MDLaunchr
Payment Processing

Processor Requested LegitScript Certification: What It Means and What to Do

Understand why a payment processor may request LegitScript certification, what the request does and does not establish, and how to prepare a documentation file without treating certification as a substitute for licensing or compliance.

MDLaunchr Team·9 min read·Updated September 15, 2026
Part of our guide: Payment Processing Guide

When a payment processor requests LegitScript certification, it is usually applying enhanced underwriting to a healthcare-related payment flow. The processor or acquirer decides whether to continue processing, based on its risk policy and documentation—not a federal LegitScript mandate. Certification is a private screening step, not a healthcare license or guarantee of approval.

Processor requesting LegitScript certification at a glance

QuestionWhat to expectWho sets it
Why was certification requested?The business appears to involve healthcare activity receiving enhanced review.Processor or acquirer
Is it required by federal law?No federal requirement was identified in the approved sources.Federal law does not establish it
What must be submitted?Business, licensing, workflow, website, billing, privacy, and advertising records.Processor, acquirer, or reviewer
How long will review take?Confirm the deadline and review timeline directly; no approved timing is established here.Processor or acquirer
What does certification cost?Confirm application, renewal, monitoring, and other fees.Processor, acquirer, or certification provider
Can certification guarantee approval?No. It does not guarantee payment-processing approval.Processor underwriting decision
What may trigger a problem?Mismatched services, unsupported health claims, unclear providers, or incomplete licensing records.Processor review and applicable law
What happens if certification is denied or delayed?Confirm whether processing pauses, ends, or follows another underwriting path.Processor or acquirer

What does a processor requesting LegitScript certification mean?

It means the processor has placed the business into a heightened compliance or risk-review workflow. The request may reflect the apparent category, website language, transaction type, or involvement of telehealth, online health services, supplements, pharmacies, or other health-related activity.

LegitScript certification is a private compliance and risk-screening program. The approved federal sources do not establish that FDA, HHS, the FTC, CMS, DEA, or another federal agency created or requires it. They also do not establish card-network thresholds, fees, monitoring rules, or approval criteria.

The request is therefore best treated as a business-process signal: the processor wants a clearer explanation of what the company does and evidence that its public claims, providers, customer journey, billing, and fulfillment arrangements align.

Is LegitScript certification required by federal law?

No, the approved federal sources do not identify a federal law that specifically requires LegitScript certification. A processor, acquirer, card network, or internal risk policy may still make certification a condition of processing, but the applicable source and consequence must be confirmed with the acquirer or processor.

Certification also does not replace state licensure, telehealth rules, pharmacy requirements, prescribing rules, privacy obligations, advertising standards, or payer requirements. HHS explains that telehealth reimbursement depends on the payer and jurisdiction, while Medicaid telehealth policies vary by state. CMS materials identify payer-specific coding and reimbursement considerations rather than treating certification as proof of billability.

Why does my processor need LegitScript certification?

The processor may need additional assurance because healthcare payment flows can combine regulated services, sensitive information, recurring billing, fulfillment, and health-related advertising. That does not by itself mean the business has violated a rule.

A review commonly becomes harder when the website promises more than the operational model supports. Examples include unclear provider responsibility, unexplained fulfillment relationships, broad effectiveness claims, inconsistent legal-entity information, or a checkout flow that does not clearly disclose recurring charges.

For related underwriting context, see How Underwriters Evaluate a Telehealth Website Before Approving Payments and What Documents Do Telehealth Merchant Account Underwriters Require?.

What documents should a healthcare merchant prepare?

Prepare a single readiness file that lets the reviewer connect the legal entity, website, providers, services, billing, and data flows:

  1. 1Corporate records: legal entity name, ownership, EIN, business addresses, responsible officers, websites, brands, and payment descriptors.
  2. 2Licensing records: applicable provider, facility, pharmacy, laboratory, or other licenses, plus the jurisdictions they cover.
  3. 3Clinical and operational description: what is offered, who provides it, where services occur, how customers enter the workflow, and how fulfillment is handled.
  4. 4Provider information: credentials, jurisdictions served, contracting relationships, and the party responsible for clinical services.
  5. 5Customer-journey evidence: advertisements, landing pages, intake screens, checkout pages, consent language, terms, privacy notices, refund policy, and cancellation flow.
  6. 6Billing controls: recurring-billing consent, cancellation records, refund procedures, dispute handling, and accurate billing descriptors.
  7. 7Advertising substantiation: support for health, safety, efficacy, diagnosis, treatment, prevention, testimonial, endorsement, and FDA-related claims.
  8. 8Privacy and security records: data map, vendor list, HIPAA analysis, breach-response plan, and applicable health-data notices.
  9. 9Processor correspondence: the exact requirement, deadline, scope, renewal cycle, fees, and consequences of non-certification.
  10. 10State review matrix: states where providers practice, patients are located, products are shipped, or the company advertises.

The goal is not to submit the largest possible file. It is to submit consistent records that accurately describe the same business model.

What advertising issues can affect certification or underwriting?

Health-related advertising generally requires competent and reliable scientific evidence under the FTC Health Products Compliance Guidance. Testimonials and expert endorsements cannot be used to communicate claims the advertiser could not substantiate directly, and a disclaimer does not automatically cure a misleading overall impression.

The FTC’s Trade Regulation Rule on the Use of Consumer Reviews and Testimonials, 16 C.F.R. Part 465, effective October 21, 2024, addresses fake or false reviews, sentiment-conditioned review incentives, certain undisclosed insider reviews, deceptive company-controlled review sites, review suppression, and fake social-media indicators.

Before review, audit claims about diagnosis, treatment, prevention, safety, effectiveness, clinical proof, guaranteed outcomes, and FDA approval. Preserve evidence that testimonials are genuine, reviewers had the claimed experience, material relationships are disclosed, and incentives are not conditioned on positive or negative sentiment.

What recurring-billing rules should a merchant review?

For covered recurring subscriptions and other negative-option programs, the FTC’s Negative Option Rule, 16 C.F.R. Part 425, requires accurate material disclosures before billing information is obtained, express informed consent to the negative-option feature, and a simple cancellation mechanism that immediately stops negative-option charges. The rule became effective January 14, 2025; compliance with key §§ 425.4–425.6 provisions began May 14, 2025.

Maintain the checkout disclosure, affirmative consent record, recurring-billing terms, cancellation requests and timestamps, evidence that charges stopped promptly, and refund or dispute procedures. Whether a specific telehealth membership, care plan, or wellness program falls within the rule depends on its structure.

Does LegitScript certification replace HIPAA or health-breach duties?

No. HIPAA applies based on the parties and activities involved, not simply because a company operates a health-related website. HHS explains that an app outside the covered-entity and business-associate structure may fall outside HIPAA, while other obligations—including the FTC Health Breach Notification Rule—may still apply.

Determine whether the business is a HIPAA covered entity, whether vendors are business associates, what information reaches the payment environment, and whether payment, scheduling, analytics, or telehealth systems receive health information. Under the HIPAA Breach Notification Rule, 45 C.F.R. §§ 164.400–414, covered entities generally must notify individuals without unreasonable delay and no later than 60 days after discovering a breach of unsecured protected health information; business associates must notify covered entities within the same outer period.

Certification does not establish that a company is HIPAA-compliant or exempt from the FTC’s health-breach requirements.

What changed recently?

The rules and guidance were checked against official sources as of September 15, 2026. Recent developments include:

  • October 21, 2024: The FTC Consumer Reviews and Testimonials Rule became effective.
  • November 15, 2024: The FTC published the final Negative Option Rule in the Federal Register.
  • January 14, 2025: The Negative Option Rule became effective.
  • May 14, 2025: Key Negative Option Rule disclosure, consent, and cancellation provisions reached their compliance date.
  • May 27, 2026: CMS issued guidance concerning certain rural health clinic and federally qualified health center distant-site telehealth billing beginning October 1, 2026.

These developments do not establish a federal LegitScript requirement. They do show why a merchant’s billing, marketing, privacy, and telehealth documentation may receive detailed scrutiny.

What do I do after a processor requests LegitScript certification?

  1. 1Founder: Save the request, deadline, account identifier, websites, brands, descriptors, and exact language describing the requirement.
  2. 2Founder and platform: Map the customer journey from advertisement and intake through clinical service, payment, fulfillment, refunds, and support.
  3. 3Founder: Identify every entity, provider, patient location, shipment destination, and payment flow involved.
  4. 4Counsel or qualified compliance adviser: Review applicable state licensure, telehealth, pharmacy, privacy, advertising, and recurring-billing issues.
  5. 5Founder and platform: Reconcile website claims, provider coverage, terms, privacy notices, checkout disclosures, cancellation flow, and operational reality.
  6. 6Founder: Assemble licensing, corporate, provider, advertising, billing, privacy, and breach-response records.
  7. 7Processor or acquirer: Confirm whether the request comes from internal underwriting, the acquirer, a card-network program, or another party.
  8. 8Founder: Submit only accurate, current materials and retain the complete submission and correspondence.
  9. 9Processor or acquirer: Confirm the decision, conditions, renewal requirements, monitoring terms, and consequences of denial, delay, suspension, or expiration.

MDLaunchr, the brand behind WhiteLabelClinic.com, is a white-label telehealth infrastructure platform—not a processor, regulator, pharmacy, or law firm. Explore how MDLaunchr and WhiteLabelClinic.com can support a compliance-first telehealth launch by organizing the infrastructure questions before underwriting or certification review.

Questions to ask your processor

Copy and paste these questions into an email:

  • “Is LegitScript certification required by the processor, the acquirer, a card network, or an internal risk policy?”
  • “Which merchant category, website feature, transaction type, or service triggered this request?”
  • “Is certification required before processing, for continued processing, or only for particular products or services?”
  • “What documents, entities, brands, websites, providers, and jurisdictions must be included?”
  • “Does approval cover all of our websites, brands, legal entities, and payment descriptors?”
  • “What are the application, renewal, review, monitoring, or other applicable fees?”
  • “What happens if certification is denied, delayed, suspended, or expires?”
  • “Are there transaction, refund, chargeback, reserve, volume, or other account conditions we must confirm?”

Ask the processor or acquirer for current card-network program details, thresholds, fees, and consequences rather than relying on an uncited estimate.

Related reading: the full guide this article belongs to.

ML
MDLaunchr Team

Written and reviewed by MDLaunchr's clinical and compliance team. We build white-label telehealth infrastructure for founders, creators, and healthcare operators—covering providers, pharmacy, technology, and compliance.

DISCLAIMER

This article is for general informational and educational purposes only and is not medical, legal, or regulatory advice. It does not create a provider-patient relationship and should not be used to diagnose or treat any condition. Telehealth and compounding regulations vary by state and change over time—consult qualified legal, clinical, and compliance professionals before launching or operating a telehealth program.

Frequently asked questions

Is LegitScript certification the same as a healthcare license?

No. It is a private compliance and risk-screening program. It does not replace state provider, facility, pharmacy, laboratory, telehealth, or other applicable authorization.

Does LegitScript certification guarantee payment-processor approval?

No. The processor or acquirer still makes the underwriting decision, and the approved sources do not establish that certification guarantees approval.

How long does LegitScript certification review take?

No approved source establishes a standard timeline. Ask the processor or acquirer for the submission deadline, review timeline, renewal cycle, and consequences of delay.

Can a processor require certification even if federal law does not?

Yes. A processor, acquirer, card network, or internal risk policy may impose a condition of processing. Ask which party created the requirement and what account activity it covers.

What should I do if my website claims are broader than my services?

Pause and reconcile the claims, provider model, customer journey, and supporting evidence before submitting materials. FTC guidance addresses substantiation and deceptive health claims.

Can MDLaunchr obtain certification for my business?

No guarantee is offered. MDLaunchr and WhiteLabelClinic.com can help qualified businesses evaluate and coordinate launch relationships, but certification and processing decisions belong to the relevant reviewer.

Keep reading

PAYMENTS

Dealing with a hold, a review, a closed account, or a first application?

MDLaunchr is not a processor and cannot promise approval. What we do is help telehealth and med spa businesses respond completely, build the underwriting packet, and get introduced to processors that underwrite healthcare.

Or read the full telehealth payment processing guide.

Dealing with a hold, review, or closed account?

Tell us what your processor said and we'll come back to you on next steps.