Joe Tuan
Joe Tuan
CEO and Founder, Topflight Apps
July 25, 2026

Two questions come up on almost every telehealth discovery call, usually before anything else: where do the doctors come from, and how does the pharmacy plug in?

The honest answer is that a direct-to-consumer telehealth business runs on two rented rails. One is a 50-state physician network that supplies the clinicians. The other is a pharmacy, often a compounding pharmacy, that fills the scripts and ships them. You rent both. What you own is the layer between them: the intake flow, the physician review queue, the prescription routing, the patient tracking. That layer is the business.

2026 was the year renters found out how exposed that leaves them. Compounded GLP-1s largely closed for routine use, and one breach at a shared backend reached dozens of brands at once. Renting the rails to launch is still the right move. The mistake is renting them and owning nothing else.

This is the buyer’s guide to choosing, integrating, and de-risking both rails. The one to send before the call.

How does a direct-to-consumer telehealth business set up its physician network and compounding pharmacy?

It rents two rails and owns the layer between them. A physician network, structured through a friendly PC and an MSO, supplies the clinicians; a pharmacy, usually a 503A compounder, fills and ships. The durable asset is the application layer you build in the middle, the intake, physician review, prescription routing, and patient tracking, because the rails are swappable and that layer is the part you keep.

 

Key Takeaways:

  1. Rent both rails to launch, and build only later. A physician network and a compounding pharmacy are both rentable, and speed is the reason to rent before you build: renting gets you live in weeks and lets you test which states and categories work before you commit capital to owning the infrastructure.
  2. Structure every rail contract so a swap is a clause you execute. The exit and records-transition terms, plus who controls the patient relationship, are what keep a rail swappable or internalizable later. HIPAA won’t hand you the patients or the records if the contract doesn’t.
  3. Own the application layer between the rails. The intake, physician review queue, prescription routing, and patient tracking are the defensible asset, because the rails are rented and swappable and that layer is the one thing you keep. 2026 was the proof: the GLP-1 compounding collapse and the OpenLoop breach left renters who owned nothing but a brand with nothing to fall back on.

 

Table of Contents

  1. The two rails every D2C telehealth business runs on
  2. Rail 1, clinical capacity: build a medical group or rent a physician network
  3. What a physician network vendor provides, and where your liability starts
  4. Why telehealth hides its doctors
  5. Rail 2, pharmacy fulfillment
  6. Compounding pharmacy integration
  7. The shared-infrastructure risk: one FDA action or breach hits every brand on the rail
  8. Due diligence: 20 questions for a physician network, 20 for a pharmacy partner
  9. Contract mechanics
  10. Own vs rent: when to bring the rails in-house
  11. How Topflight Apps helps you own the layer between the rails

The two rails every D2C telehealth business runs on

The model is simpler than the marketing makes it look. A patient lands on your platform, fills out an intake, gets reviewed by a licensed clinician, and a few days later a package shows up at their door. Behind that flow sit two vendors you rent and one asset you own.

Diagram showing a D2C telehealth platform as the owned application layer (intake, physician review queue, prescription routing, patient tracking) between two rented rails: a telehealth physician network supplying clinical capacity and a compounding pharmacy handling fulfillment, with a patient entering and a delivery reaching the patient's door

The instinct is to think the product is the drug, or the brand on the box. Both are rented. The molecule gets formulated by a compounding pharmacy you contract with; the clinicians who prescribe it work through a physician network. Swap either one and the patient barely notices. The asset you own is the software between them: intake, the physician review queue, prescription routing, patient tracking. That’s where telehealth pharmacy integration lives, and it’s the one piece a competitor can’t just go rent.

The shape repeats across categories: weight loss, hormones, hair loss, and sexual health all run the same way, a platform out front, contracted clinicians behind it, a compounding pharmacy at the end. Curology built a dermatology business on exactly this model and reached roughly 6 million patients on it. Rented rails, real scale.

When a rail moves, the brands move with it. That’s the 2026 story: compounded GLP-1s closed for routine use, and the same one-stop-shop brands shifted their programs toward hormones and other categories. The rail changed; the logos rode it.

So the rest of this guide follows the two rails: how to pick each one and wire it in, and how to structure the deal so you can swap it out or bring it in-house later. Underneath all of it sits the same move: own the layer between the rails.

Rail 1, clinical capacity: build a medical group or rent a physician network

You can’t legally be the doctor. That makes clinical capacity a build-or-rent decision before it’s anything else, and both paths trade the same two things: control and speed. Building buys control and costs you speed. Renting buys speed and hands you someone else’s structure and someone else’s risk.

The build path, and what it costs

Building means standing up your own telehealth medical group. In most states that’s a separate physician-owned professional corporation, one per state, because every state writes its own rules. The costs stack in four places:

  • Forming each PC: around $1,000 apiece, before a lawyer touches it.
  • Credentialing: 90 to 180 days per payer, at roughly $200 to $600 per clinician per payer.
  • Malpractice: coverage carried on every clinician.
  • Licensure: you have to be licensed wherever the patient sits, so cost tracks geography, from about $800 for 1 clinician in 1 state to roughly $40,000 for 5 clinicians across 10 states.

Interstate compacts take some of the sting out of state licensure. The IMLC now covers 40-plus states for physicians, with parallel compacts for nurses and psychologists. California isn’t a member, though, so every California license is a manual add. And if you go the build route, standing up the clinic itself is a multi-month project of its own, one we cover in building a GLP-1 virtual clinic.

The rent path, and what you inherit with it

Renting flips the timeline. A physician network stands you up in weeks instead of months, handling the PCs, the credentialing, the collaborative agreements, and the malpractice so your team doesn’t have to. You start in 3 to 5 favorable states and expand from there rather than trying to light up all 50 on day one.

The cost is control. You inherit the vendor’s PC and MSO structure whole, and you run on backend infrastructure that dozens of other brands share too. Both of those are their own problem, and we get to them shortly.

Rent to launch, build when the math clears

So the rule is simple. Rent to launch, and rent to test which states are worth serving. Build when volume, margin, or clinical control makes owning the group worth the cost, and that’s enough of a decision that it earns its own section later.

What a physician network vendor provides, and where your liability starts

Renting clinicians offloads the work of employing doctors. The accountability stays yours, and the line between the two is exactly where founders get surprised. Here’s what a network hands you, and what it quietly leaves on your side of the table.

What a physician network vendor provides

A telehealth physician network hands you a fairly standard package:

  • Licensed, credentialed clinicians across all 50 states (some networks are NCQA-credentialed)
  • Malpractice coverage on those clinicians
  • Clinical protocols for the conditions you treat
  • Asynchronous visits, synchronous visits, or both
  • Sometimes labs or a pharmacy bundled in

The network supplies the clinician layer, separate from your platform and separate from the pharmacy, and knowing which party owns which function is how you’ll later pin down where your liability sits. We’re keeping this at the category level; for named profiles and how to compare them, see scaling a D2C telehealth app.

What stays your liability

Three things stay yours no matter who you rent. The standard of care is the big one: if a visit falls below it, that liability is yours, and the network’s contract will make sure of it. Then there’s brand risk, quieter but just as costly, because to the patient the clinician is your brand, so a rushed or dismissive visit sends them straight to a competitor. And clinical independence is the piece enforcement polices hardest right now: your platform and its MSO can’t steer what the clinician decides.

The DOJ’s Done Global case made that last one concrete. Prosecutors treated a business model that improperly influenced clinical decisions as criminal conduct, with the exposure running to the platform, its MSO, and the investors behind them.

Controlled substances draw a hard line around which non-GLP-1 categories you can even offer. Under the DEA’s telehealth flexibility, which waives the Ryan Haight Act’s in-person requirement, a network can remotely prescribe Schedule II through V drugs without a prior in-person visit through December 31, 2026. A permanent special-registration rule that would formalize this and register D2C platforms directly is still pending. None of this touches GLP-1s, which aren’t controlled substances. Where it bites is categories like stimulants or testosterone.

Why telehealth hides its doctors: corporate practice of medicine, MSOs, and the friendly PC

The reason your doctors sit inside a separate company is a century-old doctrine, and in 2026 that arrangement got a lot less comfortable.

Why your doctors sit in a separate company

Corporate practice of medicine bars lay-owned corporations from practicing medicine or employing clinicians to deliver care. The point of the doctrine is to keep business incentives from overriding a doctor’s medical judgment. So care runs through a physician-owned professional corporation, the friendly PC, which has to be at least 51% physician-owned and is the medical group that treats patients. Everything non-clinical runs through a lay-owned management services organization (MSO): billing, technology, marketing, operations. The PC delivers care; the MSO handles the business and takes the outside investment. That two-box arrangement is the friendly PC model, and it lets capital into the business without triggering CPM.

Structure diagram of the friendly PC / MSO model used in telehealth to comply with corporate practice of medicine: a physician-owned professional corporation retains clinical control, records, and care delivery, while a lay-owned management services organization provides admin under a management services agreement in exchange for a management fee

The boundary is the only thing keeping it legal

The boundary comes down to two rules: the MSO can’t own patient records or steer clinical judgment, and the PC has to keep clinical control. When you rent a physician network, the doctors are the visible part. Underneath, you inherit the whole arrangement: its ownership split and the control terms baked into the contracts. Whatever the vendor negotiated with its own PC is now the structure you’re standing on.

It’s no longer a safe harbor

For years the MSO model telehealth companies rely on was treated as settled structure. In 2025 and 2026, states went after it directly. Two moves stand out:

  • California, effective January 1, 2026: SB 351 bars private equity and hedge funds from controlling clinical decisions, and AB 1415 adds pre-transaction notice.
  • Oregon, phasing in from January 2026: SB 951 effectively bans the friendly-physician model and voids many noncompetes.

California’s AG has gone further, looking past the paperwork to the substance of control. There are recent settlements involving Carbon Health and Aspen Dental, and an amicus arguing that an MSO’s power to replace the PC’s physician-shareholder violates corporate practice of medicine. The counsel consensus now: the PC-MSO model is no longer a de facto safe harbor.

So the control terms decide whether it holds

The boxes on the org chart are the easy part. What decides whether your structure, or your vendor’s, survives scrutiny is the control terms buried in the contracts: who can replace the PC’s physician, how the noncompetes are written, and where clinical-decision authority sits.

I’ll give the other side its due. Some argue these crackdowns backfire, hitting independent practices hardest while the funded platforms lawyer their way through, and that private equity is mostly a way to finance care. Fair enough. It doesn’t change the homework: read your vendor’s control terms before you inherit them.

Rail 2, pharmacy fulfillment: retail eRx or a compounding partner (503A vs 503B)

Fulfillment comes down to two paths: a retail pharmacy or a compounding partner. If it’s compounding, one letter-and-number distinction, 503A vs 503B, shapes your whole model, and the post-shortage enforcement climate decides what you can legally ship.

503A versus 503B, the distinction that shapes your model

Compounding splits into two regulatory categories. A 503A compounding pharmacy makes patient-specific prescriptions under state boards of pharmacy and USP standards; it isn’t FDA-registered. A 503B outsourcing facility is FDA-registered and cGMP-compliant, and it makes office-use batches without a prescription per unit, limited to substances on the FDA’s bulks or shortage lists. Both categories exist because of the Drug Quality and Security Act of 2013, passed after the 2012 NECC fungal-meningitis outbreak killed dozens of patients.

Dimension 503A compounding pharmacy 503B outsourcing facility
Prescription basis Patient-specific Rx Office-use batches, no per-unit Rx
Oversight State boards of pharmacy, USP 795/797 FDA, under cGMP
FDA registration No Yes
cGMP Exempt (if compounded per 503A) Required
What it can make Individualized formulations Only bulks-list or shortage-list substances
FDA reporting State-level Twice a year to the FDA
Best fit Async D2C, patient-specific Clinic-stock, office-use

One misread worth killing early: FDA registration isn’t a quality ranking. A 503A with real accreditation (PCAB, ISO-class cleanrooms) can match a 503B on quality. The difference is which rulebook they answer to.

Most D2C programs land on 503A

It comes down to patient specificity. Every prescription ties to a named patient, which is how async D2C prescribing already works, so hormone, hair, skin, and sexual-health programs almost all run on 503A. A 503B, built for office-use dispensing, suits clinic-stock models better.

The gating diligence item is coverage. State-by-state pharmacy licensure decides where a partner can ship: a compounding pharmacy needs a nonresident-pharmacy license in each state you serve, and gaps in that map quietly cap your addressable market.

The enforcement climate that reset the calculus

None of this matters if you can’t legally ship what you’re compounding, and for GLP-1s that’s where it gets hard. Once the shortages resolved (tirzepatide in October 2024, semaglutide in February 2025), the FDA’s “essentially a copy” standard kicked back in: a compounder can’t make a routine copy of an approved drug without documented individual clinical need, and cost or convenience doesn’t count as need. That’s the wall most compounded GLP-1 fulfillment now hits, and FDA enforcement has backed it with warning letters over misbranding when compounded versions get marketed as the approved drug.

Then, on April 30, 2026, the FDA proposed pulling semaglutide, tirzepatide, and liraglutide off the 503B bulks list entirely, on a finding of no clinical need, with a final determination still pending. So compounding stays alive for individualized formulations and non-GLP-1 categories, and precarious for GLP-1 copies. The one wildcard: HHS has floated reclassifying roughly 14 restricted peptides to allow lawful prescription compounding, so the climate isn’t static.

If you’re routing to retail pharmacies instead of compounding, e-prescribing runs through networks like Surescripts, and those mechanics live in a separate guide: integrate e-prescribing into a medical app.

Compounding pharmacy integration: what “API-integrated” means versus eRx, eFax, and a portal login

When a vendor says “integrated,” ask which rung they mean. The word covers four tiers, from a portal you type orders into by hand up to a full API, and where you land decides your engineering bill and your patient experience.

Four tiers, from least to most build effort:

  1. Provider portal or manual entry: you log into the pharmacy’s system and key in every order by hand.
  2. eFax: prescriptions go out as electronic faxes, still manual to send and to process.
  3. eRx: electronic prescribing, EPCS-certified when controlled substances are in the mix.
  4. Full API: programmatic, real-time, and hands-off once it’s built.

Build effort and control both rise as you go down the list; the day-to-day manual work runs the opposite way, heaviest at the portal and near-zero at a real API.

A real API integration means REST, webhooks, and a sandbox

Concretely: REST/JSON with OAuth 2.0 auth, endpoints for submitting orders and pulling real-time status on the order and the shipment, webhooks that push status and delivery events to you, and a sandbox to build against before go-live. One pharmacy fulfillment API, wired into your compounding pharmacy integration, handles prescription routing and refill workflows on a single connection. Compare a full API integration to eFax and portal submission, where a person retypes data on both ends. Every manual tier adds people and latency between the prescription and the patient, and that gap is where the engineering-cost and patient-experience tradeoff lives.

Cold chain and refills are where your brand gets blamed

Wiring is only half of it. The integration also has to cover the physical reality of getting a compounded drug to a patient. Sterile injectables like GLP-1s and NAD+ need cold chain shipping, with carrier tracking and delivery notifications so a temperature-sensitive vial doesn’t cook on a porch. The pharmacy handles drop shipping straight to the patient’s door, and the turnaround time, from order to doorstep in the range of 24-hour compounding to a roughly 5-day window, is a number you’re on the hook for even though the pharmacy sets it.

Refill workflows and cancellations ride the same order-management layer, and getting them wrong is where the pharmacy, your final mile, becomes your brand’s problem. A patient blames your app when a refill stalls or a canceled order still ships. Which tier you pick comes down to volume and how much manual work you can stomach: a portal login is survivable early, but past a few hundred orders a month, the toil and the error rate make the full API pay for itself.

The shared-infrastructure risk: one FDA action or breach hits every brand on the rail

Rent the same backend as a hundred other brands, and their worst day becomes yours. That’s the shared-infrastructure risk, and the blast radius is the whole rail: one bad event at the group or the pharmacy behind you, and every brand on it is exposed at once. The concentration is a side effect of renting: a handful of backends serve a big slice of the market, because renting one is faster than building your own.

One category action puts every brand on the rail in range

Take enforcement first. FDA enforcement lands on whole categories at a time. Over six months it warned more than 70 telehealth firms, and per STAT, at least 30% of them ran on just four nationwide medical groups: Beluga Health, OpenLoop, MD Integrations, and Telegra. One action against the category, and a third of the warned brands were hit through the same handful of backends. The anchor event was concrete: on March 3, 2026, the FDA sent 30 warning letters over compounded-GLP-1 marketing claims, the kind of misbranding that lands when a compounded product gets sold as the approved drug.

One backend breach becomes every renter’s breach

A data breach follows the same math. When OpenLoop, a clinical backend serving dozens of D2C brands, was breached, the exposure ran through all of them at once. The HHS OCR breach portal lists up to 716,000 individuals affected. The attacker separately claimed about 1.6 million, a figure that hasn’t been independently confirmed. Texas alone reported at least 68,160 residents affected, and multiple class-action suits followed. For scale, reporting tied roughly 3.7 million telehealth patients to two recent breaches in that same window.

When the clinical core fails, patient safety is the exposure

The last mode lives in the clinical operation itself. The DOJ sought an asset freeze and receivership against Zealthy and its CEO, describing the operation as a “runaway campaign of lawbreaking.” That’s a patient safety problem at the core of the model, and every brand routing care through it inherits the fallout.

Manufacturer and agency pressure can pile on from every direction at once. The FDA named Hims & Hers, HHS referred it to the DOJ on February 6, 2026, and Novo Nordisk sued it on February 9.

The Medvi story is the narrative version of all this: a fast-growing brand that ran on OpenLoop, so when the backend had its breach, Medvi was exposed through it. We walk through that one in what Medvi’s growth means for compounding pharmacy owners.

So the takeaway is simple: know exactly who sits behind your rails, and structure your contracts so one vendor’s worst day doesn’t become an extinction event for you. The next two sections are how you do both.

Due diligence: 20 questions for a physician network, 20 for a pharmacy partner

These two checklists are what to run before you sign. Real vendor due diligence on a clinician network for telehealth or a pharmacy partner comes down to a handful of questions most buyers skip: who keeps the patients if you leave, and how the business associate agreement (BAA) reads when things go wrong. The answers separate a rail you can swap from a rail that owns you.

20 questions for a physician network

Ask the network these:

  1. Which states are clinicians licensed in, and how is each verified?
  2. Are they NCQA-credentialed, and how often is credentialing refreshed?
  3. Malpractice coverage type: claims-made or occurrence?
  4. Who owns the clinical protocols, and can we change them?
  5. Controlled-substance prescribing, and under what DEA registration?
  6. How do you keep the MSO from steering clinical decisions?
  7. Who controls the PC, and can we see the structure?
  8. How many other brands share this medical group?
  9. Any FDA or DOJ action against the group or its brands?
  10. Who legally holds the patients and the records?
  11. What PHI do you touch, and is a signed BAA in place?
  12. Which subprocessors see PHI, and can we review them?
  13. Are we exclusive, or can we run a second network in parallel?
  14. Can you solicit or keep our patients after we leave?
  15. What are the response-time and uptime SLAs?
  16. What’s the remedy when an SLA is missed?
  17. How are async and sync visits routed and documented?
  18. How do you handle surge volume?
  19. What happens to in-flight patients if we terminate?
  20. Data export on exit: what format, how fast, at what cost?

20 questions for a pharmacy partner

The pharmacy side turns on state board of pharmacy licensure and exit terms. Ask these:

  1. 503A or 503B, and is everything we ship legally compoundable?
  2. Which states hold your nonresident-pharmacy licenses?
  3. What integration tier: portal, eFax, eRx, or full API?
  4. Cold chain handling and carrier tracking for injectables?
  5. Turnaround-time SLA, from order to doorstep?
  6. PCAB or equivalent accreditation?
  7. Third-party potency and sterility testing we can review?
  8. Any breach history, and what’s the incident-response plan?
  9. What PHI do you touch, and is a signed BAA in place?
  10. Minimum volumes, and the penalty for missing them?
  11. Are we exclusive, or can we add a second pharmacy?
  12. How do refills and cancellations move through the system?
  13. How do you handle a recalled or discontinued formulation?
  14. What’s the fill error rate, and how is it tracked?
  15. Do you support drop shipping directly to patients?
  16. How are shipping delays and lost packages handled?
  17. What order-status and reporting data do we get?
  18. Who keeps the patient records if we switch pharmacies?
  19. On exit, how fast can we export data, and at what cost?
  20. What happens to open orders if we terminate?

Most of these come down to contract language, which the next section gets into.

Contract mechanics: pricing, minimums, exclusivity, and the exit clause that decides who keeps your patients

The pitch tells you how good the vendor is; the contract tells you whether you can ever leave.

A cheap per-visit rate with no SLA is a false economy

Pricing runs across a few models: per-consult pricing, pure usage-based, SaaS or per-visit, PMPM, and revenue share. Minimum volumes often come attached, so ask what the remedy is when you miss one. And read the SLAs and response times that ride along with the price, because the cheapest per-visit rate can be the most expensive one once you factor in downtime.

Exclusivity and non-solicitation

Two questions decide whether you’re trapped. Can the vendor solicit the patient base you bring them? And are you barred from signing a second vendor? Exclusivity and non-solicitation clauses are where the trap is set, long before you ever think about leaving. A vendor that can poach your patients on the way out leaves you with nothing to negotiate with.

The exit clause is what turns a rail into lock-in

This is the clause that decides everything. HIPAA doesn’t entitle you to the counterparty’s patient records, so the contract decides who keeps the patient relationship and the records when you switch. Ignore that, and you’ve signed up for vendor lock-in without knowing it.

So negotiate the mechanics up front:

  • Data-export and transition-assistance clauses, spelling out format, frequency, and cost
  • The BAA kept alive through the full cutover, past the termination date
  • Encryption-key custody, so you can read the data you export
  • Interoperable formats like FHIR or HL7

And watch for language letting the vendor keep patient data after termination, or reuse de-identified data to train its own models. Exit clauses are the difference between leaving and being held.

Liability terms worth reading twice

The liability section is written for the vendor. Standard contracts exclude consequential damages and cap liability low, which leaves you holding the bag on a breach, so push for carve-outs where your real exposure lives. And confirm the malpractice basics: claims-made or occurrence coverage, and who pays the tail when the relationship ends.

Get all four right and switching a rail is a clause you execute on a bad quarter. Get them wrong and it’s a crisis you can’t buy your way out of. The one question the contract doesn’t answer is whether to own the rail instead of renting it, which is next.

Own vs rent: when to bring the rails in-house

Rent both rails to launch. Bringing one in-house is a move you earn later, and the reason to rent first is simple: it gets you live in weeks and lets you find out which states and categories are worth serving before you sink capital into infrastructure you own.

There are two reasons to internalize a rail, and both have to be earned. The first is economics. Once your volume and margin outgrow the per-state, per-clinician build costs from the clinical-capacity section, owning the rail costs less than renting it, and every consult stops paying a middleman’s markup. The second is control. After seeing what a single shared backend’s worst day does to every brand riding it, you may decide that owning the risk is worth the build cost, even before the pure economics get there. Neither reason applies on day one, which is why renting first is the honest default.

Keep this decision separate from the software buy-vs-build question. That’s a different axis, whether to build or buy the application itself, and it doesn’t answer the clinical and pharmacy operations decision this section does. We cover the software side in buy or build a telehealth solution.

Here’s the whole strategy in one line: rent the rails, write the contracts so you can swap or internalize them, and own the application layer in between. The rails are replaceable. The layer you build between them is the business, and it’s the one asset no vendor can hand you or take away. Build that well, and the rails underneath it become a detail you manage.

How Topflight Apps helps you own the layer between the rails

By now the shape should be clear. The two rails, your physician network and your pharmacy, are rented and swappable. The defensible asset is the layer you build between them: intake, the physician review queue, prescription routing, patient tracking. That layer is the product. The brands that got hurt in 2026 owned nothing but a logo on top of someone else’s rails.

That’s the layer Topflight Apps builds. We’ve spent 10-plus years on HIPAA-bounded healthcare software, and this is exactly the kind of build we do: custom intake, physician review queues, prescription routing, and patient tracking that you own outright, wired into whatever network and pharmacy you rent. That’s the core of our telehealth app development work. When you’d rather assemble faster than build from scratch, Specode gives you the same pieces as HIPAA-ready components, including a path to build a GLP-1 virtual clinic. Own that layer and a rail swap becomes a migration on top of infrastructure that stays put.

So when a prospect asks the two questions we opened with, where the doctors come from and how the pharmacy plugs in, you have a real answer: rent a physician network, integrate a compounding pharmacy for telehealth, and own the intake, review, routing, and tracking in between. That last part is the only one that’s yours, and it’s the one worth building right the first time.

Frequently Asked Questions

 

Do I need my own medical group to run a telehealth business?

No. Most rent a physician network to launch and build their own PC and MSO only when the volume and margin justify internalizing it.

What is the difference between a 503A and a 503B pharmacy?

A 503A compounds patient-specific prescriptions under state pharmacy boards; a 503B is an FDA-registered outsourcing facility making office-use batches under cGMP.

Can rented physician networks prescribe controlled substances?

Yes, under DEA’s telehealth flexibility through the end of 2026: Schedule II through V, with no prior in-person visit required. A permanent special-registration rule is still pending.

How do telehealth platforms integrate with compounding pharmacies?

Through one of four tiers: a provider portal, eFax, eRx, or a full API with order and shipping-status endpoints. The tier sets your engineering lift.

What did the FDA's GLP-1 warning letters mean for telehealth companies?

They targeted marketing implying compounded GLP-1s are the same as approved drugs. Post-shortage, routine GLP-1 compounding is largely closed, and the FDA has since proposed a 503B bulks exclusion.

Joe Tuan

CEO and Founder, Topflight Apps
Since 2016 I’ve been the founder & CEO of Topflight Apps, where we build and scale healthcare apps. We’ve bootstrapped the agency to $4m annually, & a team of 40, serving fortune 500 and bleeding edge healthcare & AI startups, delivered north of $200 million of value for our clients in venture funding & acquisitions. My passion is in creating solutions that hack away bureaucracy, bloat, and barriers to access. In 2014, I co-founded HealClick, a patient-matching app for DIY-ing and crowdsourcing treatment ideas for autoimmune illnesses without FDA-approved treatments.
Copy link