Regenerative Medicine Marketing Compliance, Built For Growth.
Compliance is how you grow without the risk. Consulting comes first: we check your claims, reviews and patient data. Then we build your marketing inside the rules. It’s for clinics, manufacturers, distributors, labs, stem cell banks, financing companies and even med spas.


Overview
Compliance Is An Advantage, Not A Burden.
Regenerative medicine marketing compliance means everything you put out holds up when someone reads it closely. That’s your site, ads, posts, emails, forms and reviews. The Food and Drug Administration (FDA) has not approved many cell and tissue products for the uses they are sold for. So one word in a heading can turn a careful page into a claim. A lot of businesses say too much, or play it so safe they say nothing. Know where the line is, and you can say the true thing and grow.
The Exposure
Compliance Breaks One Word At A Time.
Compliance almost never breaks on purpose. It slips in with one borrowed line or one rushed fix. A warning letter is the FDA telling a company, in writing, that it sees a significant violation. It’s informal, but it’s public. If it isn’t fixed, it can lead to seizures, injunctions, fines or prosecution. In most of the warning letters we read, the company’s own marketing language is part of the evidence.

A line about what a therapy is being studied for turns into a line about what it treats. It most often happens in a subheading nobody thinks of as copy.
A wall of photos makes the promise your words were careful not to make. The page never claims a result, but every visitor reads one anyway.
Someone got something of value for a review, and it went up with no mention of it. The words are theirs, but the choice to post them is yours.
A form asks about symptoms, illnesses and past procedures before anyone has booked. Every extra box is more data you now have to guard.
A script on a page about a certain condition sends that visit to an outside company. Nobody chose it. It came with the website template.
Old landing pages, retired ads and a service page from a vendor who moved on. They’re still live, still in Google and still yours.
Four Things We Check, In Order Of Risk.
Every project checks the same four things. Claims come first, then reviews, then patient data, then the record of what we decided and why. Each one ends with a written process. Why? Because a choice nobody writes down gets made some other way next month.

01.
Claims Review
We read every line about what a therapy or product does against what it really is. Then we rewrite it to say the true thing clearly.
02.
Testimonials And Reviews
How you ask for reviews, what you post, what you disclose and who checks. We write it down, so it stops depending on whoever has the inbox.
03.
Patient Data And Intake
What your forms collect, where it goes and what your site loads on condition pages. Most of the risk here came turned on by default.
04.
Documentation
A record of what we checked, what changed and what your lawyer approved. We keep it current, so the answer is ready before anyone asks.
What We Do
What Actually Lands On Your Desk.
Every live page, ad, post, email and form, in one list. Most owners have never seen all of it in one place.
Each risky phrase pulled out, with the reason we flagged it. You get the why, not a hunch that a page feels risky.
Not just a list of red flags. You get a new sentence you can publish, one that keeps the pitch and drops the risk.
How to ask, what to disclose and what never gets posted. Nobody on your team has to decide it on the spot.
Forms cut back to what it takes to book the first call. You stop holding data you would have to guard.
What loads on which page, and what leaves your site. Your tracking is set up so it doesn't pass along details about someone's health.
The words that get read the hardest, checked before rejected ads put a working account at risk.
What we reviewed, what changed and when. It's the file you hand your counsel, so nobody rebuilds it from memory.
A working session with your team. The people who write captions and answer messages learn where the line is before they post.
The Hard Truth
Why A General Agency Gets Compliance Wrong.
A general agency doesn’t even know to look for the rules, let alone what missing them can cost you. It writes claims that end up quoted in FDA warning letters. And that letter has your name on it, not theirs. Your marketing answers to four rulebooks: FDA, FTC, HIPAA and the states. For cell and tissue products, the FDA looks at labels and ads to judge what a product is meant for. So your own marketing can help decide which rules apply.

Stem cells are a category, not a product. Under FDA rules, what your product is and what it’s cleared or approved for set how far your claims can go. For a PRP system, we start with what the device is cleared to do.
The FTC, or Federal Trade Commission, polices ad claims, and reviews count. A general agency posts the glowing ones and never asks what is behind them. If anything of value changed hands, we make sure the reader can see it.
HIPAA is the federal privacy law for patient health data. Where it applies, you most often need the patient’s written okay before you use that data for marketing. We check that before anyone builds the list.
Keeping that data safe is a separate duty. Many general agencies have never signed a business associate agreement (BAA). We sign one as standard. And we check each form, tool and vendor that touches the data.
More states now write their own laws for this field. Florida and Utah, for example, now have their own stem cell laws, and those don’t change federal law. Licensing boards set ad rules for clinicians too, and we track them state by state.
A generic checklist, or a lawyer who only says no, leaves you with nothing to post. We show you what you can say, and the source behind it. We are not a law firm, so your own legal counsel makes the final call.
How A Compliance Review Runs.
It runs in four steps, and you start by applying. The audit costs you nothing. Once the work starts, we review, flag, fix and document, starting where the risk is highest. That’s most often the ad accounts and any service page that names a product. You get the findings as we find them, not in one pile at the end.
The cost depends on how many service lines, live pages and accounts you have, and how much is written down. So we set it after the diagnostic, not as a quote that won’t hold. Your website pages, your written content and your paid ads all make claims. Each one gives you more or less room to explain them.

01.
Audit
At no cost for businesses that apply. We read what anyone can see from outside, walk you through it, and you keep it either way.
02.
Diagnostic
If it's a fit, you open the books with us: sales numbers, follow-up, staff, systems and pricing. Then we set the scope and the cost, so the quote holds.
03.
Build
We flag each risky item with its reason and source, and the sharpest edges go first. Then we write a fix for every one, so you approve a rewrite, not a problem.
04.
Review
We log what we found, what changed, when, and who signed off. We keep it current as you grow, so the file is there the day someone asks for it.
Straight Answers
Marketing Compliance Questions We Get Asked.
How does the compliance audit work, and what does it cost?
You apply, and the compliance audit is step one. It’s at no cost, only for businesses that apply. It covers what anyone can see from outside, without a login: your site, ads, social posts, forms and published reviews. We walk you through what carries risk, why, and what to fix first. You keep it either way.
We say yes when you’re actively growing, coachable, want it done right and compliant, and we have room. If it’s a fit, you open the books with us in the diagnostic. What does the work cost? We don’t publish prices, because it depends on how many pages, accounts and service lines are in play.
Who reviews the medical claims on our site before they go live?
Our team does, led by our founder, Oscar Tellez, who has been in this industry since 2015. We read every claim for four things. What does the copy say a therapy or product does? Does anything hint at an approval or clearance that doesn’t exist? Do the disclosures sit where a reader will see them? What do your forms and tracking do with patient data?
Then it comes to you. You check it against your protocols, your counsel signs off, and we log what we found, what changed and who approved it. We flag and rewrite, but we are not a law firm, and we don’t clear anything for you.
Will you ever recommend a keyword or a page that could create an implied FDA claim?
No. Your marketing helps define what a therapy is under the law. So a page title, a web address or the short blurb Google may show under your link can carry a claim. Your main copy may never make it. A keyword that only gets clicks by hinting at a result is a legal problem before it’s a traffic win.
When a term sits close to the line, we bring you a version we can build safely, and we show you both. When there is no safe version, we tell you in writing, with the source. You and your counsel can still overrule us, knowing exactly what we see.
Is a review going to gut the marketing we already have?
Rarely. Most of what we find is a phrase, a form field or a script, not the whole plan. So most of your marketing stays as it is, and a short list gets rewritten. And what we found is that the rewrite often reads better than the line it replaced.
Do you review ad accounts, or only website copy?
Both, plus social posts, email templates, intake forms and published reviews. Ad accounts carry the most risk per word. The copy is short, and enough rejected ads can get a whole account shut down. So we check each ad and the page it sends people to. How we run paid ads covers that side.
Can we still publish patient testimonials?
Yes, with a process behind it. Two questions decide it: what does the story claim, and what sits behind it? Under the FTC’s endorsement guides, you disclose a material connection. That’s a tie the reader wouldn’t expect, like payment or a gift, that could change how much they trust the review. A story that names an outcome also reads as a claim about the therapy. Growing reviews without breaking the rules covers the asking side.
Is our analytics setup a HIPAA problem?
It can be, depending on the page. Tracking on a logged-in page, like a patient portal, still needs HIPAA handling. For public pages about a condition, a court threw out that part of HHS’s tracking guidance in 2024. But the FTC and some states still have their own rules. And keeping patient data safe is its own duty under HIPAA, for the businesses it covers. What is safe to measure covers the practical side.
Do state rules apply to us?
It depends on where you do business and where you advertise. More states are writing their own stem cell laws, and each one reads differently. Licensing boards add advertising rules for clinicians on top of that. We track the state-by-state picture as it changes, and your counsel confirms what applies to you.
Can we use AI to draft our marketing copy?
Yes, carefully. AI writes in the confident voice of health content online, and that’s the voice that turns into a disease claim. Google’s spam policies also name scaled content abuse. That means pumping out lots of pages mainly to rank, whether a person or a tool writes them. What holds up is AI for the outline and a person for the claims. We cover it in drafting compliant regen content with AI.
Will you work with our attorney?
Yes, that’s how it’s meant to work. We do the reading, the flagging and the rewriting. Then we hand your attorney an organized file instead of a folder of screenshots. The legal sign-off stays with them, because we are not a law firm, and we don’t act like one.
What do you report on compliance, and how often?
Every month, we email the report with a short video that walks you through it. For compliance, that means what we flagged, what we rewrote, what’s still open and who approved each change.
The point of the record is that it exists before anyone asks for it. A business that can show what it checked, and when, is in a stronger spot than one piecing it together under pressure.
What happens if something goes wrong with patient data?
We follow a written breach process. That’s the steps we take if patient data gets out, and it covers anyone working under us, not just us. It’s written ahead of time, so nobody makes it up while they tell you about a problem.
If you fall under HIPAA, you need a business associate agreement, or BAA, with any vendor that handles your patient data. The agreement sets the duty, and the process sets the steps. Your counsel gets the same file we do. Before any agency gets access to a form, ask it for both.
Where do form submissions and patient data actually go?
Into your system, not ours. Forms feed the HIPAA compliant system you use now. That might be your CRM, where you track leads, or your EMR, your electronic medical record. Patient data stays there, and we don’t keep a second copy of your patient list.
Access runs both ways. You get your own logins to your ad accounts, analytics and profiles, along with the monthly report. An agency that only shows you its own dashboard is deciding what you get to see about your own business.
Who else has access to our accounts?
Our team and a small group of vendors we trust, and nobody outside that. Each person who touches your systems is covered by a BAA and by the insurance we carry.
Your work doesn’t go out to a marketplace, and strangers don’t rotate through your accounts. If someone is inside your systems, we know who they are, and we can tell you.
What happens if something you published turns out to be wrong?
We correct it, date it and log it. We don’t just edit it and hope nobody noticed. And we don’t leave it up while someone decides whose problem it is.
We keep internal protocols for over one hundred scenarios. That sounds like a lot, until the day one of them happens. We write them down ahead of time, so the response isn’t made up under pressure by whoever noticed first.
Google will not sign a BAA for Analytics. How do you handle that?
That’s correct, and it’s the right question to ask. Google doesn’t sign a BAA for Analytics. So the answer isn’t to make Analytics compliant. It’s to make sure Analytics never gets patient data at all. Patient data goes to your own HIPAA compliant system, like your CRM or EMR. Analytics sees visits in total, never who the person is.
The line that matters most is whether a page sits behind a login. A patient portal or a logged-in booking page is a different problem from a public service page. We treat it that way.
The rules here moved recently. The Office for Civil Rights (OCR) at HHS, the federal health department, enforces HIPAA. In December 2022, it put out a bulletin on online tracking tools, like pixels and analytics. It updated that bulletin on March 18, 2024. One part covered public pages about a health condition or a provider, the kind anyone can see without logging in. It said a tracking tool that links a visitor’s IP address to a visit there can count as protected health information. That’s the patient data HIPAA covers.
On June 20, 2024, a federal court in Texas ruled that part unlawful and threw it out. The case is American Hospital Association v. Becerra. HHS appealed, and then it withdrew the appeal on August 29, 2024. The rest of the bulletin still stands. Tracking on logged-in pages still needs HIPAA handling. So does any tool that receives protected health information, including a BAA where one is required.
The FTC is not bound by that ruling. It enforces its own health privacy rules, including for businesses HIPAA doesn’t cover. Some states have their own health privacy laws, too. So if someone tells you this is settled, ask them: according to who? We map which systems may touch patient data, insist on an agreement where one is needed and write down each decision. Your counsel signs off before anything goes live.
WHY REGEN PORTAL
We Learned These Rules Inside The Industry.
Every part of this industry has its own claim risk. For a clinic, it hides in a service page heading. For a manufacturer, it’s the brochure a rep hands a doctor. A distributor’s reps can say things nobody checked. A lab or stem cell bank must describe what it holds without promising what the cells will do. Even a financing company’s ad can pick up a therapy claim.
A health agency built around insurance billing usually meets these rules for the first time on your account. We’ve been inside regenerative medicine since 2015, so the compliance talk comes first. Define the terms, ask the questions, and do it right.
Regenerative Medicine Only
We work in one industry, and only this one. Since 2015, we’ve worked with its claim patterns, its state rules and the questions cash-pay patients and doctors ask.
Sources, Not Opinions
Every position we take points back to the agency that published it. If we can’t show you where a rule comes from, we tell you that, too.
One Market, One Client
We never take two competing businesses in one market. For a clinic, that’s one per major city. The copy we write for you stays yours.
You Own The File
The findings, the rewrites and the records are yours. You keep all of it, no matter what happens between us.
No Long-Term Contract
We work month to month, with no yearly commitment and no fee to leave. To end it, give us thirty days notice in writing. Your accounts, pages and files are in your name, start to finish. There’s a written agreement, because both sides need one. It spells out the work, and it won’t hold you in.
Insured, And Under A BAA
A BAA is standard with us, and each person who works under us signs one too. A written breach process sits behind it.
Cyber, AI, and errors and omissions are all on our insurance. That matters, because a breach often comes in through the marketing side, not the medical record. Forms, tracking pixels and ad platforms can all handle patient data before anyone thinks to call it a record.
Apply, And We Start With Your Claims.
Apply To Work With Us.
We take about five clients a year, and only one per market. Tell us about your business and what you want to grow, and we’ll follow up.
If it’s a fit, we start with an audit of everything we can see from the outside. It’s at no cost for businesses that apply, and you keep the findings either way.
Asking about our online courses or a one-off consultation? Use the same form and pick it from the list.