Section 10: Legal, IP & Compliance
Key Verdict: High Compliance Burden Due to HIPAA
MedMinder Pro handles Protected Health Information (PHI), requiring HIPAA from Day 1. Budget $15K-$25K Year 1 for compliance. C-Corp formation essential for seed funding.
✅ Recommended Business Structure: Delaware C-Corp
Rationale: MedMinder Pro targets B2B health plans/pharmacies with $750K seed funding planned, making VC-friendly C-Corp structure optimal. Delaware incorporation offers established case law, preferred by investors for stock options, multiple funding rounds, and exits. Handles HIPAA complexities, pharmacy integrations, and IP protection better than LLC. Enables preferred stock issuance for seed round. Avoids S-Corp shareholder limits unsuitable for scaling health tech. Formation protects founders from personal liability amid high regulatory risks (HIPAA fines up to $50K/violation).
- Formation Cost: $500-$1,500 (use Stripe Atlas/Clerky for $500)
- Annual Maintenance: $800-$1,200/year (franchise tax ~$400+, registered agent $200, filings)
- Timeline: 1-2 weeks
Incorporate Before: Seed funding, B2B contracts, HIPAA BAAs, or pharmacy API integrations. Do immediately post-MVP validation.
Intellectual Property Strategy
Trademark Protection
Action Items: 1) USPTO/state search ($50 DIY). 2) File intent-to-use app. 3) Attorney for health tech nuances.
Patent Considerations
Patentable? Maybe (ML Intervention Engine)
Novel adherence prediction ML, root-cause intervention algorithms eligible post-Alice test. Pharmacy-agnostic refill optimization potentially unique.
Recommendation: File provisional patent ($2K-$4K) pre-seed to timestamp IP. Full utility post-MVP ($12K+). Trade secrets for prompts/datasets as fallback (faster/cheaper).
Trade Secrets & Copyright
- Protect: ML models, intervention logic, user pattern datasets, pharmacy API integrations.
- Methods: NDAs for all (founders/contractors), GitHub access controls, 4-year vesting IP assignment.
- Copyright: Auto on app code/UI. Add notices; track OSS (React Native deps).
Data Privacy & Protection
Privacy Documentation
- Privacy Policy: Detail PHI collection (meds, photos, surveys), sharing (pharmacies w/consent), rights. HIPAA notice required. Cost: $2K attorney (health-specific).
- Terms of Service: PHI disclaimers, consent for sharing. Cost: $2K.
- HIPAA BAA: With AWS/OpenAI/Stripe. Standard templates.
- Cookie Banner: For analytics.
Data Handling
| Data Type | Collected? | Stored? | Encryption | Retention |
|---|---|---|---|---|
| Medication lists/PHI | Yes | HIPAA cloud | At-rest + transit (AES-256) | User-deletion or 7 years |
| Photo verification | Yes | Encrypted | Yes | 30 days post-confirm |
| Payment | Via Stripe | No | Stripe | N/A |
| AI prompts/insights | Yes | Local-first | Transit | User-controlled |
AI Notes: Use HIPAA-compliant providers (e.g., AWS Bedrock, not OpenAI base). No training on PHI. Transparent: "AI analyzes patterns; consult doctor."
Terms of Service & Regulatory Compliance
Critical ToS Clauses
- Liability Limit: Cap at 12 months fees; exclude health outcomes.
- Indemnity: User for PHI accuracy; company for IP.
- IP: User licenses PHI for service; company owns app.
- Disclaimers: "Not medical advice; FDA wellness tool only."
- AUP: No falsified PHI.
Regulations
| FDA: | Exempt (non-diagnostic) |
| HIPAA: | Full (PHI) |
| CAN-SPAM: | Yes (reminders) |
| ADA: | WCAG 2.1 AA |
| EU AI Act: | Low-risk (wellness) |
| State Pharmacy: | Licensing for price tools |
Contracts, Insurance & Checklist
Key Contracts
| Agreement | Priority |
|---|---|
| HIPAA BAA (vendors) | Critical |
| IP Assignment | Critical |
| Founder Agreement | High |
| Pharmacy Partner MSA | High (Month 7+) |
| Health Plan DPA/BAA | Critical B2B |
Insurance
| Type | Cost/Year | Priority |
|---|---|---|
| Cyber Liability | $3K-$7K | 🔴 High (PHI) |
| Professional (E&O) | $2K-$5K | 🔴 High |
| D&O | $3K-$6K | High (seed) |
Compliance Checklist by Stage
Pre-Launch
- ☐ C-Corp formation + EIN
- ☐ HIPAA BAA w/cloud
- ☐ Privacy Policy + ToS live
- ☐ Trademark search
Launch
- ☐ PHI encryption impl.
- ☐ AI disclaimers
- ☐ CAN-SPAM footers
Post-Launch (0-6 mo)
- ☐ Provisional patent
- ☐ Cyber/E&O insurance
- ☐ SOC 2 prep
Growth
- ☐ SOC 2 Type 1
- ☐ State pharmacy review
- ☐ FDA wellness confirmation
Legal Budget & Risks
Approach: Templates for basics; health tech attorney for HIPAA ($300/hr, 10-15 hrs Year 1). Allocate from $100K infra budget.
Top Risks & Mitigations
| Risk | Severity | Mitigation |
|---|---|---|
| HIPAA Breach/Fines | 🔴 High | HIPAA-compliant stack (AWS), cyber insurance, annual training |
| AI Health Liability | 🔴 High | "Wellness only" disclaimers, E&O insurance, doctor prompts |
| IP Infringement | 🟡 Medium | Trademark search, provisional patent |
| Pharmacy Regs | 🟡 Medium | Legal review pre-integration |
Next Steps
- Form C-Corp via Clerky ($500, 1 week).
- Attorney consult for HIPAA setup ($1K).
- Draft/review Privacy Policy + ToS.
- Secure cyber insurance quotes.