Legal documents

Seven documents, each one written rather than assembled.

A legal page that could belong to any product tells you nothing about this one. These say what LabFlow handles, who is responsible for it, how long it is kept, which companies see it, and what has not been done yet.

The setseven documents
Documents7
Last reviewed6 August 2026, all seven
Written byThe LabFlow team, not a template
Law firm reviewNone. This is not legal advice
The HIPAA wordConscious, never compliant
Named processors5

Every document is on this page. Choosing one changes the address bar, so the link you copy is the link to that document.

The documents

HIPAA statement

HIPAA-conscious, and the difference that word is doing.

Last reviewed2026-08-06
Clauses9
URL/hipaa-compliance
BAA availableNo

The address of this page contains the word compliance because it was published under that address and is indexed there. The page itself does not claim it, and clause 01 explains why that is not a technicality.


Why the word is conscious and not compliant#

Compliance is a state an organisation is in, not a property software has. It is made of signed agreements, a documented risk analysis, workforce training, access reviews, an incident procedure, a named security official and periodic audits. A piece of software can support all of that and none of it makes the software compliant, because most of the obligations are not about software at all.

So a vendor who tells you their software satisfies HIPAA is either describing their own organisation, which tells you nothing about yours, or making a claim nobody can check. HIPAA-conscious means something narrower and verifiable: the design assumes protected health information is present, and the safeguards in clause 03 exist because of it.

The relationship HIPAA would put us in, and why it does not exist yet#

A laboratory in the United States handling protected health information is a covered entity. A vendor handling that information on its behalf is a business associate, and the relationship is created by a signed business associate agreement, not by using the product.

The safeguards that are actually built#

Each of these is a design decision with a consequence you could observe, not a value.

Safeguards built into LabFlow, and the limit of each
SafeguardWhat it doesIts limit
Tenant isolationEvery row belongs to a tenant, and every read proves the tenant from its own filters rather than trusting the caller.Proven by a live test as a non-privileged user, not by reading the policy. A policy that reads a field the query never filters on returns a clean, wrong answer.
Role-based accessWhat a person may see and do is decided on the server, on every request.A role a user could write themselves would be worthless, so roles are not writable by the account they describe.
Append-only audit trailWho did what, when and from where, written in the same transaction as the change.No application role holds update or delete on it. A trail the application can rewrite proves nothing.
Minimum necessaryA phlebotomist sees the collection list, not the whole record.It is only as good as the roles a laboratory assigns, which is the laboratory's decision.
Information out of URLsRecords are addressed by opaque identifiers, so nothing identifying reaches history, referrers or screenshots.It does not protect a screenshot of the page content itself.
Electronic signatureReleasing a report requires re-authentication, and the signature is bound to the exact version signed.Signing fails when the proof is missing or stale. That is deliberate and it will occasionally be inconvenient.
No information in text messagesThe mobile nudge draws from fixed templates and cannot carry a value, a test name or a diagnosis.It is sent from a staff member's own phone, which is why it may only ever be a nudge.

The six things that are not in place#

A statement listing only what exists is an advertisement. These are the gaps, and each is a real reason a laboratory might decide against LabFlow today.

No business associate agreement

Clause 02. It is the first thing that would have to change.

No third-party audit or certification

No SOC 2 report, no HITRUST certification, no ISO 27001. None has been started, so none is imminent.

No independent penetration test

The safeguards in clause 03 are tested only by the LabFlow team that wrote them, which is the weakest form of assurance there is.

No named security official, and no workforce

Several administrative safeguards assume an organisation with staff to train and roles to separate. The LabFlow team is not that organisation.

No contractual breach-notification timetable

What we would do is in clause 06. What we have committed to in writing is nothing, because there is no agreement to carry it.

No availability commitment

The contingency-plan requirement expects a stated recovery objective. There is not one, and the terms say so as well.

Minimum necessary, expressed as roles#

The rule is that a person sees the least information needed to do their job. In software that is not a policy document, it is a role model, and a role model that nobody can explain in a sentence will be worked around within a week.

LabFlow's roles are shaped around the laboratory's real division of work: collection, reception and accessioning, analysis and result entry, validation and release, quality management, and administration. A laboratory can narrow them further. It cannot widen a role to see another tenant, because that boundary is not a role at all.

If something went wrong#

If we discovered unauthorised access to information inside a tenant, we would tell the affected laboratory without delay, in writing, with what we know and what we do not, and we would preserve the audit trail rather than tidy it. The laboratory then notifies the people affected and its regulator, because that duty is the covered entity's and cannot be delegated to a vendor.

There is no contractual timetable behind that paragraph. It is what would happen, not what has been promised, and clause 04 lists that gap as one of the six.

Retention, because HIPAA sets one of the windows#

The audit trail is kept for six years, which is the documentation-retention period HIPAA sets. Results and reports are kept for at least two years and pathology material for ten, which come from clinical laboratory rules rather than from HIPAA. A laboratory may extend any window; it may not take one below its own regulator's floor.

All four windows, with what each is anchored to, are on the data deletion page.

Outside the United States#

HIPAA is United States law. A laboratory elsewhere has its own regime, and in Europe the relevant structure is the controller and processor split described in clause 01 of the privacy policy, together with a written processing agreement that is subject to the same gap as the business associate agreement: it does not exist yet.

The safeguards in clause 03 are not jurisdictional. They are the same wherever the tenant is.

What your laboratory still owes, whichever vendor you choose#

This is the useful part of the page, and it stays true if you pick a different product.

  • A documented risk analysis covering the whole environment, of which the software is one part.
  • A signed agreement with every vendor that touches protected health information, this one included.
  • Workforce training, and a record that it happened.
  • An access review with a real cadence, so a role granted for one week does not survive for three years.
  • An incident and breach procedure that names people rather than functions.
  • A contingency plan that has been tested, not only written.
  • Physical safeguards, which no software vendor can supply.

If a vendor tells you their product covers these, they have described a product that does not exist.

Four things no document on this page can do for you.

Legal pages are usually written to close questions. These are here to open the four that a careful buyer should ask next, because a page that leaves you feeling reassured has probably done you a disservice.

They are not legal advice, and no lawyer has read them

They are written to be accurate rather than to be defensible. Your counsel should read the terms and the HIPAA statement and expect to negotiate.

They are not a contract you can rely on for production

The governing-law clause is open and there is no business associate agreement. Both are named in the documents rather than left for you to discover.

They cannot describe your laboratory's obligations

Risk analysis, training, access review, physical safeguards and a tested contingency plan stay yours whichever system you run.

They are not evidence that any of it is implemented

A document describing a safeguard reads exactly like a document describing an intention. Ask to see the audit trail and ask to be refused a tenant that is not yours.

One page owns each fact, and the rest point at it.

Seven documents that each state a retention window are seven chances for six of them to be out of date. So each fact has a single home, and everywhere else is a link.

Retention

The four windows, and what each is anchored to

Results and reports, pathology material, the audit trail, specimen movement. The numbers live in one place and every other mention links to it.

Processors

Which companies see anything, and what each receives

Four named, with the specific thing each one gets. The cookies page describes what reaches your browser; this describes what reaches somebody else's server.

Owned by /privacy-policy, clause 03

Measurement

What analytics receives, and the commitment about session replay

Deliberately stated in identical words on two pages, so that changing one without the other is visible rather than quiet.

Stated twice: privacy clause 05, cookies clause 04

Permissions

Every Android permission, with the four-way agreement rule

The manifest, this page, the privacy policy and the store declaration must say the same thing before a build is released.

Gaps

What is missing, listed rather than omitted

No business associate agreement, no external audit, no penetration test, no tested restore, no governing-law clause, no availability commitment.

HIPAA clause 04, security clause 11

If a clause is wrong, that is worth an email.

These were written by the team that built the product, which makes them accurate about the software and untested as law. A correction, a challenge, or a question about how a specific safeguard actually works will be answered by a person who can check the code rather than by somebody reading from the same page you are.

Revision historypublished

All seven documents were rewritten in one pass on 6 August 2026. Every future revision is dated and published as an entry in the feed, so a change to a policy is something you can subscribe to.