Skip to content

Compliance

Structure that holds up when someone looks closely

Telehealth companies rarely fail on product. They fail on entity structure, licensure gaps, or modality rules that were treated as documentation instead of enforcement. We build these as controls, not policies in a folder.

Six pillars

How the structure actually works

Each of these exists because a specific failure mode is common in this industry. Together they are what makes a partner's growth defensible rather than borrowed time.

01

Corporate practice separation

Clinical services sit in affiliated professional entities. qPrescribe provides technology and administrative services under an MSO agreement, keeping the separation that state corporate-practice-of-medicine rules require.

02

Licensure enforced at routing

A consult can only reach a provider licensed and in good standing in the patient's state. Licenses are primary-source verified at onboarding and monitored continuously — not checked once a year.

03

Named medical direction

Every category has a named medical director who owns the clinical protocol, signs off on intake logic, and runs documented chart review against a sampling standard.

04

Modality rules per state

Some states and categories require synchronous video, identity verification, or a prior in-person relationship. Those rules live in the routing engine, so the platform cannot route a consult in a way the state does not allow.

05

Security posture

Patient health information is encrypted in transit and at rest, access is role-based and least-privilege, and every read of a record is logged.

06

Records and auditability

Each consult produces a durable encounter record — intake responses, provider notes, decision rationale, and transmission receipt — retained to each state's standard and exportable on request.

Control inventory

The specifics, without the marketing gloss

This is the short form of what diligence teams ask for. We will walk any of it through in detail, and say so where a control is still being built out.

Clinical governance

  • Named medical director per treatment category
  • Written clinical protocols, versioned and change-controlled
  • Documented chart review against a defined sampling rate
  • Adverse event reporting and escalation pathway
  • Quarterly protocol review against current guidelines

Provider management

  • Primary source verification of licensure and credentials
  • Continuous license and sanction monitoring
  • Malpractice coverage verified and maintained
  • DEA registration checks where scheduled therapies apply
  • Category-specific credentialing before routing eligibility

Data & security

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access control with full audit logging
  • Written data-handling agreements with every partner touching patient data

Pharmacy & dispensing

  • Partner pharmacies licensed in the destination state
  • NCPDP SCRIPT transmission with delivery confirmation
  • 503A and 503B partners verified against FDA registration
  • Cold chain validation for temperature-sensitive therapies
  • Recall and quarantine procedures with partner notification

Questions

What diligence teams ask

If your counsel has a question that is not covered here, send it over — we would rather answer it before a contract than after.

The affiliated professional entity and the treating provider do. qPrescribe is a technology and administrative services company — it does not practice medicine, and neither does the partner brand. This is the structure that keeps corporate practice of medicine rules satisfied.

This page describes our compliance program in general terms and is not legal advice. Requirements vary by state, category, and business model — your counsel should review any specific arrangement.

Diligence

Bring your counsel to the first call.

We would rather answer the hard structural questions early than discover a mismatch three months into an integration. Our regulatory lead joins partner diligence calls directly.