Changelog — 2026 Annual Policy Review

This document summarizes all substantive changes made to the Luma Health policy library as part of the 2026 annual HIPAA/HITRUST compliance review (feature/2026-review branch, PR #242). Changes are grouped by policy file in the order they were addressed during the review.

01. Introduction

  • Renamed “Messaging Platform” to “Patient Success Platform” consistently across the policy library (glossary, breach, systems access, README/index), matching terminology already used elsewhere.
  • Added a “Tonic Health Platform” glossary definition, reflecting Tonic’s acquisition by Luma.
  • Removed the outdated “Messaging Platform” section describing a discontinued product (SMS/email/voice channels, Secure Message).
  • Moved “Requesting Audit and Compliance Reports” into 08-auditing_policy.md (§8.3.1), removing the duplicate.
  • Fixed section numbering (§1.1–1.3) that collided with global section numbers used by other policy files; reordered subsections to Scope, Objectives, Compliance Inheritance for a more logical flow.
  • Fixed “Managment” typo.

03. Policy Management Policy

  • Replaced NIST (a best-practice source, not a compliance target) with ISO/IEC 27001 in the list of standards Luma maintains compliance with; noted the annual SOC 2 Type II attestation separately as a report rather than a standard.
  • Moved the OCR Audit Program Protocol tracking process to the Auditing Policy, where it fits better.

04. Risk Management Policy

  • Fixed typos (“exernal envrionment”, “Risk Managment”, a garbled controls/compliance sentence) and corrected a CIS/CISA mix-up (the Center for Internet Security is CIS, not CISA).
  • Added the missing 164.308(a)(1)(i) citation to §4.1.2 to match usage elsewhere.
  • Restructured §4.2’s product life-cycle bullets into a proper nested list.
  • Fixed a missing verb and wrong preposition/missing periods in §4.3.1 and §4.3.4; normalized capitalization of “senior management”; fixed a future/present tense inconsistency.
  • Replaced a standalone restatement of disciplinary consequences with a reference to the Employees Policy’s Workforce Sanctions section (updated twice as that section was later renumbered).

05. Roles Policy

  • Fixed a citation typo (164.308(1)(2) → 164.308(a)(2)) for the Security Officer and added HIPAA citations to §5.1.2 that were already referenced in the body text but missing from Applicable Standards.
  • Replaced an HTML-escaped parenthesis artifact with plain text; fixed “polices” → “policies”; normalized pronoun usage (“his” → “his/her”).
  • Converted an irregular bullet+number list to standard ordered-list formatting; fixed inconsistent nested-list indentation.
  • Updated the Security Officer contact to denis.savenko@lumahealth.io.
  • Renamed §5.3.3 “Sanctions of Workforce Responsibilities” to “Reporting and Investigation of Workforce Violations,” keeping only the Security Officer’s investigative role and moving the actual disciplinary substance (including the mandatory-immediate-termination carve-out for ePHI confidentiality/integrity/availability violations) to the Employees Policy, which now owns disciplinary policy end-to-end.

06. Data Management Policy

  • Rewrote the backup-service description: the intro previously named MongoDB Atlas’ backup service as if it were Luma’s only mechanism, when AWS Backup Service is the primary mechanism for AWS-hosted systems and Atlas’ own service applies only to Atlas-hosted databases. Clarified §6.2.1 and fixed an ambiguous availability-zone/replication description in §6.2.6.
  • Replaced remaining “DevOps Team” references with “Infrastructure (SRE) Team.”
  • Added new §6.3/§6.4 (Data Classification, Data De-Identification) moved from the Data Integrity Policy, where the content fit better.
  • Replaced a standalone disciplinary-consequences restatement with a reference to the Employees Policy’s Workforce Sanctions section.

07. Systems Access Policy

  • Consolidated the access-review process, which previously mixed three conflicting cadences (bi-annual, quarterly, 90-day) for what is one process, into a single review covering terminated-employee cleanup, least-privilege checks, inactive accounts, and API keys — cadence further tightened from 90 to 60 days per system as part of a later cross-policy consolidation with the Auditing Policy (§8), which separately clarified that 90 days is the threshold for disabling inactive accounts.
  • Moved the “workstations must remain at the facility” control to the Facility Access Policy, conditioned on Luma operating a physical office (the prior wording assumed an office that doesn’t currently exist).
  • Replaced an unconfirmed implementation detail (“list of workforce members with access is updated in MongoDB”) with an accurate, platform-neutral description; this was later further generalized to a policy-level statement independent of any specific admin tool.
  • Generalized workstation wipe-on-decommission language to not assume Jamf remote wipe specifically, while keeping Jamf named where it is a required technical control or specific agent capability.
  • Fixed typos (“continaing,” “possilble,” “approved be management,” “Mac OSX” → “macOS,” a broken “this includes and Remote Access” phrase).
  • Normalized explicit list numbering to the auto-numbered “1.” convention used elsewhere; fixed a skipped number and a duplicate “## 7.11” heading (renumbered to §7.13), correcting its broken incoming link from the Data Retention Policy.
  • Moved the “01.c Privilege Management” HITRUST citation here from the Auditing Policy, since it documents the access-review process.
  • Replaced remaining “Web Services Team”/”Dev Ops” references with “Infrastructure (SRE) Team”; updated the CTO contact to Marcelo Oliveira (408-890-0973, marcelo@lumahealth.io).
  • Updated cross-references and section numbers following the Data Integrity Policy’s §17.6 removal and the HR policy merge.

08. Auditing Policy

  • Added new §8.3.1 “Requesting Audit and Compliance Reports” (moved from the Introduction) and new §8.11 “Auditing HIPAA Compliance Program” (moved from Policy Management), fixing a “Complience” typo along the way.
  • Removed duplicate user-entitlement-audit bullets (60-day entitlement audit, 90-day inactive-account disablement, 60-day privileged-account audit) now that the consolidated process lives in the Systems Access Policy.
  • Required audit-report reviewers to be a Security team member (or the Privacy Officer) other than the workforce member responsible for the reviewed system, enforcing separation of duties instead of self-review.
  • Replaced yearly/quarterly log-review language with a continuous automated log-monitoring and daily Security Team review process, plus an annual effectiveness assessment.
  • Normalized remaining explicit list numbering to the “1.” convention; fixed “nessessary” → “necessary”.
  • Replaced a standalone disciplinary-consequences restatement with a reference to the Employees Policy’s Workforce Sanctions section (updated as that section was renumbered).

09. Configuration Management Policy

  • Replaced the false statement “Luma does not have root access to the virtual machines; patches are managed by AWS” with the actual patching process (EC2 via SSM/SSH by authorized personnel; EKS nodes via base image updates and node replacement).
  • Generalized GitHub-only tooling references (web interface, Dependabot, “built-in GitHub mechanisms”) to also account for Bitbucket, which Luma also uses; dropped an “LGTM comment” alternative since only the platform’s approve action is actually used.
  • Applied the single-review requirement codebase-wide, replacing a two-tier rule (implicit minimum vs. mandatory two reviewers for ePHI-touching changes) with one unconditional review requirement for every PR, and folded security-analysis/audit-log checks into standard review rather than gating them on an ePHI determination.
  • Moved the annual vulnerability-training requirement out of the PR/review procedure into the general Configuration Management policy statement, since it’s a standing obligation, not a per-PR check.
  • Narrowed a Jamf-manages-network-equipment claim to user-issued devices only, matching Jamf’s actual scope.
  • Fixed the §16.2 cross-reference, which pointed at a same-file anchor instead of the Vulnerability Scanning Policy file; fixed typos (“a a”, “maintaned,” “seperation,” “Securiy,” “knowledgable”) and normalized list numbering/indentation.
  • Added a reference to the expanded vulnerability-scanning tooling list.

10. Facility Access Policy

  • Added an explicit preamble noting Luma is fully remote and does not currently operate a physical office, scoping facility-specific controls (visitor escort, repairs, fire suppression, smart locks/keys) under “should Luma establish such a facility.”
  • Removed the media-disposal bullets and “Workstation Security” block, which duplicated content already owned by the Disposable Media Policy and Systems Access Policy; moved the corresponding HITRUST citations to those files.
  • Fixed minor typos and normalized explicit list numbering to the “1.” convention.

11. Incident Response Policy

  • Replaced “IT department” (not a team that exists at Luma) with “Security and Infrastructure (SRE) teams,” matching terminology used elsewhere.
  • Removed “Secure Chat” from the incident reporting channels list, since it isn’t a tool actually in use.
  • Fixed “affect system(s)” → “affected system(s)” and reworded an awkward anonymous-reporting sentence.

12. Breach Policy

  • Replaced a standalone disciplinary-consequences restatement with references to the Employees Policy’s Employment Policies and Workforce Sanctions sections, since sanctions/disciplinary substance now lives there and breach policy points to it rather than restating it.

13. Disaster Recovery Policy

  • Updated the CTO contact to Marcelo Oliveira (408-890-0973, marcelo@lumahealth.io).
  • Consolidated the legacy “Web Services Team,” “Ops Team,” and “Dev Ops” references into a single current “Infrastructure (SRE) Team” throughout the recovery procedures.

14. Disposable Media Policy

  • Fixed a HITRUST citation format issue (09.o) and added a cross-reference to the Data Retention Policy’s retention schedule (§18.2).
  • Fixed minor grammar issues in the reuse and termination clauses.
  • Gained the media-disposal and equipment re-use citations moved here from the Facility Access Policy.

15. IDS Policy

  • Documented the full log-monitoring toolset (Splunk, CrowdStrike on laptops, TrendMicro on select servers) in addition to DataDog, which was previously the only tool mentioned.

16. Vulnerability Scanning Policy

  • Documented the full scanning toolset (Snyk, Trivy, Rapid7 DAST, Intruder, AWS Inspector, Hamming AI, HackerGuardian) with accurate per-tool cadence.
  • Extended penetration testing and change management scope to cover AI model deployments and AI-specific threats (model poisoning, model inversion).

17. Data Integrity Policy

  • Reworded the intro to sound more professional (“Luma is committed to maintaining the integrity of the data it processes”).
  • Added a risk-based exception to the anti-malware requirement for systems where a documented risk analysis determines the system is not commonly affected by malicious software (e.g., read-only filesystems).
  • Removed §17.6 “Intrusion Detection and Vulnerability Scanning” entirely, as it duplicated the dedicated IDS and Vulnerability Scanning policies; renumbered subsequent sections accordingly.
  • Moved the Data De-Identification section to the Data Management Policy, where it fits topically.
  • Replaced remaining “DevOps team” references with “Infrastructure (SRE) team.”
  • Fixed “resctrited” → “restricted”.

19. Employees Policy (merged with former 24. Human Resources Security Policy)

  • Updated the performance-review platform reference from 15Five to Rippling.
  • Corrected performance-review eligibility and cadence to reflect actual practice: bi-annual reviews, 3-month tenure eligibility (previously documented inconsistently as annual/6-month in two separate files).
  • Merged 24-Human_Resources_Security_Policy.md into this file and deleted the former, eliminating duplicated/drifting descriptions of workforce sanctions, performance review, and security/compliance training that previously existed in both files.
  • Reordered all sections into a chronological employee-lifecycle structure: HR Roles → Background Check → Onboarding → Employment Policies → Issue Escalation → Workforce Sanctions & Disciplinary Records → Offboarding.
  • Established this file as the single source of truth for workforce sanctions and disciplinary process; other policies (Risk Management, Roles, Data Management, Auditing, Facility Access, Breach) now reference it instead of restating disciplinary consequences.
  • Updated all internal and cross-file references to the new section numbers.

21. 3rd Party Policy

  • Replaced “Google Forms” with “Luma’s internal GRC system” to reflect the actual current tool used for vendor SLA/annual reviews.
  • Fixed “Questionniare” → “Questionnaire” typo.

26. Data Transfer Impact Assessment

  • Generalized the certification claim in §26.5, which named a fixed set (ISO 27001:2022, HITRUST CSF r2, SOC 2 Type II) that goes stale as Luma now operates multiple products/business lines with different certification levels (e.g., Tonic’s HITRUST CSF e1 vs. Luma Health’s HITRUST CSF r2); now describes certifications generically as “appropriate to each of its products and business lines.”
  • Similarly generalized the §26.7 incident-management framework claim to avoid pinning to a specific ISO 27001/HITRUST version.
  • Fixed “Managment” typo.

27. Luma Health Subprocessors

  • Removed an inaccurate blanket claim that no subprocessor can access data contents due to encryption; this did not hold for messaging subprocessors (e.g., Twilio, Mailgun), which necessarily process message content in the clear to deliver it.
  • Fixed “Indentifiable” → “Identifiable” typo.

Outstanding items (not addressed in this review cycle)

The following were identified during the review but deliberately left out of scope to avoid overloading individual commits. They are candidates for a follow-up pass:

  • Several pre-existing broken same-file/cross-file anchor links using an outdated dotted-anchor style (e.g., #9.-configuration-management-policy), found in 01-introduction.md, 05-roles_policy.md, 12-breach_policy.md, 13-disaster_recovery_policy.md, 17-data_integrity_policy.md, 18-data_retention_policy.md, 19-employees_policy.md, and 21-3rd_party_policy.md.
  • Two heading-level inconsistencies where a three-part section number uses ## instead of ###: 08-auditing_policy.md §8.3.1 and 13-disaster_recovery_policy.md §13.1.1/§13.1.2.
  • Remaining sequentially-numbered lists (2., 3., 4., …) that should use the literal 1. convention relied on elsewhere: 05-roles_policy.md, 06-data_management_policy.md, 17-data_integrity_policy.md, 29-Artificial_Intelligence_Goverance_and_Use_Policy.md.
  • Minor typos: “Managment” (01-introduction.md), “appplication” (06-data_management_policy.md), “catagories”/”Contractural”/ “Juristictions”/”anually” (26-data_transfer_impact_assessment.md), and a likely “impressive” → “impermissible” wording error in 12-breach_policy.md’s breach-notification purpose statement.
  • 03-policy_management_policy.md cites HITRUST control “12.c” (a Business Continuity domain control), which appears to be a copy-paste artifact from the Disaster Recovery Policy — likely should cite a Security Policy domain (04.x) control instead; needs verification.
  • 09-configuration_management_policy.md cites HITRUST domain “06 - Configuration Management” at the top level, which conflicts with domain 06 being used as “Compliance” everywhere else in the policy library; needs verification against a canonical HITRUST reference before correcting.