How We Operate
bloodless.org is a document preparation service, not a law firm. This page explains our legal position, data protection architecture, and regulatory compliance.
Document preparation
You make every decision. Our software formats your choices into a document — nothing more.
Client-side encryption
Your medical Directive is encrypted in your browser before it ever reaches our server. We cannot read it.
Built for global use
Advance Directives are personal documents worldwide. No country prohibits software-assisted creation.
How We Operate
bloodless.org helps you create an advance medical Directive — a legal document expressing your wishes about blood transfusions and bloodless healthcare. The legal term for what we do is "scrivener" — a service that writes down what you tell it, without giving advice about what you should say.
What we do
- Present a structured questionnaire you fill in yourself
- Format your answers into a professional document
- Show published legal requirements (e.g., "New York requires two witnesses")
- Provide educational resources about medical and legal terminology
What we never do
- Give legal advice or recommend specific choices
- Select forms or provisions for you
- Review your document for legal sufficiency
- Form an attorney-client relationship
This distinction — between a tool that fills in what you decide and a service that tells you what to decide — is the foundation of our legal position. Courts and regulators have consistently upheld this model.
Legal Precedent
Services that help people create advance Directives have operated for decades without legal challenge. The precedent is well established:
| Service | Model | Legal challenges |
|---|---|---|
| Five Wishes | Paper advance Directive form, created with the American Bar Association | None — zero reported challenges |
| FreeWill | Interactive online questionnaire for advance Directives — closest comparable to bloodless.org | None — zero reported challenges |
| AARP / CaringInfo | Downloadable state-specific advance Directive forms with educational content | None — zero reported challenges |
| LegalZoom | Interactive questionnaire for wills, trusts, business documents | Challenged in 8 states — ultimately approved by the South Carolina Supreme Court (2014) as a permissible "scrivener" model |
The Federal Trade Commission and U.S. Department of Justice have submitted formal comment letters supporting technology-based legal services, suggesting states update their rules to accommodate interactive software that helps people prepare their own documents.
U.S. State-by-State Assessment
"Unauthorized practice of law" (UPL) means performing legal services — such as giving legal advice or drafting documents for someone — without being a licensed attorney. Every U.S. state has UPL laws, but the definitions and penalties vary. We researched the six highest-priority states in detail:
| State | UPL classification | Safe harbor | Risk |
|---|---|---|---|
| Texas | Civil offense | Yes — explicit statutory safe harbor for software (Gov't Code §81.101(c)) | Low |
| Pennsylvania | Misdemeanor | None statutory | Low |
| New York | Misdemeanor | None — case-by-case | Low–Medium |
| California | Misdemeanor | Legal Document Assistant framework provides a clear model | Low–Medium |
| Washington | Gross misdemeanor / felony | Affirmative defense only | Low–Medium |
| Florida | Felony (3rd degree) | None statutory | Medium |
International Position
Outside the United States, the legal landscape is more favorable, not less. Most countries do not have a UPL concept equivalent to the U.S., and advance Directives are universally treated as personal documents that individuals prepare themselves.
| Region | Legal framework | Risk |
|---|---|---|
| Brazil | No UPL equivalent. Advance Directives recognized via medical council resolution (CFM 1.995/2012). Regulated by health law, not legal practice law. LGPD (data privacy) is the primary compliance concern. | Very low |
| Mexico | No federal UPL framework. State-level Ley de Voluntad Anticipada (Mexico City 2008 model) designed for self-service completion. | Very low |
| United Kingdom | "Advance decisions" under the Mental Capacity Act 2005 are explicitly designed for completion without a solicitor. "Reserved legal activities" under the Legal Services Act 2007 do not cover advance Directive preparation. | Very low |
| Germany | Patientenverfügung (patient Directive) under BGB §1827 is a personal document. The Rechtsdienstleistungsgesetz restricts legal advice, but patient Directives are not classified as a legal proceeding. | Very low |
| Spain / Portugal | Advance Directives (voluntades anticipadas / diretivas antecipadas) are regulated by health law. Registration systems exist but do not require attorney involvement. | Very low |
| European Union (general) | GDPR and data privacy are the regulatory concern, not document preparation. No EU member state prohibits software-assisted advance Directive creation. | Very low |
The United States is actually the strictest jurisdiction for this type of service — and even there, the position is strong. Internationally, the main compliance concern shifts from "are we practicing law?" to "are we handling data correctly?" — which our encryption architecture and signed data processing agreements address directly.
Data Protection
We use client-side encryption — a technical design where your sensitive medical information is encrypted in your browser before it ever reaches our server. This is not a marketing claim; it is a verifiable architectural property of the application.
You enter your medical choices in the browser
Your browser encrypts them with your passcode (AES-256-GCM)
Our server stores only the encrypted result — we cannot read it
This means that even in the worst case — a complete server breach — an attacker would obtain email addresses and names, but not your medical decisions, religious beliefs, or healthcare choices. The encrypted content is mathematically unreadable without your personal passcode.
| Regulation | How encryption helps |
|---|---|
| GDPR | Encrypted content qualifies as a supplementary transfer measure under EDPB guidance, reducing cross-border data transfer risk |
| CCPA | Statutory breach damages ($100–750 per consumer) apply only to unencrypted data; your medical content is excluded from breach scope |
| FTC Health Breach Rule | Server breach exposes only metadata (email, name), not medical content — dramatically reducing breach severity and notification scope |
| Washington MHMDA | Washington's aggressive health privacy law (treble damages up to $25K/violation) is limited in scope because the server cannot access your health data |
Regulatory Classification
bloodless.org has been assessed against three common regulatory classifications that could apply to health-related software:
- Not a medical device (FDA) — we do not diagnose, treat, monitor, or recommend treatments. We prepare legal documents. The January 2026 FDA guidance adopted a deregulatory posture toward low-risk software.
- Not an AI system (EU AI Act) — our templates are deterministic, not machine learning. Generating prompts that users copy to their own AI tool does not make bloodless.org an AI deployer.
- Not a HIPAA covered entity — we are not a healthcare provider, health plan, or clearinghouse. However, our encryption meets or exceeds the HIPAA safe harbor standard (45 CFR 164.402).
bloodless.org is a document preparation service — the same category as LegalZoom, FreeWill, or a notary public's office. The regulatory frameworks for medical devices, AI systems, and healthcare providers do not apply.
Agreements on File
We maintain signed Data Processing Agreements (DPAs) with every third-party service that handles user data, as required by GDPR Article 28:
| Processor | Purpose | Status |
|---|---|---|
| Cloudflare | CDN, DNS, TLS termination | DPA signed |
| Resend | Transactional email delivery | DPA signed |
| Stripe | Payment processing | DPA signed |
Last updated: July 2026