A risk terms list is a prioritized roster of marketing phrases, patterns, and visual cues that create FDA, FTC, or platform enforcement exposure. For telehealth and DTC health brands, the right move is to scan every asset before it publishes, flag anything matching a high-severity entry, and hold or rewrite it. Tools like ScanCompliant, built on a database of 1,000+ risk terms, do this scan in minutes rather than days.
TL;DR:
- Using automated scans with risk term databases can identify most high- and medium-severity claims before publication.
- Visual cues like prescription-style packaging or prominent disease citations significantly increase the risk of enforcement action.
- Combining unsubstantiated efficacy claims with fabricated testimonials and undisclosed relationships often triggers penalties.
- Implementing a structured review workflow with clear severity tiers and documentation reduces repeated violations and audit risk.
- Continuous monitoring and early review of draft content help prevent accumulating violations across a brand’s marketing materials.
Table of Contents
- What Counts as a Risk Term: The Core Categories
- How Context and Visuals Turn Safe Words Into Risky Claims
- Detect, Triage, Remediate, Document: A Workflow You Can Run Today
- A Copyable Risk-Term Checklist for Your CMS Gate
- Why This Checklist Holds Up: The Regulatory and Operational Basis
- Recent Enforcement Actions That Show the Pattern
- Keeping Marketing Content Compliant Over Time
- Training Marketing Teams to Catch Risk Before It Ships
- Making Risk-Term Review Part of Your Approval Process
- How ScanCompliant Puts This Checklist to Work
- From the Compliant Team: Three Habits That Reduce Enforcement Risk
- Sources
What Counts as a Risk Term: The Core Categories
Not every risky phrase looks dangerous on its face. Some are obvious, others hide in plain sight until a regulator reads them the way a consumer would. Building a working knowledge of risk management vocabulary starts with sorting language into categories your reviewers can recognize on sight.
- Disease and treatment claims. Words like “treats,” “prevents,” “cures,” or “reverses” tied to a named condition shift a product from general wellness into drug territory under FDA’s structure/function guidance.
- Quantified outcomes and guarantees. “Lose 20 lbs in 6 weeks” or “guaranteed results” promise a specific, measurable result the brand usually cannot substantiate for every user.
- Clinical and approval-sounding language. “Clinically proven,” “FDA approved” (when the product itself isn’t), or “contains the active ingredient in [brand-name drug]” borrows credibility the product hasn’t earned.
- Testimonial and social-proof traps. Before/after photos, unverified success percentages, or paid endorsements without disclosure violate FTC’s expectations around competent and reliable evidence.
- Brand-adjacent drug phrasing. “Wegovy-like,” “generic Ozempic,” or prescription-pad imagery imply equivalence to an approved drug the product doesn’t have.
Each category above deserves its own entry in a common risk definitions library, not a single blanket ban. A blog post exploring misleading health claims walks through several of these in more depth, particularly the testimonial traps that trip up marketing teams who think a disclaimer solves everything.
How Context and Visuals Turn Safe Words Into Risky Claims
The same ten words can be perfectly fine on one landing page and a warning-letter trigger on another. That’s the part most marketing teams underestimate: FDA and FTC don’t just read your copy, they read your copy in context.
Under 21 CFR 101.93, a structure/function statement becomes an implied disease claim based on wording, product name, packaging, and how prominently a claim sits relative to a disease reference. FDA’s own compliance guidance confirms that images, product names, or placement can convert an otherwise permitted claim into a prohibited one. FTC applies a parallel test: it asks what a reasonable consumer would take away from the ad as a whole, not what the literal words say in isolation, and it requires that claim to rest on competent and reliable scientific evidence.

The NextMed complaint shows this in practice. The FTC alleged the telehealth weight-loss company combined unsubstantiated efficacy claims with fake testimonials, undisclosed material connections, and deceptive pricing mechanics. No single phrase caused the action. It was the stacked pattern of claim plus proof plus pricing structure that drew scrutiny.
Three visual and design cues consistently raise risk:
- Prescription-style packaging or design. Pill bottles, Rx symbols, or clinical color schemes on a supplement suggest drug-level efficacy.
- Disease-named citations placed prominently. Citing a study about diabetes near a claim for a general wellness product implies a disease benefit even without saying the word directly.
- Comparative language next to a drug brand. Charts or callouts that put your product side by side with a named prescription drug invite an implied-equivalence reading.
Partner resource Clinical vs. Cosmetic Claims breaks down this same distinction from a product-formulation angle, worth a look if your team writes for both supplement and cosmetic lines.
Detect, Triage, Remediate, Document: A Workflow You Can Run Today
Most compliance failures aren’t ignorance. They’re a broken process that lets risky language slip through because no one owned the review step. A tight four-stage workflow fixes that.
Detect. Run an automated scan combining keyword and pattern matching with natural language processing that catches implied claims, not just banned words. Follow it with a short human audit focused specifically on context and visuals, the two things automated tools historically miss without NLP support.
Triage. Sort every flag into three tiers with clear ownership:
- High severity: Disease claims, brand-drug comparisons, guaranteed outcomes. Hold publication; requires legal sign-off before release.
- Medium severity: Ambiguous structure/function language, unqualified testimonials, borderline comparative claims. Route to a compliance reviewer within 24 hours; allow provisional rewrite pending approval.
- Low severity: General wellness language that reads clean but needs a qualifier. Marketing lead can approve after applying the standard rewrite pattern.
Remediate. Replace banned phrases with qualified alternatives. “Cures anxiety” becomes “may support a sense of calm.” “Clinically proven to work” becomes “studied in a pilot trial of [n] participants,” when that number is real and documented. Vague qualifiers like “results may vary” rarely satisfy FTC’s substantiation standard on their own; specificity about what evidence exists does more work.
Document. Every ticket should capture the original excerpt, its location, assigned severity, the rewrite applied, and a link to substantiation. That record becomes your audit trail if a platform or regulator ever asks why a piece of content passed review.
Pro Tip: Keep your rewrite library separate from your ticket system. When the same risky phrase shows up in five different assets, your reviewers should be able to pull the approved rewrite in seconds instead of re-litigating it every time.
The pre-publish playbook for content teams covers this same detect-to-document flow with more detail on consumer-interpretation testing specifically.
A Copyable Risk-Term Checklist for Your CMS Gate
Drop this into a pre-publish validation step or a compliance ticket template. It won’t catch everything unique to your brand, but it covers the patterns that account for most enforcement actions in telehealth and supplement marketing.
High-risk, block or require legal sign-off:
- Disease-name plus outcome verb (“treats PCOS,” “reverses insulin resistance”)
- Brand-name drug comparisons (“like Ozempic,” “generic Wegovy”)
- Guaranteed numeric outcomes (“guaranteed 15 lbs”)
Medium-risk, flag for clinical/legal review:
- “Clinically proven” without a linked study
- Before/after imagery without a disclosed typical-result disclaimer
- Comparative superiority claims against unnamed competitors
Low-risk, usually passes with a qualifier:
- “May support” or “may help maintain” framed around a normal body function, paired with the required DSHEA disclaimer
| Phrase Pattern | Severity | Recommended Rewrite | Owner | Notes |
|---|---|---|---|---|
| “Cures [condition]” | High | “May support [normal function]” | Legal | Requires disease-claim review |
| “Clinically proven results” | Medium | “Studied in a [n]-person pilot” | Compliance | Link substantiation |
| “Guaranteed weight loss” | High | Remove guarantee language entirely | Legal | No outcome can be guaranteed |
| “Supports healthy energy” | Low | Add standard DSHEA disclaimer | Marketing | Standard qualifier applies |
The full regulatory review checklist expands this table with row-level guidance for email, social, and packaging separately.
Why This Checklist Holds Up: The Regulatory and Operational Basis
This isn’t a guess dressed up as a compliance framework. Every category above traces back to a specific rule, and the workflow reflects how enforcement actually plays out for telehealth and DTC brands.
- FTC’s Health Products Compliance Guidance sets the substantiation and consumer-interpretation standard behind the triage tiers.
- FDA’s structure/function guidance and 21 CFR 101.93 define exactly when context converts a safe claim into a disease claim.
- FDA’s DSHEA disclaimer guidance confirms a label disclaimer never cures deceptive advertising on its own.
Scancompliant built its detection database around these standards, tracking 1,000+ risk terms drawn from enforcement patterns, warning letters, and regulatory text. That database has already run across content for 200+ brands, and the Compliant Team maintains it as regulatory language shifts.
Recent Enforcement Actions That Show the Pattern
Enforcement against telehealth and DTC weight-loss marketing has picked up noticeably. The NextMed complaint remains the clearest recent case study: the FTC alleged the company ran unsubstantiated efficacy claims alongside fabricated testimonials, undisclosed financial relationships with endorsers, and deceptive negative-option pricing on a weight-loss membership program.
FDA activity has followed a similar arc on the drug side. Coverage from Foley’s compliance analysis documents roughly 30 warning letters targeting telehealth marketing tied to GLP-1 drugs, largely over brand-adjacent language and claims that implied prescription-grade results from non-prescription products.
The pattern across both agencies is consistent: enforcement rarely targets one bad sentence. It targets a stack of small decisions, a testimonial here, a pricing structure there, a comparison to a named drug somewhere else, that together build a case for deception. That’s why a single risky phrase caught in review often isn’t the real threat. It’s the combination that a scanning process, run consistently, is built to catch before it compounds.
Brands that treat a warning letter as a one-off communication misunderstand how these cases build. Agencies frequently reference prior complaints or industry-wide warning letter sweeps as evidence that a company should have known better, which raises the stakes for repeat patterns across a brand’s content library.
Keeping Marketing Content Compliant Over Time
A one-time content sweep fixes today’s problem and leaves tomorrow’s asset unchecked. Ongoing monitoring works differently: it treats every new piece of content, whether a landing page, an email, or a social post, as a fresh scan rather than an exception to a prior review.
The most reliable setups run scans on a fixed cadence, not just at launch. Monthly audits of live pages catch claims that drifted after a copy update or an A/B test introduced new language nobody routed through compliance. Automated scanning tools that plug into a CMS or content calendar catch this drift without requiring a human to remember to check.
Auditing also needs to cover paid social and influencer content, not just owned properties. A brand’s own site might be clean while an affiliate’s Instagram caption makes a disease claim the brand never approved. Building a review step into affiliate and influencer contracts, requiring pre-publish approval for any health-related claim, closes that gap.
Version history matters too. Keeping a dated record of what a page said and when it changed gives your team the ability to show a regulator exactly when a risky claim was caught and fixed, which matters far more than being able to say it’s fixed now.
Email marketing carries its own version of this risk, particularly around pricing and enrollment language that shifts between campaigns. A closer look at telehealth email compliance covers the negative-option and auto-renewal patterns that show up repeatedly in enforcement complaints.

Training Marketing Teams to Catch Risk Before It Ships
Copywriters and social managers aren’t lawyers, and they shouldn’t have to memorize the eCFR to do their jobs. What they need is pattern recognition: enough exposure to real examples that a risky phrase triggers a second thought before it goes into a draft.
Short, recurring training sessions work better than a single onboarding deck nobody revisits. Walking through actual flagged examples from your own content, what got caught, why, and what the approved rewrite looked like, teaches the pattern faster than abstract rules ever will. Pair that with a living glossary of approved and banned phrasing so writers have a reference point mid-draft rather than after a rejection.
Give writers the “why,” not just the “no.” A rule that says “never say clinically proven” without explaining the substantiation standard behind it gets worked around eventually. A writer who understands that FTC wants competent and reliable evidence tends to ask the right follow-up question themselves: “Do we actually have a study that backs this?”
Make the escalation path obvious. Every writer should know exactly who to ask when a claim feels borderline, and that person should be reachable within the same day, not buried in a legal team’s backlog. Slow escalation is often what pushes a writer to publish something risky rather than wait.
Common wellness content mistakes tend to repeat across teams, and a look at wellness blog legal pitfalls is a useful training reference for new hires specifically writing long-form content.
Making Risk-Term Review Part of Your Approval Process
A risk-term checklist only works if it’s built into the workflow, not treated as an optional extra step someone runs when they remember. That means adding a compliance gate to the same system where content already gets approved, whether that’s a CMS publish button, a design proof sign-off, or a paid-media launch checklist.
The strongest setups tie severity tiers directly to sign-off requirements. High-severity flags can’t clear a CMS gate without a legal approval logged in the same ticket. Medium flags route automatically to a compliance reviewer’s queue. Low flags get a lightweight check and move on. That structure keeps the process fast for the majority of content while still slowing down the pieces that carry real exposure.
Compliance also needs a seat earlier than most brands give it. Waiting until a landing page is fully designed before running a risk-term scan means any fix requires rework across copy, layout, and sometimes legal sign-off all at once. Running the scan on draft copy, before design locks it in, saves time and reduces the chance a deadline pressures someone into shipping a flagged claim anyway.
Finally, treat the risk-term database itself as a living document tied to your broader compliance program, not a static list from a training deck two years ago. Regulatory guidance shifts, enforcement patterns shift with it, and a checklist that isn’t updated becomes a false sense of security fast.
How ScanCompliant Puts This Checklist to Work
Running the workflow above by hand across every landing page, email, and social post a telehealth brand publishes isn’t realistic for most teams. Scancompliant automates the scan side of that process: it checks websites, social content, documents, and product listings against a database of 1,000+ risk terms, flags both explicit and implied claims, and returns prioritized findings in minutes instead of the days a manual legal review usually takes.

Each flagged item comes with a plain-English explanation of why it’s risky and a suggested compliant rewrite, so your reviewers aren’t starting from a blank page every time a term gets flagged. That output has already supported compliance review across 200+ brands in telehealth and DTC health, building the kind of documented audit trail regulators and platforms respect if a claim is ever questioned. For teams also weighing data handling requirements, Scancompliant’s security practices cover how content and findings are stored.
If your team is still relying on a shared spreadsheet and institutional memory to catch risky phrasing, a free trial of ScanCompliant is the fastest way to see what an automated pass on your existing content actually surfaces.
From the Compliant Team: Three Habits That Reduce Enforcement Risk
Three habits separate brands that stay clean from brands that end up in a complaint. First, document substantiation for every claim at the moment you make it, not after someone asks. Second, let automated scanning handle the first pass on every asset; save human review for what it flags as medium or high. Third, stay conservative around brand-name drug comparisons, prescription imagery, and specific numeric outcomes. When in doubt, write for what a consumer will reasonably conclude, not for what your legal team can technically defend.
— Compliant Team
This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.
Sources
- Small entity compliance guide on structure/function claims | FDA
- 21 CFR 101.93 — Statements that are disease claims | eCFR
- Health Products Compliance Guidance | Federal Trade Commission
- FTC Complaint: NextMed (Southern Health Solutions, Inc.)
- Questions and answers on dietary supplements | FDA
