Regenerative Medicine Marketing Compliance, Built For Growth.

Compliance is how you grow without the risk. Consulting comes first: we check your claims, reviews and patient data. Then we build your marketing inside the rules. It’s for clinics, manufacturers, distributors, labs, stem cell banks, financing companies and even med spas.

Overview

Compliance Is An Advantage, Not A Burden.

Regenerative medicine marketing compliance means everything you put out holds up when someone reads it closely. That’s your site, ads, posts, emails, forms and reviews. The Food and Drug Administration (FDA) has not approved many cell and tissue products for the uses they are sold for. So one word in a heading can turn a careful page into a claim. A lot of businesses say too much, or play it so safe they say nothing. Know where the line is, and you can say the true thing and grow.

Primary Sources Only
Your Counsel Decides

The Exposure

Compliance Breaks One Word At A Time.

Compliance almost never breaks on purpose. It slips in with one borrowed line or one rushed fix. A warning letter is the FDA telling a company, in writing, that it sees a significant violation. It’s informal, but it’s public. If it isn’t fixed, it can lead to seizures, injunctions, fines or prosecution. In most of the warning letters we read, the company’s own marketing language is part of the evidence.

A red, yellow and green traffic light glows in a clinic hallway
A Treatment Claim Becomes A Disease Claim

A line about what a therapy is being studied for turns into a line about what it treats. It most often happens in a subheading nobody thinks of as copy.

Before And After Says It For You

A wall of photos makes the promise your words were careful not to make. The page never claims a result, but every visitor reads one anyway.

Reviews With Something Behind Them

Someone got something of value for a review, and it went up with no mention of it. The words are theirs, but the choice to post them is yours.

Intake Forms That Ask Too Much

A form asks about symptoms, illnesses and past procedures before anyone has booked. Every extra box is more data you now have to guard.

Tracking On Condition Pages

A script on a page about a certain condition sends that visit to an outside company. Nobody chose it. It came with the website template.

Copy Nobody Owns Anymore

Old landing pages, retired ads and a service page from a vendor who moved on. They’re still live, still in Google and still yours.

Four Things We Check, In Order Of Risk.

Every project checks the same four things. Claims come first, then reviews, then patient data, then the record of what we decided and why. Each one ends with a written process. Why? Because a choice nobody writes down gets made some other way next month.

A cracked glass shield shatters inside a dark spiral funnel

01.

Claims Review

We read every line about what a therapy or product does against what it really is. Then we rewrite it to say the true thing clearly.

02.

Testimonials And Reviews

How you ask for reviews, what you post, what you disclose and who checks. We write it down, so it stops depending on whoever has the inbox.

03.

Patient Data And Intake

What your forms collect, where it goes and what your site loads on condition pages. Most of the risk here came turned on by default.

04.

Documentation

A record of what we checked, what changed and what your lawyer approved. We keep it current, so the answer is ready before anyone asks.

What We Do

What Actually Lands On Your Desk.

A Full Marketing Inventory

Every live page, ad, post, email and form, in one list. Most owners have never seen all of it in one place.

Findings, Claim By Claim

Each risky phrase pulled out, with the reason we flagged it. You get the why, not a hunch that a page feels risky.

A Lower Risk Rewrite For Each One

Not just a list of red flags. You get a new sentence you can publish, one that keeps the pitch and drops the risk.

A Testimonial And Review Process

How to ask, what to disclose and what never gets posted. Nobody on your team has to decide it on the spot.

Intake Forms Trimmed To What You Need

Forms cut back to what it takes to book the first call. You stop holding data you would have to guard.

A Tracking And Analytics Pass

What loads on which page, and what leaves your site. Your tracking is set up so it doesn't pass along details about someone's health.

Ad And Landing Page Review

The words that get read the hardest, checked before rejected ads put a working account at risk.

A Documented Trail

What we reviewed, what changed and when. It's the file you hand your counsel, so nobody rebuilds it from memory.

A Team Briefing

A working session with your team. The people who write captions and answer messages learn where the line is before they post.

The Hard Truth

Why A General Agency Gets Compliance Wrong.

A general agency doesn’t even know to look for the rules, let alone what missing them can cost you. It writes claims that end up quoted in FDA warning letters. And that letter has your name on it, not theirs. Your marketing answers to four rulebooks: FDA, FTC, HIPAA and the states. For cell and tissue products, the FDA looks at labels and ads to judge what a product is meant for. So your own marketing can help decide which rules apply.

A phone displays star ratings beneath a glowing legal scale and shield
They Treat Stem Cells Like One Product

Stem cells are a category, not a product. Under FDA rules, what your product is and what it’s cleared or approved for set how far your claims can go. For a PRP system, we start with what the device is cleared to do.

They Post Reviews Without Asking

The FTC, or Federal Trade Commission, polices ad claims, and reviews count. A general agency posts the glowing ones and never asks what is behind them. If anything of value changed hands, we make sure the reader can see it.

They Market To Your Patient List

HIPAA is the federal privacy law for patient health data. Where it applies, you most often need the patient’s written okay before you use that data for marketing. We check that before anyone builds the list.

Many Have Never Signed A BAA

Keeping that data safe is a separate duty. Many general agencies have never signed a business associate agreement (BAA). We sign one as standard. And we check each form, tool and vendor that touches the data.

They Miss The State Rules

More states now write their own laws for this field. Florida and Utah, for example, now have their own stem cell laws, and those don’t change federal law. Licensing boards set ad rules for clinicians too, and we track them state by state.

A Checklist That Only Says No

A generic checklist, or a lawyer who only says no, leaves you with nothing to post. We show you what you can say, and the source behind it. We are not a law firm, so your own legal counsel makes the final call.

How A Compliance Review Runs.

It runs in four steps, and you start by applying. The audit costs you nothing. Once the work starts, we review, flag, fix and document, starting where the risk is highest. That’s most often the ad accounts and any service page that names a product. You get the findings as we find them, not in one pile at the end.

The cost depends on how many service lines, live pages and accounts you have, and how much is written down. So we set it after the diagnostic, not as a quote that won’t hold. Your website pages, your written content and your paid ads all make claims. Each one gives you more or less room to explain them.

A tablet analytics dashboard floats in front of a glowing shield

01.

Audit

At no cost for businesses that apply. We read what anyone can see from outside, walk you through it, and you keep it either way.

02.

Diagnostic

If it's a fit, you open the books with us: sales numbers, follow-up, staff, systems and pricing. Then we set the scope and the cost, so the quote holds.

03.

Build

We flag each risky item with its reason and source, and the sharpest edges go first. Then we write a fix for every one, so you approve a rewrite, not a problem.

04.

Review

We log what we found, what changed, when, and who signed off. We keep it current as you grow, so the file is there the day someone asks for it.

Straight Answers

Marketing Compliance Questions We Get Asked.

How does the compliance audit work, and what does it cost?

You apply, and the compliance audit is step one. It’s at no cost, only for businesses that apply. It covers what anyone can see from outside, without a login: your site, ads, social posts, forms and published reviews. We walk you through what carries risk, why, and what to fix first. You keep it either way.

We say yes when you’re actively growing, coachable, want it done right and compliant, and we have room. If it’s a fit, you open the books with us in the diagnostic. What does the work cost? We don’t publish prices, because it depends on how many pages, accounts and service lines are in play.

Our team does, led by our founder, Oscar Tellez, who has been in this industry since 2015. We read every claim for four things. What does the copy say a therapy or product does? Does anything hint at an approval or clearance that doesn’t exist? Do the disclosures sit where a reader will see them? What do your forms and tracking do with patient data?

Then it comes to you. You check it against your protocols, your counsel signs off, and we log what we found, what changed and who approved it. We flag and rewrite, but we are not a law firm, and we don’t clear anything for you.

No. Your marketing helps define what a therapy is under the law. So a page title, a web address or the short blurb Google may show under your link can carry a claim. Your main copy may never make it. A keyword that only gets clicks by hinting at a result is a legal problem before it’s a traffic win.

When a term sits close to the line, we bring you a version we can build safely, and we show you both. When there is no safe version, we tell you in writing, with the source. You and your counsel can still overrule us, knowing exactly what we see.

Rarely. Most of what we find is a phrase, a form field or a script, not the whole plan. So most of your marketing stays as it is, and a short list gets rewritten. And what we found is that the rewrite often reads better than the line it replaced.

Both, plus social posts, email templates, intake forms and published reviews. Ad accounts carry the most risk per word. The copy is short, and enough rejected ads can get a whole account shut down. So we check each ad and the page it sends people to. How we run paid ads covers that side.

Yes, with a process behind it. Two questions decide it: what does the story claim, and what sits behind it? Under the FTC’s endorsement guides, you disclose a material connection. That’s a tie the reader wouldn’t expect, like payment or a gift, that could change how much they trust the review. A story that names an outcome also reads as a claim about the therapy. Growing reviews without breaking the rules covers the asking side.

It can be, depending on the page. Tracking on a logged-in page, like a patient portal, still needs HIPAA handling. For public pages about a condition, a court threw out that part of HHS’s tracking guidance in 2024. But the FTC and some states still have their own rules. And keeping patient data safe is its own duty under HIPAA, for the businesses it covers. What is safe to measure covers the practical side.

It depends on where you do business and where you advertise. More states are writing their own stem cell laws, and each one reads differently. Licensing boards add advertising rules for clinicians on top of that. We track the state-by-state picture as it changes, and your counsel confirms what applies to you.

Yes, carefully. AI writes in the confident voice of health content online, and that’s the voice that turns into a disease claim. Google’s spam policies also name scaled content abuse. That means pumping out lots of pages mainly to rank, whether a person or a tool writes them. What holds up is AI for the outline and a person for the claims. We cover it in drafting compliant regen content with AI.

Yes, that’s how it’s meant to work. We do the reading, the flagging and the rewriting. Then we hand your attorney an organized file instead of a folder of screenshots. The legal sign-off stays with them, because we are not a law firm, and we don’t act like one.

Every month, we email the report with a short video that walks you through it. For compliance, that means what we flagged, what we rewrote, what’s still open and who approved each change.

The point of the record is that it exists before anyone asks for it. A business that can show what it checked, and when, is in a stronger spot than one piecing it together under pressure.

We follow a written breach process. That’s the steps we take if patient data gets out, and it covers anyone working under us, not just us. It’s written ahead of time, so nobody makes it up while they tell you about a problem.

If you fall under HIPAA, you need a business associate agreement, or BAA, with any vendor that handles your patient data. The agreement sets the duty, and the process sets the steps. Your counsel gets the same file we do. Before any agency gets access to a form, ask it for both.

Into your system, not ours. Forms feed the HIPAA compliant system you use now. That might be your CRM, where you track leads, or your EMR, your electronic medical record. Patient data stays there, and we don’t keep a second copy of your patient list.

Access runs both ways. You get your own logins to your ad accounts, analytics and profiles, along with the monthly report. An agency that only shows you its own dashboard is deciding what you get to see about your own business.

Our team and a small group of vendors we trust, and nobody outside that. Each person who touches your systems is covered by a BAA and by the insurance we carry.

Your work doesn’t go out to a marketplace, and strangers don’t rotate through your accounts. If someone is inside your systems, we know who they are, and we can tell you.

We correct it, date it and log it. We don’t just edit it and hope nobody noticed. And we don’t leave it up while someone decides whose problem it is.

We keep internal protocols for over one hundred scenarios. That sounds like a lot, until the day one of them happens. We write them down ahead of time, so the response isn’t made up under pressure by whoever noticed first.

That’s correct, and it’s the right question to ask. Google doesn’t sign a BAA for Analytics. So the answer isn’t to make Analytics compliant. It’s to make sure Analytics never gets patient data at all. Patient data goes to your own HIPAA compliant system, like your CRM or EMR. Analytics sees visits in total, never who the person is.

The line that matters most is whether a page sits behind a login. A patient portal or a logged-in booking page is a different problem from a public service page. We treat it that way.

The rules here moved recently. The Office for Civil Rights (OCR) at HHS, the federal health department, enforces HIPAA. In December 2022, it put out a bulletin on online tracking tools, like pixels and analytics. It updated that bulletin on March 18, 2024. One part covered public pages about a health condition or a provider, the kind anyone can see without logging in. It said a tracking tool that links a visitor’s IP address to a visit there can count as protected health information. That’s the patient data HIPAA covers.

On June 20, 2024, a federal court in Texas ruled that part unlawful and threw it out. The case is American Hospital Association v. Becerra. HHS appealed, and then it withdrew the appeal on August 29, 2024. The rest of the bulletin still stands. Tracking on logged-in pages still needs HIPAA handling. So does any tool that receives protected health information, including a BAA where one is required.

The FTC is not bound by that ruling. It enforces its own health privacy rules, including for businesses HIPAA doesn’t cover. Some states have their own health privacy laws, too. So if someone tells you this is settled, ask them: according to who? We map which systems may touch patient data, insist on an agreement where one is needed and write down each decision. Your counsel signs off before anything goes live.

WHY REGEN PORTAL

We Learned These Rules Inside The Industry.

Since 2015
Everything Documented

Every part of this industry has its own claim risk. For a clinic, it hides in a service page heading. For a manufacturer, it’s the brochure a rep hands a doctor. A distributor’s reps can say things nobody checked. A lab or stem cell bank must describe what it holds without promising what the cells will do. Even a financing company’s ad can pick up a therapy claim.

A health agency built around insurance billing usually meets these rules for the first time on your account. We’ve been inside regenerative medicine since 2015, so the compliance talk comes first. Define the terms, ask the questions, and do it right.

Regenerative Medicine Only

We work in one industry, and only this one. Since 2015, we’ve worked with its claim patterns, its state rules and the questions cash-pay patients and doctors ask.

Every position we take points back to the agency that published it. If we can’t show you where a rule comes from, we tell you that, too.

We never take two competing businesses in one market. For a clinic, that’s one per major city. The copy we write for you stays yours.

The findings, the rewrites and the records are yours. You keep all of it, no matter what happens between us.

We work month to month, with no yearly commitment and no fee to leave. To end it, give us thirty days notice in writing. Your accounts, pages and files are in your name, start to finish. There’s a written agreement, because both sides need one. It spells out the work, and it won’t hold you in.

A BAA is standard with us, and each person who works under us signs one too. A written breach process sits behind it.

Cyber, AI, and errors and omissions are all on our insurance. That matters, because a breach often comes in through the marketing side, not the medical record. Forms, tracking pixels and ad platforms can all handle patient data before anyone thinks to call it a record.

Apply, And We Start With Your Claims.

Apply To Work With Us.

We take about five clients a year, and only one per market. Tell us about your business and what you want to grow, and we’ll follow up.

If it’s a fit, we start with an audit of everything we can see from the outside. It’s at no cost for businesses that apply, and you keep the findings either way.

Asking about our online courses or a one-off consultation? Use the same form and pick it from the list.

Email Us

Call Us