# HIPAA Scope Policy

**Touch2Sign Ltd**  
**Version:** 1.0  
**Effective date:** 11 July 2026  
**Owner:** Robert — Security Lead  
**Approved by:** Robert — CEO / Managing Director  
**Next review:** 11 July 2027

---

## 1. Purpose

Define Touch2Sign Ltd's position regarding the US Health Insurance Portability and Accountability Act (HIPAA) and Protected Health Information (PHI). Prevents inadvertent HIPAA scope expansion and sets clear boundaries for customers, staff, and sales.

## 2. Default position

**Touch2Sign is OUT OF HIPAA SCOPE by default.**

| Statement | Detail |
|-----------|--------|
| HIPAA covered entity? | **No** |
| HIPAA business associate? | **No** — unless separate written BAA executed (not offered by default) |
| PHI processing | **Prohibited** on the platform without executed BAA |
| HIPAA compliance marketing | **Prohibited** unless BAA programme formally launched |

This policy applies to all Touch2Sign personnel, customers, and integrations.

## 3. Definitions

| Term | Meaning |
|------|---------|
| **PHI** | Individually identifiable health information as defined in 45 CFR §160.103 |
| **BAA** | Business Associate Agreement under HIPAA §164.308(b) |
| **Covered entity** | Health plans, clearinghouses, certain healthcare providers under HIPAA |

Touch2Sign provides electronic signature and deed witnessing — not healthcare services.

## 4. Prohibited activities

Without an executed Touch2Sign BAA (currently not offered):

### 4.1 Customer prohibitions (Terms of Service)

Customers must **not**:

- Upload PHI to the Touch2Sign platform  
- Use Touch2Sign for patient medical records, clinical trial informed consent regulated as PHI, or insurance claim documents containing PHI  
- Configure workflows expecting Touch2Sign to act as a HIPAA business associate  
- Represent to their patients or regulators that Touch2Sign is HIPAA-compliant  

Terms of Service include explicit PHI prohibition — Legal maintains wording.

### 4.2 Touch2Sign personnel prohibitions

Staff must **not**:

- Tell prospects or customers that Touch2Sign is "HIPAA compliant" or "HIPAA certified"  
- Execute a BAA without CEO and Legal approval  
- Store PHI in support tickets, Slack, or demo environments  
- Create HIPAA-specific product configurations implying compliance  

### 4.3 Technical environment

- Platform controls align with general security standards (encryption, access control) — **not** mapped to HIPAA Security Rule by default  
- No BAAs with AWS or sub-processors solely for HIPAA — standard DPAs apply  
- Audit trails designed for eIDAS / general compliance — not 45 CFR Part 164 subpart C by default  

## 5. If a customer attempts to upload PHI

| Step | Action |
|------|--------|
| 1 | Support/engineering identifies potential PHI (medical record, diagnosis, treatment data) |
| 2 | Escalate to DPO and Legal immediately |
| 3 | Request customer remove content and confirm cessation |
| 4 | Delete identified PHI per Data Retention & Disposal Policy |
| 5 | Document in incident/privacy log — breach assessment if PHI was exposed |
| 6 | Do not renew or sign BAA retroactively without CEO decision |

## 6. Sales and marketing guidance

Approved statements:

- "Touch2Sign provides GDPR-aligned electronic signature and witnessing with encryption and audit trails."  
- "Touch2Sign is not intended for US HIPAA Protected Health Information. Customers must not upload PHI."  

Prohibited statements:

- "HIPAA compliant" / "HIPAA certified" / "BAA available" (unless programme launched)  
- "Suitable for patient health records" without Legal-approved disclaimer  

Enterprise questionnaire response: **"Out of scope — PHI prohibited per Terms."**

## 7. Exceptions — BAA programme (future)

If Touch2Sign launches a formal HIPAA programme:

1. CEO and Legal approve programme scope  
2. Execute Touch2Sign BAA with qualifying customers only  
3. Complete HIPAA Security Rule gap assessment and remediation  
4. Execute BAAs with relevant sub-processors (AWS BAA, etc.)  
5. Update this policy, Terms, DPA, and marketing  
6. Train all customer-facing staff  

Until then, **no BAAs**.

## 8. Relationship to other policies

General security controls (encryption, MFA, incident response) support overall data protection but do **not** constitute HIPAA compliance. Customers requiring HIPAA must use a provider with an active BAA programme — not Touch2Sign by default.

## 9. Related documents

- Information Security Policy §7  
- Acceptable Use Policy §4.3  
- Data Classification Policy  
- Data Processing Agreement  
- Terms of Service  

## 10. Review

Reviewed **annually** and before any decision to enter HIPAA scope or offer BAAs.

---

**Approval**

| Name | Role | Signature | Date |
|------|------|-----------|------|
| Robert | CEO / Security Lead | Electronic | 11 July 2026 |
