Last Updated: March 2026
Lucerna Health LLC ("Lucerna Health," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy applies to our website at getlucerna.com and our Leap platform (collectively, the "Services"). This policy explains what information we collect, how we use it, and your rights regarding it. If you do not agree with these practices, please do not use our Services.



Who We Are

Lucerna Health is a healthcare technology company that provides the Leap platform — a data management, analytics, and engagement platform used by health systems, payers, and provider organizations. This policy covers two distinct contexts:

  • Website visitors: Individuals who visit getlucerna.com for general information, to request a demo, or to contact us. We collect only basic contact information visitors choose to provide it.
  • Leap platform users: Employees and authorized users of healthcare organizations that have contracted with Lucerna Health to use the Leap platform. These users access Leap to perform their job functions, such as care management, analytics, and provider engagement.

Important: Lucerna Health acts as a Business Associate and Data Processor under HIPAA. Protected Health Information (PHI) processed through the Leap platform belongs to and is controlled by our customer organizations. We process PHI on their behalf under executed the Business Associate Agreements (BAAs). We do not collect PHI directly from patients or consumers.



Information We Collect

Website Visitors When you visit getlucerna.com, we may collect:

  • Contact information you voluntarily submit — such as your name, email address, company, and phone number when you fill out a form or request a demo
  • Usage and device information — such as your IP address, browser type, operating system, pages visited, and cookie information, collected automatically when you browse our site



Leap Platform Users When you use the Leap platform as an authorized user of a customer organization, we collect:

  • Account information — your name, work email address, job title, and the organization you represent, provided by your organization's administrator
  • Usage data — how you interact with the platform, including features used, actions taken, and session information which is used to operate and improve the platform
  • Log data — system logs including login events, access records, and audit trails, maintained for security and compliance purposes

PHI that flows through the Leap platform is processed on behalf of your organization under a BAA. Your organization's privacy policy and data practices govern the use of that PHI, not this policy.

How We Use Your Information

Website Visitors

  • To respond to inquiries and provide information about our Services
  • To send updates, announcements, or marketing communications, where you have opted in
  • To improve and maintain our website
  • To comply with applicable laws and protect our rights



Leap Platform Users

  • To provide, operate, and maintain the Leap platform
  • To authenticate users and maintain security
  • To generate audit logs and support compliance obligations including HIPAA
  • To analyze usage patterns and improve platform performance and features
  • To provide customer support
  • To fulfill our obligations under our agreement with your organization



How We Share Your Information

We do not sell your personal information. We may share information only in the following circumstances:

  • With service providers who assist us in operating our Services, under confidentiality and data processing agreements
  • With your organization, as applicable to your Leap platform account
  • To comply with a law, regulation, legal process, or governmental request
  • To assert or defend legal claims, or to prevent, detect, or investigate illegal activity or threats to safety
  • In connection with a merger, acquisition, or sale of assets, with notice to affected users

PHI processed through the Leap platform is shared only as directed by the customer organization and in accordance with the applicable BAA provisions.



Data Retention

We retain personal information for as long as necessary to provide the Services, fulfill our contractual obligations, comply with legal requirements, and resolve disputes. For Leap platform users, account data is retained for the duration of your organization's contract with Lucerna Health and for a period thereafter as required by law or our agreement. PHI is retained and disposed of in accordance with the applicable BAA and HIPAA requirements.



Security

Lucerna Health is HITRUST r2 certified. We maintain a comprehensive information security program that includes technical, administrative, and physical safeguards to protect your information. This includes encryption of data in transit (TLS) and at rest (AES), access controls, audit logging, and regular security assessments. If you have a security concern, contact us at security@lucernahealth.com.



International Data Transfers

All customer data and PHI is stored and processed in the United States in AWS data centers.

Your Rights

Website Visitors You may request access to, correction of, or deletion of personal information you have submitted to us by contacting privacy@lucernahealth.com. Leap Platform Users Because Lucerna Health processes your data on behalf of your organization, requests to access, correct, or delete your personal information or PHI should be directed to your organization's privacy or IT team. Your organization, as the Data Controller, is responsible for handling those requests. We will support your organization in fulfilling them as required under our BAA.

Cookies and Similar Technologies

We use cookies and similar technologies on our website and platform to provide a better experience, maintain security, and understand how our Services are used. Technologies We Use

  • Cookies — small data files stored on your browser, served by us or our partners
  • Pixels and web beacons — small images that collect browser or device information
  • Local storage — data stored locally on your browser or device



How We Use These Technologies

  • Authentication and security — to log you in and keep your session secure
  • Preferences — to remember your settings
  • Analytics — to understand how users interact with our Services so we can improve them



Your Choices You can set your browser to accept, reject, or notify you about cookies. Note that blocking cookies may affect the functionality of our Services. Our website does not respond to Do Not Track signals. For more information about your options, visit optout.aboutads.info.

Children

Our Services are not directed to children under 16. We do not knowingly collect their personal information.

Changes to This Policy

We may update this policy periodically. We will post changes on this page and notify you of significant changes by email or platform notification.

Contact Us

For questions about this policy or our privacy practices:

Privacy Officer: privacy@lucernahealth.com Security concerns: security@lucernahealth.com

Lucerna Health LLC 14286 Beach Boulevard #19-206 Jacksonville Beach, FL 32250

© 2026 Lucerna Health. All rights reserved.

Contact security@lucernahealth.com for security concerns

Lucerna Health Footer Logo