Your Product May Be Compliant, but Is Your Supply Chain? What the Gold Star Consent Decree Reminds Us About Managing Risk Across the Supply Chain

On September 23, 2026, FDA announced that the U.S. District Court for the District of Minnesota had entered a consent decree of permanent injunction against Gold Star Distribution, Inc., a Minnesota-based warehouse operator, and its owner. FDA had observed persistent insanitary conditions at the facility, including severe rodent and pest infestations, which put the food, drugs, medical devices, and cosmetics held by Gold Star at risk of contamination. Under the decree, Gold Star Distribution must destroy all FDA-regulated products in its possession under FDA supervision and is prohibited from receiving, holding for sale, or distributing FDA-regulated products until it complies with the Federal Food, Drug, and Cosmetic Act (FDCA), FDA regulations, and the decree. Separately, in December 2025, the Minnesota Board of Pharmacy issued a cease-and-desist order against the defendants for warehousing and distributing over-the-counter drugs without a required state license.
These actions are a reminder that compliance obligations and liability do not simply start or end at the loading dock. Brand owners, specification developers, manufacturers, and regulated supply chain service providers should take note, as the federal and state actions against Gold Star raise several important considerations that can help strengthen supply chain safety and mitigate avoidable risk:
Federal and state requirements apply together. FDA establishes federal requirements for FDA-regulated products, including facility registration and product listing requirements, while states retain important licensing and enforcement responsibilities for facilities that manufacture, store, and distribute FDA-regulated products within their borders. Qualifying a contract manufacturer, 3PL, wholesale distributor, or other supply chain service provider should include confirmation that the supplier’s operations satisfy applicable state and federal requirements.
- Prescription drugs. Prescription drug warehousing and distribution fall under a layered federal and state framework. Under the federal Drug Supply Chain Security Act (DSCSA), manufacturers, repackagers, wholesale distributors, dispensers, and 3PLs must meet the requirements applicable to their role to qualify as authorized trading partners. Wholesale distributors and 3PLs must hold the state licenses required for their operations (or, where a state does not license them, satisfy federal licensing requirements) and must report their licensure information to FDA annually. Although the DSCSA establishes standards for the prescription drug supply chain, the states remain central to licensing and oversight. Pharmaceutical companies should establish appropriate controls over outsourced activities and maintain documentation demonstrating that their third-party providers have been appropriately qualified and are meeting applicable federal and state requirements. Nonprescription (OTC) drugs fall outside the DSCSA, but their storage and distribution remain subject to FDA’s current good manufacturing practice requirements and, in many states, to state licensing, as the Minnesota order against Gold Star illustrates.
- Medical devices. Medical device warehousing and distribution activities are subject to federal FDA requirements, including establishment registration and device listing where applicable, and to state licensing requirements, depending on the activities being performed and the jurisdictions involved. Device manufacturers, including specification developers and other establishments responsible for the device under FDA’s regulatory framework, remain responsible for implementing appropriate controls over suppliers and contractors. FDA’s Quality Management System Regulation (QMSR), effective February 2, 2026, incorporates ISO 13485:2016 by reference and requires manufacturers to evaluate and select suppliers, retain responsibility for outsourced processes, and maintain records demonstrating that their suppliers and contractors have been appropriately qualified and meet applicable requirements.
- Food (including dietary supplements). FDA establishes federal food safety requirements for food manufacturers, processors, warehouses, and distributors under the FDCA and Food Safety Modernization Act (FSMA), while states and localities may impose additional licensing, registration, inspection, and enforcement requirements based on the facility’s activities and location. At the federal level, FSMA established a preventive, risk-based framework for food safety, implemented through regulations including the Current Good Manufacturing Practice (CGMP), Hazard Analysis, and Risk-Based Preventive Controls for Human Food rule, which applies broadly across the supply chain. Covered facilities generally must maintain a food safety plan addressing hazards and preventive controls, subject to applicable exemptions. Dietary supplements are subject to their own CGMP requirements under 21 C.F.R. Part 111. Where a supplier controls a hazard that requires a preventive control, the receiving facility may also need a supply-chain program to verify that supplier’s performance.
Outsourcing warehousing and distribution does not outsource regulatory risk. Under the FDCA, warehousing, fulfillment, and distribution are part of the regulated product lifecycle. Food, drugs, devices, and cosmetics held under insanitary conditions whereby they may have become contaminated with filth or rendered injurious to health may be deemed adulterated, even if they were manufactured correctly and even without proof of actual contamination. A problem at a third-party facility can result in a product quality issue, a regulatory issue, and a recall, with significant financial and reputational exposure for the company whose name is on the product. The Gold Star decree, for example, requires destruction of all FDA-regulated products in the defendants’ possession, including products belonging to customers.
- Treat supply chain service providers as part of the compliance infrastructure. A third-party service provider that stores, handles, or distributes regulated products, or that performs any manufacturing or quality-related activity, should be subject to documented, risk-based qualification procedures consistent with applicable federal and state law. Before selecting a provider, companies should conduct due diligence, including reviewing its regulatory history (including FDA inspection observations, warning letters, and state enforcement actions), registrations and licenses, certifications, quality and sanitation procedures, traceability capabilities, and insurance coverage. Drug, medical device, food, and cosmetic companies should treat these providers as an extension of their own facilities and compliance programs.
- Ongoing oversight is essential. Risk-based audits, periodic verification of registrations and licenses, review of sanitation and pest control records, and prompt follow-up on deviations help confirm that the provider continues to meet applicable requirements after the contract is signed.
Well-drafted contracts can serve as both shield and sword, protecting the company while enabling it to act. Once a qualified provider is selected, the governing agreements should address regulatory compliance requirements, auditing, incident reporting, recalls, title and risk, insurance, limitations of liability and indemnification, data processing, and termination rights and responsibilities. The agreements should accurately reflect the operating model and allocate regulatory responsibilities accordingly. The goal is not to eliminate every risk, but rather to identify the risks, put appropriate controls in place, and allocate responsibility before something goes wrong.
- Contract terms should translate regulatory requirements into specific obligations. In a regulated transaction subject to both federal and state jurisdiction, general contractual provisions requiring a service provider to comply with applicable laws are not a substitute for clearly defining the parties’ respective responsibilities. Regulatory requirements should be translated into specific, measurable contractual obligations that can be monitored, documented, and enforced between the parties. This may include specifying who must be present at state or FDA inspections, qualification standards for downstream contractors and subcontractors, records requirements, notification processes, recalls, reporting, and other critical functions, as well as establishing the processes and timelines for carrying them out. In most instances, supply chain transactions involving FDA-regulated products will require a suite of agreements, rather than a single services agreement. Depending on the products, services, and regulatory frameworks involved, those agreements may include a Master Services Agreement (MSA), Quality Agreement (QA), licensing or distribution agreement, Safety Data Exchange Agreement (SDEA), Data Processing Agreement (DPA), or other agreements addressing specific regulatory, quality, privacy, or operational requirements. These agreements should work together to create a coherent framework for allocating responsibility and managing risk.
- Insurance coverage and risk allocation. Warehousing and transportation agreements often contain broad limitations of liability that protect the provider and can significantly limit recovery following a loss. Companies engaging with a 3PL or warehousing provider need to understand those limitations before entering into the arrangement and, where possible, negotiate appropriate carve-outs for breaches and negligence. Where appropriate protections cannot be negotiated, additional risk mitigation, including insurance coverage for product held at a third-party facility and/or while in transit, is often necessary.
The strongest approach is an integrated framework that connects legal, regulatory, and quality functions. Third-party supply chain risk often crosses functional boundaries, requiring internal teams to collaborate and align on strategy. Quality and compliance may select suppliers and oversee the qualification process, while regulatory affairs defines the applicable state and federal requirements, and the legal department drafts and negotiates the governing agreements. When these functions do not communicate clearly, controls can fall through the gaps and create hidden liabilities. Smaller companies that have not yet built out separate legal, regulatory, quality, and compliance functions face the same risk, often with fewer people covering more ground.
For companies without a full internal bench, or those who are unsure whether gaps exist between these functions, experienced outside counsel can help assess supplier qualification practices, review supply chain and quality agreements, and build an integrated compliance framework. In industries subject to both federal and state oversight, it is especially important to understand the regulatory landscape and risk map before an FDA inspection, a product complaint, or a supply chain failure brings gaps to light. If you would like to discuss how the Gold Star decree may bear on your own supply chain arrangements, please contact us at info@ragaitanlaw.com.
This article is for general informational purposes only. It is not legal advice and does not create an attorney-client relationship.
