Sign in Start free trial
Industry Focus

1,000+ Risk Terms: Prepublish Website Claims Audit for Telehealth & DTC

Editor reviewing a healthcare website claims audit

A website claims audit is the systematic review of your site’s copy, images, and layout to find every explicit and implied health claim, then rank each one by FDA and FTC enforcement risk. The deliverable is not a memo. It is a prioritized findings list, a set of remediation actions, and a documented trail showing who reviewed what and when. Done right, the audit catches disease claims hiding in testimonials and product images just as often as in headlines.


TL;DR:

  • Most claims risk violations if they imply disease treatment, lack proper substantiation, or are presented through misleading testimonials or imagery.
  • Claim mapping must confirm that evidence aligns with the type of claim, as vague or unverified statements easily cross regulatory boundaries.
  • Visual layout and imagery play a critical role, as regulators assess the overall impression, including prominence and implied authority signals.
  • Maintaining a detailed, timestamped documentation trail for each claim helps protect against enforcement and supports rapid response if questioned.
  • Automated tools like Scancompliant streamline the audit process by prioritizing high-risk claims and providing clear, compliant rewrite suggestions.

Table of Contents

What to Gather Before Starting a Website Claims Audit

An audit stalls fast without the right inputs sitting in front of the reviewer. Before anyone opens a single page, assemble the raw material and lock down who signs off on what.

Pull together:

  1. Live page URLs for every revenue-generating page, plus new-launch pages and high-traffic funnel steps.
  2. Creative assets, including product images, video scripts, banner ads, and influencer or affiliate copy tied to the brand.
  3. Analytics showing where and how prominently each claim appears (above the fold, footer, pop-up modal).
  4. Substantiation files, meaning the actual study PDFs, protocols, author names, and publication dates, not just a citation number.
  5. Any prior legal or regulatory signoffs already on record for existing copy.

Once the files are in hand, settle the operational details:

  • Name a single decision owner who has final say on disposition, not a committee.
  • Set a service-level target, such as 48 to 72 hours for routine page reviews.
  • Reserve remediation slots on the calendar so fixes do not sit in a backlog for weeks.
  • Confirm which reviewers have authority to approve final language versus who can only flag risk.

Skipping this stage is the single biggest reason audits drag on for months. A regulatory review checklist built for healthcare marketing teams helps standardize this intake step so it does not get reinvented every quarter.

How Do You Run a Website Claims Audit Step by Step?

The workflow below scales from a single landing page to a full site migration. Run it in order. Skipping the evidence-mapping step is where most teams get burned, because a claim can look fine on its face and still lack the substantiation regulators expect behind it.

  1. Scope the review. Start with revenue pages, new product launches, and funnel pages with the heaviest traffic. Do not try to audit the entire site in one pass; prioritize by exposure.
  2. Capture claims verbatim. Extract exact passages, screenshot every image and its surrounding layout, and note contextual cues, like a “before and after” photo sitting next to a testimonial, that shape what a reader takes away.
  3. Map evidence to each claim. For every claim, ask what actually backs it. The FTC’s guidance sets the bar at “competent and reliable scientific evidence,” and for most health claims that means well-designed, human clinical trials, not a mechanistic explanation of how an ingredient behaves in a petri dish.
  4. Rate the risk. Use a three-tier rubric: high risk covers disease claims or claims with no substantiation at all; medium risk covers exaggerated benefit language or claims that need a qualifier; low risk covers wording tweaks or disclosure placement issues.
  5. Remediate by tier. High-risk claims usually get removed outright. Medium-risk claims often survive with a qualifier added or a link to the supporting study placed in the same visual frame. Low-risk items might just need the disclosure moved higher on the page.
  6. Verify and sign off. A named approver reviews the final language, timestamps the decision, and the record gets stored, not just emailed and forgotten.

Pro Tip: Draft two versions of every remediated claim: one with the qualifier baked into the sentence, one with it as an adjacent disclosure. Legal and marketing often disagree on which reads more natural, and having both ready cuts a full review cycle.

The evidence-mapping step deserves extra attention because it is where subjective judgment creeps in. A claim like “supports healthy metabolism” reads as a low-risk structure/function statement. Change it to a claim quantifying an improvement and you have both introduced a specific, disprovable assertion and edged toward a claim that needs real trial data behind it. The structure/function compliance guide from the FDA lays out the exact criteria auditors should apply when that line gets blurry. Teams running this internally often build out a step-by-step review process so junior reviewers apply the same standard senior counsel would.

What Are the Most Common Red Flags in a Claims Audit?

Certain patterns show up again and again once you start scanning DTC health and telehealth copy at scale. Recognizing the shape of a risky claim matters more than memorizing a list of banned words, because the same idea can be safe or dangerous depending on three or four words.

  • Disease claims disguised as benefit language. “Supports healthy blood sugar” is a structure/function claim. “Lowers blood sugar” or “treats prediabetes” crosses into disease-claim territory under 21 CFR 101.93(g), which usually requires premarket review or robust clinical substantiation.
  • “Clinically proven” without a real trial behind it. A single, small, company-funded study rarely meets the bar. The FTC’s evidence standard leans toward randomized, controlled trials, and one underpowered internal study is a common finding in enforcement actions.
  • Testimonials presented as typical results. Featuring a dramatic transformation without disclosing that it is not typical, or without disclosing a paid relationship with the person featured, is one of the most frequently cited violations in FTC guidance.
  • Imagery that implies clinical authority. A model in a lab coat next to a supplement bottle, or a stock photo of a clinical setting near a claim, can shift the net impression toward implied medical endorsement even if the text itself is careful.

The FTC’s 2022 guidance update extended these principles from dietary supplements to every health-related product category, with dozens of worked examples showing exactly how small wording shifts change the risk profile. A shorter reference for spotting these patterns quickly lives in this guide to misleading health claims for DTC brands.

How Do Images and Page Layout Create Hidden Claim Risk?

Text-only scans miss a large category of risk, because regulators evaluate the combined “net impression” of a page, not isolated sentences. A paragraph that reads as cautious can still create an aggressive claim when it sits next to the wrong photo.

  • Treat every creative asset, image, video frame, and banner, as claim-bearing material and screenshot it with its surrounding context intact.
  • Flag authority signals like lab coats, microscopes, clinical backdrops, or clinician headshots, and ask whether they imply a level of medical validation the copy does not support.
  • Check prominence. Risk disclosures buried in a footer or tucked onto a separate terms page do not satisfy fair balance if the benefit claim sits boldly in the hero section.
  • Run a rapid net-impression test: read the page as a first-time visitor with no product knowledge and write down the one claim they would walk away believing.

Pro Tip: Screenshot the page as it renders on mobile, not just desktop. Disclosure text that sits comfortably next to a claim on a wide screen often gets pushed three scrolls away on a phone, which is exactly the kind of prominence problem that shows up in enforcement reviews.

How Should You Document Every Claims Audit Finding?

An audit without a paper trail is just an opinion. If a regulator or platform ever asks why a claim was approved, the answer needs to exist in a searchable record, not in someone’s memory of a Slack conversation from eight months ago.

Each finding should carry, at minimum: the page URL, the verbatim quoted passage, a screenshot, the claim classification (disease, structure/function, or other), a link to the evidence cited, the assigned risk rating, the remediation recommendation, the reviewer’s name and date, the approver’s name and date, and the final disposition. That level of detail is what regulators actually look for during an inquiry, not a summary paragraph written after the fact.

Field Why it matters
Verbatim passage Proves exactly what was published, not a paraphrase
Screenshot Captures layout and imagery context for net-impression review
Evidence link Ties the claim to its substantiation, or shows the gap
Risk rating Drives prioritization and remediation urgency
Reviewer and approver, with dates Establishes accountability and a timestamped trail

Store substantiation files in a centralized, versioned repository linked directly to each finding rather than scattered across email threads and shared drives. Retention matters too: keep logs searchable and timestamped so they can be exported quickly if the FTC or FDA ever comes asking. This is where automation earns its keep. A platform like Scancompliant scans copy and creative assets against a database of more than 1,000 risk terms, delivers prioritized findings in minutes instead of days, and preserves the entire trail automatically, which is a meaningful advantage over a spreadsheet that three different people are updating asynchronously. Teams building this out from scratch can start with a primer on what a compliance trail actually needs to contain.

Who Regulates What: FDA Labeling vs. FTC Advertising

The two agencies split responsibility in a way that trips up a lot of marketing teams. The FDA generally governs labeling, meaning what appears on physical product packaging and inserts, while the FTC regulates advertising, which includes your website, social posts, email campaigns, and influencer content. That split matters because a claim that would never pass on a product label can still show up on a landing page if a marketing team assumes FDA rules are the only ones in play.

FDA and FTC claims oversight comparison

In practice, the two agencies coordinate closely, and a claim that draws FDA attention on packaging often draws FTC attention in the ad copy promoting that same product. The FTC’s standard is broader in one respect: it covers the entire consumer-facing experience, from hero banner to checkout page footer. That means your website claims audit cannot stop at the “About” page copy the legal team already reviewed once. It has to cover every page a paying customer might land on, including pages the marketing team spun up for a single ad campaign and never routed through formal review.

For telehealth and DTC brands specifically, this dual jurisdiction means a single sentence, say, a claim about a compounded medication’s effect, could theoretically draw scrutiny from both agencies depending on where it appears and how it is framed. Building your audit around FTC’s advertising standard as the baseline, since it covers the website itself, while keeping FDA’s labeling and structure/function rules in view for product pages, closes that gap.

When Does a Structure/Function Claim Become a Disease Claim?

Structure/function claims describe how a product affects the normal structure or function of the body, phrases like “supports joint flexibility” or “promotes healthy digestion.” FDA guidance allows these without premarket approval, provided they do not claim to diagnose, treat, cure, mitigate, or prevent a specific disease.

The line gets crossed more easily than most marketing teams expect. Naming a specific disease is the obvious trigger, but implied disease claims count just as much. Claiming a product “restores normal insulin function” edges close to implying diabetes treatment even without saying the word “diabetes.” Referencing a disease’s symptoms, “eases joint pain from arthritis,” can also flip a structure/function claim into a disease claim depending on context and emphasis.

Three factors tend to decide which side of the line a claim falls on: whether the statement names or clearly implies a specific disease, whether it claims to affect the disease’s cause rather than a general body function, and whether accompanying imagery or context (a person in a hospital gown, a reference to “patients”) reinforces a treatment implication the text alone might not carry. Qualified health claims offer a narrow middle path here. When evidence is suggestive but not conclusive, FDA’s qualified health claims framework allows a claim to run with specific qualifying language attached, rather than forcing a binary choice between a bold claim and no claim at all. Getting that qualifying language right, and making sure it is prominent rather than buried, is often the difference between a defensible page and a flagged one.

Why Fair Balance Between Benefits and Risks Matters

A page that spends four paragraphs on benefits and one line on risk, in six-point gray font, in the footer, has a fair balance problem even if every individual sentence on the page is technically true. Regulators evaluate the overall impression a reasonable consumer walks away with, and a lopsided presentation shifts that impression regardless of what the fine print says.

Fair balance means risk information gets comparable visual weight and comparable proximity to the benefit claim it modifies. If a headline claims a product “clears symptoms fast,” the relevant side-effect or limitation language needs to sit close enough that a reader scrolling past the headline actually sees it, not three screens later after a call-to-action button. Font size, color contrast, and placement all factor into this, and enforcement actions have specifically cited disclosures that were technically present but functionally invisible.

Balanced benefit and risk disclosure layout

For telehealth brands advertising prescription-adjacent products, like GLP-1 medications or compounded treatments, this standard gets stricter, not looser. The FDA has signaled increased scrutiny of direct-to-consumer advertising for these categories, with a 2025 enforcement initiative aimed at closing gaps in risk disclosure across digital advertising. Brands operating in that space benefit from a category-specific review, since the risk tolerance for a supplement claim and a prescription-adjacent claim are not the same. A GLP-1 focused compliance scanner exists specifically because generic health-claim checklists tend to under-flag risk in this category.

What Happens if Your Website Claims Are Non-Compliant?

Enforcement rarely starts with a lawsuit. It usually starts with a warning letter from the FDA or a civil investigative demand from the FTC, both of which require a documented response showing what claims were made, what evidence backed them, and what changed once the issue surfaced. Brands without an audit trail scramble at this stage, often pulling pages down entirely rather than making a defensible, targeted fix.

When enforcement escalates, consequences can include consent orders requiring specific corrective advertising, monetary penalties, and in repeated or egregious cases, injunctions barring certain claims industry-wide. The FTC has also increasingly required companies to notify affected consumers directly when a claim is found deceptive, which carries reputational cost well beyond the legal one. For telehealth and DTC brands specifically, platform policy enforcement often arrives faster than government action does. Ad platforms and payment processors can suspend accounts over claim violations long before the FTC or FDA ever opens a formal file, which makes pre-publication review a practical necessity, not just a legal one.

The pattern across enforcement cases is consistent: brands that could produce a clear record of who reviewed a claim, what evidence they relied on, and when they corrected it faced materially better outcomes than brands that could not reconstruct any of that history.

Publisher Perspective: Building Claims Audits Into the Workflow, Not Bolting Them On

Most compliance failures do not come from ignorance of the rules. They come from timing. A claim gets written, approved by marketing, published, and only reviewed by legal weeks later, if at all. By then, the cost of reversing course, both reputationally and financially, is much higher than catching it before launch.

The fix is structural: a pre-publish gate with a short checklist and one named decision owner, not a committee that meets biweekly. Pair that with a living risk-term list and brief training modules so writers and outside agencies internalize the patterns instead of waiting for a redline. Set real SLAs, something like 48 to 72 hours for routine pages with expedited slots reserved for launches, and make the escalation path for disputed claims explicit rather than assumed. Automation is what makes this sustainable at scale: let it handle the repetitive scanning so your subject matter experts spend their time on the judgment calls that actually need a human, like weighing whether a study’s evidence tier meets the substantiation bar.

*— Compliant Team *

How Scancompliant Fits Into Your Claims Audit Workflow

Everything described above, scoping, capturing claims, mapping evidence, rating risk, remediating, and documenting, is exactly what Scancompliant automates for regulatory and marketing teams who cannot spend three weeks manually screenshotting every page on a site. It scans your website, social content, documents, and product listings against a database of more than 1,000 risk terms, flags both explicit and implied claims a human reviewer might skim past, and hands back prioritized FDA and FTC findings in minutes rather than days.

Scancompliant

That speed matters most at the evidence-mapping and risk-rating steps, the two places where manual review typically bottlenecks. Scancompliant’s integrated AI assistant explains why a flagged phrase is risky in plain English and suggests compliant rewrite options, so your team spends its time evaluating evidence rather than reformatting sentences. Every scan preserves a timestamped record automatically, solving the documentation problem this article spent an entire section on. More than 200 brands already run their pre-publication reviews through the platform. If your next product launch has a publish date on the calendar, start a Scancompliant trial and run your current site through it before that date arrives, or check the security and data handling details first if procurement needs the paperwork.

This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.

Sources

S

ScanCompliant Team

← Previous
1,000+ Risk Terms List for Telehealth & DTC Marketers
Next →
5 Steps to Compliant HIPAA SMS Marketing for U.S. Healthcare Teams

Leave a Comment

Your email address will not be published. Required fields are marked *