New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs
Clinical care providers
Privacy & Security for Medical & Diagnostic Labs
Medical and diagnostic labs run some of the largest personal health information holdings in Canada, and the sector already has its own landmark regulator finding to answer to: Ontario's IPC and BC's OIPC jointly examined LifeLabs after attackers reached records on roughly 8.6 million people through an unpatched web server. Privacy Horizon builds the security leadership, privacy accountability and licensing-grade documentation a community lab company, specialty reference lab or hospital-affiliated lab needs to operate the way that finding, and the province's laboratory licensing rules, now expect.
Reviewed by the Privacy Horizon team · Last reviewed
Who this is for
CIOs, CISOs and IT directors at community lab companies and specialty or reference labs running laboratory information systems, analyzers and patient-facing portals around the clock, where a single unpatched web application can become a province-wide event.
Privacy officers, general counsel and quality managers who carry the licence-holding entity's obligations under provincial laboratory statutes alongside PHIPA, HIA or Quebec's health-information regime, often at specialty labs of 50 to 500 staff where one person wears both hats.
VPs of Quality who own the ISO 15189 accreditation cycle and need the information-security program to slot into an already-mature quality-management culture rather than compete with it.
Lab directors preparing for a hospital or health-authority contract renewal, an Ontario Laboratories Information System connection, or a consolidation deal, each of which puts documented safeguards in front of a counterparty before the relationship proceeds.

Services
Privacy & security services for medical & diagnostic labs
Each service below is scoped for how medical & diagnostic labs actually operate — their systems, their regulators and the reviews they face.
Virtual CISO
Virtual CISO for Medical & Diagnostic Labs
Virtual CISO for medical and diagnostic labs: vulnerability management, segmented instrument networks and the safeguards regulators expect after LifeLabs.
Virtual Privacy Officer
Virtual Privacy Officer for Medical & Diagnostic Labs
Virtual Privacy Officer for medical and diagnostic labs: custodian-agent status, OLIS consent handling and IPC reporting cadence, from $2,200 CAD/month.
Penetration Testing
Penetration Testing for Medical & Diagnostic Labs
Penetration testing for medical and diagnostic labs: requisition and booking web servers, segmented instrument networks, and LIS-safe test methodology.
Incident Response Planning
Incident Response Planning for Medical & Diagnostic Labs
Incident response planning for medical and diagnostic labs: ransom-decision governance, mass-notification logistics and specimen-intake downtime plans.
Privacy & Security Policy Development
Privacy & Security Policy Development for Medical & Diagnostic Labs
Privacy and security policy development for medical and diagnostic labs: the written IT-security practices and disposal terms regulators now expect.
Privacy & Security Training
Privacy & Security Training for Medical & Diagnostic Labs
Privacy and security training for medical and diagnostic labs: courier and collection-centre staff, LIS minimum-necessary access, and caller verification.
Vendor Security Review & Questionnaire Support
Vendor Security Review & Questionnaire Support for Medical & Diagnostic Labs
Vendor security review for medical and diagnostic labs: assessing LIS and portal vendors, reference labs, couriers and instrument remote-access tools.
ISO 27001 Readiness
ISO 27001 Readiness for Medical & Diagnostic Labs
ISO 27001 readiness for medical and diagnostic labs: certification that satisfies hospital RFPs, built on the quality culture ISO 15189 already created.
M&A Privacy & Security Due Diligence
M&A Privacy & Security Due Diligence for Medical & Diagnostic Labs
M&A privacy due diligence for medical and diagnostic labs: legacy LIS archives, consent histories, licensing continuity and custodian liability at close.
What you hold
What a lab's privacy and security program has to cover
A lab's information footprint runs from the requisition a physician faxes in to the result a patient reads on a portal, with instruments, couriers and a provincial repository in between.
Requisitions and results across every discipline
Chemistry, hematology, microbiology, pathology and genetics results, plus the requisitions that order them, carry health-card numbers, requisitioning-provider identity and clinical detail that outlives most retention schedules built for general office records.
Specimen metadata and chain of custody
Collection time, courier route, accessioning number and storage condition tie a physical sample to a person, and gaps in that trail create both quality-management findings and privacy exposure at once.
Laboratory information systems and instrument middleware
The LIS or LIMS platform, plus the middleware that feeds it from analyzers, holds the operational record of every test a lab runs and is the environment a privacy or security review has to reach, not just the front-end portal.
Internet-facing booking, requisition and portal applications
Web booking tools, requisition intake and patient-facing result portals sit on the public internet by design, which is precisely the layer that put LifeLabs' records at risk in 2019.
OLIS contributions and consent-withdrawal records
Every result an Ontario lab submits into the provincial Ontario Laboratories Information System, and every patient's decision to withdraw consent through ServiceOntario, has to be tracked and honoured across every system that touches that person's data.
Billing, OHIP numbers and direct-to-consumer accounts
Provincial health-card numbers and billing data travel alongside results, and labs running direct-to-consumer testing lines add payment cards and consumer accounts to the mix under a separate consent basis.
Regulatory map
The licensing and privacy regime a lab operates inside
Labs answer to a licensing body before they answer to a privacy regulator, and the two regimes are built to reinforce each other.
PHIPA custodian status by statute
Ontario laboratories and specimen collection centres are defined as health information custodians through the Laboratory and Specimen Collection Centre Licensing Act, so custodian duties attach the moment the licence does.
LSCLA licensing and quality-management conditions
Operating a lab or specimen collection centre without an LSCLA licence is not an option in Ontario, and the licence itself carries quality-management-program conditions that a privacy and security program has to be built to satisfy.
ISO 15189 Plus through Accreditation Canada Diagnostics
Sector accreditation runs on ISO 15189 Plus, assessed by Accreditation Canada Diagnostics, and gives labs a quality-management culture that few other clinical niches can build a security program on top of.
OLIS contribution and consent-withdrawal duties
Ontario Health's laboratory repository receives results from every Ontario lab, and patients can withdraw consent to have their results viewed through a ServiceOntario process a lab's own systems have to respect.
Alberta HIA and BC PIPA obligations
Labs serving Alberta's public system interact with HIA custodians and its breach-notice duty, while BC PIPA reached LifeLabs directly alongside Ontario's PHIPA in the joint 2019 investigation.
Quebec's health-information Act names labs directly
Quebec's schedule of health and social services bodies expressly includes a person or group operating a laboratory, with a designated person in charge and incident notification to the CAI and the Minister.
What goes wrong
How lab privacy and security incidents actually happen
The pattern in this sector is documented in more regulatory detail than almost any other Canadian niche, starting with the country's largest health-privacy investigation.
The LifeLabs precedent
Attackers reached LifeLabs through publicly known vulnerabilities on an internet-facing web server, a ransom was paid, and the joint IPC and OIPC BC report that followed set the sector's working definition of reasonable safeguards.
National class proceedings following a breach
A breach at this scale did not end with the regulator's findings; LifeLabs also faced class action lawsuits filed on behalf of affected patients across the country, a tail that runs years past the incident itself.
Physical records lost in transit
Ottawa street cleaners once found lab reports and patient receipts that had spilled from a recycling truck, a case the IPC turned into findings on shredding and disposal-vendor contract terms.
Result misdirection and matching errors
The IPC has dealt with lab-result matching and misdirection problems in provincial registry contexts, a recurring cause of health-sector privacy complaints that specimen-heavy workflows are especially prone to.
Unauthorized LIMS access by staff
Regulators reviewed how Public Health Ontario's laboratory information system logged and controlled staff access, a case that set the bar for what audit trails a lab now needs to keep.
When organisations call us
The moments labs bring in Privacy Horizon
Engagements almost always start with a specific contract, licence or regulator expectation, not an open-ended risk conversation.
A hospital or health-authority contract renewal
Hospital procurement now asks lab vendors to demonstrate the kind of safeguards the IPC ordered LifeLabs to formalize, including a documented custodian-or-agent position with each hospital client.
An ISO 15189 accreditation cycle
Accreditation Canada Diagnostics' review cycle is the natural moment to align security controls with the quality-management program the lab already runs for testing.
A first or renewed LSCLA licence
Licensing under the Laboratory and Specimen Collection Centre Licensing Act brings quality-management conditions that a documented information-security program supports directly.
Connecting to OLIS or expanding a send-out network
Contributing results to Ontario's laboratory repository, or adding a reference lab for specialty send-outs, introduces new data flows that need a privacy and security review before go-live.
Sector consolidation and M&A
A lab being acquired, or acquiring a smaller specialty lab, needs its legacy LIS archives, consent records and licensing status diligenced before the deal closes, not after.
A breach or near-miss at a comparable lab
A regulator finding against another lab company, or an internal incident involving misdirected results or a lost specimen, tends to be the point a board asks whether the same gaps exist internally.
Medical & Diagnostic Labs: privacy & security questions, answered
Scale and licensing both change the calculation. A single lab company can hold records on millions of people rather than the thousands a typical clinic sees, which turns notification and governance into board-level logistics. Labs also operate under a licensing regime with its own quality-management conditions, so privacy and security work has to fit inside that structure rather than stand alone the way it might at a walk-in clinic.
It depends on how the relationship is structured, and getting it wrong was one of the findings against LifeLabs, which was ordered to formalize its position with hospital clients rather than leave it implied. A lab testing samples under its own licence generally holds custodian status on its own; one working strictly under a hospital's direction may instead be acting as that hospital's agent. The distinction changes who answers for breach notice and safeguards, and it belongs in writing before a contract is signed, not worked out after an incident.
No. ISO 15189 Plus, assessed through Accreditation Canada Diagnostics, governs testing quality and competence, and it does build the kind of documentation and audit culture a security program can build on, but it is not an information-security standard. Labs pursuing a certifiable security answer for hospital or health-authority RFPs generally run ISO 27001 readiness alongside their existing 15189 cycle rather than relying on 15189 to satisfy both.
Every Ontario lab contributes results into the Ontario Laboratories Information System, and a patient can withdraw consent to have their results viewed by care providers through ServiceOntario. Once that withdrawal is registered, a lab's own systems, reporting workflows and any downstream portal need to reflect it consistently, not just the provincial repository, which is a gap that surfaces quickly during a privacy review.
The joint IPC and OIPC BC report found LifeLabs had failed to maintain reasonable safeguards, lacked comprehensive written information-security policies, and had been over-collecting information such as failed-login and password pairs it had no reason to retain. The orders that followed required written IT-security practices and a clearer custodian-or-agent position with hospital clients, which is why those two artifacts now sit near the top of what a lab's privacy program needs to produce.
The Laboratory and Specimen Collection Centre Licensing Act is the statute that makes a licensed lab a health information custodian under PHIPA in the first place, and the licence itself carries quality-management-program conditions a regulator can review. That means privacy and security gaps are not just a PHIPA risk; they can also touch the conditions attached to the licence a lab needs to keep operating.
Most start with a Virtual Privacy Officer or vCISO engagement to establish accountable ownership and close the gaps a hospital contract or licensing review would find first, then add a penetration test if booking or requisition systems are internet-facing. ISO 27001 readiness and formal M&A due diligence tend to follow once a specific accreditation cycle, RFP or acquisition puts a date on the calendar.
Related industries
Answers & guides
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.