Compliance requirements and a seamless patient experience are not opposing forces, even if they're often treated that way. In episode 2 of our Protecting Your Business series, LegitScript sits down with Nick Mortek of Vouched and Steve Sood of Wizlo to walk through what a well-built onboarding stack actually looks like, from identity verification and consent to the gaps that quietly put growing telehealth businesses at risk.
Episode #2: Compliance and the Customer Experience
Transcript
David (LegitScript): Welcome everyone to our Protecting Your Business series, which features experts from LegitScript and our compliance collective partners to help health care, telehealth, and addiction treatment operators navigate a successful business beyond certification from increasing conversions and onboarding to filling in compliance gaps that aren't always obvious.
Each episode tackles a real operational issue and shows what it takes to manage it. Today, we are talking about compliance and the patient experience and how the two don't necessarily conflict with each other as some might think. I'm David Khalaf. And for this episode, we're happy to welcome Nick Mortek, Strategic Accounts at Vouched. Vouched verifies patient identities during registration and prescription fulfillment, catching scams and stolen identities in seconds so providers can stay HIPAA compliant while cutting wait times and reducing fraud tied to prescription abuse.
Also, Steve Sood, CEO of Wizlow. Wizlow is a white label telehealth platform that gives digital clinics everything they need under one roof, including EMR, intakes, pharmacy fulfillment, payments, and a nationwide provider network so they can launch branded care programs in days instead of months.
And, of course, Naomi Moono, our Director of Strategy for LegitScript Certification, which gives businesses in highly regulated industries a way to prove legitimacy to major online platforms and major payment processors, opening doors to advertising and payment access so that they can grow their businesses.
So in our last talk, we talked about drop off impatience at onboarding. We got into the topic of friction and issues that arise from that, which come in the context of compliance. And we wanted to talk a bit today about compliance and the patient experience and how they're not necessarily opposing forces, forces, and how the operators who build for both simultaneously are the ones who are setting themselves up for success. So we're hoping to give some practical advice and walk through what a good onboarding stack looks like and how you can both meet compliance requirements and also have a great patient experience.
Nick, let's kick it off with you.
Beforehand, in a previous episode, we had talked about this false assumption that all friction is bad. There's another assumption that businesses might make, which is that maintaining compliance and maintaining a good customer experience are at opposite ends of a spectrum. Is that true?
Nick (Vouched): No. Absolutely not. Good question, David. So in terms of maintaining a good customer experience, I think in the last episode, we hit on this. But it's always important to make sure that in that patient experience that the right level of friction is applied when it comes to patient verification so that the patient feels comfortable with the service or the prescription they're getting access to.
You wanna feel that you can trust the brand that you're buying from.
You wanna know that, you know, not only that it is legit script certified that or that you're having a good experience on the platform that Wizzlo might offer. But you also wanna understand that you're getting asked questions that assure that you are who you say you are, you're the age that you are, you're in the location that you are.
Because you too want to buy from a brand that's trustworthy and not selling to minors or providing duplicate prescriptions. You wanna make sure that you're buying from a compliant brand.
David: Yeah. Steve, how about you talking if compliance and the patient experience are not mutually exclusive, how can compliance fit seamlessly into a patient's experience? And, you know, can it even enhance the experience somehow?
Steve (Wizlo): 100%. It’s a great question. I'm a big, big fan of saying, you know, compliance, you can actually use it to get ahead, especially from a patient experience. If you let them know, hey, every pharmacy that we work with is not only LegitScript certified, but we use Vouched to verify everybody. But that whole patient experience from the minute they come in to when they get the medication to even the, you know, the experience after making sure they're able to talk to the doctor's network whenever they need to, customer support whenever they need to. That experience is what customers want, especially when you know, a lot of these guys are going on medications to where they've never tried it before.
And if you're injecting something into yourself, you wanna make sure every piece that touches it, you know, by the time you get your medication is above board, and more importantly, they follow compliance. So, yes, I think it's a massive, massive piece. It's something that we actually advise. Like, for example, with LegitScript, we tell our clients like, hey, when you get LegitScript, go plaster that all over your social media. Like, my oh goodness. We're LegitScript certified. We just had a company do it, and they were so excited.
They're like, “Can we do a whole post on social media that we're LegitScript certified? I was like, “Yes! Go do that!”
Because when your clients see that, they're gonna be extremely happy and the ones that do know what it is, they go look it up that you're doing things the right way.
David: Good point. Yep.
Let's talk a bit about some of the essential layers of compliance in onboarding. So there are lots of layers to a business' onboarding stack, but I wanna zero in on a couple. Let's start with identity verification.
Naomi, it might seem obvious, but one of the core requirements for telehealth companies is to verify the identity of the patients.
Why is that so important?
Naomi (LegitScript): Yeah. And to your point, David, it might seem obvious at the surface, but it really is one of the most important areas telehealth companies have to get right, and it's backed by real regulatory weight across both federal and state law. So in The United States, specifically, there's a range of applicable federal and state laws and regulations that require telehealth providers, as an example, to establish a valid verifiable patient-provider relationship before, prescribing or dispensing medication. So identity verification is really one of the core parts of that process that makes the relationship legitimate.
And it exists for really valid reasons. It’s looking to prevent fraud, abuse and misuse to ensure that the person that is receiving care and the medication is ultimately who they say they are, that we have verified that. But on the other hand, I also think that the answer goes beyond any single federal or state or local regulation. I think knowing who a patient actually is matters beyond that legal requirement because it's foundational to operating a business that patients and platforms can trust. I think organizations that take identity verification seriously aren't always necessarily doing it just because laws and regulations are kind of forcing their hand and saying you have to do this to be compliant and to operate, but they're also doing it because it protects everything that they've built, honestly, their relationship with patients, their relationships with payment processors, and with advertising platforms, their ability to operate longer term in an industry where a huge part of the products and services they offer is about trust.
It's about legitimacy, and identifying verification plays a really big role in that.
David: I'm curious a little bit about what identity identity verification looks like today because it is not what it looked like ten or fifteen years ago, probably not even what it looked like a few years ago. Nick, what does modern identity verification look like these days?
Nick: Sure. I think it's, you know, making sure for the service or the drug that you're prescribing, that you're applying the right level of verification in terms of the risk profile of the use case, or the prescription that you're providing, number one. Number two, it's layering on verification steps given the risk profile. So you might start with a PII risk assessment for somebody that's onboarding as a new patient to your platform, which is simply taking things like full name, address, email, phone number, IP address, triangling that information with Vouched of 200 different data sources to come back on a decision on whether that person looks like who they say they are.
And that might be the first step in verification. And now they let's say, two months later, they are looking to get an actual controlled substance from the brand or the telehealth brand, they might now need to go through a higher level of verification. And that might come in the form of, Social Security number check or a date of birth check or an actual visual ID verification check. So it's it's stepping up based off of the level of friction that you need to apply or the level of risk profile that the use case or workflow has, applying that appropriately so that, again, you have the audit trail so that you're able to provide that in the case that anything might come up and, you know, the government or the DEA might come looking or knocking to to understand whether you're following the rules.
David: Let's talk about another, important layer of that compliance onboarding stack, which is consent and intake. Naomi, once a patient's identity is verified, the next critical step is consent, but consent is about what exactly and why?
Naomi: Yes, exactly right. Consent is kind of that next layer of trust and how we're thinking about that.
And I would say it covers a lot more ground than most people think. At the foundational level, we're talking about informed consent to treatment. So making sure that a patient understands the nature of the care they're receiving, the risks involved, and that they're agreeing to be treated specifically through, for example, a telehealth model. Many states do have their own telehealth specific laws and regulations, specifically related to consent requirements on top of any general informed consent standards, really precisely because remote care introduces considerations that don't always exist when you're thinking about in person visits.
But I think beyond the treatment itself, there's also consent tied to how personal health information is used and financial consent around billing and payment. So just a lot of consent considerations to take into consideration when you're getting health through specifically a telehealth model. But, again, similar to that last component that we talked about, taking a step back from those specific technical requirements that are checking that box, I think consent also really functions as a transparency signal. Right?
Patients who clearly understand what they're agreeing to and, very importantly, you know, why are far more likely to trust the organization that they're entering that relationship into, that care relationship. And it's one of the clearest moments where business can either build that confidence or create doubt, depending on how clearly the information is presented when you're thinking about consent.
David: Nick, I'm curious from your side if you have anything to add, particularly in regard to how consent and identity verification work together.
Nick: Yeah. I think that, obviously, you need to be sure that through your terms and your EULA that you're obviously advising your patients in terms of how you're going about verification.
You know, the other thing that I've been thinking about is not only you do you need to be aware of what might have, what might happen reactively from your patient verification from a government perspective or state perspective, but what might happen from an advertising or payment perspective. And I think Steve can hit on this a little bit better because he sees it more often than I do. But you have to be aware of the fact that there are penalties that come in the form that are not just from the law enforcement or the government. There can be penalties from a business perspective. Steve, you wanna hit on that or comment on that?
Steve: Yeah. I would love to. Consent goes a multitude of ways as now we get on as well. There's obviously the medical side where you wanna make sure, you know, where first, the consents are dialed in in a sense of where is the messaging going?
Is it medical or nonmedical? And then it goes beyond that, like Nick mentioned as well, where, you know, on a payment standpoint, say, you have someone in subscriptions and, you know, you guys can Google. There's massive FTC issues going on with some telehealth companies for this specifically. I'm not gonna name any names, but you can look it up.
But, you know, you wanna make sure that if you have someone in a subscription, that you have their consent and it's in a compliant subscription where when you're doing these medications, GLPs, for example, every three months, they need to have a new doctor's visit. So you can't just keep charging them over and over and over unless they've had that doctor's visit and they haven't had those medications. So it goes a long way to knowing the laws, and that's the difference of companies that, you know, you could have the FTC or the state boards or whoever knocking on your door or the opposite, and you can use it to get ahead.
David: Steve, is there any way that the experience can be more patient friendly when it comes to consent?
Steve: Yeah. Let's talk about, you know, subscriptions, for example. You wanna make sure that the patients and we use a lot of AI to help guide this through our patient journey as well. So when they log in within the patient portal, if they wanna pause their subscriptions or they haven't completed their, you know, encounter, which encounters a doctor's visit for their next refills.
It's things like that, you know, that there are steps to where they can pause it, and reactivate their subscription. It's and it's clearly outlined versus trying to hide it. Because a lot of people do that because they're like, oh, we don't want the customer to fall off. Well, that's not compliant, number one.
And it's going you know, it raises the whole thing about consent in general, and that's where you get in trouble. So we do the exact opposite, and we make sure that the customer and patient always have a clear outline for anything that they wanna do within their portal.
David: That's a great example.
I want to end today's conversation with some of the common pitfalls that all of you see in your work and why some of these missteps, you know, might be more avoidable than folks think.
Naomi, let's start with you. Let's talk about some of the common problems that you see. Some telehealth operators build a business and then think to integrate compliance into it later on, but that's problematic in a lot of ways, isn't it?
Naomi: Yes. It is absolutely problematic.
And I just have this conversation so often because it's just something that we really commonly see. Compliance is kind of an afterthought. Let's get this business up and running. Let's get patients, then let's think about certification.
Let's make sure we're operating in alignment with applicable laws and regulations after. And, obviously, it doesn't even sound right when I say it. Right? It's a really critical foundation to building your business, not an afterthought.
But in saying that, a lot of operators build their business with conversion speed as a priority. So optimizing onboarding to get patients through the funnel as quickly as possible and then, like I said, kind of treat compliance as something to layer in afterwards. But the one of the core problems with that, there's quite a few, is that a lot of times by the time they kind of go back and look to integrate compliance, they're not just adding in a feature. They're offering to discover critical gaps in their foundation that's already been built.
And retrofitting compliance back into an existing structure is 10 times harder and a lot riskier than building it from the start. And so that's really why compliance, it can't be an afterthought. It has to be the foundation that your entire business is built on. And, actually, payments is one of the clearest places that you can kind of see that play out.
So as an example, any merchant processing card not present transactions for prescription medication under pharmacy related merchant category codes for Visa and Mastercard operate under their high risk merchant frameworks. So acquirers are required to properly classify and oversee those merchants. And if they don't, they can face significant fines as we were talking about. And sometimes those fines can be 6 figures per transaction.
LegitScript certification is recognized by Visa and Mastercard as a white a way to help satisfy those requirements, and that's why there're a lot of payment processors and acquirers that actually require certification before they onboard merchants into their ecosystem. And the reason that they do that is that they don't want merchants that are treating compliance as an afterthought. They want merchants that have already prioritized demonstrating that compliance because those merchants have demonstrated compliance with applicable laws and regulations. And so they're gonna bring about a lot less risk to onboarding in their ecosystem than a merchant that has treated compliance as an afterthought, and it's not the foundation that their business is built on.
David: I like that metaphor you use of a building and creating a good foundation from the beginning rather than trying to fix a broken foundation later because that's very difficult to do.
Nick, what about you? When platforms or telehealth companies come to you for help, what are some of the gaps that they commonly have in their process?
Nick: Yeah. I think that, you know, you don't need to think that being more compliant or providing more patient verification is gonna come at the cost of less conversion. In fact, I would encourage you to talk to somebody like Steve or myself about your current patient verification funnel if you haven't already done so because I would bet that by becoming more compliant in leveraging us, we might actually be able to cover the cost through the ROI of providing a better experience to for the customer. So it never hurts to just take a look at what you're doing today with your funnel and your workflows to see how you might be able to improve it.
It doesn't take long, and we can determine if there's ways that we can improve it and if it might actually help you become more compliant and offer a better experience for your patients.
David: Good point. Steve, what about you?
Steve: Yeah. You know, right now, I feel like we live in a Wawa West Sage where you have, you know, this side, which I'm gonna label as Wawa West, where you have 16 year olds on TikTok selling red or true type. That's research only. Right?
And then you have the other side, which is us, which is, you know, doctor prescribed, legit script certified using vouch, you know, companies. And its compliance is the most important thing. I cannot touch on it enough, especially when you're dealing with these medications. And when you really, you know, take a grasp of compliance and use that to get ahead, those are the biggest brands.
Those are the $89.10 figure companies that we deal with versus this side where when you're dealing with, you know, a lot of this stuff that's happening, I mean, people can die. So compliance needs to be the foundation and the biggest pillar within everybody's company that's entering this space.
David: Good advice. Avoiding purchasing unauthorized peptides from teenagers on social media.I feel like that's one to stick in my pocket for future use. Thank you.
Steve, Nick, Naomi, thank you so much for your time, and thank you everyone for watching.
Stay tuned for another protecting your business episode coming up at a later date. Take care.