Skip to main content

Verification badges explained

Brands and pharmacies display various verification badges. Not all are equal. Here's what each means + how to verify independently.

LegitScript Certified

LegitScript Healthcare Merchant Certification

Strong signal

What it means: Telehealth provider passes LegitScript's clinical, regulatory, and business operations checks. Most widely-used third-party verification for telehealth.

Issuer: LegitScript (independent monitoring service)

How to verify: Search the brand on legitscript.com/search.

NABP-VPP

National Association of Boards of Pharmacy — Verified Pharmacy Program

Strong signal

What it means: Pharmacy is registered + verified by NABP. Strong signal for pharmacy quality, especially for compounders.

Issuer: NABP

How to verify: nabp.pharmacy/programs/accreditations-inspections

PCAB-Accredited

Pharmacy Compounding Accreditation Board

Strong signal

What it means: Compounding pharmacy passes voluntary third-party accreditation. Stricter than baseline state licensing.

Issuer: PCAB (within ACHC)

How to verify: achc.org/pcab

NAMS-CMP

NAMS Certified Menopause Practitioner

Strong signal

What it means: Clinician passed competency exam in menopause care. Strong signal for menopause + peri specialty.

Issuer: The Menopause Society (formerly NAMS)

How to verify: menopause.org/for-women/find-a-menopause-practitioner

FDA Outsourcing Facility

FDA-registered 503B outsourcing facility

Strong signal

What it means: Pharmacy meets CGMP (current good manufacturing practice) standards. Higher than 503A compounding.

Issuer: FDA

How to verify: fda.gov/drugs/human-drug-compounding/registered-outsourcing-facilities

NCQA Accredited

National Committee for Quality Assurance

Moderate signal

What it means: Health plan or integrated provider meets NCQA quality standards. Relevant for insurance-billing telehealth.

Issuer: NCQA

How to verify: ncqa.org/programs/health-plans/health-plan-accreditation

HIPAA-Compliant

HIPAA-compliant data handling

Weak signal (self-attested)

What it means: Self-attested compliance with HIPAA privacy + security rules. Required for healthcare entities, but self-attested.

Issuer: Self-attestation (not externally verified)

How to verify: No central registry. Look for published HIPAA notice of privacy practices.

SOC 2 Type II

AICPA Service Organization Control 2

Strong signal

What it means: Third-party audit of security, availability, integrity, confidentiality. Strong for tech-heavy telehealth.

Issuer: Certified public accountants (auditors)

How to verify: Request the SOC 2 report directly from the brand (typically available under NDA).

Trust hierarchy

Strong: third-party verified, periodically audited. Moderate: verified but limited scope. Weak: self-attested, no audit. When evaluating a brand, check whether they have strong signals (LegitScript, PCAB, NAMS-CMP) vs only weak ones (HIPAA self-attestation alone).