Row midpoint Shape Decorative svg added to bottom
Healthcare

Lumistry

RSI Security helped Lumistry achieve the highest level of HITRUST Certification.

Lumistry Case Study | Scalable vCISO Services by RSI Security

“I loved working with Arun and the entire RSI team. I hope to continue to do so in the future.”

– Andy Hart, VP of Information Security, Lumistry

The Challenge

Lumistry Icon

Lumistry (previously known as Digital Pharmacist) is one of the leading platforms empowering pharmacies to create an online presence for patient engagement. Lumistry is a two-time Inc. 5000 list member—most recently in 2022 on the strength of 100% IVR refill and 40% account growth.

Today, Lumistry serves over 7,000 pharmacies worldwide.

A key part of serving these pharmacies is ensuring that sensitive information concerning their clientele and personnel is protected. And, adding to the stakes, Digital Pharmacist was acquired by Lumistry in 2022 alongside three other major players in the telehealth industry (Vow Inc., CAREANIMATIONS, and VUCA Health Unite). In practice, this joining of forces multiplies the benefits for all clientele impacted—but it also means an even greater pool of sensitive data is potentially at risk across Digital Pharmacist’s and its partners’ shared ecosystems.

Lumistry faced these challenges head-on with a robust HITRUST CSF assessment, certifying its cyberdefenses with the highest level of security assurance for all stakeholders.

Step #1

RSI Security

RSI Security facilitated Lumistry’s HITRUST r2 Assessment with:

To meet its varied clients’ needs, Lumistry sought a HITRUST Risk-based, 2-year (r2) Assessment. These are the most involved and rigorous implementations of the HITRUST CSF framework, incorporating controls that meet HIPAA, PCI-DSS, GDPR, and other regulatory standards simultaneously. Arun Patel, Senior Security Consultant at RSI Security, worked closely with Hart, scoping out the risk factors to control for and safeguards that would minimize costly overlap.

 

Step #2

RSI Security

Implementation

Typical HITRUST r2 Assessments encompass Expanded Practices, including about ~375 Requirements on average for Year 1. In Lumistry’s case, there were 560 total controls implemented. This involved a robust and dynamic approach to both technical installation and project management. RSI Security’s Project Coordinator, Bella Mangmang, worked closely with both Patel and Hart to ensure smooth communication and collaboration throughout the process.

Step #3

RSI Security

Documentation

The most technically rigorous part of the HITRUST Certification process is documentation. All controls need to be substantiated with current and historical data, and there are challenges to understanding the full scope of what’s required—not to mention formatting, storage, etc. Patel and Mangmang worked with Hart and others on establishing clear guidelines for staff and other stakeholders to understand their responsibilities to ensure a swift, successful r2 Assessment.

A Brighter Path forward

Working with RSI Security, Lumistry achieved a Validated HITRUST Risk-based 2-Year (r2) Assessment. That means HITRUST CSF Certification for a 2-year period, pending an Interim Assessment after Year 1. It also means Lumistry is either already compliant with, or well positioned to easily assess for, several other regulations. For laws like HIPAA, with no baseline audit, Lumistry is set. For most others, it can “assess once, report many,” which is the goal for comprehensive cybersecurity efforts.

Beyond compliance, Lumistry is now equipped with a robust cyberdefense program that will keep all stakeholders (including others under the broader Lumistry umbrella) safe well into the future. A formalized Lumistry Information Security Program is the icing on the cake, reassuring client pharmacies and their clientele that Lumistry cares about protecting them from cyberthreats.

THE CLIENT PERSPECTIVE

“Everything about the certification process was seamless, from preparation through the actual assessment. We’re looking forward to a continued partnership with RSI Security.”

Andy Hart
VP of Information Security, Lumistry

Explore Our Case Studies

USA for IOM feature

USA for IOM

Non-Profit

Accepting digital donations independently meant taking on PCI requirements without a dedicated IT team. USA for IOM turned a complex compliance challenge into a secure fundraising foundation, gaining the knowledge, policies, and processes needed to support future growth.

Epic Games Case Study | RSI Security’s Penetration Testing Success

Epic Games

Gaming

Managing PCI compliance across a global gaming ecosystem required both immediate changes and a plan for what came next. Epic Games strengthened its architecture, streamlined assessments across international teams, and established a sustainable approach to maintaining PCI compliance long term.

Macomb Community College Case Study | RSI Security's Compliance Expertise

Macomb Community College

Education

A complex higher education environment called for a more unified approach to cybersecurity. Macomb Community College built stronger governance, implemented CIS Controls, and established a roadmap its teams could sustain long term.

Turn Your Security Challenges Into Success

Every organization’s security and compliance journey looks different. RSI Security brings the expertise, guidance, and practical support needed to navigate complex requirements, reduce risk, and build a stronger security program around your organization’s goals.