Today we offer BAAs to teams and institutions. If you are on an individual account, you do not have one, and you should not put identifiable patient information into Lunas — not in questions, and not in uploaded documents.
Our infrastructure is covered. Your questions, conversation history and uploaded documents are processed on Amazon Bedrock inside our AWS account, under our Business Associate Agreement with AWS, and the code that carries user text has no path to any other model provider — not a setting, but the absence of an alternative.
That is a statement about our vendors. It is not a BAA between you and us, and HIPAA requires the second one before a covered entity may disclose PHI to a service provider. Both sentences can be true at once: our processing is BAA-covered, and you are not covered to send us PHI. This page exists because those two are easy to read as one.
Most clinical questions do not require patient identifiers. "Does Medicare cover X for a 68-year-old with Y" is a question about coverage policy; a name, a date of birth and a record number add nothing to the answer. De-identify before you ask, and the product works exactly as well.
The same applies to uploads: an operative technique guide, a payer policy PDF or a journal article carries no patient data. A discharge summary does.
You may have seen a HIPAA badge in the product. It now appears only for accounts we have a BAA with. It previously appeared for every signed-in user, describing our infrastructure — which was accurate, but read as a statement about the reader's own compliance position. We removed it rather than reword it, because a badge is skimmed and a qualification is not.
The guarantee above covers your questions, your uploaded documents and the model that answers them. Two paths sit outside it, and we would rather name them than let you find them.
Web search. When the assistant searches the web, it sends a search phrase it composed to an outside search provider over an ordinary internet connection. Those providers are not covered by our agreement with AWS. The phrase is scanned first for obvious structured identifiers — record numbers, dates of birth, long digit strings — but that scan cannot catch a patient's NAME, and no pattern-matching can. You are asked before a web search runs, and the request says what will be sent; treat that moment as the decision point.
Library summaries. This one is named for a narrower reason, and we would rather explain it than leave it off the list. The literature-summary feature in the Library does run on the same BAA-covered infrastructure as everything else under our current configuration. But the code still contains a direct-to-Anthropic branch behind it, which the environment lock resolves before any per-user setting can reach — so it is unreachable rather than absent.
That is a weaker kind of assurance than the one above, and the difference is the whole reason this page separates them: your questions, conversations and uploads are covered because there is no other path in the code, while Library summaries are covered because the configuration says so. We are naming it until that branch is deleted, at which point this section goes and the guarantee is the same everywhere. Library search itself was moved onto the covered infrastructure outright and needs no such note.
Everything else — your questions, your conversation history, your uploaded document text, the images inside those documents, and the search vectors built from them — stays inside our AWS account. Document text is extracted and embedded on our own machines with no network access at all.
If you believe PHI has been entered into Lunas by mistake, or disclosed inappropriately, write to support@lunasai.health with "PHI" in the subject line and we will act on it and help you delete it.
Privacy and terms are being reviewed by our counsel. This document additionally needs review by someone qualified in health privacy specifically, and has not yet had it. It describes the system accurately as of the date above; it should not be relied on as a compliance opinion.