CompyMax

Is LuxSci HIPAA compliant?

Only under specific conditions

Yes — LuxSci includes the agreement at no extra cost, but an authorised officer must sign and return LuxSci's own form, and patient information must stay inside the services it lists as eligible.

Applies to LuxSci secure email, forms, text and hosting. Last reviewed against LuxSci's own documentation. Next review December 24, 2026.

Reviewed by Lisa Tran, CISSP — Healthcare Information Security Executive.

What you must do

  • Read, agree to, sign and return LuxSci's agreement before using its services with patient information.
  • Have an officer with the legal right to bind your organisation sign it — LuxSci warns that the wrong signatory can mean failing your own obligations.
  • Keep patient information inside LuxSci's eligible services: Secure High Volume Email, Secure Marketing, Secure Email Gateway, Secure Forms, Secure Text, Secure Email Hosting and Secure Web Hosting.
  • Do not let staff opt out of encryption on messages containing patient information — opting out places that data outside the agreement.
  • Review which users you have designated as exempt from HIPAA in your account, because their data is out of scope.
  • Expect LuxSci's standard form. It does not generally accept modifications and will not sign a customer-provided agreement below Enterprise.

Does LuxSci sign a business associate agreement?

Yes. LuxSci offers one. Included with LuxSci plans at no additional cost. The gate is signing and account designation rather than a pricing tier. Open LuxSci's agreement page, have an authorised officer complete the form, and return it using their electronic signature field.

See their documentation.

What this means in practice

LuxSci does not charge extra for the agreement, but it does insist on formality. You read its standard form, an officer of your organisation with authority to bind it signs, and you return it — LuxSci specifically warns that letting the wrong person sign can leave you failing your own obligations. It will not take redlines or sign your template unless you are buying at Enterprise level with a strong case.

Scope is defined by a published list of eligible services: Secure Email Hosting, Secure Email Gateway, Secure High Volume Email, Secure Marketing, Secure Forms, Secure Text and Secure Web Hosting. Anything outside that list should be treated as uncovered.

Two carve-outs catch practices repeatedly. Data is outside scope where a user has indicated a message does not contain patient information, such as by opting out of encryption, and where you have designated a user in your account as exempt from HIPAA. Both are settings your own staff control, so audit them.

How organizations get this wrong

The specific mistakes we see with LuxSci, not generic advice.

  • Letting an office manager or IT contractor sign, when LuxSci requires an officer with the legal right to bind the organisation.
  • Leaving a per-message encryption opt-out available to staff, which pushes those messages outside the agreement's scope entirely.
  • Forgetting that users you flagged as exempt from HIPAA stay exempt — their patient email is not covered.
  • Sending your own agreement template and waiting for signature; LuxSci does not sign customer-provided forms below Enterprise.

What the agreement does not cover

  • Any message where a user has indicated the content does not contain patient information, for example by opting out of encryption.
  • Data produced by a user you have designated as exempt from HIPAA compliance.
  • Any LuxSci service not named on the eligible services list.
  • Your own agreement template, which LuxSci will not sign outside an Enterprise negotiation.

Alternatives

Listed on merit. We take no payment for placement and use no affiliate links.

  • Paubox

    Simpler if you only need encrypted email without a signing ceremony

  • Hushmail

    Lower-cost fit for a solo practice needing email plus intake forms

Signing the agreement is step one. Proving it is step two.

Once you have the agreement with LuxSci, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.

$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.

Sources

Every statement above comes from LuxSci’s own published documentation, read on the date shown.

  1. Business Associate Agreement (BAA)LuxSci. No publication date given. Read July 29, 2026.
  2. HIPAA Eligible Services and Business Associate Addendum RestrictionsLuxSci. No publication date given. Read July 29, 2026.

Change history

  • First published.

This page is information, not certification and not legal advice. It reflects LuxSci’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.

Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.