Security

Last Updated: September 24, 2026

Lamics, Inc. ("Lamics") handles protected health information (PHI) on behalf of healthcare practices. This page describes the administrative, technical, and physical safeguards we use to protect that information, and how to report a security concern to us.

1. HIPAA and Business Associate Agreements

Lamics acts as a Business Associate under HIPAA for the healthcare practices we serve. We sign a Business Associate Agreement (BAA) with every customer before any PHI is processed. Our BAA is based on the Common Paper Business Associate Agreement Standard Terms, with customer-specific terms on a signed cover page. To request a copy, contact security@lamicsai.com.

Subcontractors that handle PHI on our behalf must sign agreements that protect it under terms substantially similar to our BAA.

Patients who want to exercise their HIPAA rights should contact their healthcare provider, who will direct us as needed under the BAA.

2. Infrastructure and Hosting

  • Production systems and backups are hosted on Google Cloud Platform in the United States.
  • Physical and environmental security of data centers is managed by Google Cloud. We review Google Cloud's independent attestation reports at least annually.
  • Production access is limited to members of our operations team and requires authenticated, encrypted connections.

3. Encryption

  • In transit: Data sent to and from our Services is encrypted using TLS 1.2 or higher.
  • At rest: Customer data, including backups, is encrypted at rest using AES-256.

4. Access Control

  • Role-based access control based on least privilege, with access granted according to job function.
  • Single sign-on and multi-factor authentication for internal systems.
  • User access and roles are reviewed quarterly.
  • Access for departing personnel is revoked within 24 business hours of termination.

5. People

  • Background checks for personnel before they are granted access to systems.
  • Security and HIPAA awareness training within 14 days of hire and on an ongoing basis.
  • All personnel acknowledge our information security policies, which are reviewed at least annually.

6. Vendor Management

We assess vendors that store or process customer data before onboarding them and review them at least annually, including their SOC 2 or ISO 27001 reports where available. The categories of subprocessors we use are listed in our Privacy Policy.

7. Monitoring, Backups, and Incident Response

  • Application monitoring and audit logging of access to production systems.
  • Encrypted backups of customer data, monitored for completion and failures.
  • A documented incident response process, including notification to affected customers as required by HIPAA and our BAA.

8. Compliance Program

Our security and compliance program is managed in Vanta, which continuously monitors our controls against the SOC 2 and HIPAA frameworks. Customers and prospective customers can request additional security documentation by contacting security@lamicsai.com.

9. Reporting a Vulnerability

If you believe you have found a security vulnerability in Lamics, please report it to security@lamicsai.com. We will acknowledge your report within three (3) business days and keep you informed as we investigate.

What to Include

  • A description of the issue and its potential impact
  • The affected URL, endpoint, or component
  • Steps to reproduce, including any proof-of-concept
  • How we can reach you for follow-up

Scope

In scope: lamics.ai and portal.lamics.ai. Third-party services we use are out of scope; please report issues in those services to the respective vendor.

Guidelines

  • Do not access, modify, or retain data that does not belong to you, including any patient information.
  • Do not perform denial-of-service testing, social engineering, or physical attacks.
  • Give us reasonable time to fix the issue before disclosing it publicly.

We will not pursue legal action against researchers who act in good faith and follow these guidelines. We do not currently offer a paid bug bounty. Our contact details are also published in security.txt.

Contact Us

Lamics, Inc.
Security: security@lamicsai.com
Support: support@lamicsai.com