Level up your learning with Luma experts
X
KEEPING YOUR DATA SECURE

Information Security, Data Privacy, and Trust at Luma Health

Cybersecurity is more important than ever for healthcare organizations. Our security program is anchored by industry-leading information security and data privacy certifications to assure you that we  take seriously the security of your data and your patients’ data.

Hi Trust logo TX RAMP Seal logo ISO logo DPF logo AICPA SOC logo HIIPA logo

At Luma, our goal is to put patients at the center of everything we do. Our security, privacy, and compliance programs help us support our customers and achieve this goal.”

Nick Lees

Head of Information Security & Compliance

🔍

Compliance and Certifications

Luma Health architects our security program around internationally-recognized information security and data privacy frameworks, as well as industry best practices. We undertake accredited third-party audits no less than annually to ensure ongoing compliance.

Luma’s dedicated, in-house Security and Compliance team ensures that Luma follows the latest information security frameworks and data privacy regulations, including staying up-to-date on upcoming changes. 

HITRUST CSF r2

We are HITRUST CSF r2 Certified, a risk-based certification that is the gold standard in healthcare technology.

TX-RAMP Level 2

We are TX-RAMP (Texas Risk and Authorization Management Program) Level 2 certified. Tx-RAMP is a framework designed to ensure the security and compliance of cloud services used by Texas state agencies.

ISO 27001:2022

We are ISO 27001:2022 Certified, an internationally-recognized standard for the implementation of an Information Security Management System (ISMS).

US-EU Privacy Framework

We participate in the US-EU Privacy framework, including the UK and Swiss extensions.

SOC 2 Type II

We perform a SOC 2 Type II attestation annually, providing assurance that not only do we have appropriate security controls in place, but they are also operating effectively.

HIPAA Compliant

All of Luma's software and company processes are fully HIPAA-compliant.

Stay Informed and Get in Touch

Contact our team

If you have a security concern with the Luma platform, or you have reason to believe you have discovered a security weakness or vulnerability in our platform, let us know at security@lumahealth.io.

Get the latest system status updates

View real-time information on Luma’s system status, historical uptime, and incident information at status.lumahealth.io. You can subscribe to alerts on this page to ensure you are proactively notified of any issues affecting Luma Health’s applications or services.

Zero Trust Identity and Access Management

All system access at Luma Health follows the principles of Zero Trust and Least Privilege and is centrally managed, with Single Sign On (SSO) required wherever possible. Context-aware controls ensure that certain conditions are met, such as device type encryption and location, before logins are granted.

We enforce Multi-Factor Authentication across the organization. All access is role-based, and requires management and/or system owner approval. Luma Health’s internal audit team performs access entitlement reviews every 60 days for all accounts.

Infrastructure

We operate a modern microservices-based infrastructure that is architected for high-availability with zero single points of failure. All of our infrastructure is managed via code and dynamically scales up and down based on system load and demand.

Software Development and Change Management

We have a fully-documented SDLC which follows the OWASP Top Ten. All development is performed in-house, and all new code as well as changes to existing code are subject to Static and Dynamic Application Security Testing (SAST and DAST) and peer review before being considered for a production release.

Every change and release follows our change control process, which includes peer review, testing and validation in lower environments, a backout plan, management approval, and separation of duties between development and release activities.

Vulnerability Management

We perform automated vulnerability scans of our infrastructure monthly, as well as continuous monitoring and scanning of any emerging threats. New infrastructure targets are automatically added to the scan rotation. We partner with a third party to perform external penetration testing annually. Any discovered vulnerabilities are remediated in line with our defined schedule.

Corporate Security

All employees are provided with a Luma Health-owned and controlled device that is centrally managed via an MDM solution. All devices are protected by centrally-managed security controls such as Endpoint Detection and Response (EDR), next Generation Anti-Virus, firewalls, device encryption, activity lock, and data loss prevention.

Personnel Security and Training

All employees are subject to a background check before joining Luma Health, and are required to complete information security Training, HIPAA training, and policy attestation as part of the onboarding process. Information security training is performed on an ongoing basis, which includes simulated phishing tests.

BCP and DR

All employees are subject to a background check before joining Luma Health, and are required to complete information security Training, HIPAA training, and policy attestation as part of the onboarding process. Information security training is performed on an ongoing basis, which includes simulated phishing tests.

AI Data, Privacy and Security

All employees are subject to a background check before joining Luma Health, and are required to complete information security Training, HIPAA training, and policy attestation as part of the onboarding process. Information security training is performed on an ongoing basis, which includes simulated phishing tests.

Data Privacy

We use your data only to provide contracted services. We never share or sell your data to any third parties, and your data is never used for advertising purposes.

We comply with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov.