HIPAA-aware design
Privacy and access controls are part of the product design from the start.
Security & control
OneSource OS is designed around HIPAA-aware safeguards, organization-level separation, role-based access, and human review for important actions.
Privacy and access controls are part of the product design from the start.
Luma only works with information the user is allowed to see. When access is not allowed, Luma gives a clear refusal.
A privacy layer helps prevent unsafe access and disclosure across the experience.
Luma can prepare a recommendation or draft. An authorized person reviews important actions.
Messages remain drafts until an authorized person approves them.
Sensitive actions are recorded so they can be reviewed.
Sessions, encryption, uploads, and access controls work together to protect the workspace.
Each organization has its own operational workspace. One practice's information is not another practice's search result.
People see the work that matches their role and assignments. When access is unclear, the safe response is a clear refusal.
Summaries and access messages avoid exposing sensitive details that are not needed for the task.
Recommendations point to their supporting information. Proposed changes are shown for review before they are saved, and sensitive actions remain traceable.
A recommendation is a starting point for review. Important actions identify what would happen, which records are affected, and who must approve them.
If identity, role, or organization context cannot be confirmed, Luma protects the information and explains that it cannot provide access.
OneSource OS workspace · sample information
Access-aware review
A sample workspace shows how access, review, and traceability remain visible.
Sample information is used here; no client records are shown.
Access response example
Good: I cannot access that information under your current role.
Avoid: I can see that patient is in another practice, but you do not have access.
The first response protects people and practices by ending the inquiry without confirming sensitive information elsewhere.
HIPAA posture, MFA, BAAs, and the day-to-day technology environment (Microsoft, SharePoint, Zendesk, Telzio, RingCentral, Retell AI, BastionGPT, and OneSource OS) are documented on the company Security & technology page — kept separate from OS product access controls.
Tell us which access, review, communications, or data-handling boundary matters to your evaluation.