Emergency Ruling for Florida Medical Marijuana Treatment Centers Explained.

Florida Cannabis Retailer Emergency Ruling

Last week the Florida Department of Health issued an emergency ruling regarding websites and website-based purchasing for Medical Marijuana Treatment Centers (MMTCs).

What are the new website requirements?

There’s a lot to digest, and still some clarifications to be made, but here’s an overview of what’s required:

  • A MMTC may only have one website – and it must be approved by the Florida Department of Health
  • The Department of Health must approve any changes to the URL, including redirects.
  • Purchasing or pre-ordering may only be done on a department-approved site.
  • Websites must have an age gate (customers must be at least 18 years old).
  • Website must ensure personal information obtained by an e-commerce provider remains “confidential.” This includes:
    • The website is secure with a valid SSL certificate
      • these are often included in your hosting subscription, but if not, must be purchased separately.
    • It contains an anti-virus system to prevent server access, which must be updated regularly.
    • It has a Firewall.
      • This will be included (or not) in your hosting subscription. For example, our recommended hosting platform WPEngine has a firewall for all of its servers.
    • Has dedicated user roles for those who have access to user-specific information.
      • All employees must only have access to data based on the duties for those individuals, and the permissions must be re-evaluated every three months.
      • MMTCs must maintain records of all system access – which needs to be available to be exported to the department on request within 48 hours.
    • Servers need to be in a secure location – and meet the SSAE and SOC III certifications.
    • Prior to collecting personal information – the retailer must obtain express consent (i.e. double opt-in) from the patient to use the information for that purpose. Personal information cannot be used for any other purpose.

The bottom line

There’s quite a bit to cover to make sure websites are in compliance, and MMTCs have 60 days to comply with the emergency ruling. We’re keeping up-to-date with the most recent clarifications to the rulings as we all navigate these required changes.

The full text of the emergency rule can be read here.

Need help ensuring your Florida Medical Marijuana Treatment Center website is in compliance? Reach out, and we’d love to help!

Patrick Toste from HIGHOPES

Ready to start unlocking the potential of your cannabis brand? Submit the form below and our Creative Director, Patrick, will be in touch!

Not looking to start a project? Click here to contact us instead.