Security & control

Serious controls. Clear language. No fear marketing.

OneSource OS is designed with safeguards for HIPAA-regulated work. Each organization has a separate workspace, users have role-based access, and people review important actions.

Product access is currently private. These safeguards describe the design and review standards for sensitive operational work; they are not a certification claim.

Security posture

Safeguards for HIPAA-regulated work

Privacy and access controls are part of the product design from the start. This describes the design approach, not a certification seal or a blanket compliance guarantee.

Access before assistance

Luma only works with information the user is allowed to see. When access is not allowed, Luma gives a clear refusal.

Built-in privacy protection

A privacy layer helps prevent unsafe access and disclosure across the experience.

Human review for important actions

Luma can prepare a recommendation or draft. An authorized person reviews important actions.

Human-approved messaging

Messages remain drafts until an authorized person approves them.

Traceable work

Sensitive actions are recorded so they can be reviewed.

Layered protection

Sessions, encryption, uploads, and access controls work together to protect the workspace.

How OS is designed to keep work in bounds

Practice and organization separation

Each organization has its own operational workspace. One practice's information is not another practice's search result.

Role-based access

People only see work allowed for their organization, role, team, and assignment. If access is missing or unclear, the system refuses the request.

Minimum necessary information

Summaries and access messages avoid exposing sensitive details that are not needed for the task.

Sources and change history

Recommendations should point to supporting information. Credentialing and payer-reference work keeps general guidance distinct from evidence about a specific provider or enrollment. Proposed changes are shown for review before they are saved, and sensitive actions remain traceable.

Safe connections

Each connected mailbox or tool belongs to the correct organization, practice, and purpose. Permission to receive information does not automatically include permission to send or change it.

Human review

A recommendation is a starting point for review. Important actions identify what would happen, which records are affected, and who must approve them.

When access is unclear

If identity, role, or organization context cannot be confirmed, Luma protects the information and explains that it cannot provide access.

OneSource OS workspace · sample information

Access-aware review

Show the boundary without exposing the protected record

A sample workspace shows how access, review, and traceability remain visible.

Sample information is used here; no client records are shown.

Access response example

Access-aware refusal

Good: I cannot access that information under your current role.

Avoid: I can see that patient is in another practice, but you do not have access.

The first response protects people and practices by ending the inquiry without confirming sensitive information elsewhere.

Company security & technology stack

HIPAA posture, MFA, BAAs, and the day-to-day technology environment (Microsoft, SharePoint, Zendesk, Telzio, RingCentral, Retell AI, BastionGPT, and OneSource OS) are documented on the company Security & technology page, kept separate from OS product access controls.

Read Security & technology

OneSource OS interest

Tell us what you want to follow.

OneSource OS is being shaped around the operational work OneSource handles every day. Share what caught your attention and whether you want occasional updates, a private discussion, or a future-fit conversation.

This form does not create an OS account or promise access, timing, features, or pricing. Do not include PHI or patient-specific details.

What are you interested in?

Select all that apply.