State Pharmacy Board Rules for GLP-1 Telehealth Advertising: A 50-State Survey
On March 3, 2026, the FDA issued 30 warning letters to telehealth companies for false or misleading claims about compounded GLP-1 products, a clear signal that state pharmacy board GLP-1 oversight is...
On March 3, 2026, the FDA issued 30 warning letters to telehealth companies for false or misleading claims about compounded GLP-1 products, a clear signal that state pharmacy board GLP-1 oversight is no longer running parallel to federal enforcement, it is converging with it.[1] State pharmacy boards in Mississippi, New Jersey, Oregon, and others have issued their own restrictions on salt-form semaglutide, and brand manufacturers and plaintiffs' attorneys are filing cases by the hundreds. This 50-state survey explains how state pharmacy board GLP-1 rules intersect with telehealth advertising, what compliance failures cost in penalties and litigation, and how to fix the most common tracking and marketing risks before they trigger an investigation.
The Current Enforcement Landscape
GLP-1 telehealth marketing now sits at the intersection of four enforcement systems: FDA misbranding rules, FTC deceptive-advertising authority, state pharmacy and medical board oversight, and HIPAA and state privacy enforcement against tracking technologies. Each layer has tightened materially in the last 18 months.
OCR Enforcement Trends
OCR closed 22 HIPAA enforcement actions in 2024 with more than $9.9 million in financial penalties, including a $4,750,000 settlement with Montefiore Medical Center to resolve multiple HIPAA Security Rule violations.[2] OCR's updated tracking technologies guidance states that regulated entities may not share PHI with tracking technology vendors absent a business associate agreement or patient authorization.[3]
A June 2024 ruling in the Northern District of Texas vacated the portion of OCR's bulletin treating an IP address plus a visit to an unauthenticated webpage about health conditions as PHI. However, tracking tools may not be used on authenticated webpages such as patient portals unless the disclosure of PHI is permitted by the HIPAA Privacy Rule and a valid business associate agreement is in place or authorizations have been obtained.[4]
FTC Involvement
The FTC has used its authority under both the FTC Act and the Health Breach Notification Rule to take enforcement actions against entities including GoodRx, BetterHelp, Monument, and Cerebral for disclosing sensitive health information collected online to third parties. Cerebral and Monument are direct analogs for GLP-1 telehealth operators: subscription-based virtual care models using pixel-based ad targeting. Telehealth companies should anticipate joint FDA/FTC scrutiny of advertising, state board attention to telehealth prescribing and pharmacy operations, private litigation, and payor audits as the major enforcement vectors.
Class-Action Lawsuit Explosion
The vacatur of part of the OCR bulletin did not slow private litigation. Settlements have reached multi-million-dollar levels: MarinHealth agreed to a $3 million settlement to resolve claims related to its use of the Meta Pixel tracking tool on its website between 2019 and 2025, and Pomona Valley Hospital Medical Center agreed to pay $600,000 to resolve similar claims.[5] Plaintiffs' firms continue to file putative class actions under state and federal wiretap statutes and various state statutory and common law privacy theories.
State-Level Actions
State enforcement is rising independently of OCR. The New York Attorney General imposed a $300,000 financial penalty on New York Presbyterian Hospital for using pixels and other website tracking tools.[2] On the pharmacy side, the New Jersey Board of Pharmacy has explicitly stated that the salt form of semaglutide may not be used in compounding, and other boards including the Mississippi Board of Medicine have issued comparable guidance.[6]
State Pharmacy Board Rules: 50-State Survey Highlights
Pharmacy regulation is fundamentally a state matter. The FDA regulates commercial drugs, but licensing and oversight of compounding pharmacies falls to states, which means a single national ad campaign can simultaneously violate dozens of distinct rule sets. Key state-by-state patterns include:
- Mississippi: The Mississippi Board of Pharmacy has issued direct guidance that semaglutide base appears on the approved FDA products list, but semaglutide sodium, semaglutide acetate, and other salt forms do not, and the FDA has stated that compounding with semaglutide salts does not meet section 503A requirements.[7] On the prescriber side, the Mississippi Board of Medicine has stated that off-label use of semaglutide-based legend drugs was prohibited by Board regulation, and strongly advised licensed physicians to refrain from prescribing, dispensing, or administering any compounded semaglutide until further notice.[6] In May 2023, the Mississippi State Board of Medical Licensure suspended a physician's Mississippi medical license for three months and prohibited the licensee from practicing medicine via telehealth in Mississippi until June 17, 2023.[8]
- New Jersey: The Board of Pharmacy has explicitly prohibited the use of any salt form of semaglutide in compounding, taking a stricter position than federal guidance and creating sharp exposure for telehealth ads aimed at New Jersey residents.[6]
- Oregon: The Oregon Board of Pharmacy has stated that no salt form of semaglutide is contained in an FDA-approved drug and semaglutide does not, in any form, appear on the FDA's bulks list for compounding, and warned that compounding or dispensing semaglutide in a way that fails to conform with governing law may lead to enforcement action by the Board.[9]
- California, Texas, North Carolina, West Virginia: Each has adopted varying rules on compounding, off-label prescribing, and out-of-state shipments. Several state boards initially banned compounded GLP-1 weight-loss products outright before revising their positions, illustrating how rapidly the regulatory line is moving and why advertising creative cannot rely on a single national legal review.
- Telehealth modality rules: Many states require synchronous live-video patient encounters for the initial prescription of injectable drugs, regardless of pharmacy board posture. Advertising that promises "no video required" intake flows can independently violate medical practice rules even where the pharmacy side is compliant.
The unifying federal backdrop: the FDA declared the semaglutide and tirzepatide shortages resolved, after which compounders producing essentially-copies of approved drugs became enforcement targets. FDA is aware of fraudulent compounded semaglutide and tirzepatide marketed in the U.S., and the agency has documented adverse events linked to dosing errors with compounded injectable semaglutide products.[10] Advertising that worked in 2023 may now constitute promotion of an unlawful product.
For a deeper look at multi-jurisdictional licensure exposure, see our analysis of multi-state telehealth licensing and marketing and the operational rules for advertising virtual weight loss consultations.
Specific Risks and Consequences
Financial Penalties
- FDA misbranding: Warning letters, injunctions, seizure, criminal referral. The FDA's March 2026 batch targeted 30 telehealth companies in a single round.[1]
- State pharmacy board penalties: Loss of pharmacy permit, individual pharmacist license suspension, refusal of out-of-state shipping authority, and per-prescription fines that vary by state.
- State medical board penalties: License suspension. The Mississippi State Board of Medical Licensure suspended a physician's license and prohibited her from telehealth practice in the state for several months.[8]
- HIPAA civil monetary penalties: Tiered and inflation-adjusted, with per-violation amounts and annual caps; the Montefiore settlement reached $4.75 million.[2]
- State AG actions: The $300,000 New York Presbyterian penalty illustrates that AGs will move even where OCR does not.[2]
- Class-action settlements: Recent pixel and analytics settlements include MarinHealth's $3 million and Pomona Valley's $600,000.[5]
- Brand-manufacturer litigation: As of August 2025, Novo Nordisk had filed 132 complaints in federal courts across 40 states, targeting companies whose marketing and business practices put patient safety at risk, and courts had issued 44 permanent injunctions against defendants in similar cases.[11] Eli Lilly has filed parallel actions targeting compounded tirzepatide.
Reputational Damage
Compounded GLP-1 safety failures are now front-page news. FDA received multiple reports of adverse events, some requiring hospitalization, that may be related to dosing errors associated with compounded injectable semaglutide products.[10] An advertising violation that surfaces alongside an adverse event becomes a media story, not just a regulatory file.
Operational Disruption
Corrective action plans last years. A typical multi-year CAP focuses teams on policy drafting, technical gap closure, training, and reporting on a set cadence, with day-to-day governance of third-party scripts, pixels, and tags until continuous monitoring is demonstrable. Post-incident remediation typically requires removing or reconfiguring trackers, implementing server-side controls, renegotiating BAAs, and tightening consent flows.
Personal Liability
Prescriber licenses are personal, not corporate. The Mississippi suspension example shows that the individual provider, not just the telehealth platform, takes the regulatory hit.[8] Pharmacy permits are similarly individualized, and compounding pharmacies are not insulated from liability simply because a third party drafted the ad copy; regulators and plaintiffs' attorneys look at the entire ecosystem, including dispensing pharmacies whose products were promoted.
How Violations Happen
Technical Configurations
Most HIPAA marketing violations are not malicious; they are default settings left in place. Meta Pixel, Google Analytics, TikTok Pixel, and similar tools by default transmit URL parameters, IP addresses, and form-field values to ad platforms. For a GLP-1 telehealth site, that often includes the patient's BMI, weight goal, prescription history, and condition selections from intake forms. OCR's guidance is unchanged on this point: regulated entities may not share PHI with tracking technology vendors absent a BAA or patient authorization.[3]
Vendor Relationships
If a vendor receives PHI in the course of providing services to a covered entity, it is a business associate and a BAA is required. OCR's updated guidance allows a regulated entity to use a Customer Data Platform vendor that will sign a BAA to de-identify online tracking information that includes PHI, and then disclose only de-identified information to tracking vendors that will not sign a BAA.[3] That architecture, server-side de-identification with a BAA-backed intermediary, is now the practical compliance template.
Staff Actions and Audit Triggers
Marketing teams add new pixels for campaign measurement without notifying compliance. IT teams install chat widgets and session-replay tools that capture form input. Social media teams cross-post intake-form URLs that expose query parameters. Each is a routine trigger for investigation. Unlike obscure server breaches, web-based tracking misuse leaves footprints in browser audits, vendor packet captures, and consumer complaints, all of which plaintiffs' counsel and state AG offices routinely capture.
Protection Strategies
Immediate Actions (This Week)
- Inventory every tracking tag, pixel, and analytics script on patient-facing pages, including intake forms, scheduling flows, and patient portals.
- Identify every vendor that receives data from those tags. Confirm BAA status for each.
- Capture network traffic from a sample patient journey and document what data leaves your domain.
- Audit advertising copy for "sameness" claims, FDA-approval implications, or branded comparisons. Primary violations identified in the FDA's March 2026 letters included claims implying sameness with FDA-approved products and obscuring product sourcing by advertising drug products branded with the telehealth firm's name or trademark without qualification.[1]
Short-Term Fixes (This Month)
- Remove or reconfigure client-side pixels that transmit PHI; route conversion data through a server-side, BAA-covered pipeline.
- Update privacy policies to reflect actual data flows.
- Train marketing and clinical staff on prohibited claims under FDA misbranding rules and the relevant state pharmacy board advertising prohibitions.
- Review pharmacy and telehealth contracts. As Venable LLP advises, providers should review websites, social media, and advertising materials for statements implying sameness, generic status, or FDA approval, and ensure labels and online materials accurately identify which party is actually compounding the product and avoid private-label presentations that confuse consumers.[12]
Long-Term Compliance Infrastructure
- Server-side conversion APIs with PHI filtering before data leaves the regulated environment.
- Continuous client-side monitoring for unauthorized script additions.
- Documented audit schedule covering both state pharmacy board GLP-1 advertising rules and the technical tracking stack.
- State-by-state ad copy variants for jurisdictions with unique disclosure or prohibition rules.
Vendor Evaluation Criteria
- BAA: Signed, healthcare-specific, with subcontractor flow-down clauses.
- Technical capability: Verifiable PHI stripping before transmission to ad platforms.
- Certifications: SOC 2 Type II at minimum.
- Healthcare experience: Track record with covered entities and business associates.
For closely related compliance topics, see our deep dive on FTC and HIPAA rules for virtual weight loss programs and the specific FDA and FTC restrictions on 503B compounding pharmacy GLP-1 advertising.
How Curve Addresses Each Risk
Curve is a HIPAA-compliant tracking solution designed for the exact risk profile described above. It addresses the four common failure modes:
- Automated PHI stripping: Curve intercepts tracking data server-side and removes identifiers, intake-form values, condition indicators, and prescription-related parameters before any data reaches Meta, Google, TikTok, or other ad platforms. This converts the architecture into the de-identification model OCR explicitly endorses in its updated guidance.
- Signed BAAs: Curve signs a BAA with every customer, addressing the vendor-relationship gap that triggers most tracking-technology investigations.
- Audit trails: Every event is logged with the original payload, the stripped payload, and the routing decision, producing the documentation required during OCR investigations or state AG inquiries.
- Healthcare-specific design: Filters and rule sets are built around the specific PHI patterns that appear in GLP-1 telehealth flows (weight, BMI, condition selection, prescription history, dosage) rather than generic e-commerce conversion data.
- Rapid implementation: Customers typically migrate from raw client-side pixels to a compliant server-side pipeline in days, not the multi-month timelines associated with custom build-outs.
Curve does not replace clinical or advertising-compliance review. It closes the technical gap that turns a compliant ad campaign into a HIPAA violation in the browser.
Don't Wait for Enforcement
Every day without compliant tracking is a day of risk exposure. Schedule a Compliance Assessment with Curve.
Compliance Self-Assessment Checklist
- FDA misbranding: Do any ads imply "sameness," "generic," or FDA approval of a compounded GLP-1?
- State pharmacy boards: Have you mapped advertising and shipping rules in every state where your pharmacy partner dispenses, with special attention to Mississippi, New Jersey, Oregon, California, North Carolina, and West Virginia?
- State medical boards: Does your telehealth modality (live video vs. asynchronous) satisfy the rules of every state where patients are located?
- Off-label restrictions: Are you advertising weight-loss indications in states that restrict off-label weight-loss prescribing of compounded products?
- Tracking technologies: Have you inventoried every pixel, tag, and analytics script on patient-facing pages?
- BAAs: Does every vendor receiving data have a signed BAA, or is data being de-identified by a BAA-covered intermediary first?
- Accreditation: Does your pharmacy partner hold relevant accreditations, and is your ad placement consistent with platform requirements?
- Contracts: Do your telehealth-pharmacy contracts allocate advertising responsibility, indemnification, and audit rights?
- Documentation: Do you have audit-ready logs of tracking configurations, data flows, and ad-copy approvals?
Frequently Asked Questions
What are the penalties for HIPAA marketing violations?
HIPAA civil monetary penalties are tiered and inflation-adjusted, with per-violation amounts and annual caps per category. OCR closed 22 enforcement actions in 2024 totaling more than $9.9 million, including a $4,750,000 Montefiore settlement.[2] State AGs add their own penalties; the New York AG imposed $300,000 on New York Presbyterian for pixel use. Class-action settlements have reached the multi-million-dollar range, with MarinHealth paying $3 million in 2025.[5]
Can healthcare practices be sued for using Meta Pixel?
Yes. Putative class actions continue to be filed in state and federal courts under state and federal wiretap statutes and various state statutory and common law theories, even after parts of OCR's tracking-technologies guidance were vacated. Tracking tools may not be used on authenticated webpages such as patient portals unless the disclosure of PHI is permitted by the HIPAA Privacy Rule and a valid business associate agreement is in place or authorizations have been obtained.[4] The risk is acute when pixels are placed on authenticated patient portals or pages capturing intake data.
How do I know if my GLP-1 telehealth marketing is compliant?
You need three reviews: (1) ad-copy review against FDA misbranding standards (no "sameness," no FDA-approval implication, no obscuring of the actual compounder); (2) state-by-state regulatory review against pharmacy and medical board rules in every state where you have patients or pharmacy partners; and (3) a technical review of tracking and analytics data flows for PHI leakage. The FDA has specifically targeted statements implying sameness with approved products and labels that obscure the actual compounder.[1]
What should I do if I discover a compliance violation?
Document the issue, stop the offending data flow or ad immediately, and engage counsel before any external communications. For tracking violations, OCR investigations focus on whether risk analysis, BAAs, and technical safeguards were in place; mitigation evidence affects penalty calculations. For advertising violations, expect to update or remove content, notify affected partners (including compounding pharmacies whose products were referenced), and preserve documentation. Venable LLP notes that compounders and telehealth platforms should ensure labels and online materials accurately identify which party is actually compounding the product and avoid private-label presentations that confuse consumers.[12]
Are state pharmacy board GLP-1 rules really different across all 50 states?
Yes, materially. The New Jersey Board of Pharmacy has explicitly prohibited salt forms of semaglutide in compounding,[6] the Oregon Board of Pharmacy has warned that noncompliant compounding may lead to enforcement action,[9] and Mississippi has taken the further step of telling licensed physicians to refrain from prescribing compounded semaglutide entirely. A single national ad campaign therefore needs jurisdiction-specific copy and routing rules.
Sources
- FDA, "FDA Warns 30 Telehealth Companies Against Illegal Marketing of Compounded GLP-1s" (March 3, 2026)
- HIPAA Journal, "State of HIPAA"
- Covington Inside Privacy, "HHS OCR Updates Tracking Technologies Guidance"
- HIPAA Journal, "OCR Drops Appeal in AHA Tracking Technology Case"
- HIPAA Journal, "MarinHealth Pays $3 Million to Settle Class Action Meta Pixel Lawsuit"
- Frier Levitt, "Prescribing, Compounding and Dispensing Semaglutide for Weight Loss: Pitfalls and Compliance Considerations"
- Mississippi Board of Pharmacy, "Semaglutide Compounding Guidance"
- Mississippi State Board of Medical Licensure, "Determination & Order: Laura Purdy, M.D." (May 18, 2023)
- Oregon Board of Pharmacy, "Position Statements"
- FDA, "FDA's Concerns with Unapproved GLP-1 Drugs Used for Weight Loss"
- Novo Nordisk, "Novo Nordisk expands legal action to protect US patients from unsafe, non-FDA-approved compounded 'semaglutide'" (August 5, 2025)
- Venable LLP, "FDA's Latest GLP-1 Crackdown: What Compounders and Telehealth Platforms Need to Know" (March 2026)
Related articles
- GuideGLP-1 Compounded Pharmacy Marketing: 2026 FDA Crackdown and Advertising Rules
- GuideDirect-to-Consumer GLP-1 Brand Advertising: Pharma DTC Rules for 2026
- GuideCompounding Pharmacy GLP-1 Advertising: FDA and FTC Restrictions on 503B Claims
- GuidePharmaceutical DTC Advertising Compliance 2026: FTC and FDA Rules for Direct-to-Consumer Health Claims
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit