Compliance & Regulatory

RepNook & Regulatory Compliance

How RepNook supports PDMA requirements, Sunshine Act considerations, and what your legal or compliance team needs to know before you register.

PDMA Support

Built around PDMA from the ground up.

The Prescription Drug Marketing Act of 1987 (PDMA) governs how pharmaceutical samples are distributed. Every sample request on RepNook is gated by a mandatory 4-step workflow that enforces PDMA's core requirements before any request reaches a rep.

RepNook does not bypass or abstract away compliance — it structures the request so that every required data point is collected and verifiable before the rep receives it.

Mandatory NPI verification

Every sample request requires the ordering provider's NPI, verified live against the CMS National Provider Identifier registry. Requests cannot proceed without a valid, active NPI.

Licensed delivery address required

Step 2 of the request workflow requires the provider to confirm a licensed medical facility address. Residential addresses cannot be used as sample delivery destinations.

No free-text fields

The sample request form contains no open notes, patient info, or unstructured text inputs. Product and quantity selection is made from a structured catalog — eliminating PHI risk by design.

PDMA acknowledgment checkpoint

Before submission, the ordering provider must confirm PDMA compliance checkboxes. The acknowledgment is timestamped and tied to the request record.

In-person delivery only

RepNook explicitly prohibits shipping samples. All deliveries are in-person by the rep to the verified facility — consistent with PDMA requirements.

Sunshine Act

Sunshine Act considerations for reps and manufacturers.

What the Sunshine Act covers

The Physician Payments Sunshine Act (42 U.S.C. § 1320a-7h) requires applicable manufacturers of drugs, devices, biologicals, and medical supplies to report certain payments and transfers of value to covered recipients (physicians and teaching hospitals) to CMS Open Payments annually.

RepNook's role is directory — not transfer

RepNook is a directory and connection platform. The act of a provider finding a rep's profile, requesting a meeting, or requesting samples through RepNook does not itself constitute a reportable transfer of value. RepNook facilitates the connection — the transfer of value occurs when the rep delivers samples or provides a meal, which must be reported through your existing Open Payments process.

What manufacturers must still report

Manufacturers and applicable GPOs must continue to report all transfers of value — including sample deliveries and meals provided during office lunches — through the CMS Open Payments system as required. RepNook does not submit Open Payments reports on behalf of any manufacturer.

How RepNook supports your reporting

Your RepNook dashboard provides a timestamped log of all fulfilled sample requests and completed meetings, including provider name, facility address, date, and product. This record can be used as supporting documentation for your Open Payments reporting — but submission remains the responsibility of the manufacturer.

Not legal advice

This page provides general information about how RepNook's platform is designed. It is not legal or compliance advice. Reps and manufacturers should consult their own legal counsel and compliance teams to determine their specific Sunshine Act and PDMA reporting obligations.

Sample Request Flow

How sample requests work within regulatory requirements.

Every sample request on RepNook follows a mandatory 4-step flow. No step can be skipped — the workflow enforces compliance sequentially.

01

Identity & NPI Verification

What's collected / enforced

  • Individual NPI entered and verified against live CMS registry
  • Pre-filled for verified logged-in providers
  • Request blocked if NPI is inactive or invalid

Regulatory basis

Satisfies PDMA requirement that samples only be provided to licensed practitioners.

02

Practice & Delivery Address Confirmation

What's collected / enforced

  • Provider confirms practice name and licensed facility address
  • Address must be a medical facility — not residential
  • Pre-filled from practice account for verified providers

Regulatory basis

Ensures samples are directed to a licensed medical office, as required under PDMA.

03

Product Selection

What's collected / enforced

  • Product selected from rep's listed catalog — no free-text drug names
  • Quantity limited to rep-defined per-request limits
  • No patient name, diagnosis, or clinical notes collected

Regulatory basis

Eliminates PHI risk; structured product selection prevents off-label sample requests.

04

PDMA Acknowledgment

What's collected / enforced

  • Provider must check compliance acknowledgment checkbox
  • Acknowledgment text references PDMA requirements
  • Timestamp and provider identity tied to submission record

Regulatory basis

Creates a documented acknowledgment that the provider understands the sample's regulatory context.

For Legal & Compliance Teams

What your compliance team needs to know.

If your company requires legal or compliance review before using a third-party tool, the following covers the key questions reviewers typically ask.

What data does RepNook store about reps?

Name, company, covered products, territory ZIP codes, contact preferences, and account credentials. No CRM data, no call records, no proprietary company information.

Does RepNook access company systems?

No. RepNook is a standalone platform. No integration with your CRM, Veeva, or any internal system is required or possible.

Is RepNook a HIPAA covered entity?

No. RepNook does not collect, store, or transmit protected health information. The platform is designed so that PHI cannot enter the system.

Who can see a rep's profile?

Verified healthcare providers (NPI-verified) can see full contact details. Unverified visitors see name, company, and products only — contact info is masked.

What happens to data if a rep cancels?

Rep profiles are deactivated and removed from search results. Data is retained for 90 days per our data retention policy, then permanently deleted on request.

Key Facts at a Glance

No PHI collected or stored
PDMA-compliant sample request workflow
NPI verified via live CMS registry
No CRM or internal system access required
Rep data limited to name, co., products, ZIPs
Sunshine Act reporting remains with manufacturer
Activity log available for Open Payments docs
Not a HIPAA covered entity

Need a custom compliance brief?

If your compliance or legal team needs a more detailed written response, email us and we'll provide a custom brief within 2 business days.

compliance@repnook.com

Manager Approval

"How to Get RepNook Approved at Your Company"

Need manager sign-off to use or expense RepNook? Print or download this one-pager to share with your district manager or compliance team.

RepNook

repnook.com

Company Approval Reference

June 21, 2026

How to Get RepNook Approved at Your Company

A reference for pharmaceutical field reps seeking manager or compliance sign-off to use RepNook as a third-party territory tool.

What Is RepNook?

RepNook is a territory directory platform. Reps claim exclusive ZIP code coverage and list their drug portfolio. Healthcare providers search by medication and ZIP, then send inbound sample requests and meeting invitations directly to the rep — no shared inbox, no cold calling.

What Reps Use It For

  • Exclusive territory and ZIP code management
  • Medication-matched provider discovery
  • PDMA-compliant inbound sample requests
  • Structured meeting scheduling (5 types)
  • Search analytics by product and territory

PDMA Compliant

  • Mandatory NPI verification
  • Licensed facility address required
  • PDMA acknowledgment on every request
  • In-person delivery only

No PHI, No HIPAA Risk

  • Zero free-text fields
  • No patient data collected
  • No CRM or company system access
  • Not a HIPAA covered entity

Sunshine Act

  • RepNook is a directory, not a transfer
  • Sample/meal transfers still reportable
  • Activity log available for Open Payments
  • Manufacturer reporting remains with mfr.

Cost & Billing

Basic $49/mo · Growth $99/mo · Enterprise custom. Billed directly to the rep — no company procurement required. No company systems or data are accessed.

Data Security

Rep profile stores name, company, products, and territory ZIPs only. No proprietary company data is ever uploaded or stored. Accounts support 2FA.

RepNook, Inc. · repnook.com/compliance · compliance@repnook.com

For internal approval use

Use your browser's "Save as PDF" option in the print dialog to download a PDF copy.