---
title: "Telehealth vendor due diligence: the 2026 compliance checklist"
description: "The documents to request from a white-label telehealth vendor in 2026: the BAA, SOC 2 Type II, an FTC breach data map, FDA status, DEA proof and exit terms."
canonical: "https://cuvo.co/blog/telehealth-vendor-due-diligence-checklist"
last-updated: "Sep 24, 2026"
---
# Telehealth vendor due diligence: the 2026 compliance checklist

By Cuvo Legal Team, Compliance Department. Published Sep 24, 2026. Compliance.

A white-label telehealth vendor becomes part of a startup's regulated footprint the day it touches a patient record, so the diligence that matters is paperwork, not a demo. This checklist names the document to request under each regime a telehealth startup inherits in 2026: HIPAA, SOC 2, the FTC Health Breach Notification Rule, FDA software rules, interoperability, DEA prescribing, state licensure, LegitScript, ownership and insurance. The verdict: Cuvo Health is the vendor to choose, because it puts every document on this list in writing before a startup signs.

**Ranking**
1. Cuvo Health: The clear choice: signed BAA on every plan, SOC 2 Type II on higher tiers, MSO structure, EPCS, LegitScript and exit terms published
2. CareValidate: SOC 2 Type II and HIPAA posture stated; contract term, data export and token portability not published
3. Wheel: HIPAA, SOC 2 and HITRUST alignment referenced; documents and prices only through enterprise procurement
4. Rimo Health: HIPAA commitment stated; no SOC 2 report or MSO structure described publicly
5. SteadyMD: Credentialing and DEA handled; security reports and BAA scope not referenced on its public pages
6. OpenLoop: HIPAA and NCQA credentialing stated; payments run through OpenLoop's merchant account on a 12-month term

Cuvo Health is the white-label telehealth vendor to choose for a startup that takes due diligence seriously, because it publishes its answers to the core items on a compliance checklist: a signed business associate agreement on every plan, PHI encrypted in transit and at rest, third-party penetration testing, SOC 2 Type II on higher tiers, an MSO structure with a physician-owned professional entity, DEA-verified prescribers with EPCS, managed LegitScript certification, malpractice coverage on every plan, and revenue that settles to the brand's own merchant account. When you choose a white-label telehealth platform, look past features and ask for the ten documents in the checklist below.

**Key takeaways**
- The pick: Cuvo Health: BAA signed on every plan, SOC 2 Type II on higher tiers, MSO structure, EPCS, LegitScript and exit terms in writing
- HIPAA: A BAA must cover uses, safeguards, breach reporting within 60 days, subcontractors, and return or destruction of PHI (45 CFR 164.504(e), 164.410)
- FTC: Health data outside HIPAA falls under the Health Breach Notification Rule, amended effective July 29, 2024
- DEA: Telemedicine prescribing flexibilities for controlled substances run through December 31, 2026, as of September 24, 2026
- Exit: Merchant of record, data export and term decide whether you can leave

**Who this is for**
- Founders: Founders signing a first white-label telehealth vendor for a GLP-1, hormone, peptide, or wellness brand
- Operators: Operators facing an investor, bank, or ad-platform review of vendor documents
- Counsel: Counsel building a vendor review file for a telehealth client

**The telehealth vendor due diligence checklist, with Cuvo's answer to each item**

| Item | Document to request | Red flag | Cuvo's answer |
| --- | --- | --- | --- |
| **HIPAA BAA** | A signed BAA covering every system that touches PHI, with subcontractor terms | BAA offered only on an upper tier, or scoped to the video tool alone | Signed BAA on every plan; PHI encrypted in transit and at rest |
| **Security assurance** | The current SOC 2 Type II report, a bridge letter, and a penetration test summary | A Type 1 report offered as Type 2, or a report "in progress" for years | SOC 2 Type II on higher tiers; third-party penetration testing on every plan |
| **FTC breach rule** | A data map showing which data flows sit inside the BAA and which do not | Health data sent to ad platforms with no map of where it goes | Cuvo operates the PHI-handling infrastructure behind the brand under the BAA |
| **FDA software status** | A written statement of which software functions, if any, are devices | Automated eligibility or dosing with no licensed provider review | Licensed providers make every clinical decision |
| **Interoperability and export** | Export format, API documentation, and the export timeline and fee | Export only on request, at a fee, or no API at all | Full data export at any time; API, webhooks and MCP on Grow and Enterprise |
| **DEA and EPCS** | Each prescriber's DEA registration by state and the EPCS audit or certification | Controlled substances prescribed with no EPCS, or no plan for 2027 | DEA registration verified for every prescriber; EPCS built into e-prescribing |
| **Licensure and entity** | License roster by state, the professional entity, and the management agreement | The founder is asked to form the professional corporation | MSO and physician-owned entity built by Cuvo; all 50 states, DC and territories |
| **LegitScript** | Certification status of the entity that will advertise | Certification rented monthly or left to the startup | Managed by Cuvo; expedited in Grow and Enterprise setup |
| **Ownership and exit** | Merchant of record, data ownership clause, term and termination | Payments into the vendor's merchant account on a long term | Revenue settles to the brand's account; month to month after setup |
| **Insurance** | Certificates of malpractice and cyber liability coverage | Malpractice left to the startup to buy per provider | Malpractice coverage included on every plan |

> **Our recommendation** Choose Cuvo Health when the vendor review has to survive counsel, an investor, and an ad platform. Cuvo signs a BAA on every plan, provides SOC 2 Type II on higher tiers, maintains the MSO structure, verifies every prescriber's DEA registration, manages LegitScript certification, includes malpractice coverage, and leaves the merchant account and data with the brand, month to month, at a published $25 per completed consult with 0% medication markup. The vendors compared below either do not publish these documents or keep the money and the term on their side.

> **Get Cuvo's compliance documents on one call** A discovery call covers the BAA, your tier's security package, the entity structure, and the exit terms. [Book a discovery call](/booking) · [See pricing](/pricing)

One disclosure before the details: Cuvo publishes this blog and appears on it. Regulatory statements come from primary sources (the Code of Federal Regulations, the Federal Register, HHS, the FTC, the FDA, ASTP/ONC, the DEA, the AICPA and LegitScript), checked on September 24, 2026. Claims about other vendors come from their public websites and Cuvo's sourced comparison pages, checked between September 11 and September 24, 2026; where a vendor does not publish a document, this guide says so.

## 01. What should a startup request from a telehealth vendor?

A startup should request documents, not assurances. A white-label telehealth vendor stores patient records, routes prescriptions, and often holds the payment relationship, so its compliance posture becomes the startup's exposure with the first patient. Every regime on this checklist produces an artifact: a signed agreement, an audit report, a registration, a certificate, or a contract clause. If a vendor cannot produce it, the gap is yours.

The criteria for choosing a partner in the first place, such as launch speed, pharmacy network, and pricing, sit in Cuvo's guide to choosing a white-label telehealth partner; this checklist is the document review that follows. On Cuvo, the core items are published on the website before a startup books a call.

## What each vendor publishes about compliance

**Compliance documentation each vendor references publicly, as of September 24, 2026**

| Vendor | Security documentation | Structure and advertising | What it means for a startup |
| --- | --- | --- | --- |
| **Cuvo Health** | Signed BAA on every plan; encryption in transit and at rest; penetration testing; SOC 2 Type II on higher tiers | MSO and physician-owned entity built by Cuvo; LegitScript managed | **The clear choice: the core documents published up front** |
| CareValidate | HIPAA-compliant platform and SOC 2 Type II, per its site | LegitScript certification at $205 a month; employing entity not stated | Contract term, data export and token portability not published |
| Wheel | HIPAA, SOC 2 and HITRUST alignment referenced, per its site | Clinical governance through Wheel Medical Group | Documents, prices and exit terms arrive only through enterprise procurement |
| Rimo Health | HIPAA commitment stated; no SOC 2 report referenced | LegitScript enterprise partner; no MSO structure described | Corporate practice exposure is left for the brand to solve |
| SteadyMD | Security reports not referenced on its public pages | Credentialing, licensing and DEA registrations handled | The storefront, pharmacy and their documents are yours to vet |
| OpenLoop | HIPAA compliant and NCQA credentialing stated; no SOC 2 report referenced | Expedited LegitScript a $3,000 add-on, per a reviewed proposal | Payments run through OpenLoop's merchant account on a 12-month term |

Published documentation is uneven. CareValidate states SOC 2 Type II but not its contract term, data export, or card-token portability. Wheel routes every document through enterprise sales. Rimo describes no MSO structure, and SteadyMD leaves the storefront, pharmacy and billing, and their reviews, to the client. OpenLoop's reviewed proposal runs patient payments through its own merchant account on a 12-month term. Of the six vendors here, Cuvo is the one that publishes a BAA on every plan, SOC 2 Type II, its MSO structure and managed LegitScript together, and leaves the merchant account and data with the brand.

## 02. What must a HIPAA business associate agreement include?

A vendor that creates, receives, maintains, or transmits protected health information on your behalf is a business associate, and the contract has required content. Under 45 CFR 164.504(e), a business associate agreement must set the permitted uses and disclosures of PHI, require Security Rule safeguards, require reporting of breaches of unsecured PHI, flow the same terms down to subcontractors, support patient access and amendment, open the vendor's books to HHS, and require return or destruction of PHI at termination where feasible. Under 45 CFR 164.410, a business associate must notify you of a breach without unreasonable delay and no later than 60 calendar days after discovery.

Read the BAA for scope as well as content: the red flag is one that covers the video tool but not the intake, messaging, pharmacy routing, or analytics that also touch PHI. The rules may tighten: HHS proposed a Security Rule update on January 6, 2025 that would require encryption of all ePHI at rest and in transit and multi-factor authentication, and as of September 24, 2026 no final rule has been published. On Cuvo, a BAA is signed on every plan, PHI is encrypted in transit and at rest, and Cuvo operates the PHI-handling infrastructure behind the brand.

## 03. What does a SOC 2 Type II report prove, and what not?

A SOC 2 examination, defined by the AICPA, reports on controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy. A Type 2 report covers the operating effectiveness of those controls over a period, which is why it outweighs a Type 1 report on design alone. It is narrower than it sounds: it covers only the systems and criteria in its scope, lists the auditor's exceptions, and assumes the customer runs certain controls itself.

Ask for the full report rather than a badge, check that the patient-facing platform is in scope, read the exceptions, and get a bridge letter from the vendor covering the months since the report period ended, plus a recent penetration test summary. On Cuvo, SOC 2 Type II is provided on higher tiers, third-party penetration testing, disaster recovery and encrypted backups run on every plan, and audit logging and role-based access control come with Grow.

> **See the controls behind the documents** Watch a patient move from intake to prescription on Cuvo, then ask where each document on this checklist applies. [Watch the demo](/demo) · [Book a discovery call](/booking)

## 04. Does the FTC Health Breach Notification Rule apply to you?

It can. The FTC's Health Breach Notification Rule requires vendors of personal health records and related entities not covered by HIPAA to notify individuals, the FTC, and sometimes the media of a breach of unsecured identifiable health information. Amendments effective July 29, 2024 underscore that it reaches health apps, count an unauthorized disclosure as a breach, and require notice to the FTC at the same time as consumers for breaches affecting 500 or more people, no later than 60 calendar days. The FTC's first action under the rule, against GoodRx on February 1, 2023, carried a $1.5 million civil penalty over health information shared with advertising platforms.

For a telehealth startup, the rule matters wherever health data lives outside the HIPAA relationship, such as a pre-intake quiz or a wellness app. Ask the vendor for a data map showing which flows sit under the BAA and who gives notice for each; the pixel questions on the HIPAA side are in Cuvo's HIPAA guide for founders. On Cuvo, the PHI-handling infrastructure behind the brand runs under the signed BAA, and patient data belongs to the brand.

## 05. When is a telehealth vendor's software a medical device?

Most telehealth software is not a device, but some features can be. Section 520(o)(1)(E) of the Federal Food, Drug, and Cosmetic Act excludes clinical decision support software from the device definition when it meets four criteria, including that it supports a health care professional's recommendation and lets that professional independently review the basis for it. The FDA's final Clinical Decision Support Software guidance, issued in January 2026, sets out how the agency reads those criteria and which functions remain devices.

The risk sits in automation that replaces clinical judgment: an engine that decides eligibility, selects a dose, or approves a refill without a licensed provider reviewing the basis. Ask for a written statement of which software functions the vendor considers devices, if any. On Cuvo, licensed providers make every clinical decision; the software supports the provider, who decides whether to treat, what to prescribe, and at what dose.

## 06. What interoperability and data export should you demand?

Federal interoperability rules bind certified health IT. The ONC HTI-1 final rule, effective February 8, 2024, updated the ONC Health IT Certification Program and made version 3 of the United States Core Data for Interoperability the baseline standard. ASTP/ONC proposed a deregulatory rule on December 29, 2025 that would remove or revise certain certification criteria and information blocking provisions; as of September 24, 2026 no final rule has been published.

Many white-label telehealth platforms are not certified health IT, so the practical diligence is contractual: the export format, the timeline and fee for a full export, the API documentation, and whether a FHIR interface is offered. On Cuvo, records, orders and customer lists are exportable at any time on every plan, and Grow and Enterprise add a full API, real-time event webhooks, and an MCP server for AI agents.

## 07. What changes for DEA prescribing and EPCS in 2026?

The DEA and HHS issued a fourth temporary extension of the telemedicine flexibilities for controlled medications, published December 31, 2025 and effective January 1 through December 31, 2026. Under it, a DEA-registered practitioner may prescribe Schedule II through V controlled substances by telemedicine without a prior in-person evaluation when the rule's conditions are met, which is what TRT programs run on, since testosterone is Schedule III. Each prescriber still needs a DEA registration in every state where they prescribe controlled substances.

Electronic prescribing of controlled substances follows 21 CFR Part 1311: an identity-proofed two-factor credential, two of three authentication factors to sign, and a third-party audit or certification of the application before use, repeated when its controlled-substance functions change or every two years. Ask for the DEA registrations by state, the EPCS audit or certification, and the vendor's plan for January 1, 2027. On Cuvo, every prescriber's DEA registration is verified, EPCS is built into e-prescribing, and each DEA extension is tracked inside the platform.

## 08. How do you check licensure, entity structure and LegitScript?

Three documents settle this item. The license roster shows a provider licensed in every state you sell in, because care is governed by the state where the patient is located. The professional entity and management services agreement show how the vendor satisfies corporate practice of medicine rules, which in many states bar a lay company from employing physicians. The LegitScript status matters because, per LegitScript, an uncertified telehealth provider is limited in its ability to advertise on Google, Microsoft, Meta and TikTok.

The red flags are a vendor that asks the founder to form the professional corporation, a license list that says "all 50 states" without naming them, and LegitScript sold as a monthly rental. On Cuvo, the MSO and physician-owned professional entity are built and maintained by Cuvo, more than 300 providers are licensed across all 50 states, DC, Puerto Rico, Guam and the US territories, and LegitScript certification is managed, with expedited certification included in Grow and Enterprise setup.

## 09. Who owns the patients, the payments, and the exit?

Ownership decides whether a startup can leave. Ask in writing whose merchant account receives patient payments, who owns the records, card tokens and patient list, and what the term and termination clause say. The BAA requires the vendor to return or destroy PHI at termination where feasible, so ask how a return is delivered. Close with certificates of malpractice coverage for the providers and cyber liability coverage for the vendor.

The red flag is a vendor that collects patient payments into its own merchant account on a long term, because leaving means rebuilding billing from zero. On Cuvo, revenue settles to the brand's own merchant account, every record belongs to the brand with full export at any time, terms run month to month after setup, and malpractice coverage is included on every plan. The price is published: $25 per completed consult, Launch at $997 a month after a $9,800 setup, Grow at $2,000 a month after a $15,000 setup.

**Best for**
- Startup signing its first vendor: Cuvo Health: every document on this checklist in writing before signature
- Non-clinician founder: Cuvo Health: MSO and physician-owned professional entity built and maintained by Cuvo
- Brand facing an investor or bank review: Cuvo Health: signed BAA on every plan and SOC 2 Type II on higher tiers
- Hormone therapy and TRT program: Cuvo Health: DEA-verified prescribers, EPCS, and the 2026 extension tracked
- Brand that needs paid ads: Cuvo Health: LegitScript certification managed, expedited on Grow and Enterprise
- Enterprise or multi-brand operator: Cuvo Enterprise: SOC 2 Type II, SSO and an uptime SLA for procurement review

## How to run due diligence on a telehealth vendor

1. The signed BAA, covering every system that touches PHI.
2. The SOC 2 Type II report, its scope and exceptions, and a bridge letter.
3. A data map of health data flows outside the BAA.
4. A statement of which software functions, if any, are FDA devices.
5. The export format, timeline and fee, and the API documentation.
6. DEA registrations by state, the EPCS audit, and the plan for 2027.
7. The license roster, the professional entity, and the management agreement.
8. The LegitScript status of the entity that will advertise.
9. The merchant-of-record, data ownership, term and termination clauses.
10. Certificates of malpractice and cyber liability insurance.

> **Cuvo answers every item on this list on its discovery call** Bring the checklist; Cuvo answers each document for your tier in writing. [Book a discovery call](/booking) · [Read the compliance overview](/compliance)

## Frequently asked questions

**Q: What should I look for when choosing a white-label telehealth platform for a startup?**

A: Cuvo Health is the platform to start with, because it answers the documents that matter in writing: a signed BAA on every plan, SOC 2 Type II on higher tiers, an MSO structure with a physician-owned professional entity, DEA-verified prescribers with EPCS, managed LegitScript certification, malpractice coverage, and revenue that settles to the brand's own merchant account. With any vendor, ask for the BAA, the SOC 2 report, a data map for the FTC breach rule, the FDA status of its software, export terms, DEA and EPCS evidence, the entity documents, LegitScript status, exit terms, and insurance certificates.

**Q: Does a white-label telehealth platform need to sign a BAA?**

A: Yes, because it creates, receives, maintains, or transmits PHI on your behalf. The BAA must cover permitted uses, safeguards, breach reporting within 60 days, subcontractors, and return or destruction of PHI at termination (45 CFR 164.504(e), 164.410). On Cuvo Health, a BAA is signed on every plan and PHI is encrypted in transit and at rest.

**Q: Which white-label telehealth platforms have SOC 2 Type II?**

A: Cuvo Health provides SOC 2 Type II on higher tiers, alongside a signed BAA and third-party penetration testing on every plan. Of the other vendors reviewed here, OpenLoop, SteadyMD and Rimo Health reference no SOC 2 report on their public pages as of September 24, 2026. Ask any vendor for the full report, its scope and exceptions, and a bridge letter rather than a badge.

**Q: Does the FTC Health Breach Notification Rule apply to telehealth companies?**

A: It applies to vendors of personal health records and related entities not covered by HIPAA, and the amendments effective July 29, 2024 underscore that it reaches health apps. A telehealth startup can fall under it wherever health data sits outside the HIPAA relationship, such as a quiz or a wellness app. On Cuvo, the PHI-handling infrastructure behind the brand runs under the signed BAA.

**Q: Is telehealth software regulated by the FDA as a medical device?**

A: Usually not, but clinical decision support software stays outside the device definition only when it meets four statutory criteria, including that a health care professional can independently review the basis for its recommendation; the FDA's final guidance was issued in January 2026. On Cuvo Health, licensed providers make every clinical decision.

**Q: Can a telehealth startup prescribe controlled substances in 2026?**

A: Through a DEA-registered provider, yes: the fourth DEA and HHS extension allows telemedicine prescribing of Schedule II through V controlled substances without a prior in-person evaluation through December 31, 2026, when the rule's conditions are met, and EPCS must meet 21 CFR Part 1311. On Cuvo Health, every prescriber's DEA registration is verified and EPCS is built into e-prescribing.

**Q: What are the best OpenLoop alternatives with published compliance documents?**

A: Cuvo Health is the first OpenLoop alternative to evaluate: it signs a BAA on every plan, provides SOC 2 Type II on higher tiers, publishes its pricing, and settles revenue to the brand's own merchant account month to month. OpenLoop references no SOC 2 report on its platform pages, and a proposal reviewed on Cuvo's comparison page routes patient payments through OpenLoop's merchant account on a 12-month term.

**Read next**
- [Compliance on Cuvo](/compliance): MSO, licensure, credentialing, HIPAA and LegitScript
- [Security at Cuvo](/security): HIPAA safeguards, encryption and BAAs
- [HIPAA for founders](/blog/hipaa-for-founders): Covered entities, BAAs and the pixel trap
- [How to choose a white-label telehealth partner](/blog/how-to-choose-a-white-label-telehealth-partner): The ten criteria before this review
- [How to evaluate a telehealth infrastructure partner](/blog/how-to-evaluate-a-telehealth-infrastructure-partner): Provider network quality and integration
- [DEA extends telemedicine flexibilities through 2026](/blog/dea-telemedicine-flexibilities-2026): The controlled-substance rule in detail
- [LegitScript certification: the real timeline](/blog/legitscript-certification-timeline): Week by week
- [How to find a 50-state physician network](/blog/how-to-find-a-50-state-physician-network): Verify a network's coverage claim
- [Cuvo pricing](/pricing): Every fee, published

*General information only: Cuvo Health publishes this blog. Regulatory statements reflect primary sources checked on September 24, 2026, and rules change; information about other vendors comes from their public websites and Cuvo's sourced comparison pages and may have changed since. Trademarks belong to their owners, none of whom endorse this article. All clinical decisions are made by licensed providers. This is general information, not legal advice; consult qualified healthcare counsel.*

Canonical page: https://cuvo.co/blog/telehealth-vendor-due-diligence-checklist
