Compliance

How We Operate

bloodless.org is a document preparation service, not a law firm. This page explains our legal position, data protection architecture, and regulatory compliance.

📝

Document preparation

You make every decision. Our software formats your choices into a document — nothing more.

🔒

Client-side encryption

Your medical Directive is encrypted in your browser before it ever reaches our server. We cannot read it.

🌍

Built for global use

Advance Directives are personal documents worldwide. No country prohibits software-assisted creation.

In short: No advance Directive preparation service has ever been successfully prosecuted for unauthorized practice of law in any U.S. state — and the U.S. is the strictest jurisdiction for this question. Internationally, the legal position is even more favorable.

How We Operate

bloodless.org helps you create an advance medical Directive — a legal document expressing your wishes about blood transfusions and bloodless healthcare. The legal term for what we do is "scrivener" — a service that writes down what you tell it, without giving advice about what you should say.

What we do

  • Present a structured questionnaire you fill in yourself
  • Format your answers into a professional document
  • Show published legal requirements (e.g., "New York requires two witnesses")
  • Provide educational resources about medical and legal terminology

What we never do

  • Give legal advice or recommend specific choices
  • Select forms or provisions for you
  • Review your document for legal sufficiency
  • Form an attorney-client relationship

This distinction — between a tool that fills in what you decide and a service that tells you what to decide — is the foundation of our legal position. Courts and regulators have consistently upheld this model.

Services that help people create advance Directives have operated for decades without legal challenge. The precedent is well established:

ServiceModelLegal challenges
Five WishesPaper advance Directive form, created with the American Bar AssociationNone — zero reported challenges
FreeWillInteractive online questionnaire for advance Directives — closest comparable to bloodless.orgNone — zero reported challenges
AARP / CaringInfoDownloadable state-specific advance Directive forms with educational contentNone — zero reported challenges
LegalZoomInteractive questionnaire for wills, trusts, business documentsChallenged in 8 states — ultimately approved by the South Carolina Supreme Court (2014) as a permissible "scrivener" model

The Federal Trade Commission and U.S. Department of Justice have submitted formal comment letters supporting technology-based legal services, suggesting states update their rules to accommodate interactive software that helps people prepare their own documents.

U.S. State-by-State Assessment

"Unauthorized practice of law" (UPL) means performing legal services — such as giving legal advice or drafting documents for someone — without being a licensed attorney. Every U.S. state has UPL laws, but the definitions and penalties vary. We researched the six highest-priority states in detail:

StateUPL classificationSafe harborRisk
TexasCivil offenseYes — explicit statutory safe harbor for software (Gov't Code §81.101(c))Low
PennsylvaniaMisdemeanorNone statutoryLow
New YorkMisdemeanorNone — case-by-caseLow–Medium
CaliforniaMisdemeanorLegal Document Assistant framework provides a clear modelLow–Medium
WashingtonGross misdemeanor / felonyAffirmative defense onlyLow–Medium
FloridaFelony (3rd degree)None statutoryMedium
Key fact: No U.S. state has ever targeted an advance Directive preparation service for UPL enforcement — even in Florida, where UPL is a felony and enforcement is aggressive. Every state provides statutory advance Directive forms designed for self-service completion without an attorney.

International Position

Outside the United States, the legal landscape is more favorable, not less. Most countries do not have a UPL concept equivalent to the U.S., and advance Directives are universally treated as personal documents that individuals prepare themselves.

RegionLegal frameworkRisk
BrazilNo UPL equivalent. Advance Directives recognized via medical council resolution (CFM 1.995/2012). Regulated by health law, not legal practice law. LGPD (data privacy) is the primary compliance concern.Very low
MexicoNo federal UPL framework. State-level Ley de Voluntad Anticipada (Mexico City 2008 model) designed for self-service completion.Very low
United Kingdom"Advance decisions" under the Mental Capacity Act 2005 are explicitly designed for completion without a solicitor. "Reserved legal activities" under the Legal Services Act 2007 do not cover advance Directive preparation.Very low
GermanyPatientenverfügung (patient Directive) under BGB §1827 is a personal document. The Rechtsdienstleistungsgesetz restricts legal advice, but patient Directives are not classified as a legal proceeding.Very low
Spain / PortugalAdvance Directives (voluntades anticipadas / diretivas antecipadas) are regulated by health law. Registration systems exist but do not require attorney involvement.Very low
European Union (general)GDPR and data privacy are the regulatory concern, not document preparation. No EU member state prohibits software-assisted advance Directive creation.Very low

The United States is actually the strictest jurisdiction for this type of service — and even there, the position is strong. Internationally, the main compliance concern shifts from "are we practicing law?" to "are we handling data correctly?" — which our encryption architecture and signed data processing agreements address directly.

Data Protection

We use client-side encryption — a technical design where your sensitive medical information is encrypted in your browser before it ever reaches our server. This is not a marketing claim; it is a verifiable architectural property of the application.

1

You enter your medical choices in the browser

2

Your browser encrypts them with your passcode (AES-256-GCM)

3

Our server stores only the encrypted result — we cannot read it

This means that even in the worst case — a complete server breach — an attacker would obtain email addresses and names, but not your medical decisions, religious beliefs, or healthcare choices. The encrypted content is mathematically unreadable without your personal passcode.

RegulationHow encryption helps
GDPREncrypted content qualifies as a supplementary transfer measure under EDPB guidance, reducing cross-border data transfer risk
CCPAStatutory breach damages ($100–750 per consumer) apply only to unencrypted data; your medical content is excluded from breach scope
FTC Health Breach RuleServer breach exposes only metadata (email, name), not medical content — dramatically reducing breach severity and notification scope
Washington MHMDAWashington's aggressive health privacy law (treble damages up to $25K/violation) is limited in scope because the server cannot access your health data

Regulatory Classification

bloodless.org has been assessed against three common regulatory classifications that could apply to health-related software:

  • Not a medical device (FDA) — we do not diagnose, treat, monitor, or recommend treatments. We prepare legal documents. The January 2026 FDA guidance adopted a deregulatory posture toward low-risk software.
  • Not an AI system (EU AI Act) — our templates are deterministic, not machine learning. Generating prompts that users copy to their own AI tool does not make bloodless.org an AI deployer.
  • Not a HIPAA covered entity — we are not a healthcare provider, health plan, or clearinghouse. However, our encryption meets or exceeds the HIPAA safe harbor standard (45 CFR 164.402).

bloodless.org is a document preparation service — the same category as LegalZoom, FreeWill, or a notary public's office. The regulatory frameworks for medical devices, AI systems, and healthcare providers do not apply.

Agreements on File

We maintain signed Data Processing Agreements (DPAs) with every third-party service that handles user data, as required by GDPR Article 28:

ProcessorPurposeStatus
CloudflareCDN, DNS, TLS terminationDPA signed
ResendTransactional email deliveryDPA signed
StripePayment processingDPA signed
Questions? If you have questions about our legal position or data protection practices, contact us at legal@bloodless.org.

Last updated: July 2026