Before you sign with a white-label telehealth platform, demand fifteen documents and read each one: a business associate agreement (BAA), a current SOC 2 Type II report (not a letter saying one exists), a plain statement of HITRUST status, the LegitScript certificate behind the pharmacy network, the DEA registrations of any pharmacy that will dispense controlled substances, proof of EPCS certification for the e-prescribing application, a state licensure roster plus the credentialing policy that produced it, the OIG/SAM exclusion-screening cadence, the MSO and professional-corporation (PC) agreements that make the clinical structure legal, malpractice coverage declarations, the data-ownership and export clauses, the exit terms, the subprocessor list, the breach-notification terms, and the uptime SLA. A vendor that produces ten and talks around the other five is telling you where the risk lives. This checklist scores each line, lists the red flags, gives you the demo questions, and shows how MyOrbitHealth answers every line from its published posture.
This is general information, not legal advice.
Key takeaways
- A telehealth vendor contract should be preceded by fifteen specific documents, and the most important four are the BAA, the SOC 2 Type II report, the MSO/PC agreements and the data-export clause.
- A SOC 2 Type II report tests controls over a period of months; a SOC 2 Type I or a "SOC 2 compliant" badge does not, and HITRUST-aligned architecture is not the same thing as a HITRUST certification.
- Under 21 CFR Part 1311, an EPCS application must pass a third-party audit or certification and support two-factor authentication with identity proofing before it can transmit controlled-substance prescriptions.
- DEA and HHS extended telemedicine prescribing flexibilities for controlled substances through December 31, 2026, so any vendor's EPCS and in-person-exam posture should be reviewed against what happens on January 1, 2027.
- Ownership questions, who the merchant of record is, who owns the patient records, and what it costs to leave, decide whether you own a business or rent one.
Who this is for
- Non-clinician founders choosing a white-label telehealth platform and preparing a vendor contract for counsel review.
- Operators at med spas, DTC brands and existing practices replacing a DIY stack with a single infrastructure partner.
- Product and engineering leads who need the security and data-portability evidence before an integration is approved.
What should you request from a telehealth vendor before signing?
Fifteen documents. Request them in one email, in writing, before the pricing conversation gets serious, because the answers change the price. Here is what each one is and why it matters.
1. Business associate agreement. The BAA is the HIPAA contract between the covered entity (usually the physician-owned PC) and anyone who creates, receives, maintains or transmits protected health information (PHI) on its behalf. Under 45 CFR 164.504(e) it must state permitted uses, require safeguards, require the vendor to report breaches and security incidents, flow the same terms down to subcontractors, and provide for return or destruction of PHI at termination. Ask for the vendor's standard BAA and confirm it is included in the master agreement, not sold as an upgrade.
2. SOC 2 Type II report. The actual report, under NDA, with the auditor's opinion, the system description, the period covered and the exceptions list. A Type II report covers a test period, typically six to twelve months. A Type I covers one day. A "SOC 2 in progress" means neither.
3. HITRUST status. Three honest answers exist: certified (r2 or i1, with a certificate and expiry date), aligned (architecture built against the HITRUST CSF without a validated assessment), or neither. All three are acceptable at different price points; what is not acceptable is a vendor letting you believe "aligned" means "certified." MyOrbitHealth describes its own posture as HITRUST-aligned architecture, which is the second category, and says so.
4. LegitScript certificate for the pharmacy network. LegitScript certification is what Google and Meta require before a telehealth brand can run most prescription-related ads in the United States. Ask whether the vendor's pharmacy partners are LegitScript-certified and whether the vendor will manage your brand's own certification. Our LegitScript certification guide explains what the reviewers actually check.
5. DEA registrations of partner pharmacies. Any pharmacy dispensing a controlled substance (testosterone is Schedule III, for example) must hold a DEA registration under 21 CFR Part 1301 and the relevant state controlled-substance permits. Ask for the registration numbers for the pharmacies that will serve your program, not a general assurance.
6. EPCS certification. Electronic prescribing of controlled substances is governed by 21 CFR Part 1311. The e-prescribing application must have passed a third-party audit or certification (21 CFR 1311.300), support two-factor authentication for signing, and identity-proof each prescriber before issuing credentials. Ask for the certification evidence and the identity-proofing procedure.
7. State licensure roster and credentialing policy. For every state you intend to serve, which providers hold active licenses, and what the credentialing process verified. The NCQA primary-source verification standard (license, DEA, board certification, education, work history, malpractice history, sanctions) is the recognized benchmark. See telehealth license requirements by state for why the patient's location, not the provider's, decides which license matters.
8. OIG/SAM exclusion-screening cadence. The HHS Office of Inspector General's List of Excluded Individuals/Entities and the federal System for Award Management are the two databases. The OIG's 2013 Special Advisory Bulletin on the effect of exclusion recommends checking both at hire and periodically; monthly screening is the standard careful organizations adopt. Ask when screening happens, who runs it and what happens when a hit appears.
9. MSO and PC agreements. In most states a non-physician cannot own a medical practice, so the vendor's structure places clinical care inside a physician-owned professional corporation and business services inside a management services organization (MSO). Ask for the template management services agreement, how the PC is owned, and how the vendor keeps clinical decisions with the PC. The corporate practice of medicine and MSO model guide covers the mechanics; our list of telehealth MSO companies compares who offers the structure turnkey.
10. Malpractice coverage. Who is the named insured, what are the per-claim and aggregate limits, does the policy cover telehealth and the modalities you will use (asynchronous, video, in every state), and is your brand an additional insured. Get the certificate of insurance, not a sentence in a deck. As a benchmark, MyOrbitHealth's network carries occurrence-based coverage with $1 million per occurrence and $6 million aggregate limits; occurrence-based policies cover claims arising from care delivered during the policy period even if the claim is filed later, which matters for a brand that may switch vendors.
11. Data ownership and export clauses. The contract should state that the brand owns its patient relationships, customer data and, through the PC, the medical records, and that export is available on demand in a usable format. HIPAA's right of access at 45 CFR 164.524 gives patients a 30-day clock on their own records; your vendor should give you something at least as good for the whole dataset.
12. Exit terms. Term length, auto-renewal, termination notice, termination fees, what happens to active patients mid-treatment, and how long data stays available after termination. A 12-month initial term with an early-termination penalty is common in enterprise telehealth; it is also the single clause most likely to trap a brand that outgrows a vendor.
13. Subprocessor list. Every subcontractor that touches PHI on the vendor's behalf: cloud hosting, e-prescribing rails, video, SMS and email delivery, support tooling, AI inference. A vendor that publishes the list, as MyOrbitHealth does at /subprocessors, is easier to audit than one that discloses it on request.
14. Breach-notification terms. The HIPAA Breach Notification Rule requires a business associate to notify the covered entity without unreasonable delay and no later than 60 days after discovery (45 CFR 164.410). Your BAA should be tighter than the regulatory ceiling, because your own notification clock to patients and HHS starts when the vendor discovers the breach, not when it tells you. If your brand also holds health data outside HIPAA, say in a wellness app that is not part of the clinical workflow, the FTC Health Breach Notification Rule (16 CFR Part 318, amended effective July 29, 2024) can apply separately.
15. Uptime SLA. The availability commitment, how it is measured, the service credits, and whether you can see the live numbers. A vendor that exposes real-time uptime, latency and queue health in its own console is making a stronger statement than one that quotes a percentage.
How do you score a telehealth vendor on compliance?
Score each line 0, 1 or 2 and weight the lines that can end the business. The table below totals 50. Anything under 35 should go back to the vendor with a list; anything under 25 is a different vendor.
| # | Line item | Document to demand | Red flag | Max points |
|---|---|---|---|---|
| 1 | HIPAA BAA | Signed BAA inside the master agreement | BAA sold as an add-on, or "we're a conduit so we don't need one" | 5 |
| 2 | SOC 2 Type II | Full report with period and exceptions | Badge only, Type I, or report limited to a higher plan tier | 5 |
| 3 | HITRUST status | Certificate with expiry, or a written statement of "aligned" | "HITRUST" used without the word certified or aligned | 2 |
| 4 | LegitScript | Pharmacy-network certificates and brand-certification plan | "LegitScript not needed if you don't run ads" | 3 |
| 5 | DEA registrations | Registration numbers per dispensing pharmacy | "Our pharmacies are DEA compliant" with no numbers | 3 |
| 6 | EPCS certification | 21 CFR 1311.300 audit/certification evidence, 2FA, identity proofing | Controlled substances prescribed by fax or phone fallback | 3 |
| 7 | Licensure roster and credentialing | State-by-state roster, NCQA-standard policy | Roster "available at go-live" or counts without states | 4 |
| 8 | OIG/SAM screening | Written cadence (monthly is the standard) and hit procedure | Screening at hire only | 2 |
| 9 | MSO/PC agreements | Template MSA, PC ownership, clinical-control language | Vendor or brand directs clinical decisions; percentage-of-collections fees in strong CPOM states | 5 |
| 10 | Malpractice | Certificate of insurance with limits and telehealth coverage | Coverage described but no certificate | 2 |
| 11 | Data ownership and export | Contract clause plus a demonstrated export | "Your data is safe with us" instead of "your data is yours" | 5 |
| 12 | Exit terms | Term, notice, fees, post-termination data access | Multi-year lock-in, termination fee, patients stranded at exit | 4 |
| 13 | Subprocessor list | Published or provided list with change-notification | "We don't share that" | 2 |
| 14 | Breach notification | BAA clause tighter than 60 days | Clause silent, or 60 days with no incident-reporting duty | 3 |
| 15 | Uptime SLA | Written SLA, credits, live telemetry | Uptime claim with no measurement method | 2 |
| Total | 50 |
If you will never prescribe controlled substances, drop lines 5 and 6 to 1 point each and raise line 11 to 7.
What does a SOC 2 Type II report prove, and what does it not?
A SOC 2 report is an attestation under the AICPA's trust services criteria. The auditor examines the vendor's description of its system and tests whether the stated controls operated effectively over the review period. It proves the vendor has controls over security (and, if in scope, availability, confidentiality, processing integrity and privacy) and that those controls worked during the period.
It does not prove HIPAA compliance, because SOC 2 criteria and the HIPAA Security Rule are different frameworks, although they overlap heavily. It does not prove the vendor's subcontractors are secure unless they are in scope. And it does not prove anything about the clinical or regulatory structure. Read the exceptions section first; a clean opinion with three exceptions around access reviews tells you what to ask about.
One 2026 reality: as of October 2026, per their site, Cuvo Health includes its SOC 2 Type II report on the Enterprise plan only, so do not assume the report comes with a lower tier; the MyOrbitHealth vs Cuvo comparison covers the differences. MyOrbitHealth's SOC 2 Type II applies across the platform, with a BAA in every contract and no plan tiers to gate it. Whichever vendor you evaluate, the question is the same: can I read the report before I sign?
Which regulations changed for telehealth vendors in 2025 and 2026?
Four items belong in a 2026 checklist that were not in a 2024 one.
DEA telemedicine flexibilities. DEA and HHS issued a fourth temporary extension of the COVID-era telemedicine flexibilities for controlled-substance prescribing, effective January 1, 2026 and running through December 31, 2026. DEA-registered clinicians may continue prescribing Schedule II–V medications via telemedicine without a prior in-person exam under those terms. A permanent framework, including the proposed special registration, has been discussed for years and could land at any time. Ask your vendor what its prescribing workflow looks like on January 1, 2027 if the flexibilities lapse. Our DEA telemedicine rules 2026 guide tracks this.
FDA clinical decision support guidance. FDA issued final Clinical Decision Support Software guidance in January 2026, clarifying which software functions fall outside the device definition under section 520(o)(1)(E) of the FD&C Act. Software that supports a licensed professional's decision while letting them independently review the basis for a recommendation generally stays outside the device definition; software that drives a recommendation to a patient, or that the clinician cannot independently evaluate, may not. Ask vendors with AI intake or triage how their functions are positioned under that guidance.
FTC Health Breach Notification Rule. The amended rule took effect July 29, 2024 and explicitly reaches health apps and similar online services not covered by HIPAA. If any part of your funnel collects health information outside the HIPAA-covered clinical workflow, your brand may be a "vendor of personal health records" with its own notification duties.
State corporate-practice tightening. Oregon's SB 951, signed June 9, 2025, restricts MSO control over professional medical entities with staggered effective dates (new arrangements in 2026, existing ones by 2029), and California's SB 351, signed October 6, 2025 and effective January 1, 2026, limits private equity and hedge fund interference with clinical decisions. Both shift what "clinical control stays with the PC" has to look like in a management services agreement, not only in a recital.
What are the red flags during a telehealth vendor demo?
Most red flags appear in how a vendor talks, not in what the deck says.
- "We make you fully HIPAA compliant." No vendor can. A platform covers technical safeguards; your workforce training, access-role decisions, vendor inventory and marketing-pixel hygiene stay with you. Our HIPAA for founders guide draws that line.
- Provider counts without states. "Hundreds of providers" is meaningless until you see the roster by state and specialty.
- A pharmacy network described but never named. Pharmacies have license numbers, state nonresident permits and inspection histories. Ask for names.
- Payments running through the vendor's merchant account. If the vendor is merchant of record, it holds your revenue, your chargebacks and your customer list. Decide deliberately.
- Revenue share or medication markup presented as "simple pricing." Both scale against you. A flat fee plus 0% medication markup is the structure to look for; it is what MyOrbitHealth publishes as its model.
- Clinical language from a salesperson. If the account executive tells you what dose a provider "usually" prescribes, clinical decisions are not staying with the PC.
- Export "on request, with a fee," or a 12-month term with a termination fee. Data you cannot pull yourself is data you do not own, and a lock-in is a trap for an early-stage brand.
What questions should you ask on the demo?
Bring this list and write down the answers.
- Show me the BAA. Is it in every contract at every tier?
- Send me the SOC 2 Type II report under NDA. What period did it cover, and what were the exceptions?
- Is your HITRUST status certified, aligned, or neither?
- Name the pharmacies that will serve my program, with their state licenses and LegitScript status. Will you manage my brand's LegitScript application?
- Which of those pharmacies hold DEA registrations, and is the e-prescribing application EPCS certified under 21 CFR 1311?
- Show me the licensure roster for the ten states where I expect the most patients. How were those providers credentialed, and how often are they screened against OIG and SAM?
- Who owns the PC in my structure? Show me the management services agreement and the clause that keeps clinical control with the PC.
- Who is the merchant of record? Who holds the chargebacks?
- Pull an export of a sample patient dataset right now. What format comes out?
- What is the term, the notice period and the termination fee? What happens to patients mid-treatment if I leave?
- Where is the subprocessor list published, and how will I learn when it changes?
- What is your breach-notification commitment to me, in hours or days?
- What is the uptime SLA, and can I see live uptime and latency?
- For API integration, how are webhooks authenticated, and what is the sandbox provisioning time?
- Which of my obligations do you not cover? (A vendor that answers this quickly understands the model.)
How does MyOrbitHealth answer each line?
Every claim below comes from MyOrbitHealth's published compliance posture at /compliance; ask us for the underlying documents and we will send them under NDA where required.
| Line item | MyOrbitHealth posture |
|---|---|
| HIPAA BAA | BAA included in every contract, at every scope |
| SOC 2 Type II | SOC 2 Type II across the platform; request the report under NDA |
| HITRUST | HITRUST-aligned architecture (aligned, not certified; stated plainly) |
| LegitScript | LegitScript-certified pharmacy network; managed certification for the brand, filed and tracked through approval (LegitScript decides; typically days once filed, never guaranteed) |
| DEA registrations | DEA-registered partner pharmacies where applicable to the program |
| EPCS | EPCS with two-factor identity proofing through OrbitRx, routed via Surescripts |
| Licensure and credentialing | 2,400+ board-certified MD/DO/NP/PA providers across 38+ specialties in all 50 states; NCQA-standard primary-source credentialing; bring-your-own-providers supported |
| OIG/SAM screening | Monthly OIG/SAM exclusion screening |
| MSO/PC structure | Licensed providers operate under an MSO / friendly-PC structure; MyOrbitHealth does not practice medicine |
| Malpractice | Occurrence-based professional liability coverage with $1 million per occurrence and $6 million aggregate limits; certificate of insurance provided during contracting |
| Data ownership and export | The brand owns its patients, records and data, with export at any time |
| Exit terms | No exit or termination fee; month-to-month after onboarding |
| Subprocessors | Published at /subprocessors |
| Breach notification | Specified in the BAA; US-region encrypted PHI |
| Uptime SLA | Real-time uptime, latency and queue health visible in OrbitOS; SLA terms set in the contract |
| Commercial structure | Flat platform fee scoped at onboarding; 0% medication markup; no revenue share; the brand is merchant of record |
How do you run the due diligence process end to end?
A founder can complete this in two weeks if the vendor cooperates. Where a line below says MyOrbitHealth runs it, that is what happens when we are the vendor under review; substitute the vendor you are evaluating.
| Step | MyOrbitHealth runs | You run |
|---|---|---|
| Send the fifteen-document request | Returns the document set, with confidential items such as the SOC 2 report under NDA | Drafts the request and tracks responses by line |
| Score the table | Answers follow-up questions on any line | Assigns 0/1/2 per line; flags anything under 35 total |
| Verify externally | Provides pharmacy-network and provider-credentialing details on request | Checks state pharmacy boards, LegitScript's public lookup, OIG LEIE and SAM.gov |
| Review the structure | Shares the MSA template and PC ownership explanation | Has healthcare counsel review the MSA and BAA for your states |
| Test export and API | Provisions sandbox access within a day after a short partner review | Pulls a sample export; tests signed webhooks and a documented endpoint |
| Run the demo questions | Answers all fifteen, including what stays with you | Records answers and compares against the contract text |
| Negotiate and sign | Scopes the flat platform fee to verticals, states and volume | Confirms month-to-month, no termination fee, export on demand |
For the broader evaluation beyond compliance, including product fit, launch speed and economics, see how to choose a white-label telehealth partner. For how patient communications should be papered and routed after launch, read HIPAA-compliant patient messaging.
Frequently asked questions
What documents should I request from a telehealth platform before signing?
Fifteen: the BAA, the SOC 2 Type II report, a HITRUST status statement, the LegitScript certificate for the pharmacy network, DEA registrations of dispensing pharmacies, EPCS certification evidence, a state licensure roster with the credentialing policy, the OIG/SAM screening cadence, the MSO and PC agreements, malpractice coverage certificates, data-ownership and export clauses, exit terms, the subprocessor list, breach-notification terms, and the uptime SLA. Request them in writing before pricing is final.
Does a white-label telehealth platform need to sign a BAA?
Yes. Any vendor that creates, receives, maintains or transmits PHI on behalf of the medical group is a business associate and must sign a BAA that meets 45 CFR 164.504(e). MyOrbitHealth includes a BAA in every contract; a vendor that sells the BAA as an upgrade or claims the conduit exception for a clinical platform should be disqualified.
Is a SOC 2 Type II report the same as HIPAA compliance?
No. SOC 2 is an AICPA attestation that security controls operated over a review period; HIPAA is a federal regulation with administrative, physical and technical safeguard requirements. The two overlap, and a SOC 2 Type II report is strong evidence of a mature security program, but you still need the BAA, a risk analysis and your own operational discipline.
Can a telehealth company still prescribe controlled substances via telemedicine in 2026?
Yes, under the fourth temporary extension of DEA and HHS telemedicine flexibilities, which runs through December 31, 2026. The e-prescribing application must meet 21 CFR Part 1311, including two-factor authentication and identity proofing. Ask your vendor how its workflow changes if the flexibilities lapse or a permanent rule takes effect.
What is the difference between HITRUST-certified and HITRUST-aligned?
HITRUST-certified means an assessor validated the organization against the HITRUST CSF and HITRUST issued a certificate with an expiry date. HITRUST-aligned means the architecture was built against the framework without a validated assessment. Both are legitimate; a vendor should state which one applies, as MyOrbitHealth does with HITRUST-aligned architecture.
Who should own the patient data in a white-label telehealth contract?
The brand should own its patient relationships, customer data and, through its affiliated medical group, the records, with export available on demand in a usable format and no fee to leave. MyOrbitHealth's published model gives the brand ownership of patients, records and data with export at any time, no termination fee, and month-to-month terms after onboarding.
Does the FTC Health Breach Notification Rule apply to telehealth brands?
It can. The rule, amended effective July 29, 2024, reaches vendors of personal health records and related entities, including health apps and online services not covered by HIPAA. If your brand collects health information outside the HIPAA-covered clinical workflow, for example in a wellness app or quiz funnel, counsel should assess whether the rule applies to that data.
Sources
- 45 CFR 164.504(e), business associate contract requirements (eCFR)
- 45 CFR 164.410, notification by a business associate (eCFR)
- 21 CFR Part 1311, requirements for electronic orders and prescriptions (eCFR)
- 16 CFR Part 318, FTC Health Breach Notification Rule
- FDA, Clinical Decision Support Software guidance (final, January 2026)
- HHS OIG, Special Advisory Bulletin on the Effect of Exclusion
- DEA Diversion Control Division, telemedicine
- MyOrbitHealth compliance page
Run the checklist against us
Send the fifteen-document request to MyOrbitHealth and score the answers. The compliance posture is published at /compliance, the subprocessor list at /subprocessors, and the rest comes under NDA. Book a demo and bring the question list; we will answer the fifteenth question first.
