To advertise telehealth in the United States, you need to comply with state licensing rules, protect patient data under HIPAA, meet FTC substantiation and disclosure standards, follow FDA rules on prescription-related claims, and get certified on the platforms you advertise on. If your tracking setup isn’t already keeping patient data out of ad platforms, the two fastest fixes are removing client-side pixels from any patient-authenticated page and switching to server-side, neutral-event tracking backed by signed business associate agreements.
TL;DR:
- Telehealth advertisers must ensure their campaigns comply with state licensing, HIPAA, FTC, and FDA regulations simultaneously to avoid multiple violations.
- Removing client-side pixels and switching to server-side, PHI-safe tracking is essential to prevent disclosing protected health information to third parties.
- Google requires LegitScript certification for promotion of prescription drugs, and ad content referencing specific medications or dosing gets flagged without certification.
- Advertising claims, testimonials, and disclosures must be substantiated with real data, clear pricing, and transparent licensing information to meet FTC and platform standards.
- Geotargeting and strict landing page gating based on licensing prevent patients from booking in unsupported states, reducing regulatory and platform compliance risks.
Table of Contents
- The regulatory pillars that shape telehealth advertising
- Platform rules: Google Ads, Meta, and TikTok compared
- HIPAA and online tracking: keeping PHI out of ad platforms
- Prescription drugs, GLP-1 programs, and heightened ad scrutiny
- State licensing and geographic gating done right
- FTC rules on testimonials, endorsements, and health claims
- Pre-launch compliance checklist before you spend a dollar
- Setting up the technical guardrails that keep you compliant
- What we see in the field: mistakes, fixes, and timelines
- Weighing reach against compliance
- How AdJet Marketing builds compliant telehealth campaigns
- Sources
- FAQ
The regulatory pillars that shape telehealth advertising
Telehealth advertising sits at the intersection of several rulebooks, and none of them defer to the others. You’re expected to satisfy all of them at once, which is why so many campaigns stall before launch.
State licensing law determines where you’re even allowed to advertise a service, since a provider generally needs a license in the state where the patient is physically located, not just where your clinic sits. HIPAA governs how patient information, including data collected through your website and ads, gets used and shared. The FTC’s Health Products Compliance Guidance sets the bar for what you can claim and how you have to back it up. And when prescription drugs enter the picture, FDA rules on drug advertising layer on top of everything else.
The overlap matters because a single ad can trip more than one wire at once:
- A landing page mentioning weight-loss medication can trigger FDA scrutiny, FTC substantiation requirements, and Google’s prescription drug policy simultaneously.
- A retargeting pixel on your intake form can create a HIPAA problem even if your ad copy is spotless.
- A testimonial with an implied cure claim can violate FTC rules regardless of state licensing status.
Treating these as separate checklists instead of one integrated review is where most compliance gaps start.
Platform rules: Google Ads, Meta, and TikTok compared
Each ad platform layers its own policy on top of federal law, and the requirements differ enough that a campaign compliant on one platform can get flagged on another.
Google Ads requires certification through the Healthcare and medicines policy before you can advertise telemedicine services that involve prescribing. LegitScript’s Healthcare Merchant Certification is the accepted path for most advertisers, and Google will disapprove ads or entire accounts that reference prescription drugs, dosing, or online prescribing without it. Certain keywords and landing-page phrases (like “buy without a prescription”) get flagged automatically.
Meta treats most health conditions as sensitive categories, which limits how granularly you can target based on inferred health status and restricts certain creative elements, including before-and-after imagery for some treatment types. TikTok’s health advertising policies are younger and less mapped out, and enforcement there tends to be less predictable, so creative that passes review one week can get pulled the next.
Practical mitigation looks the same across platforms:
- Geotarget campaigns to states where your providers actually hold a license.
- Gate landing pages so unlicensed states can’t reach a scheduling form.
- Add plain-language disclaimers about who the service is for and where it’s available.
Pro Tip: Run your landing page URL through LegitScript’s certification checklist before you submit for Google Ads healthcare approval. Catching a missing disclosure there is faster than waiting for a disapproval notice.
HIPAA and online tracking: keeping PHI out of ad platforms
Once a visitor is on an authenticated page, like a patient portal or an intake form tied to their identity, data collected there can become protected health information. That changes what you’re allowed to send to ad platforms.
Here’s how to think through it in order:
- Identify every page where a logged-in or identified patient interacts with your site, including portals, scheduling confirmations, and post-visit surveys.
- Remove client-side ad pixels (Meta Pixel, Google Ads tag) from those pages entirely; they capture PHI whether you intend it or not.
- Confirm with any vendor that touches that data whether a business associate agreement is in place, since HHS guidance treats tracking vendors as business associates when they receive PHI.
- Replace pixel-based tracking with server-side collection that forwards only neutral events, like “lead_complete,” with no identifiable clinical or appointment detail attached.
HHS has been direct about this: tracking technologies on patient-facing pages can disclose PHI to third parties without the safeguards HIPAA requires, and that applies even when the tracking tool is a mainstream analytics or ad platform.
Pro Tip: Audit your tag manager quarterly. Marketing teams add new pixels faster than compliance reviews catch them.
Prescription drugs, GLP-1 programs, and heightened ad scrutiny
Telehealth companies advertising prescription-based programs, GLP-1 weight-loss treatment being the clearest current example, face the tightest scrutiny of any segment in this space. The FDA’s Clear, Conspicuous, and Neutral rule sets presentation standards for major risk statements in broadcast prescription drug ads, requiring plain language delivered in both audio and readable text. That standard shapes expectations even outside broadcast media.
On the platform side, Google will not allow ads that promote prescribing or dispensing of prescription drugs unless you hold LegitScript certification, and landing pages that reference specific medications or dosing get flagged quickly.
FTC enforcement in this category has followed a pattern worth studying directly. The FTC’s complaint against NextMed, a telehealth weight-loss program, alleged deceptive pricing, unsubstantiated efficacy claims, and fabricated testimonials.
Keep your messaging safe by:
- Naming general treatment categories rather than specific drugs in ad copy.
- Stating full pricing, including subscription terms, before a patient reaches checkout.
- Avoiding outcome claims (“lose 20 pounds”) unless you can substantiate them with real data tied to your actual patients.
State licensing and geographic gating done right
The governing principle is simple to state and easy to get wrong in practice: the provider needs a license in the state where the patient is located at the moment of the visit, not where your company is headquartered.

That means your ad targeting and your landing page need to agree with each other. If your providers are licensed in Texas and Oklahoma, running a broad national Google Ads campaign that lets a visitor from Ohio book an appointment creates real exposure, even if a disclaimer on the page technically mentions licensing limits.
A few patterns handle this cleanly:
- Geotarget campaigns to licensed states at the ad platform level, not just in copy.
- Add a state-selection gate on the landing page before showing scheduling options.
- Route unsupported states to a waitlist or referral page instead of a booking form.
A disclosure works when a reader could still reasonably self-select correctly. It stops working the moment your scheduling system would let an out-of-state patient book anyway, and at that point you need a hard block, not a footnote.
FTC rules on testimonials, endorsements, and health claims
The FTC evaluates health advertising against a standard often described as competent and reliable scientific evidence, meaning you generally need real data behind claims about outcomes, not just customer impressions. The FTC’s guidance also looks at the net impression an ad creates: an implied claim through imagery or a testimonial counts the same as a written statement.
Testimonials carry their own risk since the Consumer Reviews and Testimonials Rule, effective since late 2024, targets fake reviews, undisclosed paid endorsements, and review suppression.
To stay on the right side of this:
- Only use testimonials from patients you can document as real and verify as accurate.
- Disclose any compensation or free service given in exchange for a review.
- Keep records showing where each testimonial came from and when consent was given.
- Avoid implying typical results unless you have data showing that outcome is actually typical.
Pre-launch compliance checklist before you spend a dollar
Run this sequence before any telehealth campaign goes live:
- Confirm state licensure for every provider and map it against your intended ad geography.
- Check whether the service involves prescribing; if so, review DEA and FDA considerations for that drug category.
- Apply for LegitScript certification and complete Google’s healthcare advertiser verification.
- Remove ad pixels from any patient-authenticated page and confirm server-side neutral-event tracking is live.
- Sign BAAs with every vendor that could touch patient data.
- Review ad copy and landing pages for unsubstantiated claims, missing disclosures, or testimonial provenance issues.
- Confirm pricing is stated clearly, including subscription terms, before checkout.
Pro Tip: Treat this checklist as a gate, not a formality. A single missed item, like an unremoved pixel, can undo weeks of clean creative work.
Setting up the technical guardrails that keep you compliant
Briefing an engineer or vendor on this work goes faster with specifics. Ask for:
- A server-side tagging setup (Google Tag Manager server container or equivalent) hosted on infrastructure you control.
- Neutral event names like “form_submit” or “lead_complete” with no appointment type, diagnosis, or patient identifier attached.
- A signed BAA from any vendor in the data path, including your CRM, ad platform (where offered), and analytics tool.
- A landing-page gate that checks state eligibility before revealing a scheduling widget.
If a vendor won’t sign a BAA or can’t explain what data reaches their servers, that’s the point to bring in legal counsel rather than proceed on assumptions. Learn more about PHI-safe marketing workflows and cookieless remarketing tactics that avoid sending PHI to third parties.
Pro Tip: Loop in a healthcare attorney before your first campaign touches prescription messaging or multi-state targeting. The cost is small next to a platform ban or an FTC inquiry.
What we see in the field: mistakes, fixes, and timelines
Many clinics come to us after a Google Ads account gets suspended, usually over a pixel still firing on an intake page or a testimonial nobody verified. The fix follows a predictable sequence: audit tracking and creative first, remediate HIPAA and certification gaps second, then rebuild the campaign. A realistic timeline runs three to six weeks from audit to a fully certified, compliant launch, depending on how much of the tracking stack needs rework. Some agencies build Google Ads campaigns with HIPAA-aware tracking as a standard part of the process rather than as an add-on.

Weighing reach against compliance
Tighter gating costs you some reach, and that trade-off is worth making deliberately rather than by accident. If your growth plan depends on scaling into new states quickly, plan your licensing timeline before your media budget, not after. Expect a compliant setup to ramp slower in the first few weeks while tracking and certification settle. If you’re ever unsure whether a campaign element crosses a line, pause it and get a compliance review rather than let it run on a guess.
— Felix
How AdJet Marketing builds compliant telehealth campaigns
Getting telehealth advertising right takes more coordination between legal, technical, and creative teams than most in-house marketers have time for, and that gap is where campaigns quietly become liabilities. Some agencies work with medical clinics, pain management practices, and telehealth providers on Google Ads management, HIPAA-aware tracking setups, and compliant landing page design, drawing on Google Partner certification and hands-on LegitScript and ad policy experience.
A typical engagement starts with an audit of your current tracking and creative, moves through compliance fixes and BAA coordination, then into campaign build and ongoing monitoring. Services include:
- Google Ads management built around healthcare certification requirements
- Server-side, HIPAA-aware tracking implementation
- Compliant landing page design and state-gating logic
- LegitScript and platform policy consulting
If you want a second set of eyes on your current setup, explore our landing page design services or see how we approach telemedicine marketing for providers in your position.
Sources
For primary-source confirmation, consult these directly:
- Healthcare and medicines — Google Ads policy
- HHS guidance: marketing and PHI
- Health Products Compliance Guidance — FTC
- FDA final rule on DTC presentation of major statement
For broader context on digital health messaging standards, see this partner overview of digital healthcare strategy.
This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.
FAQ
What are the new telehealth advertising guidelines for 2026?
There’s no single new federal telehealth advertising law recently; instead, providers work within existing HIPAA, FTC, and FDA frameworks alongside platform-specific updates from Google and Meta. The most active area of change is platform enforcement, particularly around LegitScript certification and prescription drug promotion on Google Ads.
What are the general rules for healthcare advertising in the United States?
Healthcare ads must be truthful, avoid deceptive claims, and be backed by competent and reliable scientific evidence under FTC guidance. Advertisers also need to protect patient data under HIPAA and follow FDA rules when prescription drugs are involved.
What is the rule about disclosing telehealth service limitations?
Telehealth ads should clearly state what the service can and cannot do, including which states it’s licensed to operate in and any conditions it doesn’t treat. This isn’t a single codified “rule” so much as a combination of state licensing law and FTC disclosure standards that together require clarity about service limitations.
What are the current CMS telehealth guidelines relevant to advertising?
CMS guidelines primarily govern Medicare and Medicaid reimbursement for telehealth visits rather than advertising content directly. Advertisers should still avoid implying coverage or reimbursement terms that aren’t accurate for the patient’s specific plan, since misleading coverage claims can trigger FTC scrutiny separately from CMS rules.
Do I need LegitScript certification to advertise telehealth services?
You need LegitScript’s Healthcare Merchant Certification if your telehealth service involves prescribing or facilitating prescription medications, since Google requires it before approving related ads. Telehealth services that don’t involve prescribing may not need it, but should still confirm current platform policy before launching.


