Version 1.0 · Draft · Owner: Legal
Download .md →Touch2Sign Ltd
Version: 1.0
Effective date: 11 July 2026
Owner: Robert — Security Lead
Approved by: Robert — CEO / Managing Director
Next review: 11 July 2027
Define Touch2Sign Ltd's position regarding the US Health Insurance Portability and Accountability Act (HIPAA) and Protected Health Information (PHI). Prevents inadvertent HIPAA scope expansion and sets clear boundaries for customers, staff, and sales.
Touch2Sign is OUT OF HIPAA SCOPE by default.
| Statement | Detail | HIPAA covered entity? | No |
|---|---|
| HIPAA business associate? | No — unless separate written BAA executed (not offered by default) |
| PHI processing | Prohibited on the platform without executed BAA |
| HIPAA compliance marketing | Prohibited unless BAA programme formally launched |
This policy applies to all Touch2Sign personnel, customers, and integrations.
| Term | Meaning | PHI | Individually identifiable health information as defined in 45 CFR §160.103 |
|---|---|
| BAA | Business Associate Agreement under HIPAA §164.308(b) |
| Covered entity | Health plans, clearinghouses, certain healthcare providers under HIPAA |
Touch2Sign provides electronic signature and deed witnessing — not healthcare services.
Without an executed Touch2Sign BAA (currently not offered):
Customers must not:
Terms of Service include explicit PHI prohibition — Legal maintains wording.
Staff must not:
| Step | Action | 1 | Support/engineering identifies potential PHI (medical record, diagnosis, treatment data) |
|---|---|
| 2 | Escalate to DPO and Legal immediately |
| 3 | Request customer remove content and confirm cessation |
| 4 | Delete identified PHI per Data Retention & Disposal Policy |
| 5 | Document in incident/privacy log — breach assessment if PHI was exposed |
| 6 | Do not renew or sign BAA retroactively without CEO decision |
Approved statements:
Prohibited statements:
Enterprise questionnaire response: "Out of scope — PHI prohibited per Terms."
If Touch2Sign launches a formal HIPAA programme:
Until then, no BAAs.
General security controls (encryption, MFA, incident response) support overall data protection but do not constitute HIPAA compliance. Customers requiring HIPAA must use a provider with an active BAA programme — not Touch2Sign by default.
Reviewed annually and before any decision to enter HIPAA scope or offer BAAs.
Approval
| Name | Role | Signature | Date | Robert | CEO / Security Lead | Electronic | 11 July 2026 |
|---|
Questions: security@touch2sign.com · privacy@touch2sign.com