Medical Spa Compliance in Florida: Supervision Requirements, Delegation Rules, and Common DOH Violations

Medical Spa Compliance in Florida

Florida’s med spa boom comes with real regulatory risk. This guide to medical spa compliance in Florida covers physician supervision requirements, delegation rules, why “name-only” medical directors face outsized liability, and the top gaps that trigger DOH investigations.

Continue reading

Michigan criminal case is important for RUO peptide companies.

Credit: Jeff Cohen

It’s not new that RUO peptide companies are the favorite target of regulators, lawmakers and Pharma. While there has been some criminal activity in the RUO space, it’s seemed till now to be largely related to other darker factual allegations—the sale of controlled substances (e.g., steroids) or even biologicals (e.g., HCG and HGH) and very “over the line” promotion of human use. But the government’s tolerance in the RUO space seems to be thinning by the moment. 

Everyone in the industry now knows re the Lilly lawsuits directed a three Texas based RUO companies and one CA based compound pharmacy. There, the primary focus was on the sale of retatrutide. But a new Michigan plea agreement resulting in a judgment on July 23, 2026 and imprisonment of 21 months should have the entire RUO industry readjusting their risk sensors. Why? Because the primary gist of the case involved semaglutide and tirzepatide. 

There’s far more to it that that and lots of learn from the case. In USA v. Brandon Piper, the facts born of the filings include—

•Sale of sema, triz and retatrutide

•Claim that the defendant intentionally mislead the government with RUO/NFHC labelling, when he knew purchasers will buying for personal use

•The website promoted the products in a manner clear they were intended for human use (e.g., claims re the products’ impact of human health, side effects)

•Lack of a prescription for the “prescription drugs” sema and tirz

•The site never asking purchasers to verify they would use the products for research

•Operation of an affiliate program where products were promoted and dosing information was provided

•“Coaching” on use of the products

•Insufficient evidence of products being tested

•The website inviting customers to conceal from the checkout page the identity of what they bought

•Lack of registration with the FDA to manufacture and sell drugs

•Labeling “Product of the USA” when the products came from China

The Pipercase is important because it demonstrates the federal government’s resolve to address concerns previously addressed in other cases and in FDA Warning Letters. But it’s value is in the fact that the details in the case are even more illustrative of what the government considered to be a criminal violation and one worthy of prosecution. It’s also very instructive to know that Mr. Piper was no kingpin by anyone’s standards. The government stated he earned a total of about $218,000 through his criminal activity. 

Attorney Rick Collins represented Mr. Piper and will be featured soon in an online webinar hosted by the American Peptide Association. 

Can a Non-Doctor Own a Medical Practice in Florida? Ownership Rules Explained

non-doctor own medical practice Florida

Can a non-doctor own a medical practice in Florida? Florida law allows certain non-physician ownership structures, but licensing, clinic exemptions, MSO arrangements, and clinical control requirements can make ownership complex. Learn the key rules and compliance considerations before starting or buying a Florida medical practice.

Continue reading

The IV Hydration Industry Is Entering a New Era of Regulatory Enforcement

By: Carlos Arce, Attorney

For years, the IV hydration industry has been one of the fastest-growing sectors in healthcare. As consumer demand for wellness services has expanded, the industry has evolved from a niche offering into a mainstream healthcare business.

Alongside that growth, regulatory expectations have also evolved. Throughout 2026, increased attention from State Attorneys General, Departments of Health, Medical Boards, and other licensing authorities has highlighted a broader focus on how IV hydration businesses are structured, governed, and operated—not simply whether they employ licensed providers.

One recurring area of review is the Corporate Practice of Medicine (“CPOM”). Regulators are increasingly evaluating questions such as:

• Who controls the medical practice?

• Is the medical director actively providing clinical leadership?

• Who develops and approves treatment protocols?

• Are non-clinical owners appropriately separated from medical decision-making?

• Can the organization demonstrate meaningful physician oversight through its documentation and operations?

Recent regulatory activity in states including California, Illinois, Indiana, and others has included requests for physician supervision protocols, standing orders, medical director agreements, quality assurance records, and related documentation that demonstrates clinical oversight in practice.

An important takeaway is that compliance extends beyond appointing a medical director. Increasingly, regulators are evaluating whether governance, physician involvement, clinical protocols, and operational processes align with applicable legal and regulatory requirements.

Rather than viewing regulatory developments as a reason for concern, IV hydration providers can use them as an opportunity to evaluate and strengthen their organizations. Periodic reviews of ownership structures, physician oversight, documentation, and operational workflows can help identify areas for improvement before questions arise.

As the industry continues to mature, organizations that invest in proactive compliance will be well positioned for sustainable growth. Building compliance into daily operations—not simply organizational charts—supports both quality patient care and long-term business success.

AI Is Transforming Healthcare—But Are Your Privacy Policies Keeping Up?

By: Carlos Arce, Attorney

Artificial intelligence is quickly becoming a standard part of healthcare operations. From ambient AI documentation tools that generate clinical notes to voice-assisted transcription platforms and automated workflow solutions, healthcare organizations are increasingly adopting technologies designed to improve efficiency and allow providers to spend more time focused on patient care.

As these tools become integrated into everyday practice, organizations should ensure their policies and compliance documentation evolve alongside the technology. AI implementation is not simply an IT decision—it also requires a thoughtful review of privacy practices, patient communications, vendor relationships, and internal governance.

Key Policies to Review

Healthcare practices adopting AI technologies should evaluate whether the following documents adequately address their use:

Notice of Privacy Practices (NPP): Consider whether the notice accurately describes how patient information may be collected, processed, stored, or disclosed through AI-assisted technologies.

Patient Consent and Intake Forms: Depending on the AI platform being used and applicable federal and state law, practices should determine whether patients should receive additional disclosures or have the opportunity to consent to—or decline—the use of AI-assisted recording or documentation during their visit.

Internal Privacy and Security Policies: Policies should address how AI tools are selected, monitored, and used by staff, including appropriate safeguards for protected health information (PHI).

Workforce Training: Employees should understand when AI tools may be used, what information may be entered into those systems, and the organization’s expectations for protecting patient privacy.

Vendor Management: Practices should verify that AI vendors handling PHI execute appropriate Business Associate Agreements (BAAs) where required and maintain HIPAA-compliant security and privacy practices.

Compliance Considerations

The use of AI may implicate several regulatory frameworks depending on the technology and the jurisdiction in which a practice operates. Organizations should evaluate their compliance obligations under HIPAA, the HITECH Act, the 21st Century Cures Act, applicable state privacy laws such as the Florida Information Protection Act (FIPA), state recording consent laws, and any applicable professional licensing requirements.

In addition to regulatory compliance, practices should establish internal procedures for evaluating new AI technologies before deployment. This includes understanding how patient data is processed, where it is stored, who has access to it, and whether the vendor’s security practices align with the organization’s compliance requirements.

Building an AI Governance Strategy

Rather than treating AI implementation as a one-time technology upgrade, healthcare organizations should incorporate AI into their ongoing compliance and risk management programs. Periodic reviews of privacy policies, consent documents, vendor agreements, and employee training materials can help ensure that organizational policies continue to reflect evolving technologies and regulatory expectations.

As AI continues to reshape healthcare delivery, practices that proactively update their policies and governance frameworks will be better positioned to integrate innovation while maintaining patient trust and supporting regulatory compliance.

Fractional Clinical Oversight vs. Legal Compliance: Why Healthcare Practices Need Both

By: Carlos Arce, Attorney

Healthcare providers across the country, including IV hydration clinics, med spas, wellness practices, and other cash-based healthcare businesses, have increasingly faced audits and investigations by state regulatory agencies regarding alleged Corporate Practice of Medicine (“CPOM”) violations and inadequate medical director oversight. One trend has become increasingly apparent.

Many of these businesses were established with the assistance of fractional medical director or supervising physician platforms. These organizations provide a valuable service by connecting practices with qualified physicians, assisting with clinical oversight, and helping providers navigate the operational aspects of launching a healthcare business. There is undoubtedly a place for these services in today’s rapidly growing healthcare industry. The problem arises when these platforms begin providing legal guidance regarding corporate structuring and regulatory compliance.

Too often, businesses are told they are “fully compliant” simply because template documents were provided or a basic management structure was recommended. However, when a state regulatory agency requests documentation demonstrating the separation between the clinical entity and the management company, the independence of medical decision-making, the authority exercised by the medical director, or the operational safeguards required under applicable state law, the necessary legal framework simply is not there. At that point, defending the practice becomes exponentially more difficult.

Regulatory compliance is not determined by whether a set of documents exists. It is determined by whether the structure, governance, operational practices, contractual relationships, and day-to-day conduct of the business comply with the specific laws and regulations of the applicable state. Every state approaches these issues differently, and many require far more than standardized agreement terms or generalized guidance.

Unfortunately, many healthcare practices operate under the belief that they are protected or compliant because they relied upon a supervising platform’s recommendations, only to discover during an audit that the legal analysis supporting those recommendations was either incomplete or nonexistent. The result is unnecessary regulatory exposure, significant legal expense, and avoidable disruption to the business.

This is not intended as criticism of fractional supervising platforms. On the contrary, they provide an important and increasingly necessary service within the healthcare ecosystem. The issue is one of professional boundaries.

Clinical oversight should remain the responsibility of physicians and clinical experts. Corporate structuring, CPOM analysis, governance documents, management services agreements, ownership structures, and state regulatory compliance should remain the responsibility of attorneys who focus their practices in healthcare law. When each professional stays within their respective area of expertise, the healthcare provider receives the benefit of both strong clinical oversight and a legally defensible business structure.

Healthcare regulation continues to become more sophisticated, and state agencies are devoting greater resources to examining ownership structures, management arrangements, and physician oversight. Providers deserve a compliance strategy that is built not only to help them launch their business, but also to withstand regulatory scrutiny years later. The goal should never be to simply “look compliant.” The goal should be to actually be compliant and to have the documentation, governance, and legal analysis necessary to prove it when regulators come knocking.