Privacy Policy

Lumen Innovations - Lumenus, CathDoc, Textify, Explify & Systolic

← Back to Home

Our Commitment: Lumen Innovations apps are designed with privacy as a core principle. We do not collect, store, or transmit Protected Health Information (PHI). Our apps are built to be HIPAA-exempt by design.

Overview

This Privacy Policy describes how Lumen Innovations ("we," "our," or "us") handles information in our applications: Lumenus (iOS app for procedure logging for medical trainees), CathDoc (iOS & Android app for CPT code management for cardiologists), Textify (Windows/macOS desktop app for PDF to text conversion for EHR documentation), Explify (Windows/macOS desktop app for AI-powered medical report explanations), and Systolic (iOS & Android app with web portal for remote patient monitoring of blood pressure).

All of our applications are designed to help healthcare professionals with documentation and billing workflows while ensuring patient privacy is never compromised.

Protected Health Information (PHI)

PHI Protection by Design: Lumenus, CathDoc, Textify, and Explify do not record patient names, medical record numbers, dates of birth, Social Security numbers, or any other identifying patient information. Systolic, Pulscribe, and YCAPortal are HIPAA-compliant healthcare platforms that do collect patient health data under appropriate safeguards and consent — see their individual sections below for full details.

How We Ensure PHI Protection

For Lumenus, CathDoc, Textify, and Explify:

For Systolic: Patient health data is collected with explicit consent under HIPAA-compliant protocols. See the Systolic section for full details on data handling, encryption, and access controls.

Lumenus - Procedure Logging App (iOS)

What Lumenus Stores

Data Type Stored Purpose
User account (email, name) Yes Authentication and identification within training program
Procedure date range Yes Case logging by week/month (specific dates not stored to protect privacy)
Specific procedure date No Not stored - could be PHI when combined with other data
Procedure type Yes Training requirements tracking
Attending physician name Yes Attestation workflow
Facility/location Yes Multi-site training tracking
Operator role (primary/secondary) Yes Competency assessment
Duty hours/shift times Yes ACGME compliance tracking
Patient name or MRN No
Patient date of birth No
Social Security numbers No

Image Library & PHI Detection

Lumenus includes an optional image library feature for educational purposes. To protect patient privacy:

User Responsibility: While we provide PHI detection tools, users are ultimately responsible for ensuring any uploaded images do not contain patient identifiers. Always review images before sharing.

CathDoc - Billing Code Manager (iOS & Android)

What CathDoc Stores

Data Type Stored Purpose
Case ID (user-entered) Yes (locally) Reference for billing workflow
Selected billing codes Yes (locally) Report generation
Selected ICD-10 codes Yes (locally) Indication documentation
Vessel/modifier selections Yes (locally) Accurate code documentation
RVU calculations Yes (locally) Reimbursement estimates
Patient name or MRN No
Any patient identifiers No

HIPAA-Exempt by Design: CathDoc uses case IDs instead of patient names. No PHI is ever entered, stored, or transmitted. Reports generated by the app contain only billing codes, ICD-10 codes, and case IDs.

Report Sharing

When generating reports for billing purposes:

Textify - PDF to Text Converter (Windows/macOS)

Complete Local Processing: Textify is a desktop application that runs entirely on your computer. No data is ever transmitted to external servers. All PDF processing happens locally on your machine.

What Textify Does NOT Store or Collect

Data Type Collected Notes
PDF file contents No Files are processed in memory only; nothing is saved
Extracted text No Text is displayed for copy/paste but not stored
Patient names or identifiers No No PHI is ever collected or transmitted
Usage analytics No No tracking, telemetry, or analytics
User accounts No No login or account required
Internet connection No App works completely offline

How Textify Works

Privacy by Architecture: Textify was intentionally designed with no network capabilities. It cannot transmit data even if it wanted to. Your documents stay on your computer.

Explify - AI-Powered Report Explanations (Windows/macOS)

PHI Scrubbing Before AI Processing: Explify automatically detects and removes Protected Health Information (PHI) from medical reports before any AI processing occurs. Patient identifiers are never sent to AI services.

How Explify Protects Patient Privacy

What Explify Uses

Data Type Stored Purpose
User API key Yes (locally) Stored securely on your device for AI service access
Teaching points Yes (cloud) Personalized AI instructions you create are synced across devices
Report history Yes (cloud) De-identified summaries only; original reports with PHI are never stored
Template settings Yes (cloud) Letter templates and preferences
Patient names or MRNs No Removed before AI processing; never stored or transmitted
Original PDF/images No Processed in memory only; not retained after session

AI Processing & Third-Party Services

User Responsibility: While Explify provides automated PHI scrubbing, users should review generated content before sharing with patients to ensure accuracy and appropriateness for clinical use.

Systolic - Remote Patient Monitoring (iOS/Android & Web Portal)

HIPAA-Compliant Healthcare Platform: Systolic is designed for Remote Patient Monitoring (RPM) of blood pressure and weight. Patient health data is collected with explicit consent and stored securely in compliance with healthcare privacy regulations.

Data Collection with Patient Consent

Unlike our other apps which are designed to be HIPAA-exempt, Systolic is a healthcare platform that collects patient health information. This data is collected only after patients provide informed consent during onboarding.

What Systolic Collects

Data Type Collected Purpose
Blood pressure readings Yes Core RPM functionality for patient monitoring
Heart rate Yes Cardiovascular health monitoring
Weight entries Yes (optional) Weight management, heart failure dry weight monitoring, and AI-powered trend analysis
HealthKit data (weight) Yes (optional) Syncing weight data from Apple Health for comprehensive tracking
Patient name Yes Patient identification within healthcare context
Phone number Yes Authentication and reminders
Date of birth Yes Patient identification and age-appropriate care
Medications Yes (optional) Care coordination and medication management
Practice affiliation Yes Connecting patients with their healthcare providers

How Patient Data is Protected

Data Sharing

Healthcare Provider Responsibility: Practices using Systolic are responsible for maintaining their own HIPAA compliance, including Business Associate Agreements and appropriate use policies.

Data Storage & Security

Lumenus

CathDoc

Textify

Explify

Systolic

Pulscribe - AI Medical Scribe (Web Application)

Audio Processing & AI Transcription: Pulscribe processes audio recordings of physician-patient encounters. Audio is streamed to Deepgram for transcription and encounter content is sent to AWS Bedrock (HIPAA-compliant mode) for AI note generation. Pulscribe is designed to minimize PHI retention — audio is not permanently stored after processing.

Data Collected by Pulscribe

Data Type Collected Purpose
Audio recordings (encounter) Temporarily Transcription via Deepgram — not retained after transcription
Encounter transcripts Yes Note generation and encounter history for physicians
Patient name (in transcript) May be present Part of captured conversation — stored in encounter record
Clinical content (HPI, A&P, medications) Yes AI-generated clinical documentation
Physician account credentials Yes Authentication — bcrypt hashed passwords
Practice and provider information Yes Multi-provider workflow and practice management

How Pulscribe Protects PHI

YCAPortal - Cardiology Imaging Platform (Web)

DICOM Medical Imaging Platform: YCAPortal stores and manages DICOM cardiac imaging studies (echocardiograms, CT scans, etc.) containing patient health information. Data is handled under HIPAA-compliant protocols with AWS infrastructure.

Data Collected by YCAPortal

Data Type Collected Purpose
DICOM imaging studies Yes Core platform functionality — cardiac imaging management
Patient name and date of birth Yes (from DICOM metadata) Patient identification extracted from imaging files
Echocardiogram measurements and findings Yes Structured clinical reporting
Physician account credentials Yes Authentication via AWS Cognito with MFA
Study access and sharing logs Yes HIPAA audit trail requirements

How YCAPortal Protects PHI

Data We Do NOT Collect

Lumenus, CathDoc, Textify, and Explify do not collect (note: Systolic, Pulscribe, and YCAPortal are healthcare platforms that do collect patient data under HIPAA-compliant protocols—see their sections above):

Third-Party Services

Lumenus

CathDoc

Textify

Explify

Systolic

Pulscribe

YCAPortal

Birdog

Your Rights

You have the right to:

To exercise these rights, contact us at privacy@lumeninnovations.com

Children's Privacy

Our apps are intended for use by medical professionals and trainees. We do not knowingly collect information from children under 13 years of age.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of significant changes through the app or via email. Continued use of our apps after changes constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Last Updated: March 13, 2026