Changelog — 2026 Annual Policy Review
This document summarizes all substantive changes made to the Luma Health policy library as part of the 2026 annual HIPAA/HITRUST compliance review (feature/2026-review branch, PR #242). Changes are grouped by policy file in the order they were addressed during the review.
01. Introduction
- Renamed “Messaging Platform” to “Patient Success Platform” consistently across the policy library (glossary, breach, systems access, README/index), matching terminology already used elsewhere.
- Added a “Tonic Health Platform” glossary definition, reflecting Tonic’s acquisition by Luma.
- Removed the outdated “Messaging Platform” section describing a discontinued product (SMS/email/voice channels, Secure Message).
- Moved “Requesting Audit and Compliance Reports” into
08-auditing_policy.md(§8.3.1), removing the duplicate. - Fixed section numbering (§1.1–1.3) that collided with global section numbers used by other policy files; reordered subsections to Scope, Objectives, Compliance Inheritance for a more logical flow.
- Fixed “Managment” typo.
03. Policy Management Policy
- Replaced NIST (a best-practice source, not a compliance target) with ISO/IEC 27001 in the list of standards Luma maintains compliance with; noted the annual SOC 2 Type II attestation separately as a report rather than a standard.
- Moved the OCR Audit Program Protocol tracking process to the Auditing Policy, where it fits better.
04. Risk Management Policy
- Fixed typos (“exernal envrionment”, “Risk Managment”, a garbled controls/compliance sentence) and corrected a CIS/CISA mix-up (the Center for Internet Security is CIS, not CISA).
- Added the missing 164.308(a)(1)(i) citation to §4.1.2 to match usage elsewhere.
- Restructured §4.2’s product life-cycle bullets into a proper nested list.
- Fixed a missing verb and wrong preposition/missing periods in §4.3.1 and §4.3.4; normalized capitalization of “senior management”; fixed a future/present tense inconsistency.
- Replaced a standalone restatement of disciplinary consequences with a reference to the Employees Policy’s Workforce Sanctions section (updated twice as that section was later renumbered).
05. Roles Policy
- Fixed a citation typo (164.308(1)(2) → 164.308(a)(2)) for the Security Officer and added HIPAA citations to §5.1.2 that were already referenced in the body text but missing from Applicable Standards.
- Replaced an HTML-escaped parenthesis artifact with plain text; fixed “polices” → “policies”; normalized pronoun usage (“his” → “his/her”).
- Converted an irregular bullet+number list to standard ordered-list formatting; fixed inconsistent nested-list indentation.
- Updated the Security Officer contact to denis.savenko@lumahealth.io.
- Renamed §5.3.3 “Sanctions of Workforce Responsibilities” to “Reporting and Investigation of Workforce Violations,” keeping only the Security Officer’s investigative role and moving the actual disciplinary substance (including the mandatory-immediate-termination carve-out for ePHI confidentiality/integrity/availability violations) to the Employees Policy, which now owns disciplinary policy end-to-end.
06. Data Management Policy
- Rewrote the backup-service description: the intro previously named MongoDB Atlas’ backup service as if it were Luma’s only mechanism, when AWS Backup Service is the primary mechanism for AWS-hosted systems and Atlas’ own service applies only to Atlas-hosted databases. Clarified §6.2.1 and fixed an ambiguous availability-zone/replication description in §6.2.6.
- Replaced remaining “DevOps Team” references with “Infrastructure (SRE) Team.”
- Added new §6.3/§6.4 (Data Classification, Data De-Identification) moved from the Data Integrity Policy, where the content fit better.
- Replaced a standalone disciplinary-consequences restatement with a reference to the Employees Policy’s Workforce Sanctions section.
07. Systems Access Policy
- Consolidated the access-review process, which previously mixed three conflicting cadences (bi-annual, quarterly, 90-day) for what is one process, into a single review covering terminated-employee cleanup, least-privilege checks, inactive accounts, and API keys — cadence further tightened from 90 to 60 days per system as part of a later cross-policy consolidation with the Auditing Policy (§8), which separately clarified that 90 days is the threshold for disabling inactive accounts.
- Moved the “workstations must remain at the facility” control to the Facility Access Policy, conditioned on Luma operating a physical office (the prior wording assumed an office that doesn’t currently exist).
- Replaced an unconfirmed implementation detail (“list of workforce members with access is updated in MongoDB”) with an accurate, platform-neutral description; this was later further generalized to a policy-level statement independent of any specific admin tool.
- Generalized workstation wipe-on-decommission language to not assume Jamf remote wipe specifically, while keeping Jamf named where it is a required technical control or specific agent capability.
- Fixed typos (“continaing,” “possilble,” “approved be management,” “Mac OSX” → “macOS,” a broken “this includes and Remote Access” phrase).
- Normalized explicit list numbering to the auto-numbered “1.” convention used elsewhere; fixed a skipped number and a duplicate “## 7.11” heading (renumbered to §7.13), correcting its broken incoming link from the Data Retention Policy.
- Moved the “01.c Privilege Management” HITRUST citation here from the Auditing Policy, since it documents the access-review process.
- Replaced remaining “Web Services Team”/”Dev Ops” references with “Infrastructure (SRE) Team”; updated the CTO contact to Marcelo Oliveira (408-890-0973, marcelo@lumahealth.io).
- Updated cross-references and section numbers following the Data Integrity Policy’s §17.6 removal and the HR policy merge.
08. Auditing Policy
- Added new §8.3.1 “Requesting Audit and Compliance Reports” (moved from the Introduction) and new §8.11 “Auditing HIPAA Compliance Program” (moved from Policy Management), fixing a “Complience” typo along the way.
- Removed duplicate user-entitlement-audit bullets (60-day entitlement audit, 90-day inactive-account disablement, 60-day privileged-account audit) now that the consolidated process lives in the Systems Access Policy.
- Required audit-report reviewers to be a Security team member (or the Privacy Officer) other than the workforce member responsible for the reviewed system, enforcing separation of duties instead of self-review.
- Replaced yearly/quarterly log-review language with a continuous automated log-monitoring and daily Security Team review process, plus an annual effectiveness assessment.
- Normalized remaining explicit list numbering to the “1.” convention; fixed “nessessary” → “necessary”.
- Replaced a standalone disciplinary-consequences restatement with a reference to the Employees Policy’s Workforce Sanctions section (updated as that section was renumbered).
09. Configuration Management Policy
- Replaced the false statement “Luma does not have root access to the virtual machines; patches are managed by AWS” with the actual patching process (EC2 via SSM/SSH by authorized personnel; EKS nodes via base image updates and node replacement).
- Generalized GitHub-only tooling references (web interface, Dependabot, “built-in GitHub mechanisms”) to also account for Bitbucket, which Luma also uses; dropped an “LGTM comment” alternative since only the platform’s approve action is actually used.
- Applied the single-review requirement codebase-wide, replacing a two-tier rule (implicit minimum vs. mandatory two reviewers for ePHI-touching changes) with one unconditional review requirement for every PR, and folded security-analysis/audit-log checks into standard review rather than gating them on an ePHI determination.
- Moved the annual vulnerability-training requirement out of the PR/review procedure into the general Configuration Management policy statement, since it’s a standing obligation, not a per-PR check.
- Narrowed a Jamf-manages-network-equipment claim to user-issued devices only, matching Jamf’s actual scope.
- Fixed the §16.2 cross-reference, which pointed at a same-file anchor instead of the Vulnerability Scanning Policy file; fixed typos (“a a”, “maintaned,” “seperation,” “Securiy,” “knowledgable”) and normalized list numbering/indentation.
- Added a reference to the expanded vulnerability-scanning tooling list.
10. Facility Access Policy
- Added an explicit preamble noting Luma is fully remote and does not currently operate a physical office, scoping facility-specific controls (visitor escort, repairs, fire suppression, smart locks/keys) under “should Luma establish such a facility.”
- Removed the media-disposal bullets and “Workstation Security” block, which duplicated content already owned by the Disposable Media Policy and Systems Access Policy; moved the corresponding HITRUST citations to those files.
- Fixed minor typos and normalized explicit list numbering to the “1.” convention.
11. Incident Response Policy
- Replaced “IT department” (not a team that exists at Luma) with “Security and Infrastructure (SRE) teams,” matching terminology used elsewhere.
- Removed “Secure Chat” from the incident reporting channels list, since it isn’t a tool actually in use.
- Fixed “affect system(s)” → “affected system(s)” and reworded an awkward anonymous-reporting sentence.
12. Breach Policy
- Replaced a standalone disciplinary-consequences restatement with references to the Employees Policy’s Employment Policies and Workforce Sanctions sections, since sanctions/disciplinary substance now lives there and breach policy points to it rather than restating it.
13. Disaster Recovery Policy
- Updated the CTO contact to Marcelo Oliveira (408-890-0973, marcelo@lumahealth.io).
- Consolidated the legacy “Web Services Team,” “Ops Team,” and “Dev Ops” references into a single current “Infrastructure (SRE) Team” throughout the recovery procedures.
14. Disposable Media Policy
- Fixed a HITRUST citation format issue (09.o) and added a cross-reference to the Data Retention Policy’s retention schedule (§18.2).
- Fixed minor grammar issues in the reuse and termination clauses.
- Gained the media-disposal and equipment re-use citations moved here from the Facility Access Policy.
15. IDS Policy
- Documented the full log-monitoring toolset (Splunk, CrowdStrike on laptops, TrendMicro on select servers) in addition to DataDog, which was previously the only tool mentioned.
16. Vulnerability Scanning Policy
- Documented the full scanning toolset (Snyk, Trivy, Rapid7 DAST, Intruder, AWS Inspector, Hamming AI, HackerGuardian) with accurate per-tool cadence.
- Extended penetration testing and change management scope to cover AI model deployments and AI-specific threats (model poisoning, model inversion).
17. Data Integrity Policy
- Reworded the intro to sound more professional (“Luma is committed to maintaining the integrity of the data it processes”).
- Added a risk-based exception to the anti-malware requirement for systems where a documented risk analysis determines the system is not commonly affected by malicious software (e.g., read-only filesystems).
- Removed §17.6 “Intrusion Detection and Vulnerability Scanning” entirely, as it duplicated the dedicated IDS and Vulnerability Scanning policies; renumbered subsequent sections accordingly.
- Moved the Data De-Identification section to the Data Management Policy, where it fits topically.
- Replaced remaining “DevOps team” references with “Infrastructure (SRE) team.”
- Fixed “resctrited” → “restricted”.
19. Employees Policy (merged with former 24. Human Resources Security Policy)
- Updated the performance-review platform reference from 15Five to Rippling.
- Corrected performance-review eligibility and cadence to reflect actual practice: bi-annual reviews, 3-month tenure eligibility (previously documented inconsistently as annual/6-month in two separate files).
- Merged
24-Human_Resources_Security_Policy.mdinto this file and deleted the former, eliminating duplicated/drifting descriptions of workforce sanctions, performance review, and security/compliance training that previously existed in both files. - Reordered all sections into a chronological employee-lifecycle structure: HR Roles → Background Check → Onboarding → Employment Policies → Issue Escalation → Workforce Sanctions & Disciplinary Records → Offboarding.
- Established this file as the single source of truth for workforce sanctions and disciplinary process; other policies (Risk Management, Roles, Data Management, Auditing, Facility Access, Breach) now reference it instead of restating disciplinary consequences.
- Updated all internal and cross-file references to the new section numbers.
21. 3rd Party Policy
- Replaced “Google Forms” with “Luma’s internal GRC system” to reflect the actual current tool used for vendor SLA/annual reviews.
- Fixed “Questionniare” → “Questionnaire” typo.
26. Data Transfer Impact Assessment
- Generalized the certification claim in §26.5, which named a fixed set (ISO 27001:2022, HITRUST CSF r2, SOC 2 Type II) that goes stale as Luma now operates multiple products/business lines with different certification levels (e.g., Tonic’s HITRUST CSF e1 vs. Luma Health’s HITRUST CSF r2); now describes certifications generically as “appropriate to each of its products and business lines.”
- Similarly generalized the §26.7 incident-management framework claim to avoid pinning to a specific ISO 27001/HITRUST version.
- Fixed “Managment” typo.
27. Luma Health Subprocessors
- Removed an inaccurate blanket claim that no subprocessor can access data contents due to encryption; this did not hold for messaging subprocessors (e.g., Twilio, Mailgun), which necessarily process message content in the clear to deliver it.
- Fixed “Indentifiable” → “Identifiable” typo.
Outstanding items (not addressed in this review cycle)
The following were identified during the review but deliberately left out of scope to avoid overloading individual commits. They are candidates for a follow-up pass:
- Several pre-existing broken same-file/cross-file anchor links using an outdated dotted-anchor style (e.g.,
#9.-configuration-management-policy), found in01-introduction.md,05-roles_policy.md,12-breach_policy.md,13-disaster_recovery_policy.md,17-data_integrity_policy.md,18-data_retention_policy.md,19-employees_policy.md, and21-3rd_party_policy.md. - Two heading-level inconsistencies where a three-part section number uses
##instead of###:08-auditing_policy.md§8.3.1 and13-disaster_recovery_policy.md§13.1.1/§13.1.2. - Remaining sequentially-numbered lists (
2.,3.,4., …) that should use the literal1.convention relied on elsewhere:05-roles_policy.md,06-data_management_policy.md,17-data_integrity_policy.md,29-Artificial_Intelligence_Goverance_and_Use_Policy.md. - Minor typos: “Managment” (
01-introduction.md), “appplication” (06-data_management_policy.md), “catagories”/”Contractural”/ “Juristictions”/”anually” (26-data_transfer_impact_assessment.md), and a likely “impressive” → “impermissible” wording error in12-breach_policy.md’s breach-notification purpose statement. 03-policy_management_policy.mdcites HITRUST control “12.c” (a Business Continuity domain control), which appears to be a copy-paste artifact from the Disaster Recovery Policy — likely should cite a Security Policy domain (04.x) control instead; needs verification.09-configuration_management_policy.mdcites HITRUST domain “06 - Configuration Management” at the top level, which conflicts with domain 06 being used as “Compliance” everywhere else in the policy library; needs verification against a canonical HITRUST reference before correcting.