Compliance · Sensitive data governance
ISOVERTIC Sensitive Data Governance
Four steps, each with a written output the client keeps. Designed against the FTC's Section 5 standard for health data disclosure as well as HIPAA.
01
Data map
Before any campaign launches we map every touchpoint where sensitive data could be collected, transmitted, or observed: forms, pixels, call recording, chat, CRM sync, ad platform uploads.
Output · A written data flow map, reviewed by client compliance.
02
Classification
Each data element is classified: PHI, non PHI health data, financial, biometric, or non sensitive. The class decides the tooling.
Output · A classification register per field.
03
Tooling gate
No tool enters the stack without a signed BAA for PHI, a DPA for non PHI regulated data, or explicit sign off for non sensitive data.
Output · A tooling register the client can audit at any time.
04
Ongoing review
Quarterly review of tracker inventory, pixel firing rules, ad platform audience uploads, and third party script inventory.
Output · A written compliance diff report each quarter.
Recent FTC enforcement against GoodRx, BetterHelp, Cerebral, and Flo Health treats disclosure of health data to advertising platforms as a Section 5 violation even where HIPAA does not apply. Our sensitive data governance is designed against that standard, not only HIPAA.
GoodRx · BetterHelp · Cerebral · Flo Health
ISOVERTIC · ISOVERTIC is an assumed name of Rocket Creative LLC. 600 Johnson Ave, Suite D5, Bohemia, NY 11716 · sale@isovertic.com · https://isovertic.com