HIPAA

HIPAA compliant lab software, with a BAA for every US lab.

Lab Desk builds the HIPAA safeguards into the product and signs a Business Associate Agreement with every US lab. Your team gets on with the work.

Lab Desk: HIPAA compliant lab software, with a BAA for every US lab.

Business Associate Agreement

A BAA for every US lab, not just the big ones.

When Lab Desk stores and processes your patients' health information, we act as your business associate. The BAA sets out how we protect that information and what we do if something goes wrong.

  • Easy to put in place.

    Accept it as a click-through at sign-up, or ask us for a signed copy.

  • Breach notice.

    We tell your lab about a breach without unreasonable delay, and no later than 60 days after discovery.

  • Sub-processors.

    Every service that handles patient data is covered by its own BAA with us.

  • Return or deletion.

    When you leave, you can export your data. We then delete it and confirm the deletion.

Safeguards

How Lab Desk maps to HIPAA.

HIPAA has no official certificate. These are the safeguards we build and keep on record.

FeatureHow Lab Desk handles itHIPAA requirement
Unique loginsEvery staff member has their own account. No shared logins.Unique user identification
Multi-factor authenticationA second step at sign-in, on top of the password.Person or entity authentication
Automatic logoffSessions end after a period of inactivity.Automatic logoff
Role-based accessStaff see only what their role needs.Minimum necessary standard
Audit logViews, edits, shares and exports are recorded. Admins can view and export the log.Audit controls
EncryptionTLS 1.2 or higher in transit. Database, files and backups encrypted at rest.Encryption and transmission security
Secure result linksLinks expire and ask for an identity check. Every open is logged.Access control and audit controls
Email and paymentsEmails carry only a notice and link. No results or test names go to Stripe.Minimum necessary standard
BackupsRegular backups in the US with tested restores.Data backup and disaster recovery plan
Breach noticeWe notify your lab without unreasonable delay, and within 60 days of discovery.Breach notification by a business associate

Mapping to the HIPAA Security, Privacy and Breach Notification Rules. Your adviser can confirm how it fits your lab's own policies.

Infrastructure

Hosted on AWS, under an AWS BAA.

Lab Desk runs on Amazon Web Services in the US. We have a BAA with AWS and use only HIPAA-eligible AWS services for patient data.

That covers hosting, the database, file storage and backups, the AI that flags results and drafts summaries (Amazon Bedrock), and result emails (Amazon SES).

  • AI inputs are never used to train models
  • Emails carry only a generic notice and a secure link
  • Card details handled by Stripe, never stored by Lab Desk
Lab Desk: Hosted on AWS, under an AWS BAA.

Shared responsibility

What your lab is still responsible for.

HIPAA applies to your lab as the covered entity. Lab Desk gives you the tools, and some duties stay with you.

  • Your policies.

    Your own risk analysis, security policies and a named privacy and security officer.

  • Who gets access.

    Deciding which staff get which role, and removing access when someone leaves.

  • Staff training.

    Training your team on privacy, passwords and handling patient information.

  • Reporting breaches.

    Notifying affected patients and HHS when required, using the details we give you.

  • Reviewing results.

    Checking every AI flag and summary before release. The AI assists. It does not diagnose.

  • Patient notices.

    Your notice of privacy practices and any patient permissions your lab needs.

Frequently asked questions

Is Lab Desk HIPAA compliant?

Yes. Lab Desk meets HIPAA requirements for protecting health information and signs a BAA with every US lab. No official certification exists for HIPAA, so compliance is shown through safeguards, agreements and records.

Do you sign a BAA?

Yes, with every US lab, whatever the plan. Accept it at sign-up or ask us for a signed copy.

How fast will you tell us about a breach?

Without unreasonable delay, and no later than 60 days after discovery, with the details your lab needs to decide on its own notices.

Is email a safe way to send results?

Email is not end-to-end secure, so Lab Desk never puts results in it. The email carries a generic notice and a secure link. The patient passes an identity check to see their results.

Does the AI send patient data outside Lab Desk?

No. The built-in AI runs on AWS under our AWS BAA, and inputs are never used to train models.

Not legal advice

These pages describe the safeguards Lab Desk provides. They are not legal advice. Please confirm your own obligations with your legal or compliance adviser.

Need a BAA before you start?

Join early access, or talk to us and we will send the BAA for review.