Your data security matters to us. Jerome's Digital Shop is committed to protecting your information through enterprise-grade security practices aligned with internationally recognized standards.
๐
ISO 27001
Information Security Management
โ
SOC 2
Trust Services Criteria
โฅ
HIPAA
Health Information Privacy
01 โ Security & Compliance Overview
Jerome's Digital Shop (jeromesdigitalshop.com) is an e-commerce platform offering premium digital products including ebooks, educational guides, trading resources, and professional development materials. We are founded by a Registered Nurse (RN-BSN) and Pharmacy Technician with deep understanding of data protection in both healthcare and digital commerce.
Our security practices are aligned with three internationally recognized frameworks:
ISO 27001:2022 โ The international standard for Information Security Management Systems (ISMS), providing the governance backbone for our security program.
SOC 2 (Trust Services Criteria) โ Verifying that our controls for security, availability, processing integrity, confidentiality, and privacy meet rigorous standards.
HIPAA (Health Insurance Portability and Accountability Act) โ Ensuring compliance with U.S. federal requirements for protecting health information, given our healthcare-adjacent product offerings.
Our Commitment
Compliance is not a destination โ it's a continuous process. We regularly review and update our security controls, conduct risk assessments, and invest in protecting your data at every stage of its lifecycle.
02 โ What Data We Collect
We collect only the minimum data necessary to provide our services and fulfill your orders:
Data Type
Examples
Purpose
Account Information
Name, email address
Order fulfillment, digital product delivery, account management
Transaction Data
Purchase history, order IDs
Order processing, customer support, refund handling
Payment Information
Processed by third-party gateway (we never store card numbers)
Payment processing via PCI-compliant provider
Device & Usage Data
Browser type, IP address, pages visited
Site optimization, security monitoring, analytics
Communication Data
Support emails, contact form submissions
Customer service, responding to inquiries
Payment Security
We never store your credit card numbers, CVV codes, or full payment credentials on our servers. All payment processing is handled by PCI DSS-compliant payment gateways (e.g., Stripe, PayPal) that maintain the highest levels of payment security certification.
03 โ How We Use Your Data
Your data is used strictly for the following purposes:
Order Fulfillment โ Delivering your purchased digital products and processing transactions.
Customer Support โ Responding to inquiries, troubleshooting issues, and managing your account.
Service Improvement โ Analyzing usage patterns to improve our website, products, and user experience.
Security Monitoring โ Detecting and preventing unauthorized access, fraud, and security threats.
Legal Compliance โ Meeting our obligations under applicable laws, including tax reporting and fraud prevention.
Communications โ Sending order confirmations, product updates, and (with your consent) promotional materials. You may opt out of marketing communications at any time.
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
04 โ How We Protect Your Data
We implement multiple layers of security controls aligned with ISO 27001, SOC 2, and HIPAA requirements:
Encryption
TLS 1.2+ encryption on all connections โ every page on our site is served over HTTPS with HSTS enabled.
AES-256 encryption at rest for stored data, including databases and backups.
Encrypted backups stored in geographically separate locations for disaster recovery.
Infrastructure Security
Web Application Firewall (WAF) protecting against OWASP Top 10 attacks (SQL injection, XSS, CSRF).
DDoS mitigation via CDN with rate limiting on all endpoints.
Security headers including Content-Security-Policy, X-Frame-Options, and Referrer-Policy.
Regular vulnerability scanning with critical findings remediated within 72 hours.
Monitoring & Logging
Comprehensive audit logging of all administrative actions, data access events, and authentication attempts.
Real-time alerting on suspicious activity including failed login attempts, bulk data exports, and privilege escalation.
Log retention for a minimum of 6 years in tamper-proof, append-only storage (per HIPAA requirements).
05 โ Access Control & Authentication
Access to systems containing customer data is strictly controlled:
Multi-Factor Authentication (MFA) required for all administrative access โ TOTP or hardware key (FIDO2).
Role-Based Access Control (RBAC) enforcing the principle of least privilege โ personnel only access data required for their function.
Unique user IDs โ no shared accounts. Every action is traceable to an individual.
Session management with automatic timeout after 15 minutes of inactivity for administrative sessions.
Quarterly access reviews to verify all user permissions remain appropriate.
Immediate revocation of access upon role change or personnel departure.
06 โ Data Classification & Handling
All data is classified into four tiers with corresponding handling requirements:
Level
Description
Protection
Restricted
Protected Health Information (PHI), SSNs, clinical data
Standard access controls, internal-only distribution
Public
Published content, website copy, marketing materials
Integrity controls to prevent unauthorized modification
Data Lifecycle
Data is managed through its complete lifecycle:
Collection: Data is classified at the point of creation with appropriate metadata tagging.
Storage: Encryption requirements applied per classification level. Restricted data never stored on personal devices.
Transmission: TLS minimum. Restricted data requires end-to-end encryption.
Retention: Defined periods per data type โ PHI retained 6 years; financial data 7 years; customer PII for duration of relationship plus 3 years.
Disposal: Cryptographic erasure or certified destruction with documented disposal events.
07 โ HIPAA Notice of Privacy Practices
Given our founder's healthcare background (RN-BSN, Pharmacy Technician) and our healthcare-adjacent digital products, we maintain HIPAA-aligned practices to protect any health-related information that may be collected through our platform.
Administrative Safeguards
Designated HIPAA Privacy Officer and Security Officer
Annual Security Risk Assessment (SRA) conducted and documented
Workforce HIPAA training within 30 days of access to PHI, then annually
Documented sanctions policy for HIPAA violations
Contingency plan including backup, disaster recovery, and emergency mode operation
Physical Safeguards
Facility access controls with documented physical security measures
Device and media disposal procedures โ certified wipe or physical destruction
Technical Safeguards
Unique user identification โ no shared accounts
Emergency access (break-glass) procedure with full audit trail
Automatic session logoff after โค 15 minutes of inactivity
AES-256 encryption for PHI at rest; TLS 1.2+ for PHI in transit
Audit controls generating logs for all systems that create, store, or transmit PHI
Integrity controls to verify PHI has not been altered without authorization
Person/entity authentication via MFA for all digital PHI access
Minimum Necessary Standard
We access, use, and disclose only the minimum amount of Protected Health Information necessary to accomplish the intended purpose. This applies to internal use, disclosures to business associates, and requests for PHI from external parties.
08 โ Third-Party Services & Business Associate Agreements
We carefully select third-party service providers and require appropriate safeguards:
Service Type
Safeguards
Web Hosting
HIPAA-eligible hosting with Business Associate Agreement (BAA) where applicable. Data encrypted at rest and in transit.
Payment Processing
PCI DSS Level 1 compliant gateway. We never receive or store raw card data. BAA in place where payment metadata intersects health data.
Email Services
TLS-encrypted transport. PHI is never included in marketing emails. HIPAA-compliant email solutions used for any health-related correspondence.
Analytics
Privacy-first analytics that do not track PHI. No analytics scripts on pages that collect health information.
Cloud Storage
Encrypted with BAA in place for any storage containing PHI or Restricted data.
All business associates are contractually required to:
Implement appropriate security safeguards
Report breaches of unsecured PHI promptly
Ensure subcontractors also maintain BAAs
Return or destroy PHI upon contract termination
Make practices available for compliance audits
09 โ Incident Response & Breach Notification
We maintain a documented Incident Response Plan with defined severity levels and response procedures:
Severity
Definition
Response Time
SEV-1 (Critical)
Active breach involving Restricted/PHI data or system-wide compromise
Within 1 hour
SEV-2 (High)
Confirmed unauthorized access to Confidential data or major service disruption
Within 4 hours
SEV-3 (Medium)
Suspected incident with limited scope
Within 24 hours
SEV-4 (Low)
Minor event, no data exposure confirmed
Within 72 hours
HIPAA Breach Notification
In the event of a breach involving Protected Health Information, we comply with federal notification requirements under 45 CFR ยงยง 164.404โ408:
Individual notification โ within 60 calendar days of discovering the breach, via written notice.
Media notification โ if โฅ 500 residents of a single state/jurisdiction are affected, prominent media outlets notified within 60 days.
All notification content includes: description of the breach, types of information involved, steps you should take, our investigation and mitigation actions, and contact information for questions.
10 โ Your Rights
You have the following rights regarding your personal data and any Protected Health Information:
Right to Access โ Request copies of your personal data or PHI. We will respond within 30 days.
Right to Amendment โ Request corrections to inaccurate personal data or PHI. We will respond within 60 days.
Right to Deletion โ Request deletion of your personal data, subject to legal retention requirements.
Right to Restrict Processing โ Request limitations on how your data is used or disclosed.
Right to Data Portability โ Receive your data in a structured, machine-readable format.
Right to an Accounting of Disclosures โ Request a log of who accessed your PHI and for what purpose.
Right to Confidential Communications โ Request alternative methods of communication (e.g., "contact me only by email").
Right to Opt Out โ Unsubscribe from marketing communications at any time with no impact on your purchased products or services.
To exercise any of these rights, please contact us using the information below.
11 โ Contact Us
Privacy & Security Inquiries
For questions about this policy, data access requests, or to report a security concern: