Security & HIPAA. What we built to protect patient data.
Lucido handles real patient data on treatment days, so every control on this page is on for every clinic from day one, at the one flat price. Here is how your clinic's data is protected: where it lives, who can get in, what we keep, and for how long.
Where the data lives
The entire system runs on Amazon Web Services using HIPAA-eligible services, covered by a signed AWS Business Associate Addendum. AWS is our only infrastructure subprocessor; the one other PHI-touching service is the HIPAA fax carrier behind one-click REMS filing, under its own signed BAA.
Every connection uses TLS. Everything stored (the database, its automated backups, and the audit log) is encrypted at rest on a customer-managed AWS KMS key. No unencrypted copy exists.
The database runs in a private network with no public address. Application traffic reaches it through the app; nothing is exposed directly to the open internet.
An AWS Web Application Firewall sits in front of the site with managed rule groups and a per-IP rate limit, and the application enforces its own rate limits and a per-clinic staff-PIN lockout.
Who can get in
Owner accounts use two-factor sign-in (an authenticator app or a texted code), and the requirement is on by default for every new clinic. One-time recovery codes provide a safe way back in if a device is lost.
Owner sessions time out after fifteen minutes of inactivity and have a twelve-hour absolute cap, so an unattended reception screen doesn't stay open.
Clinicians use a daily clinic code and a personal PIN on their own phones: no shared passwords, and a lockout after repeated wrong PINs.
Day to day, our platform tools show clinic-level counts. If we ever open a clinic's records, the tool requires a typed reason first, and the access is written to that clinic's own audit log where you can read it.
What we keep, and what we don't
For each patient, Lucido stores a name, date of birth, sex, and medication list, plus the session's vitals, observations, and lot numbers: the fields the SPRAVATO® REMS form asks for. There is no field for an address, a Social Security number, or an insurance ID.
There is no analytics or ad code in the product, and nothing is shared with data brokers. The one outbound path for a form is the one you press: one-click REMS filing, over a BAA-covered HIPAA fax service. Billing runs on Stripe with billing data only, never PHI.
Once a session is discharged it's locked. Every action that touches patient information lands in an append-only audit log that can't be edited or deleted, retained seven years and exportable by the clinic at any time.
Completed session records auto-delete on a schedule the clinic sets: 14 days by default, adjustable between 1 and 90 in settings. Lucido is the day-of monitor, not a long-term record store; clinics keep their own records through exports.
Closing the account runs the wind-down the BAA describes: an export window first (the filed REMS PDFs and the audit-log CSV), then deletion of the clinic's records and the owner's login.
Mental-health confidentiality
Esketamine records are mental-health treatment records, and some state laws, like the Illinois Mental Health and Developmental Disabilities Confidentiality Act (740 ILCS 110), protect them more strictly than HIPAA. Lucido is built to that stricter standard. Patient data is disclosed only to the clinic, to AWS, and — when the clinic files by one-click fax — to the REMS program via a BAA-covered fax carrier; no other third-party data egress, and redisclosure notices on the records the product generates.
How we keep it that way
We maintain a HIPAA security program in writing (a security risk analysis, incident-response and breach-notification procedures, and workforce policies), kept current as the product changes.
A multi-region CloudTrail records infrastructure activity to write-once storage with seven-year retention, alongside the application's own append-only audit log.
Point-in-time database backups are encrypted, and we have restored from them for real: a June 2026 production drill brought a full copy back in about twelve minutes, with a measured data-loss window of about six minutes.
Error-rate, latency, and uptime alarms page the team automatically, so problems surface before a clinic has to report them.
Security researchers: our disclosure contact and policy live at /.well-known/security.txt. Lucido is built by a small team in Illinois; a security question goes straight to the people who wrote the code. We're glad to walk a clinic's medical director or IT reviewer through the full posture in detail, and to sign a Business Associate Agreement before any real patient data is added.
Try it at your own clinic.
Sign up and set your clinic up yourself, no sales call needed, or request demo access and a 20-minute live walkthrough with the founder.