GLP-1 Ad Copy Review: Claims That Draw Letters
A working ad copy review process for GLP-1 marketing teams: intake, a four-pass rubric, named sign-off, launch logging, and post-launch monitoring that actually holds.
The reliable way to keep GLP-1 ad copy out of trouble is a standing review process with named sign-off, a written rubric, and a log of what shipped, not a legal review requested whenever someone feels nervous. FDA sent 30 warning letters to telehealth companies over compounded GLP-1 promotional claims on 3 March 2026 and 25 more during the week of 15 June 2026, and the cited material was almost always routine growth work that nobody thought needed review. Curve is the HIPAA-compliant tracking layer that makes this process measurable, so compliant copy can be judged on real downstream outcomes, with a signed BAA on every plan.
Why ad hoc review fails
Most telehealth teams have a review process on paper. It usually says copy goes to legal before launch. It fails for structural reasons rather than lazy ones.
Volume is the first. A performance team ships dozens of creative variants a week, plus quiz result copy, plus email, plus SMS, plus creator briefs. No counsel reviews that throughput, so the team quietly defines review as applying to campaigns rather than to variants, and the variants are where the aggressive claims live.
Surface blindness is the second. Review covers the landing page because the landing page feels like the official artifact. The FDA reads promotional communications broadly, which includes the quiz, the result screen, the abandoned-cart email, the affiliate's script, and the ad itself.
Absence of a record is the third. When a letter arrives naming a specific communication, the question is what was running, when, and who approved it. Teams that cannot answer spend the first week of a fifteen working day response window reconstructing history instead of fixing it.
Stage one: intake that makes review possible
Review starts before writing. Give every campaign or creative batch an intake record with five fields, filled by whoever requests the work.
- Product being promoted. The specific compounded formulation, not "GLP-1 program".
- Every surface in scope. Ad copy, image or video, landing page, quiz, result screen, email sequence, SMS, creator brief. If a surface is not listed, it is not reviewed, and everyone knows that.
- Claims the campaign depends on. Written out as sentences. If the campaign only works with a numeric outcome claim, that has to be visible at intake rather than discovered at launch.
- Substantiation available. What document supports each claim, for the product actually dispensed.
- Reviewer and deadline. A person, not a queue.
Intake takes ten minutes and removes most of the argument later. Teams resist it until the first time a reviewer rejects a headline and the requester can point to the claim being listed at intake, which reframes the conversation as a substantiation gap rather than a personal veto.
Stage two: the four-pass rubric
Run four passes in order. Do not merge them. Reviewers who look for everything at once find the obvious thing and stop.
Pass one: equivalence
Read for any statement positioning a compounded product as the same as an approved drug. Compounded GLP-1 products are not FDA-approved. Flag brand names used to describe what the patient receives, phrases like "generic" or "the affordable version of", ingredient-equivalence language, comparison graphics whose only differing row is price, and any use of the approved drug's trial results as evidence for yours.
Search brand-term paid search separately. An ad triggered by a brand query whose headline implies the searcher will receive that brand makes the claim in the match, not in the words.
Pass two: substantiation
Highlight every number and every superlative. For each, name the document that supports it for your product. If the honest answer is that the support is the approved drug's label or a class-level study, the claim does not survive this pass.
Timeline promises are the most commonly missed. "Results in weeks" is a numeric claim wearing a word.
Pass three: balance as rendered
Open the page on a phone. Scroll at reading speed. Stop at the primary call to action and write down what risk information the visitor has seen by that point. Anything behind an accordion, a modal, or a link has not been seen. Do the same for video by watching once at normal speed without pausing.
Then check the ad itself. Paid social copy needs a risk reference on its own, because you cannot assume the click.
Pass four: endorsement and testimonials
Flag every FDA reference. Registration is not approval, and a registered facility statement placed inside a benefits block reads as an approval claim regardless of intent. Then read testimonials as claims. Before-and-after imagery is an outcome claim in pictures, and Meta rejects most before-and-after weight-loss imagery anyway. Check that typicality is presented next to the story rather than in a global footer.
Stage three: sign-off that means something
A review that ends in a chat message does not survive an enforcement inquiry. Three rules make sign-off real.
- One named approver per surface. Not a channel, not a team. The name goes in the record.
- Approval attaches to a version. A copy change after approval is unapproved copy, including a headline swap made inside the ad platform at eleven at night.
- Rejections are written with a reason category. Equivalence, substantiation, balance, endorsement, testimonial. Categories are what teach the team, and after a quarter the pattern in your rejection log tells you which writer or which brief keeps generating the same failure.
Give the approver an explicit escalation path to counsel with a threshold, so routine work does not consume legal time and genuinely novel claims do not get waved through by someone applying a rubric outside their competence.
Stage four: the launch log
Log every shipped variant with its approval, its live dates, and a rendered capture of the surface. A screenshot of the page as it appeared and the exact ad copy text, stored somewhere durable, not a link to a platform interface whose content changes when someone edits the ad.
This is the single highest-leverage habit in the whole process. When a warning letter names a communication, you can produce it immediately, see whether identical claims ran elsewhere, and take everything down in one pass instead of discovering a surviving variant three months later.
Stage five: post-launch monitoring
Review does not end at launch. Three signals deserve a standing check.
- Platform rejections. Meta requires prior authorization for prescription drug advertising and admits only pharmaceutical manufacturers, online pharmacies, and telehealth providers. It rejects branded pharmaceutical weight-loss terms and most before-and-after imagery. A rejection is a claim-quality signal. Route it back through the rubric instead of rewording until something passes, because iterating past a classifier optimizes toward the most aggressive claim it happens to miss.
- Creator and affiliate output. Audit what actually shipped, not what was briefed. This is consistently the loosest copy in the funnel and it is attributed to you.
- Drift. Quiz result screens, email sequences, and site modules get edited by people who were never in the review. Re-render the full path monthly.
What this costs you if measurement is broken
Every rejection in this process removes something a writer believed was carrying conversion. Without measurement, the review team becomes the department that says no and the growth team routes around it. With measurement, a rejection is testable: ship the compliant variant, watch what happens to real downstream outcomes, and settle the argument with data.
Here is the trap. The obvious way to get that measurement is a Meta Pixel or Google tag on the funnel, and on a GLP-1 funnel that tag sends the page URL, which frequently names the medication. It sends quiz completions with answers attached when the form is instrumented naively. It sends a durable browser identifier that ties the whole sequence to one person.
Meta and Google do not sign BAAs for their advertising products. Each of those calls tells a vendor with no BAA that an identifiable person is interested in a specific treatment. Healthcare pixel litigation on that mechanism has produced settlements cumulatively past $100 million, and it is entirely separate from anything the FDA is looking at. A team can run a perfect copy review and still be carrying it. Our piece on why client-side pixels break HIPAA covers the mechanism in detail.
How Curve makes the review loop measurable
Curve is HIPAA-compliant ad tracking, attribution, and analytics for healthcare. It replaces client-side pixels with a server-side path, which gives the review process a way to prove itself without exposing patients.
- Server-side collection. The Curve script installs in place of the Meta Pixel and Google tag. Events reach Curve's US-hosted infrastructure rather than going straight to ad platforms.
- Per-destination field mapping. Only explicitly mapped fields forward, and the default is that nothing goes. Medication-naming URLs, quiz answers, and free-text fields stay behind, so variant testing does not disclose what the variant was about.
- Neutral event aliases. The ad platform receives a neutral conversion name rather than the service line, so your campaign structure is not a treatment list sitting in an ad account.
- Identifier hashing. Email, phone, and name are SHA-256 hashed per each platform's conversion API requirements.
- Bridge tokens. Attribution survives the handoff into a separate intake or booking tool, which is where telehealth funnels usually lose the chain and where copy tests go dark exactly when the answer matters.
- PHI-pattern detection. Payloads containing PHI-shaped values such as SSNs, MRN-style identifiers, or long numeric sequences are flagged, which is how you learn that a quiz field changed shape after a redesign.
Clean conversions forward server-side to Meta CAPI, Google Ads Enhanced Conversions, TikTok Events API, Microsoft, and LinkedIn. Offline conversion uploads with click-ID matching let you push genuine downstream outcomes back, so a compliant headline is judged on patients who start treatment rather than on quiz completions. A signed BAA is included on every plan. If your funnel hands off to an intake tool, our guide to routing ad clicks to a CRM without PHI is the companion read.
Frequently asked questions
Who should own ad copy review, marketing or legal?
Marketing should own the rubric passes and legal should own the escalation threshold. Routing every variant to counsel guarantees the process gets bypassed on volume. Routing nothing guarantees novel claims ship unexamined.
How long should review take?
Set a published turnaround, commonly one to two business days for routine variants, and hold it. Unpredictable review time is the single most common reason teams launch first and review later.
Do we need to review every creative variant?
Every variant that changes a claim. Aspect ratio, image crop, and audience targeting changes do not need a fresh pass. A headline, a subheadline, a result screen, or an on-image text change does.
What do we do with copy already live that fails the rubric?
Take it down or correct it and record what changed, rather than quietly editing. Then widen the sweep, because the same sentence usually exists in three other places. A response that fixes only the cited page invites a follow-up.
Does Meta approving our ad mean it is compliant?
No. Platform policy and FDA expectations are separate regimes, stricter than each other in different places. Approval means a classifier did not object. It is not a regulatory finding.
Can we track which compliant variants convert without sending PHI?
Yes, if the clinical content stays in systems whose vendors signed BAAs and ad platforms receive only a neutral, hashed, matched conversion signal. That separation is what Curve's server-side path with per-destination field mapping and neutral aliases is built to enforce by default.
Where to start
Stand up the smallest version this week. One intake form, the four passes written on a single page, one named approver, and a launch log with rendered captures. Run it on next week's creative batch and fix the friction you find rather than designing the perfect process first.
Then close the measurement gap, because a review process without outcome data becomes a negotiation. Curve gives you server-side collection, per-destination field mapping, hashed identifiers, neutral event aliases, and bridge-token attribution, so a compliant variant can be proven on real patient outcomes instead of argued about. Run the free compliance scanner against your funnel, or visit curvecompliance.com and we will walk your team through it.
Reviewed August 2026. This is general information, not legal or regulatory advice. FDA positions and platform policies change; consult qualified counsel about your specific promotional materials.
Related articles
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit