentage of revenue. Common in permissive states, dangerous in strict ones. California and New York have historically treated percentage-based management fees as unlawful fee-splitting with a non-physician. Many national telehealth structures avoid them entirely for that reason.
Get an FMV analysis in writing, refresh it periodically, and paper the services the MSO actually performs. In a dispute, the documentation is the defense.
What structuring mistakes create the most risk?
Regulators and plaintiffs' lawyers do not just read your org chart; they look at how the arrangement operates. The recurring failure modes:
The MSO controls clinical decisions. If the MSO sets treatment protocols, dictates which drugs get prescribed, imposes prescribing quotas, or hires and fires physicians, the "independent" PC is a fiction and the whole structure can be recharacterized as unlicensed corporate practice. Clinical protocols must be owned and approved by the PC's physicians. The MSO can suggest, analyze, and administer; it cannot decide.
Percentage fees in strict states. Covered above. A revenue-share MSA that would be routine in Florida can be a fee-splitting violation in California or New York.
A captive physician with no real authority. If the friendly physician is paid a token stipend, never reviews anything, and signs whatever the MSO sends, expect that to surface badly in litigation or a board inquiry. The physician owner needs genuine involvement: protocol review, quality oversight, real compensation for a real role.
No succession mechanics. The stock transfer restriction agreement should cover the physician dying, losing their license, or walking away. Without it, your clinical entity is hostage to one person's life events.
Marketing that practices medicine. Ads promising specific medications or guaranteed prescriptions ("Get semaglutide today") imply the outcome is predetermined, which undercuts the claim that an independent clinician is exercising judgment. It is also a red flag for LegitScript certification, which most payment processors and ad platforms require for telehealth advertisers.
DIY entity setup without healthcare counsel. Generic startup lawyers routinely form a single LLC that "does telehealth." Unwinding that after launch, re-papering patient relationships into a new PC, is far more expensive than doing it right the first time.
What do founders actually need to know about HIPAA?
HIPAA governs protected health information (PHI): anything tying a person's identity to their health status, treatment, or payment. The PC is a covered entity. Your MSO, handling PHI on the PC's behalf, is a business associate and must sign a business associate agreement (BAA) accepting HIPAA obligations directly. So must every downstream vendor that touches PHI: EMR, video vendor, cloud host, analytics, customer support platform.
The founder-level checklist:
- BAAs with every PHI-touching vendor. No BAA, no PHI. This rules out consumer email or standard Slack for patient communication.
- Marketing data is the classic trap. Sending intake or patient-status data to ad platforms via tracking pixels has drawn FTC and OCR enforcement against several telehealth companies. Keep the marketing stack strictly separated from the clinical stack.
- Minimum necessary access. Your growth team does not need to see diagnoses. Role-based access controls are a HIPAA expectation, not a nice-to-have.
- Breach costs are real. A documented security program (risk assessment, encryption, training, incident response) is the baseline; penalties scale with negligence.
If you buy rather than build your platform, HIPAA-compliant infrastructure with BAAs in place should come standard; the white-label telehealth platform guide covers what to verify.
What other compliance rules apply to telehealth brands?
Beyond CPOM and HIPAA, four more areas belong on every founder's radar. Brief versions:
Anti-kickback and fee-splitting laws. The federal Anti-Kickback Statute applies when federal healthcare programs are involved, but most states have all-payer statutes that reach pure cash-pay telehealth. Practical rule: never pay anyone per referral or per prescription, and keep every vendor fee at fair market value.
Telehealth prescribing rules. States regulate whether a valid patient-provider relationship can be formed asynchronously (intake forms plus messaging) or requires synchronous video for an initial visit. Controlled substances add the federal Ryan Haight Act layer: testosterone is Schedule III, which is why TRT programs carry prescribing requirements a hair-loss brand does not. Your provider network needs per-state, per-modality logic built in.
State licensure. Providers must be licensed where the patient is located at the time of the visit. A "50-state" offering really means a provider network mapped to all 50 states plus DC, with routing that matches patient location to a licensed clinician.
Pharmacy and compounding rules. If your model includes fulfillment, pharmacy partners need licenses in the ship-to states, and compounded products (common in GLP-1 and peptide businesses) carry their own FDA and state board constraints.
Should you build this structure yourself or use an infrastructure partner?
You can build the stack yourself: healthcare counsel to form the PC and MSO, a friendly physician recruited and papered correctly, FMV analysis for the MSA, BAAs across a vendor stack you assemble, per-state prescribing logic you maintain. Founders do it. It costs real legal fees and, more painfully, months of calendar time before your first patient, and the maintenance burden of 50 states' rule changes never ends.
The alternative is the reason white-label telehealth infrastructure exists as a category. Reputable partners, MyOrbitHealth among them, ship the MSO/friendly-PC structure pre-built: PC entities formed, a physician network licensed across all 50 states, the MSA and FMV framework papered, a HIPAA-compliant platform with BAAs in place, prescribing rules encoded per state and modality. You plug your brand into a compliance chassis that already runs. That trade-off, and what it costs, is covered in our breakdown of what it costs to start a telehealth business.
Diligence still matters. Ask any prospective partner who owns the PC, how clinical independence is protected, whether fees are FMV-supported, and how they handle strict-state rules. A partner who answers crisply has done the work.
Frequently asked questions
Can a non-doctor legally own a telehealth company?
Yes. A non-clinician can own the management services organization, which holds the brand, technology, customer relationships, and business operations. The medical practice itself must be owned by a licensed physician through a professional corporation in most states, and the two entities are connected by a management services agreement.
What is a friendly PC?
A friendly PC is a professional corporation owned by a licensed physician that delivers the clinical care in an MSO arrangement. It is "friendly" because stock transfer restrictions and succession agreements keep the entity stable and aligned with the MSO relationship, while the physician retains full authority over all clinical decisions.
Is the MSO model legal in California, Texas, and New York?
Yes, properly structured MSO arrangements operate in all three states. But these are strict corporate practice of medicine states: they scrutinize whether the MSO controls clinical decisions and whether management fees amount to fee-splitting. Percentage-of-revenue fees and MSO influence over protocols or prescribing are the fastest ways to get in trouble there.
Who owns the patients in an MSO structure?
The PC owns the medical records and the treatment relationship; patient charts belong to the practice. The MSO typically owns the brand relationship and customer data on the commercial side, subject to HIPAA limits on how clinical data can be used. Well-drafted agreements define this boundary explicitly, including what happens if the parties separate.
Does the MSO model protect me from all compliance risk?
No. It solves the corporate practice of medicine problem specifically. You still need HIPAA compliance with BAAs across your vendor stack, fair-market-value management fees, kickback-free marketing arrangements, state-by-state prescribing compliance, and properly licensed providers. The MSO structure is the foundation, not the whole building.
How long does it take to set up an MSO and friendly PC from scratch?
Expect several months when building independently: entity formation in multiple states, recruiting and papering the friendly physician, drafting the MSA with FMV support, and assembling a HIPAA-compliant vendor stack. This is why many founders launch on infrastructure partners that provide the structure pre-built, which compresses legal setup from months to contract review. See our guide to starting a telehealth business without a medical license for the full launch path.
Launch on a compliance structure that already works
The MSO model is solved architecture. The expensive mistakes come from rebuilding it badly, not from the model itself. MyOrbitHealth provides the full structure pre-built: friendly-PC entities, a 50-state licensed provider network, HIPAA-compliant intake, EMR, and patient portal, pharmacy fulfillment partners, and the compliance layer maintained for you, while you own the brand, the customers, and the marketing. Book a demo with MyOrbitHealth to see how founders launch compliant telehealth brands without building the legal stack themselves.