Compliance & Security Documentation

Last updated: September 29, 2026

1. Overview

EnrollSure provides a HIPAA-compliant electronic signing and Medicare client intake platform designed for licensed insurance agents and their beneficiaries. Our platform enables secure collection of health information, digital execution of compliance documents (Scope of Appointment, Permission to Contact), and tamper-evident document signing with comprehensive audit trails. This document describes the technical and procedural controls that ensure the integrity, authenticity, and legal validity of electronically signed documents processed through EnrollSure.

2. Electronic Signing Process

Every document signing event follows a structured process designed to establish signer identity, capture intent, and produce a tamper-evident record:

  1. Secure Link Delivery: The agent sends a unique, time-limited signing link to the beneficiary via email. Each link contains a cryptographically random identifier and has a configurable expiration period.
  2. No Email Open Tracking: Transactional email contains no tracking pixel and no rewritten links. Nothing is recorded when a message is merely opened or previewed by a mail client; the audit trail begins when the beneficiary opens the link itself.
  3. Document Access: The beneficiary opens the signing link and views the document in a secure, browser-based viewer. The system records when the link was first opened (with the IP address and browser) and when signing first started (time only).
  4. Identity Verification (Optional): The signer may verify their identity via a one-time passcode (OTP) sent to their email address. The 6-digit OTP expires after 10 minutes and is protected against brute-force attacks (maximum 5 attempts).
  5. E-Consent Capture: Before signing, the signer must explicitly check a consent box confirming they agree to receive and sign documents electronically. This consent is timestamped and recorded.
  6. Signature Capture: The signer draws their signature or initials on the document using a digital signature pad. The signature image is captured as a PNG and embedded into the PDF.
  7. Audit Trail Generation: A complete audit trail page is appended to the signed PDF documenting the entire signing event, including all hashes, attribution data, and verification status.
  8. Document Finalization: The signed PDF is locked with metadata markers, hashed using SHA-256, and stored along with all attribution data in the database.

3. Document Integrity & Tamper Evidence

EnrollSure uses cryptographic hashing to ensure documents cannot be modified after signing without detection:

  • Original Document Hash (SHA-256): Before any signatures are applied, a SHA-256 hash of the original PDF is computed and stored. This allows verification that the base document was not altered before signing.
  • Signature Image Hash (SHA-256): The raw signature image data is independently hashed and stored. This proves the specific signature that was captured at signing time.
  • Signed Document Hash (SHA-256): After all signatures are embedded, the audit trail page is appended, and PDF metadata is locked, a final SHA-256 hash of the complete document is computed and stored. Any subsequent modification of the PDF will produce a different hash.
  • PDF Metadata Locking: The signed PDF's metadata (Title, Producer, Subject, Keywords) is set with finalization markers that indicate the document has been completed through the EnrollSure signing process. The Producer field records the platform version and the Subject field records the document identifier.

To verify a document's integrity, the PDF can be converted to base64, its SHA-256 hash computed, and compared against the stored signed document hash in the EnrollSure database. A match confirms the document has not been altered since signing.

4. Attribution & Non-Repudiation

Every signing event captures comprehensive attribution data to establish who signed, when, where, and from what device. This data supports non-repudiation and is recorded both in the database and on the audit trail page embedded in the PDF:

Data PointDescription
IP AddressThe signer's IP address, captured from request headers
TimestampISO 8601 timestamp of the signing event in UTC
User AgentBrowser and operating system identification string
Device FingerprintScreen resolution, timezone, language, platform, color depth, touch capability, and CPU cores
Geographic LocationCity, region, and country derived from an IP geolocation lookup, when IP geolocation is enabled (otherwise left blank)
E-ConsentExplicit checkbox consent with timestamp confirming agreement to electronic signing
OTP VerificationEmail one-time passcode verification status (when used)

5. Data Security & Encryption

EnrollSure implements multiple layers of security to protect data at rest and in transit:

Encryption in Transit

  • All connections to EnrollSure use HTTPS (TLS)
  • HTTPS is enforced on all endpoints with HSTS headers
  • Our servers call outside services (such as email, payments, calendars, and CRM endpoints) over HTTPS; CRM, Partner API callback, and IP geolocation addresses must be HTTPS

Encryption at Rest

  • Database (Neon PostgreSQL) uses AES-256 encryption at rest
  • Stored PDFs, drawn signatures, and signed documents are protected by the database's encryption at rest
  • Intake survey answers (name, contact details, date of birth, address, Medicare identifiers, medications, doctors, hospitals, and pharmacies) and the client's typed SOA signature are also encrypted with AES-256-GCM before they are stored

Authentication & Access Control

  • Passwords are hashed using bcrypt with a cost factor of 12 rounds
  • JWT-based authentication with secure, HTTP-only, SameSite cookies
  • Two-factor authentication (2FA) by emailed code or authenticator app
  • Automatic sign-out after 15 minutes of inactivity
  • Role-based access control (RBAC) with Superadmin, Admin, and Agent roles
  • Multi-tenant data isolation ensures organizations cannot access other organizations' data

Application Security

  • Input validation with Zod schemas on key endpoints, including sign-up, sign-in, intake surveys, document signing, and public contact forms
  • Prisma ORM generates parameterized queries, preventing SQL injection
  • Rate limiting on authentication and signing endpoints prevents brute-force attacks
  • Content Security Policy (CSP) headers prevent cross-site scripting (XSS)

6. HIPAA Compliance

EnrollSure is designed and operated in accordance with the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule and Security Rule. The following controls address HIPAA requirements:

Administrative Safeguards

  • Role-based access controls enforce the minimum necessary standard for PHI access
  • Audit logging records viewing a submission's full details, PDF and signed-document downloads, sends, signing events, and CRM syncs, and logs which intake submission fields change when a client submits, an agent signs, or a CRM sync runs
  • Workforce training and access management procedures are maintained

Technical Safeguards

  • Unique user identification with individual accounts and credentials
  • Automatic session termination after inactivity periods
  • Encryption of ePHI in transit (TLS) and at rest (AES-256)
  • Audit controls that record and examine activity in information systems containing ePHI
  • Integrity controls including SHA-256 document hashing to detect unauthorized alterations
  • Person or entity authentication via passwords, 2FA, and OTP verification

Physical Safeguards

  • Infrastructure hosted on Amazon Web Services (AWS Amplify) and Neon, both of which maintain SOC 2 Type II compliance; AWS services are covered under an executed Business Associate Agreement
  • No on-premise servers or physical media containing PHI
  • Cloud infrastructure providers maintain physical access controls and environmental safeguards

7. Database Compliance

EnrollSure's data layer is built on industry-standard technologies with strong compliance profiles:

Neon PostgreSQL

  • Fully managed, serverless PostgreSQL database
  • Data encrypted at rest using AES-256
  • SOC 2 Type II compliant infrastructure
  • Automated backups with point-in-time recovery
  • Network isolation with secure connection strings
  • All database connections require SSL/TLS

Prisma ORM

  • All queries are parameterized, preventing SQL injection attacks
  • Type-safe database access eliminates runtime type errors
  • Schema migrations are version-controlled and auditable
  • Connection pooling with secure credential management

8. CMS Regulatory Compliance

EnrollSure supports Medicare insurance agents in meeting Centers for Medicare & Medicaid Services (CMS) regulatory requirements:

Scope of Appointment (SOA)

  • Electronically generated SOA documents with beneficiary and agent information
  • Product type checkboxes per CMS requirements (Medicare Advantage, Part D, etc.)
  • Digital signature capture with timestamp and IP address
  • No-obligation and no-impact statements included per CMS guidelines
  • PDF generation with all required fields for CMS audit readiness

Permission to Contact (PTC)

  • Permission to Contact recorded with each survey submission, with a timestamp and IP address when it is given. The box is pre-checked, and the client can uncheck it before submitting.
  • Permission to Contact has its own checkbox, separate from the Scope of Appointment signature and the consent to electronic records
  • CAN-SPAM compliant with unsubscribe management

48-Hour Rule

CMS eliminated the 48-hour waiting period between Scope of Appointment (SOA) completion and the sales appointment as of October 1, 2026. SOA forms are still required for all Medicare sales meetings. EnrollSure no longer collects a 48-hour acknowledgment; acknowledgments and timestamps captured on earlier submissions are retained with those records and in the audit trail.

9. Audit Trail Contents

Every signed document includes a dedicated audit trail page appended to the PDF. The audit trail page contains the following information:

Document Information

Document ID, document name, original document hash (SHA-256), signed document hash (SHA-256)

Signer Information

Full name, email address (if the signer entered one), signature hash (SHA-256)

Signing Event

ISO 8601 timestamp, IP address, user agent, device information (platform, screen resolution), geographic location (city, region, country) when IP geolocation is enabled

Verification

Identity verification method (Email OTP / Not Required), e-consent timestamp

Integrity Notice

Statement that the document was electronically signed via EnrollSure, with instructions for hash-based tamper verification

In addition to the embedded PDF audit trail, the signing event data described above is stored in the EnrollSure database, and the signing is recorded in the audit log. The database also records when the signing link was first opened (with the IP address and browser) and when signing first started.

10. Data Retention

Intake survey submissions (with their SOA and Client Summary PDFs), signed documents and their signing records, and audit logs are kept for 10 years from when they are created; a scheduled job then deletes them from the database. If an organization is deleted sooner, its submissions, PDFs, and signed documents are deleted at that time, while audit log entries are kept until they are 10 years old. Deleted data can remain in database backups until those backups expire. Section 7 of our Privacy Policy describes what deletion removes and what is kept.

11. Contact Information

For questions about our compliance practices or security controls, please contact us:

Email: compliance@enrollsure.io
Website: https://enrollsure.io
Address: 113 GA Hwy 94 E #10, Statenville, GA 31648