Touch2Sign Policy Library
← All policies

HIPAA Scope Decision (Out of Scope)

Version 1.0 · Draft · Owner: Legal

Download .md →

HIPAA Scope Policy

Touch2Sign Ltd

Version: 1.0

Effective date: 11 July 2026

Owner: Robert — Security Lead

Approved by: Robert — CEO / Managing Director

Next review: 11 July 2027


1. Purpose

Define Touch2Sign Ltd's position regarding the US Health Insurance Portability and Accountability Act (HIPAA) and Protected Health Information (PHI). Prevents inadvertent HIPAA scope expansion and sets clear boundaries for customers, staff, and sales.

2. Default position

Touch2Sign is OUT OF HIPAA SCOPE by default.

Statement Detail
HIPAA covered entity? No
HIPAA business associate? No — unless separate written BAA executed (not offered by default)
PHI processing Prohibited on the platform without executed BAA
HIPAA compliance marketing Prohibited unless BAA programme formally launched

This policy applies to all Touch2Sign personnel, customers, and integrations.

3. Definitions

Term Meaning
PHI Individually identifiable health information as defined in 45 CFR §160.103
BAA Business Associate Agreement under HIPAA §164.308(b)
Covered entity Health plans, clearinghouses, certain healthcare providers under HIPAA

Touch2Sign provides electronic signature and deed witnessing — not healthcare services.

4. Prohibited activities

Without an executed Touch2Sign BAA (currently not offered):

4.1 Customer prohibitions (Terms of Service)

Customers must not:

  • Upload PHI to the Touch2Sign platform
  • Use Touch2Sign for patient medical records, clinical trial informed consent regulated as PHI, or insurance claim documents containing PHI
  • Configure workflows expecting Touch2Sign to act as a HIPAA business associate
  • Represent to their patients or regulators that Touch2Sign is HIPAA-compliant

Terms of Service include explicit PHI prohibition — Legal maintains wording.

4.2 Touch2Sign personnel prohibitions

Staff must not:

  • Tell prospects or customers that Touch2Sign is "HIPAA compliant" or "HIPAA certified"
  • Execute a BAA without CEO and Legal approval
  • Store PHI in support tickets, Slack, or demo environments
  • Create HIPAA-specific product configurations implying compliance

4.3 Technical environment

  • Platform controls align with general security standards (encryption, access control) — not mapped to HIPAA Security Rule by default
  • No BAAs with AWS or sub-processors solely for HIPAA — standard DPAs apply
  • Audit trails designed for eIDAS / general compliance — not 45 CFR Part 164 subpart C by default

5. If a customer attempts to upload PHI

Step Action
1 Support/engineering identifies potential PHI (medical record, diagnosis, treatment data)
2 Escalate to DPO and Legal immediately
3 Request customer remove content and confirm cessation
4 Delete identified PHI per Data Retention & Disposal Policy
5 Document in incident/privacy log — breach assessment if PHI was exposed
6 Do not renew or sign BAA retroactively without CEO decision

6. Sales and marketing guidance

Approved statements:

  • "Touch2Sign provides GDPR-aligned electronic signature and witnessing with encryption and audit trails."
  • "Touch2Sign is not intended for US HIPAA Protected Health Information. Customers must not upload PHI."

Prohibited statements:

  • "HIPAA compliant" / "HIPAA certified" / "BAA available" (unless programme launched)
  • "Suitable for patient health records" without Legal-approved disclaimer

Enterprise questionnaire response: "Out of scope — PHI prohibited per Terms."

7. Exceptions — BAA programme (future)

If Touch2Sign launches a formal HIPAA programme:

  1. CEO and Legal approve programme scope
  2. Execute Touch2Sign BAA with qualifying customers only
  3. Complete HIPAA Security Rule gap assessment and remediation
  4. Execute BAAs with relevant sub-processors (AWS BAA, etc.)
  5. Update this policy, Terms, DPA, and marketing
  6. Train all customer-facing staff

Until then, no BAAs.

8. Relationship to other policies

General security controls (encryption, MFA, incident response) support overall data protection but do not constitute HIPAA compliance. Customers requiring HIPAA must use a provider with an active BAA programme — not Touch2Sign by default.

9. Related documents

  • Information Security Policy §7
  • Acceptable Use Policy §4.3
  • Data Classification Policy
  • Data Processing Agreement
  • Terms of Service

10. Review

Reviewed annually and before any decision to enter HIPAA scope or offer BAAs.


Approval

Name Role Signature Date
Robert CEO / Security Lead Electronic 11 July 2026

Questions: security@touch2sign.com · privacy@touch2sign.com