HIPAA
HIPAA compliant lab software, with a BAA for every US lab.
Lab Desk builds the HIPAA safeguards into the product and signs a Business Associate Agreement with every US lab. Your team gets on with the work.

Business Associate Agreement
A BAA for every US lab, not just the big ones.
When Lab Desk stores and processes your patients' health information, we act as your business associate. The BAA sets out how we protect that information and what we do if something goes wrong.
Easy to put in place.
Accept it as a click-through at sign-up, or ask us for a signed copy.
Breach notice.
We tell your lab about a breach without unreasonable delay, and no later than 60 days after discovery.
Sub-processors.
Every service that handles patient data is covered by its own BAA with us.
Return or deletion.
When you leave, you can export your data. We then delete it and confirm the deletion.
Safeguards
How Lab Desk maps to HIPAA.
HIPAA has no official certificate. These are the safeguards we build and keep on record.
| Feature | How Lab Desk handles it | HIPAA requirement |
|---|---|---|
| Unique logins | Every staff member has their own account. No shared logins. | Unique user identification |
| Multi-factor authentication | A second step at sign-in, on top of the password. | Person or entity authentication |
| Automatic logoff | Sessions end after a period of inactivity. | Automatic logoff |
| Role-based access | Staff see only what their role needs. | Minimum necessary standard |
| Audit log | Views, edits, shares and exports are recorded. Admins can view and export the log. | Audit controls |
| Encryption | TLS 1.2 or higher in transit. Database, files and backups encrypted at rest. | Encryption and transmission security |
| Secure result links | Links expire and ask for an identity check. Every open is logged. | Access control and audit controls |
| Email and payments | Emails carry only a notice and link. No results or test names go to Stripe. | Minimum necessary standard |
| Backups | Regular backups in the US with tested restores. | Data backup and disaster recovery plan |
| Breach notice | We notify your lab without unreasonable delay, and within 60 days of discovery. | Breach notification by a business associate |
Mapping to the HIPAA Security, Privacy and Breach Notification Rules. Your adviser can confirm how it fits your lab's own policies.
Infrastructure
Hosted on AWS, under an AWS BAA.
Lab Desk runs on Amazon Web Services in the US. We have a BAA with AWS and use only HIPAA-eligible AWS services for patient data.
That covers hosting, the database, file storage and backups, the AI that flags results and drafts summaries (Amazon Bedrock), and result emails (Amazon SES).
- AI inputs are never used to train models
- Emails carry only a generic notice and a secure link
- Card details handled by Stripe, never stored by Lab Desk

Shared responsibility
What your lab is still responsible for.
HIPAA applies to your lab as the covered entity. Lab Desk gives you the tools, and some duties stay with you.
Your policies.
Your own risk analysis, security policies and a named privacy and security officer.
Who gets access.
Deciding which staff get which role, and removing access when someone leaves.
Staff training.
Training your team on privacy, passwords and handling patient information.
Reporting breaches.
Notifying affected patients and HHS when required, using the details we give you.
Reviewing results.
Checking every AI flag and summary before release. The AI assists. It does not diagnose.
Patient notices.
Your notice of privacy practices and any patient permissions your lab needs.
Frequently asked questions
Is Lab Desk HIPAA compliant?
Yes. Lab Desk meets HIPAA requirements for protecting health information and signs a BAA with every US lab. No official certification exists for HIPAA, so compliance is shown through safeguards, agreements and records.
Do you sign a BAA?
Yes, with every US lab, whatever the plan. Accept it at sign-up or ask us for a signed copy.
How fast will you tell us about a breach?
Without unreasonable delay, and no later than 60 days after discovery, with the details your lab needs to decide on its own notices.
Is email a safe way to send results?
Email is not end-to-end secure, so Lab Desk never puts results in it. The email carries a generic notice and a secure link. The patient passes an identity check to see their results.
Does the AI send patient data outside Lab Desk?
No. The built-in AI runs on AWS under our AWS BAA, and inputs are never used to train models.
Not legal advice
These pages describe the safeguards Lab Desk provides. They are not legal advice. Please confirm your own obligations with your legal or compliance adviser.
Need a BAA before you start?
Join early access, or talk to us and we will send the BAA for review.