What makes a laboratory different
A pathology lab is easy to mistake for a normal business that happens to own expensive equipment. That assumption is where the trouble starts.
In an ordinary office, the right answer to an out-of-date PC is to patch it. In a laboratory, the PC bolted to the side of an analyser is part of a validated method. Updating it can invalidate that validation and, in some cases, void vendor support. A well-meaning engineer running Windows Update across the estate is not a maintenance task here — it is an incident.
The same inversion runs through everything. Turnaround time is a clinical commitment, so downtime has a patient at the end of it. Results move over interfaces that fail without symptoms. Storage is dominated by imaging that grows relentlessly and can never be deleted. And the whole thing is assessed against ISO 15189 by an assessor who will ask who had access, what changed, and how you know.
We provide managed IT support for private pathology and diagnostic laboratories. We start from how a lab actually runs, and from a clear view of what belongs to your instrument vendors.
Segment your instrument estate instead of patching it
This is the problem we are called about most, and the one where generic advice does the most damage.
A large share of analyser-attached PCs run an operating system that is out of support and locked by the vendor. You cannot patch them without risking revalidation. You cannot easily replace them. And they sit on the same flat network as email and the internet.
The answer is not to patch. It is to stop the unpatchable machine being reachable:
- The instrument estate goes on its own network segment
- Routing is explicit — instruments talk to the LIMS and the middleware, and to nothing else
- No general internet access, no browsing, no email on instrument PCs
- Monitoring on what is actually communicating, so anything unexpected is visible
None of this requires the vendor’s permission, because none of it changes the validated machine. It is the highest-value change most laboratories can make, and it is routinely missing.
Laboratory interfaces fail quietly
An analyser can run perfectly while its interface to the LIMS is dead. Samples process, results generate, and nothing arrives. The failure surfaces when a clinician chases a result that was never routed, by which point you are reconstructing hours of work.
We monitor the interfaces and the middleware carrying them — HL7 and ASTM connections, result routing, queue depth — so a dropped connection produces an alert within minutes. Where the fault is the analyser’s or the LIMS vendor’s, we take that up with them directly. You should not be the message-passing layer between two of your own suppliers.
Answer your assessor from records, not recollection
UKAS accreditation to ISO 15189 covers competence and quality across the laboratory, and parts of it land squarely on IT: control of access, control of records, control of change, and the integrity of the data behind a report.
We maintain the technical half of that evidence — access records and reviews, audit trails, change history and approvals, documented configuration, and backups that have been restore-tested rather than assumed. When an assessor asks who could see what and when it changed, the answer comes from a record.
To be precise about the boundary: your quality management system, your procedures and your representation at assessment all sit with your quality lead. What we do is make the IT questions answerable.
Test data protected to clinical standard
Patient test data is special-category personal data under UK GDPR and the Data Protection Act 2018 — a higher duty of care than ordinary business information, and it flows further than people expect: requesting clinicians, courier manifests, reporting portals, and the archive.
Where you hold NHS contracts or touch NHS systems, the Data Security and Protection Toolkit applies and is submitted annually. Where you do not, it is not legally required, and we will say so before you spend anything on it. UK GDPR applies either way, so the underlying controls are the same: access on a need-to-know basis, multi-factor authentication throughout, encryption at rest and in transit, and audit trails that record who accessed which record.
Cyber Essentials is voluntary, but increasingly written into NHS and pharmaceutical supply-chain contracts. If your commercial pipeline includes either, it is worth having before it is asked for.
Size storage to survive digital pathology
Whole-slide imaging changes the shape of a laboratory’s storage problem. A single slide can run to several gigabytes, the archive only ever grows, and retention obligations mean very little of it can be deleted.
We design for that explicitly — tiered storage so live cases stay fast while the archive stays affordable, backup windows that actually complete, and restore testing so retrieving a historic slide or report is routine. A backup you have never restored is a hope, not a plan; in a laboratory it is also a compliance gap.
Getting a 3am freezer alarm to a human
Laboratories do not stop at five. Support hours are scoped against your real operating pattern — overnight runs, weekend cover, and the specific alerts that must reach a human immediately.
Cold-chain and freezer monitoring belongs in that category. A -80 failure discovered in the morning is an archive lost. Those alarms are treated as incidents with a defined escalation path, not as another line in a monitoring dashboard nobody reads.
Exactly where our scope ends
We are direct about scope, because in a regulated laboratory a vague division of responsibility is itself a risk. We handle infrastructure, networking, segmentation, storage, backup, security and support. Your analyser and LIMS vendors own their applications and validations. Your quality lead owns the QMS. We set those boundaries out at the start and coordinate across them, so nothing falls into the gap between suppliers.
If you would like to talk through your instrument estate, your interfaces, or how your IT evidence would stand up at your next assessment, we are glad to discuss it in confidence.
Also relevant: healthcare IT support for the wider clinical picture, and IT support in London for pricing and response times.
When another approach fits better
If any of these describe you, we are glad to point you somewhere better suited.
- You need us to configure, validate or modify analyser software itself — that is your vendor's responsibility and we will not touch it.
- You want a provider who will patch the instrument estate on a standard schedule. We segment it instead, deliberately.
- You are looking for someone to write or validate your quality management system. We supply the technical evidence; the QMS is yours.
- Your laboratory sits outside the UK regulatory perimeter — our compliance work is built around UKAS, the DSPT and UK GDPR.
