The Promo Review

Handling Unsolicited Requests for Off-Label Drug Information

Manufacturers must verify requests are unsolicited before sharing off-label drug information.

Staff Writer · · 11 min read
Cover illustration for “Handling Unsolicited Requests for Off-Label Drug Information”
MLR and promotional review · September 11, 2026 · 11 min read · 2,390 words

When a doctor prescribes an approved drug or device for a dose, condition, or patient group the FDA hasn't cleared, that's off-label use. Doctors do it all the time, above all in oncology, pediatrics, and psychiatry, and it creates one of the toughest compliance traps a drug or device maker can hit: physicians may prescribe off-label freely, yet the manufacturer can never push that use.

That imbalance isn't something you can argue about. 21 U.S.C. §331 and 21 CFR 201 spell it out: any drug promoted with claims beyond its approved label is misbranded, period. Each process below is meant to control that one legal risk. The FDA allows one small exception: drugmakers can share scientific, non-promotional information if a health care provider asks first, without being prompted. This piece then goes through that exception in order, from the moment a question arrives to the moment a file closes.

What makes a request genuinely unsolicited, and why that determination comes first

FDA separates requests the company did nothing to prompt from those that trace back to something the company did. An unsolicited request comes straight from a health care provider or other individual, with nothing from the company or its reps sparking it. A solicited request is one that grows out of a promotional presentation, a sales visit, or a conference booth, something the company did that prompted the person to ask.

Only the first type allows an off-label answer. If the request is solicited or public, the company must redirect the requestor to a private channel instead of providing off-label details, even if those details are scientifically sound. Companies that cross this line rarely mean harm; they do it because a sales rep honestly thinks accurate information serves the physician. Intent doesn't matter to the FDA here. What matters is the order: whether the company's promotion or the provider's question came first.

In practice, questions don't come labeled. A physician asking about an unapproved dosing schedule as a sales detailing visit ends, or during dinner at a sponsored event, creates the exact ambiguity FDA guidance was made to address. Where the question was asked counts for more than how it was phrased. The FDA's go-to reference on this threshold question is still its 2011 draft guidance on responding to unsolicited requests, posted December 27, 2011, and it's worth noting that even now, more than ten years on, the document has never left draft status.

Because every next step depends on whether the request is unsolicited or solicited, documentation must begin at once: how the question arrived, where, the exact wording used, and the surrounding context, captured before anyone routes it anywhere. There's a reason companies put warning signs in their standard procedures. Questions raised at promotional events, questions coming after a sales rep's product pitch, or questions sent through a channel the company itself opened and promoted all warrant a second look before anyone drafts a response.

Who can receive an off-label response, and which channel they must receive it through

The permitted audience is narrow. The permitted audience includes health care providers, and the January 2025 SIUU final guidance addresses firm-initiated scientific communications. A patient or caregiver who asks the same question doesn’t automatically get the same answer, and smaller Medical Information teams often wrongly handle patient inquiries like provider inquiries. You need to know who's asking before deciding what to say back.

Where it happens matters too. When a question arrives somewhere public, a conference Q&A, a social media comment, a discussion board thread, the company can't respond in that spot. The 2011 draft guidance says the substantive response must go privately, one-on-one, to the specific person who asked. They can briefly point the person to a private channel in public, though. The actual off-label content is not.

Most companies didn't even consider these online channels ten years ago, but the rule covers them now. A chatbot query, website chat message, or public forum question still means you must find the actual person who asked and reply to them in private. You can't reply in the public post, even if you choose your words carefully.

Answering an off-label question publicly promotes it to anyone reading that forum, no matter how it's phrased. No form of "just this once, briefly" holds up in an FDA review. Before anyone writes a real answer, intake steps must log the request's channel and route public ones privately.

Which personnel are authorized to respond, and why sales must stay out

FDA's 2011 guidance directs off-label requests to Medical Information or Medical Affairs, with sales and marketing generally excluded from responding. This isn't bureaucratic turf-drawing. When a rep answers an off-label question, even one that's accurate and taken straight from an approved document, it creates a record that looks like promotion masked as helpfulness, because the rep's job is promotional. FDA lets Medical Affairs handle this instead of sales because they don't have sales quotas.

Medical Science Liaisons, trained in scientific exchange, respond to unsolicited off-label questions while adhering to approved materials.

January 2025 muddied the picture, and companies shouldn’t consider it settled. For the first time, the SIUU final guidance allows sales and marketing staff to share off-label scientific information during detailing visits, under specific conditions. That breaks with more than ten years of practice. But the guidance is final while marked "not for current implementation," pending OMB review of its information-collection provisions. No company should be rerouting sales teams based on a document that hasn't passed that review, and jumping ahead here means taking on risk the guidance itself hasn't approved yet. SOP logic must keep two tracks apart: the 2011 unsolicited-request framework, which stays with Medical Affairs no matter what, and firm-initiated SIUU communications under the new guidance, which technically widen sales eligibility but are still on hold.

What the January 2025 SIUU guidance changed about qualifying scientific content

Released January 6 and posted January 7, the January 2025 guidance, formally titled "Communications From Firms to Health Care Providers Regarding Scientific Information on Unapproved Uses of Approved/Cleared Medical Products: Questions and Answers," closes out roughly a decade of FDA drafting that began in 2014 and included another draft in 2023.

Three things changed, and the second is bigger than it looks. Firms can now put together their own presentations summing up qualifying source publications, including clinical practice guidelines, instead of only using content taken straight from an accompanying reprint. The standard fell from a combined "scientifically sound and clinically relevant" test to only "scientifically sound," so clinical relevance is no longer a separate hurdle firms had to clear. Qualifying evidence now covers clinical practice guidelines and other publication types that the old scope left out.

Cutting two criteria down to one might look like a relaxation. Assume it is, and enforcement will set you straight. In September 2025, FDA warned a firm for promoting a device to treat conditions outside standard medical care. FDA indicated that evidence must meet a rigorous standard to support efficacy claims. Removing "clinically relevant" didn't lower the bar; it merged two hurdles into one that real data, not anecdote, must still clear.

None of those broader content allowances touch the core rule: each reply still has to be truthful, non-misleading, balanced, and fully cited, with risk and benefit information included.

How to structure the response itself: required elements and prohibited moves

A compliant response follows a fairly set pattern. It says plainly that the use being discussed isn't approved. It includes a disclaimer, such as "unapproved use; safety and efficacy not established for this indication." It also fully cites the scientific literature. It puts benefit and risk side by side, with dosing guidance, adverse event data, and contraindications right next to any efficacy claims. And it only answers the question asked, without straying into off-label areas the requestor never raised.

The banned items go the opposite way. Don't go beyond what was actually asked. No sales pitch, no side-by-side claims, nothing suggesting one product tops another. No cutting back or watering down risk details just to tidy up the reply. Avoid using unsupported anecdotes or data that do not meet scientific standards. And no firing off the same response to several recipients like a broadcast, since each one must go to its specific requestor.

Medical, Legal, and Regulatory teams often review this content before it is sent. MLR review checks that the language hits "scientifically sound," "non-promotional," and "balanced" at the same time, a tougher needle to thread than it sounds, and the difficulty is structural, not procedural.

MLR usually sands down the specifics to play it safe. Content that clears MLR review but sheds its clinical specifics can miss the very person it was meant to help: the physician who posed the question. Choose specific detail over vague safety, and back that choice with citations, not hedged language that technically says nothing wrong. Templates must remain clinically useful while adhering to compliance requirements.

The documentation trail that compliance and audit teams require at every step

Every step of this process creates a paper trail, and that trail is the goal, not a side effect. Receipt is logged with the date, time, channel, the request itself, worded as the requestor put it or closely paraphrased, and proof of who the requestor is and their professional role. The triage decision is also logged: whether the request was deemed unsolicited or solicited and why, and whether the asker qualified as a permissible recipient.

Channel choice is recorded separately, public forum or private channel, along with the routing decision that followed. They log the whole reply: what was sent, where it came from, the disclaimers included, and who approved it. Delivery is also verified, noting the private channel used, the date, and proof it reached the specific requestor.

Documentation at every step is critical for compliance. Any safety issue a requestor brings up has to be captured and sent to pharmacovigilance and adverse event reporting. This duty stands no matter what you do with the off-label reply, and the FDA won't buy "we already sent the answer" as an excuse for skipping it.

More firms now handle this via case management platforms such as Veeva Vault MedInquiry, which logs incoming questions, follows each one through fulfillment, and connects automatically to adverse event databases. AstraZeneca, Bayer, and Pfizer have documented Veeva MedInquiry rollouts that were in place through 2025.

The documentation record is what allows a company to show an FDA reviewer that a specific communication truly answered a genuine unsolicited question, rather than being a disguised promotional push. Records must be kept under the relevant rules, and the file must be easy to find during inspection.

How enforcement actions reveal where process failures actually occur

The enforcement surge in September 2025 killed the notion that broader SIUU permissions meant less oversight. The FDA issued a significant number of warning letters about misleading ads during that period. Looser content rules didn't mean lighter penalties for mistakes, and any firm that saw the SIUU update as a green light got it wrong.

The laser device warning letter from that same period is instructive. FDA cited a firm for marketing laser devices to treat conditions outside standard medical care, based on a case study that said the device cured peripheral neuropathy. By saying a single undocumented case study isn't solid science, FDA gave us our best public look at how the new standard works in practice.

Then, in April 2026, Morgan Lewis reported an FDA warning letter that cited a drug manufacturer for improperly using AI in manufacturing and quality processes, a notable case of AI-related regulatory attention in the pharmaceutical industry. AI-assisted content doesn't get its own lane. It gets judged by the same bar as human-written material, and claiming "the AI wrote it" won't cut it as a mitigating factor in any future letter.

Past off-label promotion settlements hint at the financial stakes: DOJ and FDA enforcement in this area has recorded figures of $2.2 billion, $430 million, and $7.9 billion. Fines that big make good records and solid processes a matter of staying in business, not just ticking compliance boxes.

These cases show the same breakdowns again and again: evidence that fails the scientifically sound test, case studies and anecdotes posing as real data, sales or marketing doing work that belongs to Medical Affairs, public replies to public questions rather than private follow-up, and AI-generated text making its way into promotional materials without proper review. Five separate failures, one cause: someone skipped a step the process was built to keep from being skipped.

Where digital channels and AI systems create new compliance exposures the standard process does not yet fully address

FDA's 2011 draft guidance addressed digital channels like discussion boards. That logic technically covers chatbots, AI assistants, and AI-driven medical info portals now, yet none of them were considered when the guidance was drafted, and the gaps become obvious on closer inspection.

A general-purpose AI chatbot follows none of the rules a manufacturer does. It responds to off-label questions without disclaimers, balanced risk data, or any need for the evidence to be scientifically sound. For makers whose products come up in AI outputs they never wrote or reviewed, the mismatch between a label's actual wording and an AI system's answer is a growing risk.

FDA can enforce rules on materials that manufacturers, their agents, or their contractors create or distribute. An answer produced by a general‑purpose AI model that has no link to the manufacturer falls outside that authority, for now at least. But that shifts quickly if the manufacturer partners with the AI platform, answers medical questions through it directly, or drops AI-written text into approved materials without checking it again. The technology isn't the line. The relationship is what matters.

FDA has stated it plans to deploy AI and other tech-enabled tools to monitor promotional activity proactively, and it has also singled out closing "digital loopholes", algorithm-driven advertising, chatbot interactions, and AI-generated health content as an enforcement priority. The process built around the 2011 guidance and the 2025 SIUU update wasn't made for any of this, and treating current SOPs as enough for AI-mediated conversations is the next big compliance failure heading our way. Firms here need routing rules and record-keeping built for AI conversations, not just the old channels the current framework covers.

Sources

  1. Communications From Firms to Health Care Providers Regarding Scientific Information on Unapproved Uses of Approved/Cleared Medical Products: Questions and Answers
  2. Off-Label Promotion: A Compliance Guide for MSL Teams | IntuitionLabs
  3. Responding to Unsolicited Requests for Off-Label Information About Prescription Drugs and Medical Devices
  4. foleyhoag.com
  5. Responding to Unsolicited Requests for Off-Label Information About Prescription Drugs and Medical Devices
  6. FDA broadens scope on communication about unapproved uses to HCPs
  7. arnoldporter.com

More in MLR and promotional review