Is Luma AI (Dream Machine) HIPAA compliant?
NoLuma AI · Video
No documented BAA. Luma AI does not appear to offer one for Luma AI (Dream Machine), so treat it as unsuitable for PHI until confirmed otherwise.
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- Business Associate Agreement
- Not offered
- No BAA was found in Luma AI's published materials for this service.
- Enterprise route
- Enterprise or API (only tiers with a contractual no-training guarantee, DPA and SSO)
- For regulated use, validate the BAA, configured service and users under the Enterprise or API (only tiers with a contractual no-training guarantee, DPA and SSO) contract.
- Default data training
- Opt-out required
- Free and standard paid consumer tiers grant Luma rights to train on your input and output; there is no in-app opt-out for consumer tiers.
- Business-tier training
- No by default
- Enterprise and API customers get an explicit no-training guarantee via the Enterprise agreement or API Terms.
Practical risk: Luma trains on your content on consumer tiers; only Enterprise and API get a contractual no-training guarantee. It is explicitly not HIPAA-ready and has no verified SOC 2 or ISO 27001, so treat it as a creative tool rather than a compliance-grade one.
How to make a decision
Check the precise account tier, written contract and intended data before approving Luma AI (Dream Machine). A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on Luma AI (Dream Machine)
Is Luma AI (Dream Machine) GDPR compliant?Is Luma AI (Dream Machine) SOC 2 compliant?Is Luma AI (Dream Machine) ISO 27001 certified?Does Luma AI (Dream Machine) train on your data?
See the full Luma AI (Dream Machine) risk profile, with every data-handling fact and its source, or browse all rated AI tools.