LumèDocs

HIPAA and security

How Lumè protects client data — the BAA, data isolation, roles, and audit logging.

A medical spa handles protected health information, so Lumè is built to be HIPAA-compliant from the ground up — not as an add-on or a higher pricing tier. This article explains how your data is protected and the small part you play in keeping it that way.

The BAA

A Business Associate Agreement (BAA) is the contract HIPAA requires between you and any service that handles patient data on your behalf. With Lumè, the BAA is included in every account, at every plan — there's no separate paperwork to chase or upgrade to buy. The cloud infrastructure Lumè runs on is itself covered by a signed BAA, so the chain of responsibility holds end to end.

How your data is protected

  • Isolation. Your spa's data is separated from every other spa's at the database level. One business can never see another's records.
  • Access by role. People only reach the parts of the app their role calls for — your front desk works the calendar and checkout without seeing financials, for instance.
  • Audit logging. Sensitive actions are recorded: when protected health information is read, when records change, when forms are signed (with a timestamp and audit details), and when financial records are reopened or voided. If you ever need to know who did what, there's a trail.
  • Encryption. Data is encrypted in transit and at rest.

Your part

Good security is shared. A few habits keep your side strong:

  • Give each team member their own login and the role that fits their job — don't share accounts.
  • Sign out on shared front-desk devices at the end of a shift, so the record of who did what stays accurate.
  • Deactivate people when they leave (see Employees and roles).
  • Use a strong, unique password.

Questions

If you have a specific compliance question — or need documentation for your own records — reach the Lumè team through Support.

Last updated June 4, 2026