🔍
Compliance and Certifications
Luma Health architects our security program around internationally-recognized
information security and data privacy frameworks, as well as industry best practices.
We undertake accredited third-party audits no less than annually to ensure ongoing compliance.
Luma’s dedicated, in-house Security and Compliance team ensures that
Luma follows the latest information security frameworks and data privacy
regulations, including staying up-to-date on upcoming changes.
HITRUST CSF r2
We are HITRUST CSF r2 Certified, a risk-based certification that is the gold standard in healthcare technology.
TX-RAMP Level 2
We are TX-RAMP (Texas Risk and Authorization Management Program) Level 2 certified.
Tx-RAMP is a framework designed to ensure the security and compliance of cloud services used by Texas state agencies.
ISO 27001:2022
We are ISO 27001:2022 Certified, an internationally-recognized standard for the
implementation of an Information Security Management System (ISMS).
US-EU Privacy Framework
We participate in the US-EU Privacy framework, including the UK and Swiss extensions.
SOC 2 Type II
We perform a SOC 2 Type II attestation annually, providing assurance
that not only do we have appropriate security controls in place,
but they are also operating effectively.
HIPAA Compliant
All of Luma's software and company processes are fully
HIPAA-compliant.