Why a Laboratory Is Not an Office With Instruments
Most IT providers treat a pathology lab as a normal business that happens to own expensive equipment. That assumption is where the trouble starts.
In an ordinary office, the right answer to an out-of-date PC is to patch it. In a laboratory, the PC bolted to the side of an analyser is part of a validated method. Updating it can invalidate that validation and, in some cases, void vendor support. A well-meaning engineer running Windows Update across the estate is not a maintenance task here — it is an incident.
The same inversion runs through everything. Turnaround time is a clinical commitment, so downtime has a patient at the end of it. Results move over interfaces that fail without symptoms. Storage is dominated by imaging that grows relentlessly and can never be deleted. And the whole thing is assessed against ISO 15189 by an assessor who will ask who had access, what changed, and how you know.
Nerdster provides managed IT support for private pathology and diagnostic laboratories that starts from how a lab actually runs — and, just as importantly, from what we will not touch.
The Instrument Estate: Segment, Don’t Patch
This is the problem we are called about most, and the one where generic advice does the most damage.
A large share of analyser-attached PCs run an operating system that is out of support and locked by the vendor. You cannot patch them without risking revalidation. You cannot easily replace them. And they sit on the same flat network as email and the internet.
The answer is not to patch. It is to stop the unpatchable machine being reachable:
- The instrument estate goes on its own network segment
- Routing is explicit — instruments talk to the LIMS and the middleware, and to nothing else
- No general internet access, no browsing, no email on instrument PCs
- Monitoring on what is actually communicating, so anything unexpected is visible
None of this requires the vendor’s permission, because none of it changes the validated machine. It is the highest-value change most laboratories can make, and it is routinely missing.
Interfaces Fail Quietly — So Watch Them
An analyser can run perfectly while its interface to the LIMS is dead. Samples process, results generate, and nothing arrives. The failure surfaces when a clinician chases a result that was never routed, by which point you are reconstructing hours of work.
We monitor the interfaces and the middleware carrying them — HL7 and ASTM connections, result routing, queue depth — so a dropped connection produces an alert within minutes. Where the fault is the analyser’s or the LIMS vendor’s, we take that up with them directly. You should not be the message-passing layer between two of your own suppliers.
Evidence, Not Recollection, at Assessment
UKAS accreditation to ISO 15189 covers competence and quality across the laboratory, and parts of it land squarely on IT: control of access, control of records, control of change, and the integrity of the data behind a report.
We maintain the technical half of that evidence — access records and reviews, audit trails, change history and approvals, documented configuration, and backups that have been restore-tested rather than assumed. When an assessor asks who could see what and when it changed, the answer comes from a record.
To be precise about the boundary: we do not write your quality management system, we do not own your procedures, and we do not represent you at assessment. Those are yours. We make the IT questions answerable.
Data Protection Where the Data Is Clinical
Patient test data is special-category personal data under UK GDPR and the Data Protection Act 2018 — a higher duty of care than ordinary business information, and it flows further than people expect: requesting clinicians, courier manifests, reporting portals, and the archive.
Where you hold NHS contracts or touch NHS systems, the Data Security and Protection Toolkit applies and is submitted annually. Where you do not, it is not legally required — and we will say so rather than sell you a submission you do not owe. UK GDPR applies either way, so the underlying controls are the same: access on a need-to-know basis, multi-factor authentication throughout, encryption at rest and in transit, and audit trails that record who accessed which record.
Cyber Essentials is voluntary, but increasingly written into NHS and pharmaceutical supply-chain contracts. If your commercial pipeline includes either, it is worth having before it is asked for.
Storage That Survives Digital Pathology
Whole-slide imaging changes the shape of a laboratory’s storage problem. A single slide can run to several gigabytes, the archive only ever grows, and retention obligations mean very little of it can be deleted.
We design for that explicitly — tiered storage so live cases stay fast while the archive stays affordable, backup windows that actually complete, and restore testing so retrieving a historic slide or report is routine. A backup you have never restored is a hope, not a plan; in a laboratory it is also a compliance gap.
Out of Hours, and the Alarms That Cannot Wait
Laboratories do not stop at five. Support hours are scoped against your real operating pattern — overnight runs, weekend cover, and the specific alerts that must reach a human immediately.
Cold-chain and freezer monitoring belongs in that category. A -80 failure discovered in the morning is an archive lost. Those alarms are treated as incidents with a defined escalation path, not as another line in a monitoring dashboard nobody reads.
Working With Us
We are direct about scope, because in a regulated laboratory a vague division of responsibility is itself a risk. We handle infrastructure, networking, segmentation, storage, backup, security and support. Your analyser and LIMS vendors own their applications and validations. Your quality lead owns the QMS. We make those boundaries explicit at the start and coordinate across them rather than hiding behind them.
If you would like to talk through your instrument estate, your interfaces, or how your IT evidence would stand up at your next assessment, we are glad to discuss it in confidence.
Also relevant: healthcare IT support for the wider clinical picture, and IT support in London for pricing and response times.
Probably not us if
We would rather say so now than discover it three months in.
- You need us to configure, validate or modify analyser software itself — that is your vendor's responsibility and we will not touch it.
- You want a provider who will patch the instrument estate on a standard schedule. We segment it instead, deliberately.
- You are looking for someone to write or validate your quality management system. We supply the technical evidence; the QMS is yours.
- Your laboratory sits outside the UK regulatory perimeter — our compliance work is built around UKAS, the DSPT and UK GDPR.
