# POL-249 — A regulated vertical needs a warning that sector rules sit on top

> Where the brand is in a regulated vertical, the generated documents must be accompanied by a warning that sector rules apply on top of them.

- **Rule ID:** POL-249
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `generated policy + product warning`
- **Severity:** HIGH — Rejected by at least one carrier or provider, and a common cause of failure at the rest.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** TCR
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-249/

## Why this rule exists

A generated policy that satisfies every carrier requirement can still be badly wrong for a clinic, a lender, a school or an insurer, because HIPAA, GLBA and FERPA impose obligations no 10DLC checklist mentions. The danger is specific to generation: a document that looks finished stops the reader looking for what is missing.

## How to fix it

Where the brand is in healthcare, financial services, insurance or education, say plainly that the sector's own rules are not covered here and route the document to someone who knows them. Done when the warning names the applicable regime rather than warning in general.

## Example of a compliant value

```text
This policy covers the messaging requirements. It does not address HIPAA, which applies to Riverside Dental as a covered entity — have your privacy officer review it before publishing.
```

## Notes

Conditional on the vertical, which the registration carries as free text rather than as a controlled list, so the condition sits in the criteria rather than in a tag. The verticals named in the catalog are financial services, healthcare, education and insurance.
