Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Clinical care providers

Privacy & Security for Medical & Diagnostic Labs

Medical and diagnostic labs run some of the largest personal health information holdings in Canada, and the sector already has its own landmark regulator finding to answer to: Ontario's IPC and BC's OIPC jointly examined LifeLabs after attackers reached records on roughly 8.6 million people through an unpatched web server. Privacy Horizon builds the security leadership, privacy accountability and licensing-grade documentation a community lab company, specialty reference lab or hospital-affiliated lab needs to operate the way that finding, and the province's laboratory licensing rules, now expect.

Reviewed by the Privacy Horizon team · Last reviewed

Who this is for

CIOs, CISOs and IT directors at community lab companies and specialty or reference labs running laboratory information systems, analyzers and patient-facing portals around the clock, where a single unpatched web application can become a province-wide event.

Privacy officers, general counsel and quality managers who carry the licence-holding entity's obligations under provincial laboratory statutes alongside PHIPA, HIA or Quebec's health-information regime, often at specialty labs of 50 to 500 staff where one person wears both hats.

VPs of Quality who own the ISO 15189 accreditation cycle and need the information-security program to slot into an already-mature quality-management culture rather than compete with it.

Lab directors preparing for a hospital or health-authority contract renewal, an Ontario Laboratories Information System connection, or a consolidation deal, each of which puts documented safeguards in front of a counterparty before the relationship proceeds.

Close-up of a doctor gloves working in a testing laboratory

Services

Privacy & security services for medical & diagnostic labs

Each service below is scoped for how medical & diagnostic labs actually operate — their systems, their regulators and the reviews they face.

What you hold

What a lab's privacy and security program has to cover

A lab's information footprint runs from the requisition a physician faxes in to the result a patient reads on a portal, with instruments, couriers and a provincial repository in between.

Requisitions and results across every discipline

Chemistry, hematology, microbiology, pathology and genetics results, plus the requisitions that order them, carry health-card numbers, requisitioning-provider identity and clinical detail that outlives most retention schedules built for general office records.

Specimen metadata and chain of custody

Collection time, courier route, accessioning number and storage condition tie a physical sample to a person, and gaps in that trail create both quality-management findings and privacy exposure at once.

Laboratory information systems and instrument middleware

The LIS or LIMS platform, plus the middleware that feeds it from analyzers, holds the operational record of every test a lab runs and is the environment a privacy or security review has to reach, not just the front-end portal.

Internet-facing booking, requisition and portal applications

Web booking tools, requisition intake and patient-facing result portals sit on the public internet by design, which is precisely the layer that put LifeLabs' records at risk in 2019.

OLIS contributions and consent-withdrawal records

Every result an Ontario lab submits into the provincial Ontario Laboratories Information System, and every patient's decision to withdraw consent through ServiceOntario, has to be tracked and honoured across every system that touches that person's data.

Billing, OHIP numbers and direct-to-consumer accounts

Provincial health-card numbers and billing data travel alongside results, and labs running direct-to-consumer testing lines add payment cards and consumer accounts to the mix under a separate consent basis.

Regulatory map

The licensing and privacy regime a lab operates inside

Labs answer to a licensing body before they answer to a privacy regulator, and the two regimes are built to reinforce each other.

PHIPA custodian status by statute

Ontario laboratories and specimen collection centres are defined as health information custodians through the Laboratory and Specimen Collection Centre Licensing Act, so custodian duties attach the moment the licence does.

Read our guide →

LSCLA licensing and quality-management conditions

Operating a lab or specimen collection centre without an LSCLA licence is not an option in Ontario, and the licence itself carries quality-management-program conditions that a privacy and security program has to be built to satisfy.

Primary source →

ISO 15189 Plus through Accreditation Canada Diagnostics

Sector accreditation runs on ISO 15189 Plus, assessed by Accreditation Canada Diagnostics, and gives labs a quality-management culture that few other clinical niches can build a security program on top of.

Primary source →

OLIS contribution and consent-withdrawal duties

Ontario Health's laboratory repository receives results from every Ontario lab, and patients can withdraw consent to have their results viewed through a ServiceOntario process a lab's own systems have to respect.

Primary source →

Alberta HIA and BC PIPA obligations

Labs serving Alberta's public system interact with HIA custodians and its breach-notice duty, while BC PIPA reached LifeLabs directly alongside Ontario's PHIPA in the joint 2019 investigation.

Primary source →

Quebec's health-information Act names labs directly

Quebec's schedule of health and social services bodies expressly includes a person or group operating a laboratory, with a designated person in charge and incident notification to the CAI and the Minister.

Primary source →

What goes wrong

How lab privacy and security incidents actually happen

The pattern in this sector is documented in more regulatory detail than almost any other Canadian niche, starting with the country's largest health-privacy investigation.

  • The LifeLabs precedent

    Attackers reached LifeLabs through publicly known vulnerabilities on an internet-facing web server, a ransom was paid, and the joint IPC and OIPC BC report that followed set the sector's working definition of reasonable safeguards.

    Source →

  • National class proceedings following a breach

    A breach at this scale did not end with the regulator's findings; LifeLabs also faced class action lawsuits filed on behalf of affected patients across the country, a tail that runs years past the incident itself.

  • Physical records lost in transit

    Ottawa street cleaners once found lab reports and patient receipts that had spilled from a recycling truck, a case the IPC turned into findings on shredding and disposal-vendor contract terms.

  • Result misdirection and matching errors

    The IPC has dealt with lab-result matching and misdirection problems in provincial registry contexts, a recurring cause of health-sector privacy complaints that specimen-heavy workflows are especially prone to.

  • Unauthorized LIMS access by staff

    Regulators reviewed how Public Health Ontario's laboratory information system logged and controlled staff access, a case that set the bar for what audit trails a lab now needs to keep.

When organisations call us

The moments labs bring in Privacy Horizon

Engagements almost always start with a specific contract, licence or regulator expectation, not an open-ended risk conversation.

  • A hospital or health-authority contract renewal

    Hospital procurement now asks lab vendors to demonstrate the kind of safeguards the IPC ordered LifeLabs to formalize, including a documented custodian-or-agent position with each hospital client.

  • An ISO 15189 accreditation cycle

    Accreditation Canada Diagnostics' review cycle is the natural moment to align security controls with the quality-management program the lab already runs for testing.

  • A first or renewed LSCLA licence

    Licensing under the Laboratory and Specimen Collection Centre Licensing Act brings quality-management conditions that a documented information-security program supports directly.

  • Connecting to OLIS or expanding a send-out network

    Contributing results to Ontario's laboratory repository, or adding a reference lab for specialty send-outs, introduces new data flows that need a privacy and security review before go-live.

  • Sector consolidation and M&A

    A lab being acquired, or acquiring a smaller specialty lab, needs its legacy LIS archives, consent records and licensing status diligenced before the deal closes, not after.

  • A breach or near-miss at a comparable lab

    A regulator finding against another lab company, or an internal incident involving misdirected results or a lost specimen, tends to be the point a board asks whether the same gaps exist internally.

Medical & Diagnostic Labs: privacy & security questions, answered

Scale and licensing both change the calculation. A single lab company can hold records on millions of people rather than the thousands a typical clinic sees, which turns notification and governance into board-level logistics. Labs also operate under a licensing regime with its own quality-management conditions, so privacy and security work has to fit inside that structure rather than stand alone the way it might at a walk-in clinic.

It depends on how the relationship is structured, and getting it wrong was one of the findings against LifeLabs, which was ordered to formalize its position with hospital clients rather than leave it implied. A lab testing samples under its own licence generally holds custodian status on its own; one working strictly under a hospital's direction may instead be acting as that hospital's agent. The distinction changes who answers for breach notice and safeguards, and it belongs in writing before a contract is signed, not worked out after an incident.

No. ISO 15189 Plus, assessed through Accreditation Canada Diagnostics, governs testing quality and competence, and it does build the kind of documentation and audit culture a security program can build on, but it is not an information-security standard. Labs pursuing a certifiable security answer for hospital or health-authority RFPs generally run ISO 27001 readiness alongside their existing 15189 cycle rather than relying on 15189 to satisfy both.

The joint IPC and OIPC BC report found LifeLabs had failed to maintain reasonable safeguards, lacked comprehensive written information-security policies, and had been over-collecting information such as failed-login and password pairs it had no reason to retain. The orders that followed required written IT-security practices and a clearer custodian-or-agent position with hospital clients, which is why those two artifacts now sit near the top of what a lab's privacy program needs to produce.

The Laboratory and Specimen Collection Centre Licensing Act is the statute that makes a licensed lab a health information custodian under PHIPA in the first place, and the licence itself carries quality-management-program conditions a regulator can review. That means privacy and security gaps are not just a PHIPA risk; they can also touch the conditions attached to the licence a lab needs to keep operating.

Most start with a Virtual Privacy Officer or vCISO engagement to establish accountable ownership and close the gaps a hospital contract or licensing review would find first, then add a penetration test if booking or requisition systems are internet-facing. ISO 27001 readiness and formal M&A due diligence tend to follow once a specific accreditation cycle, RFP or acquisition puts a date on the calendar.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.