Payment underwriting often begins with a review of the live website. The central question is whether the site clearly explains who is selling what, how customers are billed, what clinical role the business plays, and how billing concerns are handled.
There is no universal federal telehealth merchant-underwriting checklist. Processors set their own commercial, fraud, dispute, and compliance standards. The framework below is an operational readiness guide based on federal agency requirements, guidance, and enforcement priorities—not a promise that an application will be accepted.
Why the website matters
A processor or acquiring bank is not reviewing only the checkout page. The website helps an underwriter understand the transaction, assess potential dispute concerns, and determine whether the public-facing offer matches the merchant application and supporting documents.
The site should also distinguish business operations from clinical decision-making. A technology platform or management company may support scheduling, payments, communications, or administrative coordination, while appropriately licensed clinicians or provider organizations remain responsible for clinical decisions where applicable. The website should make that relationship understandable rather than suggesting that a software company diagnoses, treats, prescribes, or promises clinical results.
For related payment topics, see the telehealth payments and merchant-account resource hub.
1. Business identity and service description
Before reviewing individual policies, an underwriter needs a coherent description of the business. Check whether the website clearly states:
- The legal business name and operating entity.
- Customer-service contact information and support channels.
- What the customer is purchasing.
- Whether the offer is clinical care, a consultation, a membership, care coordination, software access, or another service.
- The provider organization or clinicians responsible for care, where applicable.
- The states or jurisdictions served, or that availability depends on location.
- A consistent business name across the website, payment application, bank account, invoices, and card-statement descriptor.
Ambiguity can lead to follow-up questions. Depending on the business model, a processor may request ownership records, provider agreements, licensing information, fulfillment details, or an explanation of which entity receives customer funds. The website cannot replace those documents, but it should not contradict them.
2. Healthcare claims and testimonials
Health-related marketing presents a separate review issue. The FTC explains that health claims need appropriate substantiation. Claims can be express or implied and may arise from headlines, images, testimonials, product names, and before-and-after presentations—not only from technical copy.
Review the site for statements involving:
- Promised outcomes or claims that results carry no meaningful uncertainty.
- Claims to treat, cure, prevent, or reverse a serious condition.
- Unqualified safety or efficacy statements.
- Testimonials implying outcomes that typical customers should expect.
- Suggestions that a service or product is FDA-approved, equivalent to an FDA-approved product, or an alternative to one without appropriate support.
A disclaimer in small type may not correct a misleading headline. A better workflow is to maintain a substantiation file for each material health claim, identify the evidence supporting it, and remove unsupported superlatives before submitting a merchant application. FDA materials also illustrate why online claims suggesting approval or making unsupported disease-related representations can create regulatory concern.
Underwriters are not the final authority on whether a claim is lawful, and processor acceptance does not validate a claim. Health-marketing review should involve qualified compliance, legal, and clinical reviewers as appropriate.
3. Privacy notices, tracking, and sensitive information
Privacy language should match the website’s actual data flow. A healthcare business should be able to explain what information is collected during scheduling, intake, payment, customer support, and telehealth encounters—and which third parties receive or process it.
A website review may include:
- 1A visible privacy policy reflecting current practices.
- 2A HIPAA Notice of Privacy Practices when the business is a covered healthcare provider required to provide one.
- 3Information about analytics, advertising pixels, session recording, and other tracking technologies.
- 4A coherent explanation of technology vendors and, where required, business associate relationships.
- 5A payment flow that avoids collecting sensitive health information unnecessarily.
- 6A clear distinction between payment information and health information, including how each is protected and shared.
HHS guidance identifies privacy and security issues associated with telehealth technology and online tracking. Covered providers and health plans may also need compliant technology vendors and business associate agreements where required. Responsibilities vary by role and arrangement; a software platform, management company, provider entity, and third-party administrator may not have the same obligations.
A privacy policy drafted for general e-commerce may not fit a telehealth workflow. The policy should describe the intake, scheduling, communications, payment, and tracking systems actually in use.
4. Pricing, subscriptions, and cancellation
Recurring billing receives particular attention because unclear renewals and difficult cancellation processes can create customer confusion and disputes. Before payment, the website should state the total price, billing frequency, trial or introductory terms, renewal timing, and cancellation method in language customers can readily notice and understand.
A checkout review should answer four questions:
| Review question | Website evidence to look for |
|---|---|
| What is being purchased? | A specific description of the service, membership, consultation, or access period |
| When will the customer be charged? | Price, billing interval, trial conversion, and renewal terms near the purchase action |
| How does cancellation work? | Practical instructions that match the actual process |
| What record proves consent? | Timestamped enrollment, terms version, confirmation, and cancellation records |
“Cancel anytime” should match the real process. The business should retain records of consent, cancellation requests, customer support, refunds, and relevant communications. The card descriptor should also be recognizable and consistent with the brand customers saw when enrolling.
The FTC announced a final Click-to-Cancel rule in October 2024 addressing recurring-payment disclosures, informed consent, and cancellation. The FTC also published a March 12, 2026 proposed rulemaking concerning possible amendments to its Negative Option Rule. That proposal is not, by itself, a current final requirement. Because rule text, effective dates, and litigation status can change, confirm current requirements before launch with qualified counsel.
5. Refund and no-refund policies
A refund policy is not merely a footer item. It affects customer expectations and may influence disputes after payment.
The live site should explain:
- What event makes a customer eligible for a refund.
- Whether unused services, missed appointments, failed intake, or duplicate charges qualify.
- The deadline for requesting a refund.
- Whether cancellation stops future billing immediately or at the end of a billing period.
- How a customer submits a request.
- Expected processing time.
- Whether different services or states have different terms.
A business may use a no-refund policy in some circumstances, but material conditions should be disclosed before payment and written plainly. Do not advertise a refund right that the operational team does not consistently honor. Keep a documented process for reviewing requests and recording decisions.
A website-readiness workflow before applying
Use this sequence rather than treating the review as a one-time copywriting exercise:
1. Map the transaction. Identify the legal merchant, service sold, customer journey, clinical entity, billing schedule, and fulfillment responsibility.
2. Compare public and private records. Reconcile the website with the payment application, bank account, invoices, agreements, provider information, and card descriptor.
3. Test the customer path. Navigate from the landing page to checkout and confirm that price, renewal, cancellation, privacy, and refund information appears before payment.
4. Audit claims. Create a substantiation record for material healthcare claims and remove unsupported approval suggestions and typical-outcome implications.
5. Review data practices. Inventory intake fields, payment pages, analytics, advertising tools, session recording, telehealth technology, and third-party vendors.
6. Preserve evidence. Store terms versions, consent records, cancellation timestamps, support tickets, refunds, and website change logs.
7. Complete state review. Federal materials do not answer every state question. Before serving a state, evaluate professional licensing, telehealth practice rules, corporate-practice restrictions, privacy and health-data laws, automatic-renewal requirements, advertising limits, and entity obligations with qualified state-specific counsel and clinical or compliance reviewers.
This process describes risk signals a processor may evaluate; it is not a federally required application form. Preparation can make the business model easier to understand and the application more internally consistent, but it cannot determine the processor’s decision.
What website readiness can—and cannot—do
A clear site may reduce avoidable questions, but it does not establish a processing rate, reserve arrangement, or uninterrupted processing. Processor-specific decisions may also consider information outside the website, such as the merchant’s ownership, business structure, transaction profile, fulfillment arrangements, and expected dispute exposure. Those factors are separate from the website framework described here and should be confirmed directly with the processor or acquiring partner.
MDLaunchr is the brand behind WhiteLabelClinic.com, a white-label telehealth infrastructure platform designed to help qualified businesses evaluate and coordinate the technology, operational, compliance, clinical-network, and fulfillment relationships involved in launching telehealth services. Explore how MDLaunchr and WhiteLabelClinic.com can support a compliance-first telehealth launch.
Frequently asked questions
Is website readiness enough to secure a telehealth merchant account?
No. Website readiness is one part of underwriting. A processor may also review information outside the site, including business structure, fulfillment relationships, transaction profile, and expected dispute exposure. A polished website cannot determine approval.
What do underwriters look for on a healthcare website first?
They commonly need to understand the legal merchant, service being sold, provider or clinical role, pricing, billing frequency, cancellation process, refund policy, privacy disclosures, and business contact information. Consistency between the website and application is important.
Should a telehealth website display a HIPAA Notice of Privacy Practices?
A covered healthcare provider required to provide a Notice of Privacy Practices should make it available as required by HIPAA, including through appropriate electronic delivery and website access where applicable. Whether a particular business is a covered entity or business associate depends on its role and arrangements and requires qualified review.
Can a disclaimer fix an unsupported healthcare claim?
Not necessarily. The FTC evaluates the overall net impression of advertising, and qualifying information should be clear and conspicuous. A disclaimer should not be used to rescue a headline or testimonial that communicates an unsupported health outcome.
Does a no-refund policy prevent payment disputes?
No. A no-refund policy may set contractual expectations, but it should be disclosed before payment and applied consistently. Clear service descriptions, cancellation procedures, support records, and timely review of legitimate billing issues may help reduce confusion, but no policy eliminates disputes.
Written and reviewed by MDLaunchr's clinical and compliance team. We build white-label telehealth infrastructure for founders, creators, and healthcare operators—covering providers, pharmacy, technology, and compliance.
This article is for general informational and educational purposes only and is not medical, legal, or regulatory advice. It does not create a provider-patient relationship and should not be used to diagnose or treat any condition. Telehealth and compounding regulations vary by state and change over time—consult qualified legal, clinical, and compliance professionals before launching or operating a telehealth program.
Frequently asked questions
Is website readiness enough to secure a telehealth merchant account?
No. Website readiness is one part of underwriting. A processor may also review information outside the site, including business structure, fulfillment relationships, transaction profile, and expected dispute exposure. A polished website cannot determine approval.
What do underwriters look for on a healthcare website first?
They commonly need to understand the legal merchant, service being sold, provider or clinical role, pricing, billing frequency, cancellation process, refund policy, privacy disclosures, and business contact information. Consistency between the website and application is important.
Should a telehealth website display a HIPAA Notice of Privacy Practices?
A covered healthcare provider required to provide a Notice of Privacy Practices should make it available as required by HIPAA, including through appropriate electronic delivery and website access where applicable. Whether a particular business is a covered entity or business associate depends on its role and arrangements and requires qualified review.
Can a disclaimer fix an unsupported healthcare claim?
Not necessarily. The FTC evaluates the overall net impression of advertising, and qualifying information should be clear and conspicuous. A disclaimer should not be used to rescue a headline or testimonial that communicates an unsupported health outcome.
Does a no-refund policy prevent payment disputes?
No. A no-refund policy may set contractual expectations, but it should be disclosed before payment and applied consistently. Clear service descriptions, cancellation procedures, support records, and timely review of legitimate billing issues may help reduce confusion, but no policy eliminates disputes.
- Federal Trade Commission — Health ClaimsFederal Trade Commission Announces Final Click Cancel Rule Making It Easier Consumers End RecurringRule Concerning Use Prenotification Negative Option Plans 2Complying Telemarketing Sales RuleMore 5 Million Refunds Sent Consumers Result Ftcs Action Against Cerebral Over Deceptive
- U.S. Department of Health & Human Services — Privacy Practices Health Care ProviderGuidance
- HHS Telehealth — HIPAA for Telehealth Technology
- U.S. Food & Drug Administration — Fraudulent Products