Updated September 2026 · Compliance

Telehealth compliance: who holds what

Telehealth compliance is not one thing. It is a stack of separate obligations that each attach to a specific party: the medical entity, the individual provider, the pharmacy, the platform and the brand. Launches fail when nobody can say which party holds which piece. As of September 2026 the stack for a direct-to-consumer telehealth brand is: a corporate practice of medicine structure (a physician-owned professional entity paired with a management services organization), providers licensed in every state where patients sit, NCQA-standard credentialing with ongoing exclusion screening, DEA registration and EPCS if anything controlled is prescribed, a HIPAA program with a business associate agreement in every vendor contract, state modality and prescribing rules, LegitScript certification for paid ads and payments, and someone watching rule changes every month. MyOrbitHealth holds the clinical and regulatory layers inside one contract: 2,400+ board-certified MD, DO, NP and PA providers across all 50 states, credentialing with monthly OIG-LEIE and SAM.gov screening, EPCS with two-factor identity proofing, a LegitScript-certified pharmacy network, HIPAA plus BAA in every contract, SOC 2 Type II and managed LegitScript certification. You hold the brand, the patients, the data and the merchant account. This page is general information, not legal advice.

Doing it yourself vs a clinician network vs MyOrbitHealth

Three ways to stand up a compliant telehealth brand. The table shows who carries each task in each model. A clinician network supplies providers and little else; the brand still builds the entity, the privacy program and the pharmacy relationships around them.

Doing it yourself vs a clinician network vs MyOrbitHealth
Entity and MSO or friendly-PC structureDIY: you form the PC in each state plus the MSO, with counsel. Clinician network: you, same as DIY. MyOrbitHealth: held inside the network; you contract with the platform and never own a medical practice.
Provider licensing in patient statesDIY: recruit and license per state, expect months. Clinician network: supplied, but coverage gaps are your problem. MyOrbitHealth: 2,400+ providers licensed across all 50 states, coverage maintained by us.
Credentialing and exclusion screeningDIY: build primary-source verification and monthly OIG-LEIE and SAM.gov checks. Clinician network: varies, ask for the standard. MyOrbitHealth: NCQA-standard credentialing, monthly exclusion screening, continuous license monitoring, malpractice handled in the network.
DEA registration and EPCSDIY: each prescriber registers, you buy and certify an EPCS system. Clinician network: prescribers bring registrations, EPCS tooling is still yours. MyOrbitHealth: DEA registration verified at credentialing, OrbitRx delivers EPCS with two-factor identity proofing via Surescripts.
Pharmacy licensure and routingDIY: contract 503A and retail pharmacies, verify licensure in every ship-to state. Clinician network: not included. MyOrbitHealth: LegitScript-certified pharmacy network, 503A plus retail, cold chain, routed by state.
HIPAA program and BAAsDIY: policies, training, risk analysis, a BAA with every vendor touching PHI. Clinician network: you, plus a BAA with the network. MyOrbitHealth: HIPAA plus BAA in every contract, SOC 2 Type II report under NDA, HITRUST-aligned controls.
LegitScript certificationDIY: assemble the file, apply, answer reviewers. Clinician network: you. MyOrbitHealth: we prepare, file and manage your application through approval; LegitScript decides, and certification is not guaranteed.
State modality and prescribing rulesDIY: track which states require video, which allow async, which restrict specific drugs. Clinician network: only for the prescriber's own act. MyOrbitHealth: encoded into Orbit Intake and OrbitRx routing so the right modality is enforced per state.
Ad-platform policyDIY: read Google and Meta healthcare policies, get certified, keep claims compliant. Clinician network: not included. MyOrbitHealth: certification handled and claim guidance provided; your team still writes the ads.
Ongoing rule monitoringDIY: counsel on retainer or a compliance hire. Clinician network: rarely. MyOrbitHealth: federal and state changes tracked by our compliance team and pushed into platform rules; you get a change note, not a research project.

Corporate practice of medicine and the MSO structure

Corporate practice of medicine (CPOM) is the doctrine, enforced to different degrees by most states, that a business owned by non-physicians may not practice medicine or control clinical judgment. It is why a brand cannot hire doctors into a Delaware C-corp and start prescribing. The workaround is well understood, but it has to be built correctly.

01

The professional entity

Care is delivered by a professional corporation or PLLC owned by a licensed physician. It employs or contracts the providers, holds the patient relationship in the legal sense, and is the name on the clinical record. Strict CPOM states such as California, Texas and New York enforce ownership rules with real consequences.

02

The management services organization

The MSO is the non-clinical company that provides everything else: technology, staffing, billing, marketing, administration. It contracts with the professional entity under a management services agreement and is paid a fee for those services. The MSO can be owned by anyone. This is where a brand lives.

03

What the agreement must not do

Regulators look at substance, not labels. The MSA cannot give the MSO control over diagnosis, treatment, prescribing, referrals or clinical hiring decisions. Fees that look like a percentage of clinical revenue draw fee-splitting scrutiny in several states. Have counsel review the agreement against the states you serve.

04

How it works on MyOrbitHealth

The provider network already operates under a compliant professional entity and MSO structure. Your brand signs one platform agreement, sets the program, and the network's clinicians make every clinical decision independently. A flat platform fee scoped at onboarding, 0% medication markup and no revenue share keep the economics clear of fee-splitting questions.

Licensure across 50 states and the Interstate Medical Licensure Compact

Medicine is regulated where the patient is, not where the provider is. A provider treating a patient in Ohio needs an Ohio license regardless of where the provider sits. That one rule drives most of the operational cost of a national program.

01

What the IMLC does and does not do

The Interstate Medical Licensure Compact is an expedited pathway for MDs and DOs to obtain full licenses in member states. As of September 2026, 44 states plus the District of Columbia and Guam participate, with more in process. Be precise: the Compact issues separate state licenses faster. It does not create one license that works everywhere, and each license keeps its own renewal, CME and fee obligations.

02

Nurse practitioners and physician assistants

NPs and PAs are not covered by the IMLC. The APRN Compact and the PA Licensure Compact exist but, as of September 2026, are still being implemented and are not yet operational at scale. In practice a multi-state NP or PA program means state-by-state licensing, and supervision or collaboration rules differ by state.

03

The coverage math

A national program needs licensed capacity in every state where you accept patients, at every hour you promise availability, and it has to survive vacations, license lapses and churn. MyOrbitHealth carries 2,400+ providers across 38+ specialties and all 50 states with continuous license monitoring, so one provider's license issue never becomes a state outage for your brand.

04

Modality rules by state

States also set how an encounter may be conducted. Some require synchronous audio-video to establish a relationship, some allow asynchronous intake for many conditions, and some restrict specific drug classes or require an in-person exam. On the platform these rules are enforced at routing time, so an intake in a video-only state never reaches a provider as an async case.

DEA telemedicine flexibilities, as of September 2026

Controlled substances add a federal layer on top of everything above. Every date here matters, because the current rules are temporary and the replacement rule is not yet public. Confirm status on dea.gov before relying on any of this.

01

The current extension

On December 31, 2025, DEA and HHS published the fourth temporary extension of the telemedicine flexibilities, effective January 1, 2026 through December 31, 2026. Under it, a DEA-registered practitioner may prescribe Schedule II through V controlled substances via audio-video telemedicine without a prior in-person evaluation, and Schedule III through V narcotic medications for opioid use disorder via audio-only, subject to state law.

02

The special registration rule

DEA proposed a telemedicine special registration framework in January 2025 and received more than 6,400 comments. On August 25, 2026, DEA sent the final rule to the White House Office of Information and Regulatory Affairs; the federal regulatory agenda anticipates final action in November 2026. As of September 23, 2026 the final text is not published, so nobody outside the review knows what changed.

03

What a brand should plan for

Plan for the flexibilities to end on December 31, 2026 and for a special registration regime to replace them, possibly with separate registration categories, PDMP checks and limits on Schedule II prescribing without in-person care. If your program depends on controlled substances, build the in-person or hybrid pathway now, not in December. Non-controlled programs are unaffected.

04

What MyOrbitHealth holds

DEA registration is verified for every prescriber at credentialing. OrbitRx delivers EPCS with two-factor identity proofing through Surescripts. When the final rule publishes, its requirements are encoded into prescribing rules and provider workflows and brands receive a change note. Whether your program should include controlled substances remains a decision for the professional entity and your counsel.

HIPAA telehealth compliance, SOC 2 Type II and PHI handling

HIPAA applies to the covered entity delivering care and to every business associate that creates, receives, stores or transmits protected health information for it. In a telehealth stack that is the platform, the pharmacy, the lab, the messaging vendor, sometimes the payment processor, and often the brand itself.

01

The BAA is the contract that matters

A business associate agreement is required, in writing, before PHI moves. It allocates breach notification duties, permitted uses, safeguards and subcontractor flow-down. A vendor that resists signing one is telling you it is not built for this. MyOrbitHealth includes a BAA in every contract, and our subcontractors carry the same terms.

02

HIPAA versus SOC 2 versus HITRUST

HIPAA is law and has no certification; you comply or you do not. SOC 2 Type II is an auditor's report that controls operated effectively over a period, and it is what enterprise partners ask for. HITRUST is a certifiable framework that maps HIPAA into testable controls. MyOrbitHealth maintains a SOC 2 Type II report, available under NDA, and its control set is HITRUST-aligned.

03

Where PHI lives on the platform

Intake answers, visits, prescriptions, lab results and messages live in OrbitOS and the Patient Portal, encrypted in transit and at rest, with role-based access and audit logs. The brand owns the patients, the records and the data, with export at any time. The API and webhooks let you pass an event like order completed to marketing systems without moving the clinical record.

04

What still sits with the brand

A BAA does not make your marketing compliant. Tracking pixels on pages where patients enter health information, condition-specific email lists and support staff reading clinical notes are brand-side decisions. The platform gives you a clean boundary; keeping the marketing stack on the right side of it is your team's job, and we will tell you where the line is.

LegitScript and ad platforms

Google, Meta and the major card networks rely on LegitScript's healthcare merchant certification to decide whether a telehealth brand can run paid healthcare ads or process healthcare payments at scale. Without it, most paid channels are closed. The full process is on our LegitScript page at /legitscript.

01

What reviewers check

Prescriber licensure, the prescribing model, pharmacy relationships and their licensure, privacy practices, ownership and corporate structure, and whether the live storefront's claims match the file. Most of that evidence is the material the earlier sections describe, which is why compliance and marketing cannot be separate projects.

02

Managed certification

MyOrbitHealth prepares the file, submits the application for your domain in your name, answers reviewer questions and manages it through approval, then keeps the evidence current. Because the clinical and privacy documentation already exists inside the network, brands typically see a decision in days once filed, not months. LegitScript decides, not us, and certification is never guaranteed.

03

Platform policy is a separate layer

Certification opens the door; each ad platform's healthcare policy still governs what you can say. Before-and-after claims, certain drug names and outcome guarantees get ads rejected regardless of certification status. Certified brands still lose accounts over claim language. Treat platform policy as a living document your marketing lead owns.

Vendor vetting checklist: eight questions to ask any platform

Use these on us and on anyone else. The answers should be specific and documented. A vague answer to any of them means the compliance risk is about to become yours.

Vendor vetting checklist: eight questions to ask any platform
1. Who is the covered entity and who owns the professional corporation?You want a named, physician-owned professional entity and a written MSO agreement. If the vendor cannot explain its own CPOM structure, it does not have one.
2. How are providers credentialed and how often re-screened?Primary-source verification to an NCQA standard, monthly OIG-LEIE and SAM.gov exclusion screening and continuous license monitoring, not a one-time check at hire.
3. Is EPCS certified with two-factor identity proofing?Required for any controlled-substance prescribing. Ask which certified system, whether it routes through Surescripts, and how DEA registrations are verified.
4. Are the pharmacies LegitScript-certified and licensed in every ship-to state?Ask for the list. Ask how 503A compounded products and cold-chain shipments are handled and who is responsible when a state changes its rules.
5. Will you sign a BAA and share your SOC 2 Type II report?Both should be yes. The report should be a Type II covering a period, not a Type I point in time, and available under NDA without a fight.
6. Who owns the patients, records and data, and how do we export?The brand should own all three, with export at any time and no exit fee. If leaving the platform means leaving your patients behind, you do not own your business.
7. How is the fee structured?A flat platform fee scoped at onboarding, 0% medication markup and no revenue share keeps the arrangement clear of fee-splitting concerns. Revenue-share models deserve a hard look from counsel.
8. Who monitors rule changes and how do they reach us?Ask for the last three regulatory changes the vendor pushed to customers and how each was communicated. Rules moved every quarter in 2025 and 2026. No answer means no monitoring.

Frequently asked questions

Can a non-clinician own a telehealth brand?
Yes, with the right structure. A non-clinician can own the brand and the management services organization that provides technology, marketing and administration. Clinical care must be delivered by a physician-owned professional entity in states that enforce the corporate practice of medicine doctrine, and the MSO cannot control clinical decisions. On MyOrbitHealth that structure already exists, so your company contracts with the platform and never owns a medical practice. General information, not legal advice; confirm with counsel for your states.
What is an MSO?
A management services organization is a non-clinical company that provides business services to a medical practice under a written management services agreement: technology, staffing, billing, marketing and administration. It is paid a fee for those services and is how non-physician owners and brands participate in healthcare without practicing medicine. The agreement must leave clinical judgment, prescribing, referrals and clinical hiring decisions with the licensed professional entity.
Do I need a provider licensed in every state?
A provider must be licensed in the state where the patient is located during the visit. If you accept patients in all 50 states, you need licensed capacity in all 50 states. The Interstate Medical Licensure Compact speeds physician licensing in its 44 member states as of September 2026, but it still issues separate state licenses and does not cover NPs or PAs. MyOrbitHealth maintains 2,400+ providers across all 50 states so a brand does not build that coverage itself.
Are controlled substances allowed via telehealth in 2026?
As of September 2026, yes, under a temporary federal extension. DEA and HHS extended the telemedicine flexibilities through December 31, 2026, allowing DEA-registered practitioners to prescribe Schedule II through V controlled substances via audio-video telemedicine without a prior in-person evaluation, subject to state law. A final special registration rule entered federal review on August 25, 2026 and is expected late in 2026; its contents are not public. Plan for the rules to change on January 1, 2027 and confirm status on dea.gov. General information, not legal advice.
Is HIPAA the same as LegitScript?
No. HIPAA is federal privacy and security law governing how protected health information is handled by covered entities and business associates; there is no HIPAA certification, only compliance. LegitScript is a private certification body whose healthcare merchant review Google, Meta and card networks use to decide who may advertise and process healthcare payments. A brand needs both: a HIPAA program with BAAs for the data, and LegitScript certification for paid acquisition. They overlap in evidence, not in purpose.
Who monitors rule changes?
On a DIY or clinician-network model, the brand does, usually through outside counsel or a compliance hire. On MyOrbitHealth our compliance team tracks federal and state changes, including DEA telemedicine rules, state modality and prescribing restrictions, licensure compacts and ad-platform healthcare policy, and encodes them into platform routing and provider workflows. Brands receive a change note describing what changed and what, if anything, they need to do. Marketing claim language and brand-side data practices remain the brand's responsibility.

Go deeper: the MSO model for telehealth, explained, telehealth prescribing rules in 2026, HIPAA for founders, and telehealth licensing by state.

This page is general information, not legal or medical advice.

Launch on a compliant structure

A working MSO and professional entity, 2,400+ credentialed providers in all 50 states, EPCS, a LegitScript-certified pharmacy network, HIPAA plus BAA in every contract and managed LegitScript certification, live in days under your brand.