Security
Built like it matters — because it does.
Every after-hours call routed to Lumexa carries a small piece of a patient's day. This page describes the security controls we operate to protect that information — and the shared responsibility between Lumexa, your practice, and our infrastructure providers.
Last updated: August 1, 2026. This page is maintained by Lumexa and describes current, enabled controls. It is not an independent certification.
Encryption in transit & at rest
All traffic between callers, your practice, and the Lumexa dashboard is encrypted using TLS. Call recordings, transcripts, and dashboard data are stored encrypted at rest by our cloud infrastructure providers.
Access controls
Practice data is scoped to your practice. Staff sign in with unique accounts; internal Lumexa access to patient information is limited to a small number of staff on a need-to-know basis, logged, and reviewed.
Hardened infrastructure
Lumexa runs on managed cloud infrastructure with isolated environments, network segmentation, and automated patching. Secrets and API keys are stored in a dedicated secrets manager, never in source code.
PMS integrations
Connections to Dentrix, Open Dental, and Eaglesoft use credentials you provide and can revoke at any time. Only the data required to write appointments and read availability is exchanged.
HIPAA-conscious operations
Lumexa is designed to support HIPAA obligations for US dental practices. A Business Associate Agreement (BAA) is available prior to production use where protected information will be processed.
Staff training & background
Lumexa personnel with access to production systems complete security and privacy training and are bound by confidentiality obligations.
Shared responsibility
Lumexa operates the AI receptionist, dashboard, and underlying platform. Your practice owns account hygiene at your end: strong passwords, prompt removal of access when staff leave, and keeping the phone-forwarding, PMS credentials, and patient-facing scripts you configure current. Our cloud, telephony, and model providers are responsible for their own infrastructure security under agreements with Lumexa.
Data segregation
Practice data is logically segregated so that one practice cannot access another practice's calls, transcripts, or reports. Role-based access inside the dashboard lets you decide who at your practice can view full transcripts versus summaries.
Monitoring & incident response
Production systems are monitored for availability and anomalous activity. If we identify a security incident that materially affects your practice's data, we will notify affected practices without undue delay and provide the information you need to meet your own obligations.
Backups & continuity
Practice data is backed up on a defined schedule. Backups are encrypted and used only for recovery. We test restore procedures periodically so that we can bring service back if infrastructure fails.
Reporting a vulnerability
If you believe you've found a security issue in Lumexa, we want to hear from you. Please email us with details and steps to reproduce. We ask that you avoid accessing data that isn't yours and give us reasonable time to respond before public disclosure.
Questions from procurement
For BAAs, security questionnaires, current subprocessor lists, or details we haven't published here, reach out and we'll respond directly.
This page describes controls Lumexa currently operates. It is not a certification and does not create a legal contract. The Business Associate Agreement and your order form govern the terms of your engagement with Lumexa.
