🧪 Launching later this year — now accepting founding laboratories. Join the waitlist.
Inspection-ready by design

Built for labs that get inspected for real.

Lablytics was designed around the compliance requirements clinical labs live with every day — not bolted on afterwards when a customer first asks. Here is exactly where we stand, stated the way you’d want a vendor to state it.

BAA available · SOC 2 attestation in progress.

COMPLIANCE STATUS BOARD
Vendor posture — four frameworksREVIEWED JUL 2026
HIPAA — Privacy & Security Rules · BAA available.Supported by design
CAP — Accreditation documentation & records.Supported by design
CLIA — Competency, QC & procedure records.Supported by design
SOC 2 — Independent security attestation.Attestation in progress
NOTHING OVERSTATED · NOTHING BOLTED ONBAA available
We’ll be straight with you about where we are.Status log · Updated Jul 2026

Lablytics is pre-launch. It wasn’t designed by a software company entering healthcare — it was designed by a Medical Laboratory Scientist who has been through inspections, competency reviews, and quality management firsthand. Compliance shaped the architecture from the first commit; it wasn’t added when a customer asked.

HIPAAAccess controls, audit logging, encryption, and secure data handling are designed to support the Privacy and Security Rules. A BAA is available to every lab that requires one.
CAP / CLIAThese are lab accreditation and regulatory frameworks — not software certifications, and we won’t pretend otherwise. They informed how documentation, training records, and audit trails are structured, so your records stay in the state an inspector expects to find them.
SOC 2A SOC 2 is an independent attestation, not a certificate — and a Type II report requires an auditor to observe controls operating over a period of months. Our Type I report is targeted ahead of launch, and the Type II observation window begins at launch, with the report to follow. Waitlist members receive each report as it’s issued.

We’d rather tell you precisely where we are than imply we’ve achieved something we haven’t. If that costs us a deal with a lab that needs a completed Type II today, that’s the right outcome for that lab.

I have stood at the bench during a CAP inspection. I know what it feels like when the documentation isn’t where it should be, and when the answer an inspector needs takes thirty minutes to assemble. Lablytics is built so that moment never happens to you.

Founder, LablyticsMedical Laboratory Scientist & Developer
What each standard means for your lab

Compliance built in — not bolted on.

The requirements clinical labs live under shaped how Lablytics was designed. Here’s what that means in practice, standard by standard.

HIPAA
Health Insurance Portability and Accountability Act
Supported by design

Protecting patient information isn't an abstract requirement — it's part of the daily responsibility of every clinical laboratory. Lablytics is designed around the Privacy and Security Rules: access controls, audit logging, encryption, and secure data handling.

  • Your lab's data is handled with the rigor expected for patient information
  • Security controls are the default — not optional settings that depend on manual configuration
  • A Business Associate Agreement is available for every lab that requires one
CAP
College of American Pathologists accreditation
Supported by design

CAP accreditation requires documentation, training records, and quality management systems that are current, consistent, and verifiable on demand. Those requirements informed every documentation and training feature in the platform.

  • Records and competency sign-offs stay in a format an inspector can review immediately
  • Mandatory read acknowledgements, version control, and audit trails are standard
  • Inspection prep becomes reviewing records — not assembling them from scratch
CLIA
Clinical Laboratory Improvement Amendments
Supported by design

CLIA requires labs to demonstrate ongoing staff competency, maintain quality control records, and document the procedures that govern testing. Every training, competency, and operational module is built around those requirements.

  • Competency records stay organized, current, and available on demand
  • Procedure documentation is version-controlled and acknowledgement-tracked
  • Your CLIA documentation becomes a byproduct of daily work — not a separate effort
SOC 2
Service Organization Control — Type I & Type II
Attestation in progress

A SOC 2 report is an independent auditor's attestation that security controls work the way we say they do — not just that they exist on paper. We're building to those controls now rather than retrofitting them later.

  • Type I report targeted ahead of public launch
  • Type II observation period begins at launch; the report follows and is shared with every customer
  • Waitlist members receive each report as soon as it's issued
How we protect your data

Your IT security review, answered in advance.

These are the questions hospital security teams actually ask. Plain answers, no chasing.

Encryption

Encrypted in transit and at rest

Data is encrypted in transit and at rest using industry-standard encryption, protecting information throughout its lifecycle.

Access & identity

Role-based access, per your org chart

Every person in your lab sees exactly what their role requires — nothing more. Access is controlled at the role level, not managed manually per person, and identity requirements for health systems (MFA, single sign-on) are addressed during your security review.

Audit trail

Every action logged

Who did what, when, and from where — logged, retained, and always available to your administrators. The audit trail is the same one an inspector would want to see.

Backups & recovery

Backed up on a schedule, restores tested

Your lab's data is backed up regularly, and recovery procedures are documented and tested — not assumed to work the day you need them.

Incident response

Prompt notification, per HIPAA rules

In the event of a security incident, you are notified promptly and in accordance with HIPAA breach notification requirements — not when you happen to ask.

Tenant isolation

No shared data between labs

Your lab's data is logically isolated from every other lab on the platform. No unintended access or exposure of records between organizations.

Data residency

US-only storage and processing

Your lab's data is stored and processed within the United States, on infrastructure that meets HIPAA-eligible service requirements. It does not leave US jurisdiction.

Before onboarding, your security and compliance teams get the full packet: our Business Associate Agreement, security architecture overview, infrastructure and subprocessor details, and — as each is issued — our SOC 2 Type I and Type II reports. No chasing required.

Our customer commitments

What you can hold us to.

Not aspirations. Commitments — in force from the moment your lab goes live.

Your data is never sold

We don't sell, share, or monetize your lab's data. It's yours — used only to provide the service you signed up for.

You leave with everything

Full data export in a portable, standard format — before, during, or after cancellation. No data held hostage.

Deletion handled responsibly

On request, data is removed according to applicable retention requirements — and we don't retain deleted records beyond what the law requires.

BAA without pushback

A Business Associate Agreement is available for any lab that requires one. We will not push back on signing it.

Transparency about incidents

If something goes wrong with your data, you'll know promptly — not when you happen to ask.

Data stays in the US

Stored and processed within the United States. It does not leave US jurisdiction.

Common questions

Things your team will ask before signing up.

Will Lablytics sign a Business Associate Agreement?
Yes. A BAA is available for every lab that requires one as part of onboarding, and you can request it at any point before your lab goes live. Waitlist members receive a copy of our standard BAA ahead of launch.
Is Lablytics CAP or CLIA certified?
CAP and CLIA are accreditation and regulatory frameworks for laboratories — not software certifications, so no software can honestly claim them. Your lab holds the accreditation; Lablytics helps you maintain the documentation, training records, and operational consistency that support it, in the state an inspector expects to find them.
When will the SOC 2 reports be available?
Our SOC 2 Type I report — an auditor's point-in-time attestation that our controls are properly designed — is targeted ahead of public launch. A Type II report requires the auditor to observe those controls operating over a period of months, so its observation window begins at launch and the report follows. Waitlist members receive each report as soon as it's issued.
Where is our laboratory data stored?
Within the United States, on infrastructure that meets HIPAA-eligible service requirements with the physical and logical controls appropriate for healthcare data. Your data does not leave US jurisdiction.
What happens to our data if we leave Lablytics?
You leave with everything. Full export in a portable, standard format is available at any time — before, during, or after cancellation — and deleted records aren't retained beyond what applicable law requires.
Who can access our laboratory's data?
Authorized members of your lab team, based on their assigned roles. Lablytics staff can access your data only in documented, auditable circumstances — for example, resolving a support issue you've specifically requested help with — and every such access is logged and visible in your audit trail.
Does Lablytics integrate with our LIS?
No LIS integration is required — Lablytics runs alongside your existing LIS and touches the operational layer it leaves untouched. Identity integration (single sign-on for your health system) is a separate question, and one we address directly during your IT security review.
Launching later this year

A platform built for the environment your lab operates in.

Join the waitlist to be among the first labs on the platform. Waitlist members receive our BAA and each SOC 2 report ahead of go-live.

Join the waitlist
No credit cardBAA available on requestSOC 2 reports shared as issued