Operations

Who Owns What on a White-Label Telehealth Platform: Patients, Data, Payments, and Brand

Founders on Reddit have stopped asking which platform has the best features and started asking who owns the patient, the records, the card tokens, the pharmacy contract, and the domain when the relationship ends. Those are the right questions, and most sales pages do not answer them. Here are the five ownership dimensions, what each model gives you, the contract language to demand, and where Turbopills stands.

The question buyers are actually asking

Three threads from one week in September 2026 say it plainly. On r/TeleMedicine (September 16): "i want to actually own the business. like my patients, my merchant account, all of it. not just be some affiliate running traffic for someone else." On r/telehealth (September 17): "who actually owns the patient data? who owns the card tokens? do you pay per patient or flat? these things matter alot when ur trying to build something sellable." And on r/TeleMedicine again (September 14), a founder choosing between building a TRT backend and buying one: "dont know if you actually own ur stuff or if they lock u in."

The short answer is that "white label" now covers three different ownership structures, and the label on the sales page will not tell you which one you are buying. There are five things a telehealth business owns or rents: the clinical entity that treats patients, the patient relationship and records, the payment relationship, the pharmacy contracts, and the brand with everything attached to it. Each one has a contract clause that decides it. This post goes through all five, and we state our own position at the end, because a vendor that will not is telling you the answer.


The five dimensions

WhatAffiliate-style turnkeyPlatform under your brandSelf-assembled stackWhat to demand in writing
Clinical entity (the PC)Platform's PC treats the patient; you marketYour PC, or a structure set up with your counsel, with providers routed by the platformYour PC, your cliniciansWho owns the professional entity in each state, and who is medical director
Patient relationship and recordsPatient is the platform's; you may see a dashboardPatient is yours; records exportable in structured formYoursExport format, timeline and cost at termination; API access today
PaymentsPlatform is merchant of record; you are paid a commission or spreadYour gateway accounts; platform runs billing logic on themYour processorMerchant of record; token portability; who carries reserves and chargeback history
Pharmacy contractsPlatform's pharmacy, platform's marginIntegrated network, your choice of pharmacy where offeredYour contractsWhether you can add or switch a pharmacy without a services engagement; any exclusivity
Brand and storefrontCo-branded page on their clinicYour domain, your brand kit, your product catalogYour codeDomain and trademark ownership; what happens to the storefront and configuration on exit

None of the three is wrong. The affiliate model is the right choice for a creator who wants a revenue line and zero operations, and the vendors who sell it (Karpa's affiliate tier is free) are honest about it. The trouble starts when a founder who wants to build a company buys the first model thinking it is the second.


The clinical entity decides everything downstream

Under HIPAA, patient records belong to the covered entity that delivered care. If a platform's professional corporation treats your patients, the chart is legally that PC's chart, the patient is that PC's patient, and any "you own your data" promise on the website is describing a dashboard, not ownership. There is nothing scandalous in that; medicine is regulated that way. It just means the first question in every evaluation is who owns the professional entity in the states you serve.

Most non-clinician founders answer that with a management services organization and a friendly PC, a structure we explained in the MSO and friendly-PC model post: a licensed physician owns the PC, the founder's company owns the brand, technology and business assets, and a management agreement links them. A platform can route cases to licensed providers, supply a network, and run the workflow, but it cannot replace that structure, and a vendor that implies it can is selling the affiliate model with different words. A September 13 post from a physician staffing operator on Reddit put the diligence questions well: who owns the professional entity in each state, which physician is licensed there, who supervises the NP or PA, who does chart review.


Patients and records: exportable, or just visible

"Your data is available on request" is the phrase to watch for. Ask instead what a full export contains (patients, charts, orders, subscriptions, messages, consents), in what format (structured data, not PDFs), how long it takes, and what it costs at termination. Then ask whether you can read the same data programmatically today, because a vendor with a real API has already answered the export question; the data is yours to pull whenever you want. The data ownership question list has the full set.

Records are half of it. The other half is the relationship: can you email and text your patients under your brand, from your systems, with your consent language, or does every touch go through the platform's messaging with the platform's name on it. That is the difference between a patient base you can retain and a patient base you are borrowing, and it is also the difference between a funnel you own and one that lives inside someone else's account, which we wrote about in first-party conversion infrastructure.


Payments: merchant of record, tokens, and the history you cannot move

The merchant of record is the business whose name is on the card statement and whose account the processor underwrites. When the platform is merchant of record, three things follow. Your revenue flows through their account before it reaches you, on their settlement schedule. Their underwriting, reserves and chargeback ratio govern your business; if their VAMP ratio crosses Visa's 1.5% threshold, in effect since April 1, 2026, every merchant under that account feels it. And the card tokens belong to their processor relationship, not yours.

When the merchant account is yours, the platform runs billing logic on your gateway (Stripe, Authorize.net, Square, whichever you were approved for) and the tokens, the reserves, the dispute history and the settlement terms stay with you. That is harder at the start, because you have to pass underwriting in a restricted category yourself; Stripe's May 13, 2026 restricted-businesses page lists telemedicine, online pharmacies and card-not-present prescription products as requiring approval, and passing processor review covers how. It is worth the effort, because a buyer of your company will want the payment history to come with it, and stored payment credentials can be migrated between processors only by the account holder who owns them.


Pharmacy: the contract with the most margin hidden in it

Ask three questions. Whose account is the pharmacy relationship on, and could you keep it if you left the platform. Is there an exclusivity clause, on either side. And where does the medication margin go: Cuvo publishes a 0% markup, Karpa says pass-through at cost, several vendors say nothing, and question 40 of the demo scorecard exists because "do you make money on pharmacy margin beyond the platform fee" is the question vendors most often answer with a change of subject. Pharmacy routing architecture explains why the ability to add or switch a pharmacy without a services project matters more than which pharmacies are on the logo wall.


Brand: the domain, the trademark, the configuration

Brand ownership is the easy one to check and the easy one to forget. Whose name is on the domain registration. Is the storefront on your domain or on a subdomain of theirs. If you leave, does the product catalog, intake configuration, pricing and content leave with you in a usable form, or does it evaporate with the login. The trademark question sounds paranoid until an acquirer's counsel asks it.


What makes the business sellable

Acquirers in this category pay for cohort data (retention curves by month, not subscriber counts), owned payment relationships, structured records that migrate cleanly, transferable pharmacy and clinician arrangements, and a brand that is actually yours. Every one of those maps to a row in the table above. The Hacker News thread on the Medvi story in April 2026 made the point from the other direction, describing a brand assembled from rented services as "vulnerable to their service providers stealing the business out from under them." That risk is a contract structure, and you choose it on the day you sign.


Where Turbopills stands

We build a platform under your brand, so read this as a position to verify rather than a neutral summary. The storefront runs on your domain with your brand kit and your product catalog. Billing runs on your own gateway accounts, so you are the merchant of record and the tokens, history and settlements are yours. Your data is readable through the GraphQL API today, not only at termination. Cases route to licensed providers through state-aware routing, and the clinical entity structure for your program is set up with your counsel; ask us in the demo exactly how the PC, the providers and the platform relate in your states, because that answer depends on your setup, not on a slide. Pharmacy is an integrated network with live order status, and the demo is where you should test how adding or switching one actually works.

Where a founder wants the affiliate model, we are the wrong fit, and we will say so. Our interest is the founder who plans to sell the company one day and wants the ownership questions settled on day one, because unwinding them later is what the migration playbook is about.


FAQ

Who owns patient data on a white-label telehealth platform? Legally, the covered entity that delivered care owns the medical record. If the platform's professional corporation treats your patients, the records are that entity's, whatever the dashboard says. If your own PC (or a structure set up with your counsel) delivers care, the records are yours and the platform is a business associate holding them for you. Ask who owns the professional entity in each state before asking about data export.

What is a merchant of record in telehealth? The business whose name appears on the card statement and whose account the processor underwrites. When the platform is merchant of record, your revenue flows through its account and its reserves, chargeback ratio and settlement terms govern you. When you hold the merchant account, the platform runs billing on your gateway and the payment relationship, tokens and history are yours.

Can I take my patients with me if I leave a platform? Only if the patients are yours to begin with (your clinical entity), the records export in structured form, and the payment credentials sit in a processor account you own. Get the export format, timeline and cost in writing before signing, and confirm you can read your data through an API while you are still a customer.

Do I need a medical license to use a white-label telehealth platform? No, but someone licensed has to own the clinical entity. Non-clinician founders typically use a management services organization with a physician-owned professional corporation; the platform supplies workflow and providers, not the legal structure.

More from Operations

Operations

Patient-Reported Outcomes in DTC Telehealth: How to Collect PROs Without Breaking Conversion or Trust

Patient-reported outcomes are moving from research artifact to table stakes in DTC telehealth. The FDA's late-2025 real-world evidence guidance, ICH M14 adoption in March 2026, and rising payer and employer demand all point in the same direction. Brands that collect PROs cleanly can defend clinical claims, win partnerships, retain patients longer, and tell a better story. Brands that turn the patient portal into a survey form will damage both conversion and trust.

Read post
Operations

Side-Effect Triage and Adverse-Event Workflows: The Safety Layer That Builds Trust

GLP-1 medication errors are exploding in FDA data, adverse-event counts tied to compounded semaglutide and tirzepatide keep climbing, and FDA warning letters have hit telehealth marketing twice this year. Regulators are now reading DTC programs through a safety lens, and so are patients. The programs that treat side-effect triage as core infrastructure, not a support afterthought, will churn less, spend less on support, and look better in every review and AI answer written about them. Here is how to build that layer.

Read post
Operations

Build vs. Buy a Telehealth Platform in 2026: How the Two-Person Telehealth Company Changed the Answer

The build-vs-buy question is the first infrastructure decision every telehealth founder makes, and the answer changed in 2026. Tiny teams are launching national telehealth brands by treating every dependency as a service instead of a hire: licensed providers, pharmacy fulfillment, compliance scaffolding, and the platform itself. This is the honest decision framework for founders weighing a custom build against modern white-label infrastructure.

Read post