Pharma Marketing Compliance: A Working Guide for Media Teams
A working guide to pharma marketing compliance for media teams: who regulates what, what the media team owns, and a checklist by campaign stage.
The short answer
Pharma marketing compliance for a media team means three things: running only MLR-approved claims with the required risk information in every format, using data and targeting that respect HIPAA, the FTC, and state health privacy laws, and keeping records that show what ran, where, and to whom. FDA's Office of Prescription Drug Promotion governs the message. Privacy regulators govern the data. Your job is to make sure the plan does not break either set of rules in execution.
This guide is for planners, buyers, analytics leads, and account people who sit between a brand's regulatory team and the platforms that actually serve the ads. It is not legal advice. It is a map of who regulates what, which decisions land on the media team's desk, and where campaigns usually go wrong.
If you want the older, shorter overview of creative and targeting rules, start with the pharma advertising compliance guide. This one is organized around regulators and campaign stages instead.
What pharma marketing compliance covers for a media team
Media teams need a narrower view than regulatory affairs or legal. You are not deciding whether a claim is supported by substantial evidence. You are deciding which version of an approved asset runs in which placement, which audience it reaches, which pixels fire on the landing page, and whether the record of all that holds up if someone asks a year later.
That breaks into two halves that often get managed by different people:
- Message compliance. Fair balance, the ISI, the ad type (product claim, reminder, or help-seeking), and making sure the format does not cut off or bury risk information.
- Data compliance. How audiences are built, what health information flows to ad platforms, consent, sensitive locations, and what tags collect on brand and patient sites.
The failures that hurt most usually sit in the gap between the two. A perfectly approved banner can still be a problem if it is served against a targeting segment built from data the brand had no right to use. A clean data flow can still produce a violative ad if the ISI was truncated by a publisher's ad template.
Who regulates what: FDA, FTC, HHS, and the states
The table below is a simplification, but it is the version I would put on a slide for a new planner. Check current rules with your regulatory team; several of these areas have changed in the last few years and are still moving.
| Regulator | What it covers | Where it touches media | Typical media team question |
|---|---|---|---|
| FDA, Office of Prescription Drug Promotion (OPDP) | Prescription drug advertising and promotional labeling under the FD&C Act and 21 CFR 202.1 | Claims, fair balance, ISI, ad type, format limits, Form FDA 2253 submissions | Does this unit size or video length still carry the required risk information? |
| FTC | OTC drug advertising, unfair or deceptive practices, the Health Breach Notification Rule for non-HIPAA health apps | Pixels and SDKs that share health data, privacy promises, health apps and tools | Does our symptom tracker or savings tool send health data to ad platforms? |
| HHS Office for Civil Rights | HIPAA for covered entities (providers, plans, clearinghouses) and their business associates | Hub programs, pharmacy partners, provider data, tracking on covered entity sites | Is this data PHI, and do we have a valid authorization to use it for marketing? |
| State attorneys general (and some private plaintiffs) | Consumer health data laws (for example Washington, Nevada, Connecticut) and comprehensive privacy laws such as California's | Consent for collection and sharing, geofencing near health facilities, sale of health data, opt-outs | Do we need separate consent before this audience can be built or shared? |
| Platforms and industry codes | Google, Meta, and other platform health policies; NAI and PhRMA codes | Certification, sensitive category restrictions, prohibited targeting | Will the platform even accept this targeting setup? |
Two points get missed. First, FDA generally does not approve ads before they run; most materials are submitted at first use, which makes internal review the real gate. Second, HIPAA reaches pharma marketing far less often than people assume, while state consumer health laws reach it more often than people assume. Both are covered below.
FDA rules on the message: fair balance, ad types, and enforcement
The core FDA rule is that prescription drug advertising cannot be false or misleading and must present a fair balance of benefit and risk information. In digital that turns into format questions: how ISI scrolls in a 300x250, how risk appears in a six-second bumper, and whether a social post with a character limit can carry a product claim at all. Fair balance in digital pharma ads walks through banners, video, and social formats, including the clear, conspicuous, and neutral standard FDA finalized for TV and radio major statements.
The ad type sets what the ad is allowed to say. A product claim ad names the drug and what it treats and has to carry risk. A reminder ad names the drug without the indication and is not available for every product. A help-seeking ad talks about a condition without naming a drug. Mixing them in one placement or sequence can turn two compliant ads into one noncompliant one. Reminder, help-seeking, and product claim ads explained covers the differences and how media planning can accidentally combine them.
Enforcement has been more active recently. FDA announced a large wave of DTC enforcement letters in September 2025 and said it would pursue rulemaking on the broadcast "adequate provision" approach; as of this writing in 2026 a proposed rule was still expected rather than final, so check its current status. Reading the letters themselves is the best training available. What media teams can learn from OPDP untitled and warning letters explains how to read them and which themes keep showing up.
Privacy rules on the data: HIPAA, the FTC, and state laws
A drug manufacturer is usually not a HIPAA covered entity, so HIPAA does not govern most brand media directly. It does govern the data that covered entities and their business associates hold, which matters when a hub, pharmacy, or provider partner is involved, and when a covered entity's website runs tracking tags. HIPAA and pharma advertising lays out where it applies and where it does not, including the 2024 court decision that vacated part of HHS's tracking guidance.
Where HIPAA stops, other rules start. The FTC's Health Breach Notification Rule, updated in 2024, treats an unauthorized disclosure of health data from a covered app or tool as a breach, which puts pixels and SDKs on brand-owned tools in scope. See the FTC Health Breach Notification Rule for health marketers.
State laws are the fastest-moving piece. Washington's My Health My Data Act, Nevada's SB 370, and Connecticut's amendments to its privacy law all define consumer health data broadly and restrict geofencing around health facilities. Some require separate consent for collection and for sharing. State consumer health data laws and pharma media covers what media teams usually have to change.
The practical control point for most of this is the brand website and any tool or app the brand runs. Tracking pixel governance on pharma and health websites describes the inventory, consent, and audit routine I would expect to see.
What the media team owns and what it does not
Regulatory responsibility sits with the manufacturer. That does not mean the agency or in-house media team is a bystander. In practice, the media team owns:
- Running only approved creative versions, in approved sizes and lengths, with the approved ISI treatment.
- Keeping targeting, data sources, and exclusions within what privacy review approved.
- Placement controls: sensitive category exclusions, brand safety settings, and publisher lists.
- Forwarding potential adverse events from comments, emails, or publisher reports to the client's safety process within the agreed window.
- Records: trafficking sheets, approval codes, tag inventories, and change logs.
The media team does not own claim substantiation, label interpretation, or legal judgments on privacy law. When a planner starts deciding those, something has gone wrong with the process. MLR review for programmatic media covers what to submit so reviewers can make those calls quickly, and what compliance capabilities to require from a pharma media agency turns this list into contract and RFP language.
A compliance checklist by campaign stage
This is the checklist I would want a team to run. It is not exhaustive and it does not replace your company's SOPs, but most of the problems I have seen would have been caught by one of these lines.
| Stage | Check | Owner (typical) |
|---|---|---|
| Brief | Confirm ad type for each tactic (product claim, reminder, help-seeking) and whether the product has a boxed warning | Brand and regulatory |
| Brief | List every data source behind each audience, with its consent basis and any state law exposure | Media and privacy |
| Planning | Map every format and size to an approved ISI treatment; drop units that cannot carry it | Media and creative |
| Planning | Check geofence, location, and sensitive condition targeting against state law and platform policy | Media and privacy |
| MLR submission | Submit the creative in context: unit sizes, ISI behavior, landing pages, targeting description, and sequencing | Agency and brand |
| Trafficking | Match every live tag to an approval code and expiry date; no unapproved variants | Ad operations |
| Prelaunch QA | Render each unit on real inventory and confirm ISI scrolls, links work, and the landing page matches | Ad operations and QA |
| Prelaunch QA | Scan landing pages for tags and confirm what each one sends | Analytics and privacy |
| In flight | Monitor comments and publisher reports for potential adverse events; forward per SOP | Social and account teams |
| In flight | Re-review when creative, audience, or landing page changes, even if the change looks small | All |
| Wrap | Archive trafficking sheets, placement reports, tag scans, and approval records | Agency and brand |
The prelaunch rows are where good plans meet bad ad templates; the prelaunch QA checklist for pharma programmatic goes further.
Where pharma marketing compliance usually breaks
The patterns repeat across brands and agencies:
- Format drift. A plan adds a new unit size, a shorter video cut, or a native format late in the process and nobody resubmits. The ISI does not fit, or the major statement gets compressed.
- Audience drift. A vendor segment gets swapped for a "similar" one with a different data source. Privacy review approved the first, not the second.
- Landing page drift. Someone adds a chat widget, heatmap tool, or new ad pixel to a branded page after launch. Nobody re-scans.
- Sequencing that mixes ad types. A help-seeking unit and a branded unit run back to back with the same look, and the pair reads as one product claim without risk information.
- Adverse event leakage. A comment that mentions a side effect sits in a social inbox for a week because no one on the media side knew it counted.
None of these need a new regulation to fix. They need a change log, a re-review trigger, and a named owner.
Practical takeaway
Pick one live campaign and build a single sheet with three columns for every placement: the approved creative code and ISI treatment, the audience and its data source, and the tags firing on its landing page. If any cell is blank or says "same as before," that is your first compliance fix. Then bring the sheet to your regulatory and privacy partners and agree on which changes trigger re-review. Treat this guide as orientation, not legal advice, and confirm specifics with them.
Frequently asked questions
Who regulates pharmaceutical advertising in the US?
FDA, through the Office of Prescription Drug Promotion, oversees prescription drug promotion, while the FTC covers over-the-counter drug advertising and unfair or deceptive data practices. HHS OCR enforces HIPAA against covered entities and business associates, and state attorneys general enforce state privacy and consumer protection laws. Each one reaches a different part of a media plan.
Does FDA approve drug ads before they run?
Generally no. Companies submit most promotional materials to FDA on Form FDA 2253 at the time of first use, and FDA may comment or act afterward. Pre-clearance applies only in limited situations, so the company's own MLR review is the practical gate.
Is the media agency responsible for compliance?
The manufacturer carries the regulatory responsibility, but the agency is responsible for running only approved materials, following targeting and data rules in the contract, and passing potential adverse events to the client. Most enforcement problems that touch media come from execution gaps, not from the regulation being unclear.
Is this guide legal advice?
No. It is a practitioner's orientation for media teams. Rules, guidance, and enforcement priorities change, so confirm specifics with your regulatory, legal, and privacy colleagues before acting.
Sources
- FDA, The Office of Prescription Drug Promotion (OPDP)
- eCFR, 21 CFR 202.1 Prescription-drug advertisements
- HHS OCR, Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates
- FTC, Health Breach Notification Rule: The Basics for Business
- Washington State Office of the Attorney General, Protecting Washingtonians' Personal Health Data and Privacy
External guidance and platform documentation change. Links were current at publication; check them again before relying on them for a decision.
Editorial note. Analysis and frameworks are the author's own and do not represent Acxiom or any current or former employer, client, or named platform. Examples labeled hypothetical or illustrative are not results from real campaigns. Nothing here is legal, regulatory, or medical advice.
Everything in this series
This guide is the entry point. Each article below answers one narrower decision in depth.
Fair Balance in Digital Pharma Ads: Banners, Video, and Social
What fair balance means in digital pharma ads under 21 CFR 202.1, how ISI works in banners, video, and social, and the format mistakes that cause problems.
8 min read →Compliance & PrivacyOPDP Untitled and Warning Letters: What Media Teams Can Learn
What OPDP untitled letters and warning letters are, the themes that recur, how media format and placement contribute, and how to read the letters on FDA's site.
6 min read →Compliance & PrivacyHIPAA and Pharma Advertising: Where It Applies and Where It Does Not
HIPAA and pharma advertising explained: why manufacturers are usually not covered entities, when HIPAA reaches marketing data, and what tracking guidance means.
7 min read →Compliance & PrivacyState Consumer Health Data Laws and Pharma Media
How state health privacy laws like Washington's My Health My Data Act affect pharma media: consent, sharing, geofencing bans, and what teams must change.
7 min read →Compliance & PrivacyThe FTC Health Breach Notification Rule: What Health Marketers Need to Know
The FTC Health Breach Notification Rule explained for marketers: who it covers after the 2024 update, why pixel sharing can be a breach, and what to check.
7 min read →Compliance & PrivacyWhat Compliance Capabilities to Require From a Pharma Media Agency
What compliance and specialist capabilities a pharma brand should require from its media agency: a checklist for MLR, ISI, adverse events, and privacy.
6 min read →Compliance & PrivacyMLR Review for Programmatic Media: How to Get Faster Approvals
How MLR review works for programmatic media: what reviewers check in creative, targeting, and landing pages, what to submit, and how to speed approvals.
6 min read →Compliance & PrivacyReminder Ads, Help-Seeking Ads, and Product Claim Ads Explained
Reminder ads, help seeking ads, and product claim ads explained: what each FDA ad type can say, when risk information is required, and how media can mix them.
7 min read →Compliance & PrivacyTracking Pixel Governance on Pharma and Health Websites
A practical guide to tracking pixel governance on pharma and health websites: tag inventory, what pixels send, server tagging, consent, and audit cadence.
6 min read →New pharma programmatic breakdowns, occasionally
One email when I publish something worth reading. Benchmarks, measurement teardowns, and case studies with the caveats attached. No cadence promises, no reselling your address.
Unsubscribe any time. See the privacy policy.
Working through this decision on a real plan?
I work on health and pharma data, identity, and activation, after five years running HCP and DTC programmatic agency-side. Happy to talk through how this applies to your situation.