Skip to main content

LumisReach’s HIPAA posture

If your business handles Protected Health Information (PHI), you sign one Business Associate Agreement — with LumisReach. We’ve already executed BAAs with the subprocessors in our stack that require them. You don’t need to chase individual provider BAAs; we handle that upstream. Once your BAA is on file, we set hipaa_enabled on your workspace. That flag activates real runtime controls (described below), not just a contractual posture.

Our subprocessor BAA status

We use several third-party services to deliver LumisReach. Here’s where each one stands today — informational only; you don’t act on this list. If you need documentation of any individual subprocessor BAA for your own compliance audit, email compliance@lumisreach.com and we’ll provide it.

How to request a BAA from LumisReach

  1. Email support@lumisreach.com with subject “HIPAA BAA Request”.
  2. Include:
    • Your legal entity name
    • The workspace or team that will handle PHI
    • Your primary compliance contact (name + email)
  3. What happens next:
    • We respond within 2 business days with our standard BAA.
    • For customers who can sign as-is: same-day workspace activation once the BAA is countersigned.
    • For customers needing legal markup: we route through our counsel; typical close in 5–10 business days.
  4. After signing: We record execution on your workspace (baaSignedAt) and flip hipaa_enabled = true. The runtime controls below take effect immediately.
If you’re a partner with consistent healthcare volume, ask us about platform-wide HIPAA — a single agreement that covers your entire downstream customer base. Details on the HIPAA add-on page.

What hipaa_enabled does

A workspace with hipaa_enabled: true enforces the following at runtime:
  1. Voice AI provider HIPAA mode — every AI assistant we create on your behalf is provisioned with the upstream provider’s HIPAA setting enabled, routing inference through BAA-covered paths only.
  2. Recording disclosure locked on — you cannot save a custom assistant greeting that omits the “this call is recorded” disclosure. Our default greetings include it in 40+ languages.
  3. Recording retention cappedrecordingRetentionDays cannot exceed 30, and recordingEnabled cannot be turned off.
  4. LLM routing prefers BAA-covered model providers; fallback to non-BAA providers is blocked.
  5. Integration installs gated — third-party apps that handle PHI but don’t have a subprocessor BAA on file (e.g., certain CRM and messaging integrations) are blocked from being installed on the workspace. The full list is shown in the integrations directory with a HIPAA notice.
  6. Audit log — every compliance-relevant mutation (flag flips, BAA recording, retention changes, blocked installs) is recorded.
Flipping the flag is reversible — we don’t mass-delete historical data — but the flag itself can only be enabled when baaSignedAt is set, which requires a fully executed BAA on our side.

Security baseline LumisReach always provides

Regardless of whether hipaa_enabled is set:
  • TLS 1.3 in transit, AES-256 at rest.
  • Encrypted credential storage (LUMISREACH_ENCRYPTION_KEY).
  • Row-level access control — every API query runs through buildOwnershipFilter which scopes results to the authenticated principal’s org/team visibility.
  • Audit log on every mutation via tRPC middleware.
  • Breach notification procedures per § 164.410.
Missing something your compliance officer needs? Email compliance@lumisreach.com.