HIPAA-Compliant Private AI, Deployed Inside Your Network

Your clinicians are already using AI with patient data. Regulators are already writing the rules that govern it. Lumen, the private AI platform from Cognetryx, gives you a governed alternative that runs entirely inside your health system, so PHI never leaves and OCR readiness is built in.

  • 71%

    Healthcare workers using personal AI accounts for work

    Netskope, 2025

  • 81%

    Healthcare data policy violations involving regulated data

    Netskope, 2025

  • $10.9M

    Average cost of a healthcare data breach

    IBM, 2025

See it in action

Every answer traces back to the exact line in your own files

Ask in plain language. Get an answer drawn only from your documents, with the source passage shown and highlighted, so anyone can check the work.

Lumen · grounded in your documents

How long do we have to give a patient their records after a written request?

Answer

Within 30 days of the written request. You may take one 30-day extension if you notify the patient in writing of the reason and the date the records will be available.

↳ Section 5, ¶2 · p.22↳ Section 5, ¶4 · p.22

Answered from 2 passages in your Health Information Management policy

Riverside Health SystemHealth Information Management

HIM Policy & Procedure
Patient Rights Section

Section 5: Patient Access to Records

ScopeThe patient's designated record set, including medical and billing records.
FormatProvided in the form and format requested when readily producible.
StandardHIPAA Privacy Rule, 45 CFR 164.524.

Procedure

1. Each request is verified against the patient's identity on file before any records are released.

2. Protected health information requested by a patient must be provided within 30 days of the written request.

3. Records are provided in the form and format the patient requests, when readily producible.

4. A single 30-day extension is permitted if the patient is notified in writing of the reason and the date the records will be available.

5. Fees are cost-based and limited to the amount allowed under policy and applicable law.

6. Any denial, where permitted, is documented and includes the patient's right to review.

HIM-PR-05 · Rev 4 · Effective 2025-11-15 · Owner: Director, Health Information ManagementUncontrolled when printed · p.22

Compliance Mapping

How the Architecture Addresses What Regulators Ask

Federal and state pressures are converging in 2026 and 2027. Here is how Lumen directly addresses each framework without bolt-on governance layers.

FrameworkThe RequirementHow Lumen Addresses It
HIPAA Privacy & Security RuleSafeguards for protected health information including administrative, physical, and technical controls.PHI stays inside your network. Existing Security Rule safeguards apply. No new BAA relationships to govern.
Proposed HIPAA Security Rule UpdateTechnology asset inventory including AI tools, network maps of ePHI flows, annual compliance audits.Inventoried as internal infrastructure. ePHI never leaves the network boundary. Annual audit artifacts generated natively.
HITECH ActBreach notification obligations, enhanced enforcement, audit trail requirements.Comprehensive audit logging owned by your organization. No third-party processors to coordinate breach response with.
Colorado AI Act, SB 26-189 (effective January 2027)Governance and disclosure requirements on high-risk AI systems affecting consequential decisions.Traceable reasoning paths and human-in-the-loop controls support disclosure and governance obligations.
Texas AI Disclosure RequirementsPlain-language disclosure of AI involvement in high-risk healthcare scenarios.Every output carries source attribution. Disclosure messaging configurable at the workflow level.
State Medical Board Rules (CA, others)AI systems must not imply they hold a healthcare license or practice medicine.Output framing controlled by the institution. System behavior bounded by governance your team configures.

The 2026 compliance picture

Healthcare breach exposure keeps climbing. HHS Office for Civil Rights data shows the number of individuals affected by healthcare data breaches rose from 27 million in 2020 to 259 million in 2024, and the first half of 2026 is running roughly 29% ahead of the same point last year. Meanwhile, the proposed update to the HIPAA Security Rule, still pending in 2026, would make safeguards like encryption and multi-factor authentication mandatory rather than optional. Any AI that touches PHI falls under that bar. Running the model inside your own network, where PHI never leaves, answers the encryption and access questions by architecture instead of by vendor promise.

Source: HHS Office for Civil Rights; proposed HIPAA Security Rule update. See how the HIPAA Security Rule applies to AI.

Common Questions

What CMIOs and Compliance Leaders Ask

Is Lumen HIPAA compliant?

Lumen runs entirely inside your health system's network. Because protected health information never leaves your environment, no third party creates, receives, maintains, or transmits PHI on your behalf. The system occupies the same regulatory position as your EHR and is governed by your existing HIPAA Security Rule safeguards, access controls, and audit frameworks.

Do we need a Business Associate Agreement (BAA) with Cognetryx?

Because Lumen runs inside your network as internal infrastructure, we are not a HIPAA business associate for the AI processing itself. No PHI flows to Cognetryx servers. BAA obligations that exist with cloud AI vendors are eliminated by the deployment architecture. A service agreement covers our professional services and support.

How does Lumen handle shadow AI already happening in our hospital?

Shadow AI is a symptom of documentation burden. Treating it as a staff discipline problem misreads the cause. When clinicians and administrators have a governed alternative that is faster and more accurate than ChatGPT for their real workflows, shadow AI usage falls dramatically. Lumen grounds AI responses in your institutional documentation, clinical protocols, and policies, making the sanctioned tool the better one.

What happens during an OCR audit or examiner review?

Every AI interaction is logged with user identity, timestamp, source documents referenced, and output generated. This audit trail is owned by your organization and available on demand. Because PHI never left your network, the examiner's hardest question has the simplest possible answer: the data never left. Your compliance team receives a traceable reasoning path for every consequential output.

How long does deployment take?

Most health system deployments go live in four weeks, with full production rollout in 90 days. Cognetryx includes white-glove onboarding, staff training, board presentations, and 30 days of on-site support. Timeline depends on infrastructure readiness and the scope of institutional documentation to be integrated.

What clinical and administrative use cases does Lumen support?

Clinical documentation support, policy and protocol lookup, discharge planning assistance, coding and billing workflows, claim denial response, compliance research, board and regulatory reporting, staff onboarding, and clinical informatics Q&A. The system is grounded in your institutional knowledge, so use cases expand naturally as more documentation is indexed.

See it answer from real documents

A 30-minute live demo. We reply within 24 hours.

See it in action