Skip to main content
Guide

State Pharmacy Board Rules for GLP-1 Telehealth Advertising: A 50-State Survey

On March 3, 2026, the FDA issued 30 warning letters to telehealth companies for false or misleading claims about compounded GLP-1 products, a clear signal that state pharmacy board GLP-1 oversight is...

13 min read

On March 3, 2026, the FDA issued 30 warning letters to telehealth companies for false or misleading claims about compounded GLP-1 products, a clear signal that state pharmacy board GLP-1 oversight is no longer running parallel to federal enforcement, it is converging with it.[1] State pharmacy boards in Mississippi, New Jersey, Oregon, and others have issued their own restrictions on salt-form semaglutide, and brand manufacturers and plaintiffs' attorneys are filing cases by the hundreds. This 50-state survey explains how state pharmacy board GLP-1 rules intersect with telehealth advertising, what compliance failures cost in penalties and litigation, and how to fix the most common tracking and marketing risks before they trigger an investigation.

The Current Enforcement Landscape

GLP-1 telehealth marketing now sits at the intersection of four enforcement systems: FDA misbranding rules, FTC deceptive-advertising authority, state pharmacy and medical board oversight, and HIPAA and state privacy enforcement against tracking technologies. Each layer has tightened materially in the last 18 months.

OCR Enforcement Trends

OCR closed 22 HIPAA enforcement actions in 2024 with more than $9.9 million in financial penalties, including a $4,750,000 settlement with Montefiore Medical Center to resolve multiple HIPAA Security Rule violations.[2] OCR's updated tracking technologies guidance states that regulated entities may not share PHI with tracking technology vendors absent a business associate agreement or patient authorization.[3]

A June 2024 ruling in the Northern District of Texas vacated the portion of OCR's bulletin treating an IP address plus a visit to an unauthenticated webpage about health conditions as PHI. However, tracking tools may not be used on authenticated webpages such as patient portals unless the disclosure of PHI is permitted by the HIPAA Privacy Rule and a valid business associate agreement is in place or authorizations have been obtained.[4]

FTC Involvement

The FTC has used its authority under both the FTC Act and the Health Breach Notification Rule to take enforcement actions against entities including GoodRx, BetterHelp, Monument, and Cerebral for disclosing sensitive health information collected online to third parties. Cerebral and Monument are direct analogs for GLP-1 telehealth operators: subscription-based virtual care models using pixel-based ad targeting. Telehealth companies should anticipate joint FDA/FTC scrutiny of advertising, state board attention to telehealth prescribing and pharmacy operations, private litigation, and payor audits as the major enforcement vectors.

Class-Action Lawsuit Explosion

The vacatur of part of the OCR bulletin did not slow private litigation. Settlements have reached multi-million-dollar levels: MarinHealth agreed to a $3 million settlement to resolve claims related to its use of the Meta Pixel tracking tool on its website between 2019 and 2025, and Pomona Valley Hospital Medical Center agreed to pay $600,000 to resolve similar claims.[5] Plaintiffs' firms continue to file putative class actions under state and federal wiretap statutes and various state statutory and common law privacy theories.

State-Level Actions

State enforcement is rising independently of OCR. The New York Attorney General imposed a $300,000 financial penalty on New York Presbyterian Hospital for using pixels and other website tracking tools.[2] On the pharmacy side, the New Jersey Board of Pharmacy has explicitly stated that the salt form of semaglutide may not be used in compounding, and other boards including the Mississippi Board of Medicine have issued comparable guidance.[6]

State Pharmacy Board Rules: 50-State Survey Highlights

Pharmacy regulation is fundamentally a state matter. The FDA regulates commercial drugs, but licensing and oversight of compounding pharmacies falls to states, which means a single national ad campaign can simultaneously violate dozens of distinct rule sets. Key state-by-state patterns include:

The unifying federal backdrop: the FDA declared the semaglutide and tirzepatide shortages resolved, after which compounders producing essentially-copies of approved drugs became enforcement targets. FDA is aware of fraudulent compounded semaglutide and tirzepatide marketed in the U.S., and the agency has documented adverse events linked to dosing errors with compounded injectable semaglutide products.[10] Advertising that worked in 2023 may now constitute promotion of an unlawful product.

For a deeper look at multi-jurisdictional licensure exposure, see our analysis of multi-state telehealth licensing and marketing and the operational rules for advertising virtual weight loss consultations.

Specific Risks and Consequences

Financial Penalties

Reputational Damage

Compounded GLP-1 safety failures are now front-page news. FDA received multiple reports of adverse events, some requiring hospitalization, that may be related to dosing errors associated with compounded injectable semaglutide products.[10] An advertising violation that surfaces alongside an adverse event becomes a media story, not just a regulatory file.

Operational Disruption

Corrective action plans last years. A typical multi-year CAP focuses teams on policy drafting, technical gap closure, training, and reporting on a set cadence, with day-to-day governance of third-party scripts, pixels, and tags until continuous monitoring is demonstrable. Post-incident remediation typically requires removing or reconfiguring trackers, implementing server-side controls, renegotiating BAAs, and tightening consent flows.

Personal Liability

Prescriber licenses are personal, not corporate. The Mississippi suspension example shows that the individual provider, not just the telehealth platform, takes the regulatory hit.[8] Pharmacy permits are similarly individualized, and compounding pharmacies are not insulated from liability simply because a third party drafted the ad copy; regulators and plaintiffs' attorneys look at the entire ecosystem, including dispensing pharmacies whose products were promoted.

How Violations Happen

Technical Configurations

Most HIPAA marketing violations are not malicious; they are default settings left in place. Meta Pixel, Google Analytics, TikTok Pixel, and similar tools by default transmit URL parameters, IP addresses, and form-field values to ad platforms. For a GLP-1 telehealth site, that often includes the patient's BMI, weight goal, prescription history, and condition selections from intake forms. OCR's guidance is unchanged on this point: regulated entities may not share PHI with tracking technology vendors absent a BAA or patient authorization.[3]

Vendor Relationships

If a vendor receives PHI in the course of providing services to a covered entity, it is a business associate and a BAA is required. OCR's updated guidance allows a regulated entity to use a Customer Data Platform vendor that will sign a BAA to de-identify online tracking information that includes PHI, and then disclose only de-identified information to tracking vendors that will not sign a BAA.[3] That architecture, server-side de-identification with a BAA-backed intermediary, is now the practical compliance template.

Staff Actions and Audit Triggers

Marketing teams add new pixels for campaign measurement without notifying compliance. IT teams install chat widgets and session-replay tools that capture form input. Social media teams cross-post intake-form URLs that expose query parameters. Each is a routine trigger for investigation. Unlike obscure server breaches, web-based tracking misuse leaves footprints in browser audits, vendor packet captures, and consumer complaints, all of which plaintiffs' counsel and state AG offices routinely capture.

Protection Strategies

Immediate Actions (This Week)

  1. Inventory every tracking tag, pixel, and analytics script on patient-facing pages, including intake forms, scheduling flows, and patient portals.
  2. Identify every vendor that receives data from those tags. Confirm BAA status for each.
  3. Capture network traffic from a sample patient journey and document what data leaves your domain.
  4. Audit advertising copy for "sameness" claims, FDA-approval implications, or branded comparisons. Primary violations identified in the FDA's March 2026 letters included claims implying sameness with FDA-approved products and obscuring product sourcing by advertising drug products branded with the telehealth firm's name or trademark without qualification.[1]

Short-Term Fixes (This Month)

  1. Remove or reconfigure client-side pixels that transmit PHI; route conversion data through a server-side, BAA-covered pipeline.
  2. Update privacy policies to reflect actual data flows.
  3. Train marketing and clinical staff on prohibited claims under FDA misbranding rules and the relevant state pharmacy board advertising prohibitions.
  4. Review pharmacy and telehealth contracts. As Venable LLP advises, providers should review websites, social media, and advertising materials for statements implying sameness, generic status, or FDA approval, and ensure labels and online materials accurately identify which party is actually compounding the product and avoid private-label presentations that confuse consumers.[12]

Long-Term Compliance Infrastructure

  • Server-side conversion APIs with PHI filtering before data leaves the regulated environment.
  • Continuous client-side monitoring for unauthorized script additions.
  • Documented audit schedule covering both state pharmacy board GLP-1 advertising rules and the technical tracking stack.
  • State-by-state ad copy variants for jurisdictions with unique disclosure or prohibition rules.

Vendor Evaluation Criteria

  • BAA: Signed, healthcare-specific, with subcontractor flow-down clauses.
  • Technical capability: Verifiable PHI stripping before transmission to ad platforms.
  • Certifications: SOC 2 Type II at minimum.
  • Healthcare experience: Track record with covered entities and business associates.

For closely related compliance topics, see our deep dive on FTC and HIPAA rules for virtual weight loss programs and the specific FDA and FTC restrictions on 503B compounding pharmacy GLP-1 advertising.

How Curve Addresses Each Risk

Curve is a HIPAA-compliant tracking solution designed for the exact risk profile described above. It addresses the four common failure modes:

  • Automated PHI stripping: Curve intercepts tracking data server-side and removes identifiers, intake-form values, condition indicators, and prescription-related parameters before any data reaches Meta, Google, TikTok, or other ad platforms. This converts the architecture into the de-identification model OCR explicitly endorses in its updated guidance.
  • Signed BAAs: Curve signs a BAA with every customer, addressing the vendor-relationship gap that triggers most tracking-technology investigations.
  • Audit trails: Every event is logged with the original payload, the stripped payload, and the routing decision, producing the documentation required during OCR investigations or state AG inquiries.
  • Healthcare-specific design: Filters and rule sets are built around the specific PHI patterns that appear in GLP-1 telehealth flows (weight, BMI, condition selection, prescription history, dosage) rather than generic e-commerce conversion data.
  • Rapid implementation: Customers typically migrate from raw client-side pixels to a compliant server-side pipeline in days, not the multi-month timelines associated with custom build-outs.

Curve does not replace clinical or advertising-compliance review. It closes the technical gap that turns a compliant ad campaign into a HIPAA violation in the browser.

Don't Wait for Enforcement

Every day without compliant tracking is a day of risk exposure. Schedule a Compliance Assessment with Curve.

Compliance Self-Assessment Checklist

  • FDA misbranding: Do any ads imply "sameness," "generic," or FDA approval of a compounded GLP-1?
  • State pharmacy boards: Have you mapped advertising and shipping rules in every state where your pharmacy partner dispenses, with special attention to Mississippi, New Jersey, Oregon, California, North Carolina, and West Virginia?
  • State medical boards: Does your telehealth modality (live video vs. asynchronous) satisfy the rules of every state where patients are located?
  • Off-label restrictions: Are you advertising weight-loss indications in states that restrict off-label weight-loss prescribing of compounded products?
  • Tracking technologies: Have you inventoried every pixel, tag, and analytics script on patient-facing pages?
  • BAAs: Does every vendor receiving data have a signed BAA, or is data being de-identified by a BAA-covered intermediary first?
  • Accreditation: Does your pharmacy partner hold relevant accreditations, and is your ad placement consistent with platform requirements?
  • Contracts: Do your telehealth-pharmacy contracts allocate advertising responsibility, indemnification, and audit rights?
  • Documentation: Do you have audit-ready logs of tracking configurations, data flows, and ad-copy approvals?

Frequently Asked Questions

What are the penalties for HIPAA marketing violations?

HIPAA civil monetary penalties are tiered and inflation-adjusted, with per-violation amounts and annual caps per category. OCR closed 22 enforcement actions in 2024 totaling more than $9.9 million, including a $4,750,000 Montefiore settlement.[2] State AGs add their own penalties; the New York AG imposed $300,000 on New York Presbyterian for pixel use. Class-action settlements have reached the multi-million-dollar range, with MarinHealth paying $3 million in 2025.[5]

Can healthcare practices be sued for using Meta Pixel?

Yes. Putative class actions continue to be filed in state and federal courts under state and federal wiretap statutes and various state statutory and common law theories, even after parts of OCR's tracking-technologies guidance were vacated. Tracking tools may not be used on authenticated webpages such as patient portals unless the disclosure of PHI is permitted by the HIPAA Privacy Rule and a valid business associate agreement is in place or authorizations have been obtained.[4] The risk is acute when pixels are placed on authenticated patient portals or pages capturing intake data.

How do I know if my GLP-1 telehealth marketing is compliant?

You need three reviews: (1) ad-copy review against FDA misbranding standards (no "sameness," no FDA-approval implication, no obscuring of the actual compounder); (2) state-by-state regulatory review against pharmacy and medical board rules in every state where you have patients or pharmacy partners; and (3) a technical review of tracking and analytics data flows for PHI leakage. The FDA has specifically targeted statements implying sameness with approved products and labels that obscure the actual compounder.[1]

What should I do if I discover a compliance violation?

Document the issue, stop the offending data flow or ad immediately, and engage counsel before any external communications. For tracking violations, OCR investigations focus on whether risk analysis, BAAs, and technical safeguards were in place; mitigation evidence affects penalty calculations. For advertising violations, expect to update or remove content, notify affected partners (including compounding pharmacies whose products were referenced), and preserve documentation. Venable LLP notes that compounders and telehealth platforms should ensure labels and online materials accurately identify which party is actually compounding the product and avoid private-label presentations that confuse consumers.[12]

Are state pharmacy board GLP-1 rules really different across all 50 states?

Yes, materially. The New Jersey Board of Pharmacy has explicitly prohibited salt forms of semaglutide in compounding,[6] the Oregon Board of Pharmacy has warned that noncompliant compounding may lead to enforcement action,[9] and Mississippi has taken the further step of telling licensed physicians to refrain from prescribing compounded semaglutide entirely. A single national ad campaign therefore needs jurisdiction-specific copy and routing rules.

Sources

  1. FDA, "FDA Warns 30 Telehealth Companies Against Illegal Marketing of Compounded GLP-1s" (March 3, 2026)
  2. HIPAA Journal, "State of HIPAA"
  3. Covington Inside Privacy, "HHS OCR Updates Tracking Technologies Guidance"
  4. HIPAA Journal, "OCR Drops Appeal in AHA Tracking Technology Case"
  5. HIPAA Journal, "MarinHealth Pays $3 Million to Settle Class Action Meta Pixel Lawsuit"
  6. Frier Levitt, "Prescribing, Compounding and Dispensing Semaglutide for Weight Loss: Pitfalls and Compliance Considerations"
  7. Mississippi Board of Pharmacy, "Semaglutide Compounding Guidance"
  8. Mississippi State Board of Medical Licensure, "Determination & Order: Laura Purdy, M.D." (May 18, 2023)
  9. Oregon Board of Pharmacy, "Position Statements"
  10. FDA, "FDA's Concerns with Unapproved GLP-1 Drugs Used for Weight Loss"
  11. Novo Nordisk, "Novo Nordisk expands legal action to protect US patients from unsafe, non-FDA-approved compounded 'semaglutide'" (August 5, 2025)
  12. Venable LLP, "FDA's Latest GLP-1 Crackdown: What Compounders and Telehealth Platforms Need to Know" (March 2026)

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit