Safeguards for HIPAA-regulated work
Privacy and access controls are part of the product design from the start. This describes the design approach, not a certification seal or a blanket compliance guarantee.
Security & control
OneSource OS is designed with safeguards for HIPAA-regulated work. Each organization has a separate workspace, users have role-based access, and people review important actions.
Privacy and access controls are part of the product design from the start. This describes the design approach, not a certification seal or a blanket compliance guarantee.
Luma only works with information the user is allowed to see. When access is not allowed, Luma gives a clear refusal.
A privacy layer helps prevent unsafe access and disclosure across the experience.
Luma can prepare a recommendation or draft. An authorized person reviews important actions.
Messages remain drafts until an authorized person approves them.
Sensitive actions are recorded so they can be reviewed.
Sessions, encryption, uploads, and access controls work together to protect the workspace.
Each organization has its own operational workspace. One practice's information is not another practice's search result.
People only see work allowed for their organization, role, team, and assignment. If access is missing or unclear, the system refuses the request.
Summaries and access messages avoid exposing sensitive details that are not needed for the task.
Recommendations should point to supporting information. Credentialing and payer-reference work keeps general guidance distinct from evidence about a specific provider or enrollment. Proposed changes are shown for review before they are saved, and sensitive actions remain traceable.
Each connected mailbox or tool belongs to the correct organization, practice, and purpose. Permission to receive information does not automatically include permission to send or change it.
A recommendation is a starting point for review. Important actions identify what would happen, which records are affected, and who must approve them.
If identity, role, or organization context cannot be confirmed, Luma protects the information and explains that it cannot provide access.
OneSource OS workspace · sample information
Access-aware review
A sample workspace shows how access, review, and traceability remain visible.
Sample information is used here; no client records are shown.
Access response example
Good: I cannot access that information under your current role.
Avoid: I can see that patient is in another practice, but you do not have access.
The first response protects people and practices by ending the inquiry without confirming sensitive information elsewhere.
HIPAA posture, MFA, BAAs, and the day-to-day technology environment (Microsoft, SharePoint, Zendesk, Telzio, RingCentral, Retell AI, BastionGPT, and OneSource OS) are documented on the company Security & technology page, kept separate from OS product access controls.
OneSource OS interest
OneSource OS is being shaped around the operational work OneSource handles every day. Share what caught your attention and whether you want occasional updates, a private discussion, or a future-fit conversation.
This form does not create an OS account or promise access, timing, features, or pricing. Do not include PHI or patient-specific details.