The recent sentencing of Done founder Ruthia He to six years in federal prison is another reminder that rapid growth in telehealth does not reduce the need for meaningful compliance safeguards.
According to the Department of Justice, Done’s leadership prioritized rapid growth and prescription volume over appropriate medical judgment, resulting in unlawful prescribing practices involving controlled substances. While the circumstances of this case are particularly serious, the broader enforcement concerns extend beyond one telehealth company.
What Telehealth Providers Should Be Watching
Federal regulators continue to examine how telehealth services are structured and operated. Compliance concerns can extend beyond individual prescribing decisions to the broader business model supporting those services.
Telehealth organizations should pay close attention to clinical independence and physician oversight, medical necessity and documentation, controlled substance prescribing protocols, marketing and lead-generation relationships, compensation arrangements, and corporate governance and compliance infrastructure.
MDRXLAW advises healthcare organizations on investigations and compliance as they develop and review compliance programs designed to address regulatory risks.
Growth and Compliance Need to Work Together
Rapid growth can create new compliance risks if policies and oversight do not keep pace. A telehealth company may need to regularly reassess how its prescribing practices, contracts, marketing arrangements, documentation, and internal compliance programs operate as the business changes.
Compliance should not be treated as something to address only after receiving a subpoena, audit, or government inquiry. Reviewing potential issues early can help organizations identify gaps and address them before they become enforcement matters.
Healthcare organizations facing regulatory scrutiny may also need to understand how to respond when government agencies request information or begin an investigation. MDRXLAW provides guidance and representation in government investigations, including matters involving audits, subpoenas, and other government inquiries.
What Telehealth Organizations Should Review
Telehealth providers and businesses should consider reviewing their internal policies and procedures, prescribing practices, physician oversight structures, marketing relationships, compensation arrangements, and documentation practices.
For organizations operating in digital healthcare, these issues form part of the broader legal and regulatory considerations addressed through MDRXLAW’s Digital Health / Telehealth practice.
The goal is to ensure that the operational model supporting growth is consistent with applicable healthcare and regulatory requirements.
At MDRXLAW, we advise telehealth companies, healthcare providers, physician practices, management organizations, and investors on regulatory compliance, government investigations, audits, and enforcement matters.
For assistance, contact MDRXLAW at 212.668.0200 or info@mdrxlaw.com


