LegitScript is not grading your website. It is reading your business through it.
It is easy to treat LegitScript certification as a web task: clean up a few pages, add a privacy policy, submit. That framing is why sites get sent back. LegitScript is evaluating the business against its published certification standards, and the website is simply where most of the evidence lives. The reviewer is not asking whether the site looks professional. They are asking whether the public pages tell the same, verifiable story as the application about who prescribes, who dispenses, where you operate, and what you claim.
So the useful way to prepare a site is to read the standards as a build specification, and then make the website and the application agree before anyone submits. Most first-round failures are not exotic. They are a disclosure that is missing, a claim that overreaches, or a page somewhere that contradicts the rest.
The nine standards, read as a build spec.
LegitScript certifies against nine standards: licensure and business registration, legal compliance, prior discipline and history, affiliates and partners, patient services, privacy, validity of prescription, transparency, and advertising. Read as instructions to a developer and a founder, they become concrete.
- Licensure and business registration. The entity behind the site is real, named, and registered, and the site does not hide who is operating it.
- Legal compliance and validity of prescription. The flow shows a legitimate clinical path. A patient is evaluated by a licensed provider before a prescription, and the site does not imply medication without a real prescribing step.
- Affiliates and partners. The provider group and the pharmacy relationships are disclosed, not blurred into an anonymous "our doctors" and "our pharmacy."
- Patient services and privacy. There is a genuine way to reach support, and a privacy policy that matches how the site actually handles data.
- Transparency and advertising. Pricing, policies, and claims are accurate and consistent, and the marketing does not promise outcomes the clinical reality cannot support.
- Prior discipline and history. Nothing on the site contradicts the business's regulatory history as disclosed in the application.
None of that is a design problem. It is an alignment problem between what the business is and what the website says it is.
The disclosures reviewers expect to find.
A large share of the preparation is making sure a handful of things are present, accurate, and easy to find.
- Who prescribes, named as a provider group or clinical entity, not just a stock photo.
- Who dispenses, with the pharmacy relationship disclosed, including compounding where relevant.
- Where the service is available, stated honestly rather than implying all fifty states when it is fewer.
- A privacy policy, terms, refund and cancellation terms, and real contact information, each describing what the business actually does.
- Ownership and operator identity, so the business behind the brand is not anonymous.
The test for each is the same: could a reviewer confirm it against the application without having to ask you? Every place they would have to ask is a place the review slows down or bounces.
The claims that fail a review.
The other half of preparation is removing or rewording the claims that reliably draw a problem. Guaranteed results, before and after imagery used as proof of a medical outcome, testimonials making clinical promises, pricing or subscription language that hides the real terms, and marketing that treats a compounded medication as interchangeable with a brand-name product are the usual culprits. The fix is rarely clever wording. It is making the claim defensible or removing it, and keeping the marketing pages and the clinical pages from saying two different things.
Your domains are part of the application.
This is the item that catches otherwise careful businesses. One of the certification standards requires an applicant to provide all domain names and websites under its control. That is not only the primary site. It is the staging subdomain still resolving in public, the old landing pages from a past campaign, the microsite a contractor built and never took down, and anything behind a login that makes a claim the public pages do not. Inventorying every domain and loading each one signed in to nothing, before you submit, turns a likely first-round finding into something you already fixed.
A pre-submission checklist you can run this week.
- Put the website and the draft application side by side and confirm they describe the same business: same provider relationship, same pharmacy, same states, same claims.
- Confirm the five disclosures are present and accurate: provider, pharmacy, states served, policies, operator identity.
- Read every product and program page against the advertising standard and remove or reword claims you could not defend.
- Inventory every domain, subdomain, and landing page under your control, and load each one, including the ones behind a login and the ones you stopped using.
- Settle who is the merchant and advertiser of record, so the right entity files and the site shows what that entity needs to show.
Do those five and you have removed most of the reasons a healthcare site is returned on the first pass.
This is operational guidance, not legal advice, and certification is decided by LegitScript against its own standards, not by any agency preparing you for it. ToolBX Media is a LegitScript partner, and the work above is the readiness pass we run before a submission: you can see the surrounding questions in the LegitScript and med spa FAQs and the 75 healthcare commerce questions, and the hands-on version is a telehealth program fit review or the full build in telehealth and GLP-1 website development. The related read on who else reads your site, your payment processor, is in your payment processor scans your site before your first sale, and once you are certified and turn on paid traffic, the tracking has to stay clean too, which is HIPAA-compliant attribution for GLP-1 ads. If you run a national brand, the related question of how the medical group and the storefront appear on the site is in corporate practice of medicine, your website, the MSO and the friendly PC.
Common questions
What does LegitScript actually review on my website?
LegitScript reviews your business against its nine healthcare certification standards, and the website is where most of that review happens because it is the public evidence of how the business operates. The standards cover licensure and business registration, legal compliance, prior discipline and history, affiliates and partners, patient services, privacy, validity of prescription, transparency, and advertising. A reviewer is reading your pages to confirm the site tells the same story as the application: who prescribes, who dispenses, where you are allowed to operate, what you claim, and what your policies say.
How do I pass LegitScript certification on the first try?
Make the website and the application describe the same business before you submit, and remove the claims that reliably fail. In practice that means naming the provider and pharmacy relationships, publishing accurate privacy, terms, refund and contact information, stating where you are licensed to operate, keeping medical and marketing claims defensible, and inventorying every domain you control. Most first-round problems are disclosure gaps and overreaching claims, not deep technical faults, which is why a structured pre-submission pass catches the majority of them.
Can a web agency guarantee I get LegitScript certified?
No, and anyone who promises approval is misreading the process. Certification is decided by LegitScript against its own standards after its own review. What preparation can do is remove the predictable reasons a site is sent back: missing disclosures, inconsistent information between the site and the application, undisclosed partners, unsupportable claims, and forgotten domains. You should expect your website prepared to meet the standards, not a guarantee of the outcome, which stays with LegitScript.
Does LegitScript look at pages behind a login or old subdomains?
Yes. One of the certification standards requires an applicant to provide all domain names and websites under its control, so staging sites, old landing pages, and subdomains you stopped using are in scope, not out of it. Content behind a login is also relevant, because a claim that appears only to logged-in patients is still a claim your business is making. A common first-round failure is a conservative public site paired with a forgotten page somewhere that says something the standards do not allow.
Do I need LegitScript if I use a telehealth platform like Altro, Qualiphy, or a compounding pharmacy?
It depends on who is the merchant and advertiser of record, and that is worth settling early rather than assuming. If you operate your own brand, storefront, and ad accounts, certification generally attaches to your business even when the clinical work runs through a platform or an outside pharmacy. If you are selling entirely inside another company's certified infrastructure, the certification may sit with them. Confirm which applies to your setup before you build the application, because it changes who files and what the site has to show.
Sources
- LegitScript, Healthcare Certification, including the nine certification standards checked 2026-10-07
Want this costed for your build?
Tell us what you already have and what is not working, and we will come back with the shape of the work and what drives the number.