GLP-1 Payment Compliance For Medspas In 2025

As GLP-1 medications like semaglutide and tirzepatide continue gaining popularity in the medspa and weight loss industries, medspas are facing increased scrutiny around how they accept payments for these treatments. The reality is that most low-risk payment providers like Square, Stripe, and Boulevard do not support GLP-1 sales—and many medspas are learning this the hard way…

Written by

Corepay

Last updated on

Compliance, Merchant Services

As GLP-1 medications like semaglutide and tirzepatide continue gaining popularity in the medspa and weight loss industries, medspas are facing increased scrutiny around how they accept payments for these treatments. The reality is that most low-risk payment providers like Square, Stripe, and Boulevard do not support GLP-1 sales—and many medspas are learning this the hard way when their accounts are terminated without warning.

At Corepay, we work with hundreds of medspas and weight loss clinics every year to help them get compliant and stay operational. Below, we break down everything you need to know about GLP-1 payment compliance in 2025, including a full checklist and how Corepay helps you meet every requirement.


GLP-1 Payment Compliance Checklist for Medspas (2025)

Compliance AreaWhy It MattersSquare / StripeCorepay
LegitScript CertificationRequired by acquiring banks & PSPs for selling GLP-1 drugs online❌ Not supported. Accounts often shut down upon review✅ Corepay partners directly with LegitScript to streamline certification
FDA-Approved Drugs OnlyCompounded semaglutide/tirzepatide banned as of May 2025❌ No ability to enforce this requirement✅ We ensure your merchant file supports FDA-approved sourcing only
Prior Authorization & Clinical DocumentationRequired for GLP-1 claims post-April 2025 to reduce fraud & dispute exposure❌ Not supported; no structure for medical workflows✅ Netvalve gateway supports document submission, fraud scoring
Chargeback & VAMP ControlsGLP-1 is high risk. Merchants need fraud filters and real-time alerts❌ No access to CB mitigation, orchestration, or VAMP data✅ Includes CB-Alert, RDR, tokenization, fraud & dispute tracking
Compliant Marketing OversightPrevents misleading claims that trigger flags or legal issues⚠️ No proactive enforcement until after complaints✅ We vet marketing copy and disclaimers to meet card brand rules
Licensed Medical OversightMany states require MD supervision or ownership for injectables❌ Not validated or checked by low-risk processors✅ Corepay’s underwriting process includes review of licensing & ownership
Work with a High-Risk Payment ProcessorGLP-1 is considered high-risk and requires proper underwriting & tools❌ Not supported; accounts get flagged or terminated✅ Corepay is a trusted high-risk payment processor with banking redundancy

Why Low-Risk Processors Fail Medspas

Low-risk platforms like Square and Stripe are not built to handle regulated medical services. While they are great for facials, skincare, and injectables, they draw the line at anything prescription-based. GLP-1 treatments fall squarely in the “high-risk” category due to their medical complexity, potential for abuse, and increased fraud/chargeback rates.

Even if your account gets initially approved on Square or Stripe, you’re operating on borrowed time. Once your business scales or gets flagged for a routine review, the provider is likely to shut you down and freeze your funds.


What You Actually Need to Be Compliant

1. LegitScript Certification

This isn’t optional. If you sell GLP-1s online, acquiring banks require you to be LegitScript-certified. Corepay has a direct partnership with LegitScript, and we assist merchants through the certification process, from gathering documentation to application submission

*Corepay is an official Legitscript payment processor..

2. Only Sell FDA-Approved GLP-1s

The FDA ended its enforcement discretion on compounded semaglutide and tirzepatide in May 2025. If your medspa is still sourcing from 503A/503B compounding pharmacies, you’re not compliant. Corepay only supports FDA-approved GLP-1s and requires verification.

3. Medical Documentation Support

Many insurance providers now require diagnosis codes, clinical documentation, and prior authorization before processing GLP-1 payments. Corepay’s Netvalve gateway supports uploading documents, reviewing workflows, and flagging incomplete claims.

4. Chargeback & Fraud Controls

GLP-1 services tend to carry a higher dispute rate due to recurring billing, unrealistic expectations, or aggressive marketing. That means you’re vulnerable to Visa’s VAMP program thresholds. Corepay includes built-in fraud prevention, chargeback alerts (CB-Alert), and dispute response automation.

5. Compliant Advertising

You can’t advertise GLP-1s the same way you promote facials. Misleading claims like “lose 30 pounds in 30 days” are red flags. We help merchants revise landing pages, disclaimers, and advertising language to avoid compliance issues.

6. Licensed Oversight

In many states, medspas must be owned by physicians or have an MD supervising injectors. Corepay validates that your licenses and entity structure meet state and federal regulations during underwriting.

7. Work with a High-Risk Payment Processor

GLP-1 falls under high-risk classification due to chargeback potential, regulatory scrutiny, and card brand restrictions. Low-risk processors simply can’t support these needs. Corepay specializes in high-risk merchant accounts, ensuring your business stays operational while remaining compliant.


Why Corepay Is the Right Fit

GLP-1 compliance isn’t a guessing game. We’ve worked with hundreds of medspas offering prescription weight loss programs, and we know what it takes to stay compliant and keep your merchant account active.

What you get with Corepay:

  • LegitScript onboarding assistance
  • Properly underwritten high-risk merchant accounts
  • Full FDA and medical license documentation support
  • Integration with our Netvalve gateway for fraud prevention and orchestration
  • Chargeback prevention alerts, tokenization, and dynamic descriptors
  • Review of marketing language for card brand compliance

Whether you’re offering GLP-1s in-person, via telehealth, or a combination of both, Corepay gives you everything you need to stay compliant, protected, and profitable.

Learn more about high risk credit card processing compliance here.


Corepay vs. Low-Risk Payment Solutions

FeatureLow-Risk Solutions (e.g., Stripe, Square)Corepay
GLP-1 Support❌ Not allowed✅ Fully supported with proper underwriting
High-Risk Merchant Approval❌ Not available✅ Tailored onboarding and approval
LegitScript Partnership❌ No✅ Direct partner with onboarding assistance
Chargeback & Fraud Tools⚠️ Limited or none✅ CB-Alert, tokenization, orchestration, dispute alerts
FDA-Approved Medication Enforcement❌ No validation✅ Enforced during underwriting and ongoing monitoring
Compliance with VAMP Requirements❌ Not supported✅ VAMP ratio tracking and proactive mitigation
Medical License & Entity Review❌ Not validated✅ Required for onboarding
Custom Gateway (Netvalve)❌ No✅ Advanced routing, 3DS,
Risk Redundancy / Banking Flexibility❌ None✅ Multiple banking relationships for stability

Final Thoughts

GLP-1 treatments offer huge growth potential for medspas, but only if you’re backed by the right infrastructure. Don’t risk your business by using a low-risk payment processor that isn’t built to support regulated healthcare.

Corepay is your full-stack solution for high-risk, high-growth clinics offering GLP-1 weight loss programs. From compliance to fraud protection to onboarding speed, we help you scale with confidence.

Looking to switch or get started? Reach out to our team today and we’ll walk you through the approval process.

Power your payments with Corepay
Secure your business with reliable payment processing. Fast approvals, competitive rates, and expert support tailored to your industry.
Apply now

Want more?