Blogs
>
Healthcare Merchant Risk Keeps Changing After Onboarding

Healthcare Merchant Risk Keeps Changing After Onboarding

Guy Raveh
Oct 4, 2026
Share:

Index

Last updated: 
Oct 5, 2026

What 2026 Healthcare Enforcement Shows About Merchant Risk After Onboarding

‍

TL;DR

‍

  • Monitoring isn't a nice-to-have, it's a must. Four public U.S. actions from 2026 show healthcare merchant risk changing after onboarding along four separate dimensions: operational behavior, products and fulfillment, networks and relationships, and the use of AI.
    ‍
  • In each case, the risk sat in something that can change without any change to the merchant's legal entity, merchant category code (MCC), or stated business model, which are the fields most monitoring programs rely on.
    ‍
  • A point-in-time underwriting decision describes a merchant as it was on the day of review, so ongoing monitoring has to track the customer journey, the fulfillment chain, the relationship network, and the adoption of AI, and in our view it should run at least monthly.
    ‍
  • ‍

‍

Monitoring isn't a nice-to-have, it's a must

Over the past two years I've watched the conversation around merchant risk move away from onboarding and toward what happens after it. Card schemes have been moving toward continuous monitoring because a merchant that passed review can look different a few months later without triggering a single re-underwriting event.

‍

For acquirers, payment facilitators (PayFacs), payment service providers (PSPs), and marketplaces, the underwriting file typically captures the legal entity, the beneficial owners, the products listed at the time of review, and the website as it appeared on that date. Everything that changes after that date has to be picked up by monitoring, or it isn't picked up at all.

‍

Healthcare is where I've seen this gap most clearly this year. Telehealth providers, online prescription services, durable medical equipment (DME) suppliers, and diagnostics companies can change their checkout flows, fulfillment partners, business relationships, and clinical workflows while their legal entity and MCC stay exactly the same.

‍

The four cases below each show one of those changes. All four are U.S. matters, and I describe each using the language of the agency involved. Healthcare is the example here, but the lesson is about monitoring.

‍

‍

‍

‍

Healthcare Merchant Risk Keeps Changing After Onboarding

‍

‍

‍

1. Operational behavior: an FTC complaint over telehealth billing and privacy practices

On July 29, 2026, the Federal Trade Commission (FTC) filed a complaint against telehealth provider Hims & Hers in the U.S. District Court for the Northern District of California. Utah joined the complaint, as did California through Los Angeles County Counsel. The FTC's announcement describes a pattern at intake and checkout.

‍

Consumers were asked for billing information and told they would not be charged unless medication was prescribed. According to the complaint, most were instead charged and enrolled in recurring subscriptions shortly after submitting the intake form, before they had a chance to consult a provider or approve treatment.

‍

The company also did not clearly disclose when monthly refills would occur, which made it hard to cancel before the next billing cycle. Before 2023, cancellation ran through customer service only, by phone, email, or chat. After an online cancellation option launched in 2023, the button appeared only after a consumer selected an option to add or remove items from an order, then moved through several more steps.

‍

Separately, the complaint alleges the company shared consumers' health information with advertising platforms, including Meta and Snap, through shared customer lists and third-party tracking technology, despite public statements promising patient privacy.

‍

The FTC alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act (ROSCA). Utah and California allege violations of their own consumer protection and false advertising laws. These are allegations, and the court will decide the case.

‍

None of this concerns the medication itself. It concerns the checkout flow, the timing of the first charge, subscription disclosures, the cancellation path, and third-party trackers on the website, all of which a merchant can change through a routine product release without notifying its acquirer.

‍

For healthcare subscription merchants, we track when the first charge occurs relative to clinical review, how renewal terms are disclosed at checkout, how many steps it takes to cancel, and whether the trackers present on the site match the merchant's stated privacy practices. Each is a monitoring signal, not a one-time check, because each can open a gap between what a consumer expects to pay and what they're actually charged.

‍

‍

‍

2. Products and fulfillment: FDA warning letters on compounded GLP-1s

On March 3, 2026, the U.S. Food and Drug Administration (FDA) announced 30 warning letters to telehealth companies over false or misleading claims about compounded glucagon-like peptide-1 (GLP-1) products sold on their websites.

‍

The FDA flagged two problems: claims implying the compounded products were equivalent to FDA-approved products, and branding that used the telehealth company's own name or trademark without qualification, implying the telehealth company itself was the compounder.

‍

The agency described this as its second round of letters since a crackdown on misleading direct-to-consumer pharmaceutical advertising that began in September 2025, and said it had sent more letters to pharmaceutical and telehealth firms in the preceding six months than in the entire previous decade.

‍

Compounded drugs are not FDA-approved: the agency does not review their safety, effectiveness, or quality before they reach the market.

‍

A telehealth storefront can present a single branded product while the prescribing entity, the compounding pharmacy, the dispensing pharmacy, and the product's regulatory status all sit with third parties invisible on the merchant's website. A merchant can switch compounding partners or add a new product category without touching its legal entity.

‍

When we review a telehealth merchant selling prescription products, we verify which entity writes the prescription, which pharmacy compounds and dispenses it, whether that pharmacy is licensed in the states the merchant serves, whether the product is labeled as compounded, and whether marketing claims compare it to an FDA-approved drug.

‍

‍

Bar chart of suspected counterfeit semaglutide reports in EudraVigilance, rising from 1 in 2020 to 92 in 2025
Source: https://www.frontiersin.org/journals/pharmacology/articles/10.3389/fphar.2026.1805842/full

‍

‍

‍

3. Networks and relationships: the TelevisitMD guilty plea

On March 27, 2026, the U.S. Department of Justice (DOJ) announced that Christopher Harwood, owner and operator of telemedicine company TelevisitMD, pleaded guilty to conspiracy to commit health care fraud and wire fraud in a $46.2 million Medicare fraud scheme spanning more than six years.

‍

According to court documents cited by DOJ, Harwood and his co-conspirators used telemarketing campaigns to induce Medicare patients to accept orthotic braces and genetic tests they didn't need, then paid doctors to approve the orders.

‍

Those doctors skipped Medicare's telemedicine rules, had no real relationship with the patients, and signed orders without meaningful interaction.

‍

Harwood sold the signed orders to DME suppliers, laboratories, and marketers who were part of the scheme, and also owned multiple Florida DME supply companies that billed Medicare for braces patients never wanted.

‍

Medicare paid $17.9 million on the claims; Harwood personally received more than $10.4 million, agreed to pay $17.9 million in restitution, and faces a maximum sentence of 20 years. HHS-OIG and the FBI investigated the case.

‍

This fraud ran through Medicare, not card rails, but its structure is the part that matters for acquirers and marketplaces. The scheme spanned telemarketers, a telemedicine company, physicians, DME suppliers, and laboratories, with a single owner sitting on more than one side of that chain. Reviewed individually, each entity could pass as an operating business.

‍

The risk only became visible once the relationships between entities were mapped, which is the same structural gap that shows up in connected merchant networks more broadly: the individual merchant passes review, and the risk sits in who it's connected to. For healthcare merchants, that means watching for shared ownership across telemedicine, DME, pharmacy, and laboratory entities, shared addresses, phone numbers, and web infrastructure, and referral or marketing relationships that route patients between related entities.

‍

‍

‍

4. AI: a change in workflow can be a change in risk profile

The FDA's Digital Health Center of Excellence has published a discussion paper, Considerations for the Regulation of Generative AI-Enabled Medical Devices, seeking stakeholder input on risk assessment, premarket evaluation, postmarket monitoring, and related topics.

‍

The FDA is explicit that the paper is for discussion only, not draft or final guidance, and feedback is open until October 19, 2026. States are moving faster. California's AB 3030, effective January 1, 2025, requires health facilities, clinics, and physician offices using generative AI to produce patient communications with clinical content to include a disclaimer and instructions for reaching a human provider, unless a licensed provider reviews the communication first.

‍

Texas's Responsible Artificial Intelligence Governance Act, effective January 1, 2026, requires providers to disclose when AI is used in diagnosis or treatment.

‍

This next part is our view, not a regulatory position. A healthcare merchant can introduce AI into patient intake, eligibility screening, clinical decision support, or patient messaging without changing its legal entity, product catalog, or MCC, and each introduction can shift its regulatory exposure in three ways: it can create disclosure obligations that vary by state, it can raise the question of whether a software function falls under FDA device oversight, and it can change who, or what, is making a decision a licensed clinician used to make.

‍

That complaint is a useful reminder of why that last point matters, even though it doesn't involve AI at all: it centers on whether consumers got the provider consultation they were told to expect. Where intake and eligibility decisions are automated, whether a licensed clinician reviews each case becomes a question risk teams need to be able to answer.

‍

We treat AI adoption in clinical or patient-facing functions as a change event that triggers reassessment, and look for AI-powered chat or intake on the merchant's website, public statements about automating clinical or eligibility steps, AI disclosures (or the absence of them) in the states the merchant serves, and whether a licensed provider reviews AI-generated clinical communications.

‍

‍

‍

Where monitoring programs fall short

‍

Looking across these four cases, a merchant that is never monitored after onboarding keeps being judged on a file that describes a checkout flow, a set of fulfillment partners, a network of related entities, and a clinical workflow that may no longer exist.

‍

Monitoring alone doesn't close that gap if it watches the wrong things, because a program that tracks only the legal entity, the MCC, and the stated business model would have missed all four cases, since none of those fields changed, and a program that reviews each merchant on its own would not have seen a structure like TelevisitMD's, where the risk sat in how the entities were connected rather than in any one of them.

‍

Frequency is the other half of the problem, since each change described here can happen within a single product release, and regulators are moving on a cycle of months rather than years, as the FDA's second round of GLP-1 letters, roughly six months after its crackdown began, shows.

‍

For that reason we recommend reviewing healthcare merchants at least once a month, and reassessing in between whenever a checkout flow, product category, fulfillment partner, connected entity, or AI workflow changes, which is our judgment based on what we see in the market and not a regulatory requirement.

‍

I can do the same pass on the rest of the article. A few short lines are still there, such as "States are moving faster." Some of those come from the live article itself.

‍

‍

‍

‍

Four controls we recommend for healthcare merchant portfolios

‍

Retest the customer journey. Track first-charge timing, renewal disclosures, the cancellation path, and third-party trackers against the merchant's stated privacy practices, and retest at regular intervals, since these change with routine product releases.

‍

Verify the fulfillment chain. For prescription products, confirm the prescribing entity, the compounding and dispensing pharmacies, their licensing in the states served, and how products are labeled and marketed relative to FDA-approved drugs.

‍

Map relationships. Connect the merchant to its owners, its infrastructure, and its referral and marketing partners, and reassess when those connections change.

‍

Treat AI adoption as a change event. When a healthcare merchant introduces AI into intake, eligibility, clinical decision support, or patient communications, reassess its regulatory exposure against the states it serves.

‍

Public regulator activity feeds all four controls. FTC complaints, FDA warning letters, and DOJ releases are published and dated, and when one of them names a merchant in a portfolio, or a merchant with a comparable model, it should trigger review.

‍

These cases come from healthcare, but the same holds for any merchant whose business can change faster than its file. Monitoring isn't a nice-to-have, it's a must.

‍

‍

‍

‍

How Ballerine approaches healthcare merchant risk

Ballerine is an AI-native merchant risk management platform built for acquirers, PayFacs, PSPs, and marketplaces. It covers merchant onboarding, merchant underwriting, and ongoing merchant monitoring.

‍

For healthcare merchants, Ballerine connects signals from a merchant's website and customer journey, its product and fulfillment claims, its ownership and business relationships, and its use of AI in patient-facing workflows, and flags changes that alter the merchant's risk profile after onboarding.

‍

Because Ballerine builds AI systems and also evaluates merchants that deploy them, the team is positioned to assess when a healthcare merchant's AI adoption changes its risk profile, and when it does not.

‍

‍

‍

This article summarizes publicly available information from U.S. government sources as of September 29, 2026. Descriptions of the complaint discussed in this article reflect allegations, and the case will be decided by the court. This article does not constitute legal advice.

‍

About the Author
Guy Raveh
Risk and Fraud Researcher
@
Ballerine
Guy Raveh is a Risk and Intelligence Researcher at Ballerine, bringing together deep experience in AI, compliance, fraud, and risk. Over nearly a decade, he has worked on building and applying AI models, including at Wix, and has developed first-hand knowledge of the challenges facing risk and compliance teams. A Certified Anti-Money Laundering Specialist (CAMS), Guy now works closely with Ballerine’s data science team to develop new risk intelligence models and adapt them to the complex problems financial institutions face in merchant risk.

Reeza Hendricks

What 2026 Healthcare Enforcement Shows About Merchant Risk After Onboarding

‍

TL;DR

‍

  • Monitoring isn't a nice-to-have, it's a must. Four public U.S. actions from 2026 show healthcare merchant risk changing after onboarding along four separate dimensions: operational behavior, products and fulfillment, networks and relationships, and the use of AI.
    ‍
  • In each case, the risk sat in something that can change without any change to the merchant's legal entity, merchant category code (MCC), or stated business model, which are the fields most monitoring programs rely on.
    ‍
  • A point-in-time underwriting decision describes a merchant as it was on the day of review, so ongoing monitoring has to track the customer journey, the fulfillment chain, the relationship network, and the adoption of AI, and in our view it should run at least monthly.
    ‍
  • ‍

‍

Monitoring isn't a nice-to-have, it's a must

Over the past two years I've watched the conversation around merchant risk move away from onboarding and toward what happens after it. Card schemes have been moving toward continuous monitoring because a merchant that passed review can look different a few months later without triggering a single re-underwriting event.

‍

For acquirers, payment facilitators (PayFacs), payment service providers (PSPs), and marketplaces, the underwriting file typically captures the legal entity, the beneficial owners, the products listed at the time of review, and the website as it appeared on that date. Everything that changes after that date has to be picked up by monitoring, or it isn't picked up at all.

‍

Healthcare is where I've seen this gap most clearly this year. Telehealth providers, online prescription services, durable medical equipment (DME) suppliers, and diagnostics companies can change their checkout flows, fulfillment partners, business relationships, and clinical workflows while their legal entity and MCC stay exactly the same.

‍

The four cases below each show one of those changes. All four are U.S. matters, and I describe each using the language of the agency involved. Healthcare is the example here, but the lesson is about monitoring.

‍

‍

‍

‍

Healthcare Merchant Risk Keeps Changing After Onboarding

‍

‍

‍

1. Operational behavior: an FTC complaint over telehealth billing and privacy practices

On July 29, 2026, the Federal Trade Commission (FTC) filed a complaint against telehealth provider Hims & Hers in the U.S. District Court for the Northern District of California. Utah joined the complaint, as did California through Los Angeles County Counsel. The FTC's announcement describes a pattern at intake and checkout.

‍

Consumers were asked for billing information and told they would not be charged unless medication was prescribed. According to the complaint, most were instead charged and enrolled in recurring subscriptions shortly after submitting the intake form, before they had a chance to consult a provider or approve treatment.

‍

The company also did not clearly disclose when monthly refills would occur, which made it hard to cancel before the next billing cycle. Before 2023, cancellation ran through customer service only, by phone, email, or chat. After an online cancellation option launched in 2023, the button appeared only after a consumer selected an option to add or remove items from an order, then moved through several more steps.

‍

Separately, the complaint alleges the company shared consumers' health information with advertising platforms, including Meta and Snap, through shared customer lists and third-party tracking technology, despite public statements promising patient privacy.

‍

The FTC alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act (ROSCA). Utah and California allege violations of their own consumer protection and false advertising laws. These are allegations, and the court will decide the case.

‍

None of this concerns the medication itself. It concerns the checkout flow, the timing of the first charge, subscription disclosures, the cancellation path, and third-party trackers on the website, all of which a merchant can change through a routine product release without notifying its acquirer.

‍

For healthcare subscription merchants, we track when the first charge occurs relative to clinical review, how renewal terms are disclosed at checkout, how many steps it takes to cancel, and whether the trackers present on the site match the merchant's stated privacy practices. Each is a monitoring signal, not a one-time check, because each can open a gap between what a consumer expects to pay and what they're actually charged.

‍

‍

‍

2. Products and fulfillment: FDA warning letters on compounded GLP-1s

On March 3, 2026, the U.S. Food and Drug Administration (FDA) announced 30 warning letters to telehealth companies over false or misleading claims about compounded glucagon-like peptide-1 (GLP-1) products sold on their websites.

‍

The FDA flagged two problems: claims implying the compounded products were equivalent to FDA-approved products, and branding that used the telehealth company's own name or trademark without qualification, implying the telehealth company itself was the compounder.

‍

The agency described this as its second round of letters since a crackdown on misleading direct-to-consumer pharmaceutical advertising that began in September 2025, and said it had sent more letters to pharmaceutical and telehealth firms in the preceding six months than in the entire previous decade.

‍

Compounded drugs are not FDA-approved: the agency does not review their safety, effectiveness, or quality before they reach the market.

‍

A telehealth storefront can present a single branded product while the prescribing entity, the compounding pharmacy, the dispensing pharmacy, and the product's regulatory status all sit with third parties invisible on the merchant's website. A merchant can switch compounding partners or add a new product category without touching its legal entity.

‍

When we review a telehealth merchant selling prescription products, we verify which entity writes the prescription, which pharmacy compounds and dispenses it, whether that pharmacy is licensed in the states the merchant serves, whether the product is labeled as compounded, and whether marketing claims compare it to an FDA-approved drug.

‍

‍

Bar chart of suspected counterfeit semaglutide reports in EudraVigilance, rising from 1 in 2020 to 92 in 2025
Source: https://www.frontiersin.org/journals/pharmacology/articles/10.3389/fphar.2026.1805842/full

‍

‍

‍

3. Networks and relationships: the TelevisitMD guilty plea

On March 27, 2026, the U.S. Department of Justice (DOJ) announced that Christopher Harwood, owner and operator of telemedicine company TelevisitMD, pleaded guilty to conspiracy to commit health care fraud and wire fraud in a $46.2 million Medicare fraud scheme spanning more than six years.

‍

According to court documents cited by DOJ, Harwood and his co-conspirators used telemarketing campaigns to induce Medicare patients to accept orthotic braces and genetic tests they didn't need, then paid doctors to approve the orders.

‍

Those doctors skipped Medicare's telemedicine rules, had no real relationship with the patients, and signed orders without meaningful interaction.

‍

Harwood sold the signed orders to DME suppliers, laboratories, and marketers who were part of the scheme, and also owned multiple Florida DME supply companies that billed Medicare for braces patients never wanted.

‍

Medicare paid $17.9 million on the claims; Harwood personally received more than $10.4 million, agreed to pay $17.9 million in restitution, and faces a maximum sentence of 20 years. HHS-OIG and the FBI investigated the case.

‍

This fraud ran through Medicare, not card rails, but its structure is the part that matters for acquirers and marketplaces. The scheme spanned telemarketers, a telemedicine company, physicians, DME suppliers, and laboratories, with a single owner sitting on more than one side of that chain. Reviewed individually, each entity could pass as an operating business.

‍

The risk only became visible once the relationships between entities were mapped, which is the same structural gap that shows up in connected merchant networks more broadly: the individual merchant passes review, and the risk sits in who it's connected to. For healthcare merchants, that means watching for shared ownership across telemedicine, DME, pharmacy, and laboratory entities, shared addresses, phone numbers, and web infrastructure, and referral or marketing relationships that route patients between related entities.

‍

‍

‍

4. AI: a change in workflow can be a change in risk profile

The FDA's Digital Health Center of Excellence has published a discussion paper, Considerations for the Regulation of Generative AI-Enabled Medical Devices, seeking stakeholder input on risk assessment, premarket evaluation, postmarket monitoring, and related topics.

‍

The FDA is explicit that the paper is for discussion only, not draft or final guidance, and feedback is open until October 19, 2026. States are moving faster. California's AB 3030, effective January 1, 2025, requires health facilities, clinics, and physician offices using generative AI to produce patient communications with clinical content to include a disclaimer and instructions for reaching a human provider, unless a licensed provider reviews the communication first.

‍

Texas's Responsible Artificial Intelligence Governance Act, effective January 1, 2026, requires providers to disclose when AI is used in diagnosis or treatment.

‍

This next part is our view, not a regulatory position. A healthcare merchant can introduce AI into patient intake, eligibility screening, clinical decision support, or patient messaging without changing its legal entity, product catalog, or MCC, and each introduction can shift its regulatory exposure in three ways: it can create disclosure obligations that vary by state, it can raise the question of whether a software function falls under FDA device oversight, and it can change who, or what, is making a decision a licensed clinician used to make.

‍

That complaint is a useful reminder of why that last point matters, even though it doesn't involve AI at all: it centers on whether consumers got the provider consultation they were told to expect. Where intake and eligibility decisions are automated, whether a licensed clinician reviews each case becomes a question risk teams need to be able to answer.

‍

We treat AI adoption in clinical or patient-facing functions as a change event that triggers reassessment, and look for AI-powered chat or intake on the merchant's website, public statements about automating clinical or eligibility steps, AI disclosures (or the absence of them) in the states the merchant serves, and whether a licensed provider reviews AI-generated clinical communications.

‍

‍

‍

Where monitoring programs fall short

‍

Looking across these four cases, a merchant that is never monitored after onboarding keeps being judged on a file that describes a checkout flow, a set of fulfillment partners, a network of related entities, and a clinical workflow that may no longer exist.

‍

Monitoring alone doesn't close that gap if it watches the wrong things, because a program that tracks only the legal entity, the MCC, and the stated business model would have missed all four cases, since none of those fields changed, and a program that reviews each merchant on its own would not have seen a structure like TelevisitMD's, where the risk sat in how the entities were connected rather than in any one of them.

‍

Frequency is the other half of the problem, since each change described here can happen within a single product release, and regulators are moving on a cycle of months rather than years, as the FDA's second round of GLP-1 letters, roughly six months after its crackdown began, shows.

‍

For that reason we recommend reviewing healthcare merchants at least once a month, and reassessing in between whenever a checkout flow, product category, fulfillment partner, connected entity, or AI workflow changes, which is our judgment based on what we see in the market and not a regulatory requirement.

‍

I can do the same pass on the rest of the article. A few short lines are still there, such as "States are moving faster." Some of those come from the live article itself.

‍

‍

‍

‍

Four controls we recommend for healthcare merchant portfolios

‍

Retest the customer journey. Track first-charge timing, renewal disclosures, the cancellation path, and third-party trackers against the merchant's stated privacy practices, and retest at regular intervals, since these change with routine product releases.

‍

Verify the fulfillment chain. For prescription products, confirm the prescribing entity, the compounding and dispensing pharmacies, their licensing in the states served, and how products are labeled and marketed relative to FDA-approved drugs.

‍

Map relationships. Connect the merchant to its owners, its infrastructure, and its referral and marketing partners, and reassess when those connections change.

‍

Treat AI adoption as a change event. When a healthcare merchant introduces AI into intake, eligibility, clinical decision support, or patient communications, reassess its regulatory exposure against the states it serves.

‍

Public regulator activity feeds all four controls. FTC complaints, FDA warning letters, and DOJ releases are published and dated, and when one of them names a merchant in a portfolio, or a merchant with a comparable model, it should trigger review.

‍

These cases come from healthcare, but the same holds for any merchant whose business can change faster than its file. Monitoring isn't a nice-to-have, it's a must.

‍

‍

‍

‍

How Ballerine approaches healthcare merchant risk

Ballerine is an AI-native merchant risk management platform built for acquirers, PayFacs, PSPs, and marketplaces. It covers merchant onboarding, merchant underwriting, and ongoing merchant monitoring.

‍

For healthcare merchants, Ballerine connects signals from a merchant's website and customer journey, its product and fulfillment claims, its ownership and business relationships, and its use of AI in patient-facing workflows, and flags changes that alter the merchant's risk profile after onboarding.

‍

Because Ballerine builds AI systems and also evaluates merchants that deploy them, the team is positioned to assess when a healthcare merchant's AI adoption changes its risk profile, and when it does not.

‍

‍

‍

This article summarizes publicly available information from U.S. government sources as of September 29, 2026. Descriptions of the complaint discussed in this article reflect allegations, and the case will be decided by the court. This article does not constitute legal advice.

‍