Guiding Principles

At Lane Health, we strive to provide services to our customers in a secure and responsible manner. As we built an industry only pre-tax and post-tax lending platform, HSA and other benefits administration solutions, as well as customer facing web and mobile interfaces, we’ve done it with security built into the architecture and our processes. Lane Health is committed to protecting the confidential information, data integrity, and transparency of our operations.

This page goes over our approach to securing PII against cyber-attacks—combining secure design and quality engineering practices, developing strong connections with the cybersecurity community, and developing a world-class Risk & Compliance process.

Cybersecurity

Lane Health follows industry accepted best practices when it comes to security. We established joined internal operations between SREs, NOC and Software Engineering teams to implement and deploy controls designed to secure the perimeter of our systems and minimize the threat of attacks.

Fraud Prevention

Our Fraud Prevention Operation is employing the best practices of fraud prevention and cybersecurity monitoring through rigorous security training and systematic monitoring to identify and secure the data of our clients.

Compliance

Lane Health Compliance department operates at the enterprise level: managing operational, financial, and security risks for the entire company. They interface with internal and external audit entities and implement state of the industry transparent operation.

Incident Management and Communication

Lane Health created a robust Incident Management and Communication policy that was certified by our banking institution.

Privacy

Lane Health developed the Data Privacy policy based on the detailed analysis of government regulations and validated by rigorous audits. Our state-of-the-art technology teams build systems with security and privacy in mind. The Privacy Policy can be found here

Lane Health Security Features:

  • Regular 3rd-party vulnerability scanning and testing
  • Dynamic capacity and scalability management
  • Intrusion detection monitoring
  • Multiple redundant data centers
  • Annual review of policies
  • Call centers with high responsiveness SLA
  • All employees and contractors with access to Lane Health systems and data complete mandatory compliance, privacy, and security training as part of hiring process
  • Third party verification of cloud-native architecture for Health Insurance Portability and Accountability Act (HIPAA) compliance
  • Background checks for US employees with access to PII

Security and Vulnerability Reporting

Lane Health encourages security researchers to report discovered issues with Lane Health systems by reporting them to securityreporting@lanehealth.com.