Security

Built with security in mind from day one.

Your lab handles sensitive health information. Lab Desk is designed to protect it at every step, from the first order to the moment a patient opens their results.

Lab Desk: Built with security in mind from day one.

Compliance

The rules your lab works under, built in.

HIPAA, PIPEDA and Quebec Law 25 have no official certificate. We show compliance through product safeguards, signed agreements and kept records.

  • HIPAA compliant.

    Lab Desk meets HIPAA requirements for protecting health information, and signs a Business Associate Agreement (BAA) with every US lab.

  • UK GDPR compliant.

    UK labs use uk.labdesk.app, hosted in the UK under UK GDPR, with a Data Processing Agreement (DPA).

  • Canada.

    Lab Desk is built to follow PIPEDA's privacy principles, and supports Quebec labs with Law 25 requirements such as privacy impact assessments.

Where your data lives

US and Canada in the US. The UK in the UK.

Labs in the United States and Canada use app.labdesk.app, with data hosted in secure US data centers. Labs in the United Kingdom use uk.labdesk.app, with data hosted in London, so UK patient data stays in the UK.

Canadian labs are told their data is stored in the US, and our Data Processing Agreement sets out how it is protected.

  • Separate databases, storage, logs and backups for the UK
  • Backups stay in the same region as the live data
  • Quebec labs get a ready privacy impact assessment pack
Lab Desk: US and Canada in the US. The UK in the UK.

AI and your data

Your data is never used to train AI.

Lab Desk's AI flags abnormal results and drafts patient-friendly summaries for your lab only. We never use your patients' data to train AI models, ours or anyone else's. Staff review every flag and summary before anything is shared.

  • AI runs on AWS in your lab's hosting region
  • The AI service does not use inputs to train models
  • AI assists staff review. It never diagnoses.
Lab Desk: Your data is never used to train AI.

How we protect your data

Safeguards at every step.

  • Encryption.

    Data is encrypted in transit (TLS 1.2 or higher) and at rest, including the database, files and backups.

  • Access control.

    Role-based permissions give each staff member only the access they need. Every user has their own login.

  • Sign-in protection.

    Multi-factor authentication and automatic logoff after a period of inactivity.

  • Audit trail.

    Views, edits, shares and exports are logged. Lab admins can view and export the log.

  • Secure result links.

    Each link is unique, expires, and asks the patient for an identity check such as date of birth. Every open is logged.

  • Email delivery.

    Emails carry a generic notice and a secure link to the result, never the report itself.

  • Payments by Stripe.

    Card details are handled by Stripe and never stored by Lab Desk. No results or test names are sent to Stripe.

  • Backups.

    Data is backed up regularly, restores are tested, and backups stay in your region.

Your lab stays in control

  • You own your data and can export it at any time.
  • Patient access, correction and deletion requests can be handled from the patient's record.
  • Consent to email and link delivery is recorded for each patient.
  • If you leave Lab Desk, you can export everything first. Your data is then deleted a set number of days after you leave (confirmed in your agreement), and you get a deletion confirmation.

Documents and contacts

DPA
For every lab. Covers safeguards, sub-processors, data location, incident notice and deletion.
BAA
For every US lab. Accept it at sign-up or ask us for a signed copy.
Security contact
Report a concern or ask a question at security@labdesk.app.

Frequently asked questions

Is Lab Desk HIPAA compliant?

Yes. Lab Desk meets HIPAA requirements for protecting health information, and we sign a Business Associate Agreement (BAA) with every US lab. HIPAA has no official certificate, so compliance is shown through safeguards and signed agreements.

Is Lab Desk GDPR compliant?

Yes, including UK GDPR for labs in the UK. UK labs use uk.labdesk.app, hosted in London.

Where is my data stored?

US and Canadian labs: in secure US data centers, on app.labdesk.app. UK labs: in the UK, on uk.labdesk.app.

Is patient data used to train AI?

Never. Your patients' data is not used to train AI models, ours or anyone else's.

Do result emails contain patient results?

No. Emails carry only a generic notice and a secure link. The patient opens the link and passes an identity check to see their results.

How do I report a security concern?

Email security@labdesk.app. We read every report.

Not legal advice

These pages describe the safeguards Lab Desk provides. They are not legal advice. Please confirm your own obligations with your legal or compliance adviser.

Security questions before you sign up?

Talk to us, or join early access and see the safeguards for yourself.