Sector dossier

IT Support for Pathology and Diagnostic Laboratories

A lab is not an office with microscopes. Your instrument PCs cannot be patched like laptops, your LIMS interfaces fail silently, and your turnaround time is a clinical commitment — we build IT around all three.

Cyber Essentials aligned · UKAS ISO 15189 & DSPT aware · we do not touch validated instruments

Sector
Private pathology & diagnostic laboratories
Applies to
London & Greater London
Last reviewed

Sector evidence

What applies to your firm

Regulation that applies

  • UKAS accreditation to ISO 15189
  • UK GDPR & DPA 2018 (special category)
  • NHS DSPT (where NHS data or contracts apply)
  • HTA licensing (where relevant material is stored)
  • Cyber Essentials / Cyber Essentials Plus

Systems we support

  • LIMS / LIS platforms such as Clinisys or Sunquest
  • Analyser interfaces over HL7 v2 and ASTM
  • Interface middleware and result routing
  • Digital pathology and whole-slide imaging
  • Cold-chain and freezer alarm monitoring

What firms bring to us

  • Analyser-attached PCs running vendor-locked, out-of-support Windows that cannot be patched or re-imaged without invalidating the method
  • A LIMS interface dropping quietly — results stop routing and nobody notices until a clinician chases
  • Turnaround time commitments that make an hour of downtime a clinical problem, not an inconvenience
  • Evidencing IT controls at UKAS assessment — access records, audit trails, change control and document control
  • Whole-slide imaging files measured in gigabytes per slide, on a network built for spreadsheets
  • Handling patient identifiable data as special-category data under UK GDPR, across requesting clinicians, couriers and reporting

ISO 15189

The standard UKAS accredits medical laboratories against

Special category

Status of patient test data under UK GDPR

24/7

Operating pattern most diagnostic labs run to

Why a Laboratory Is Not an Office With Instruments

Most IT providers treat a pathology lab as a normal business that happens to own expensive equipment. That assumption is where the trouble starts.

In an ordinary office, the right answer to an out-of-date PC is to patch it. In a laboratory, the PC bolted to the side of an analyser is part of a validated method. Updating it can invalidate that validation and, in some cases, void vendor support. A well-meaning engineer running Windows Update across the estate is not a maintenance task here — it is an incident.

The same inversion runs through everything. Turnaround time is a clinical commitment, so downtime has a patient at the end of it. Results move over interfaces that fail without symptoms. Storage is dominated by imaging that grows relentlessly and can never be deleted. And the whole thing is assessed against ISO 15189 by an assessor who will ask who had access, what changed, and how you know.

Nerdster provides managed IT support for private pathology and diagnostic laboratories that starts from how a lab actually runs — and, just as importantly, from what we will not touch.

The Instrument Estate: Segment, Don’t Patch

This is the problem we are called about most, and the one where generic advice does the most damage.

A large share of analyser-attached PCs run an operating system that is out of support and locked by the vendor. You cannot patch them without risking revalidation. You cannot easily replace them. And they sit on the same flat network as email and the internet.

The answer is not to patch. It is to stop the unpatchable machine being reachable:

  • The instrument estate goes on its own network segment
  • Routing is explicit — instruments talk to the LIMS and the middleware, and to nothing else
  • No general internet access, no browsing, no email on instrument PCs
  • Monitoring on what is actually communicating, so anything unexpected is visible

None of this requires the vendor’s permission, because none of it changes the validated machine. It is the highest-value change most laboratories can make, and it is routinely missing.

Interfaces Fail Quietly — So Watch Them

An analyser can run perfectly while its interface to the LIMS is dead. Samples process, results generate, and nothing arrives. The failure surfaces when a clinician chases a result that was never routed, by which point you are reconstructing hours of work.

We monitor the interfaces and the middleware carrying them — HL7 and ASTM connections, result routing, queue depth — so a dropped connection produces an alert within minutes. Where the fault is the analyser’s or the LIMS vendor’s, we take that up with them directly. You should not be the message-passing layer between two of your own suppliers.

Evidence, Not Recollection, at Assessment

UKAS accreditation to ISO 15189 covers competence and quality across the laboratory, and parts of it land squarely on IT: control of access, control of records, control of change, and the integrity of the data behind a report.

We maintain the technical half of that evidence — access records and reviews, audit trails, change history and approvals, documented configuration, and backups that have been restore-tested rather than assumed. When an assessor asks who could see what and when it changed, the answer comes from a record.

To be precise about the boundary: we do not write your quality management system, we do not own your procedures, and we do not represent you at assessment. Those are yours. We make the IT questions answerable.

Data Protection Where the Data Is Clinical

Patient test data is special-category personal data under UK GDPR and the Data Protection Act 2018 — a higher duty of care than ordinary business information, and it flows further than people expect: requesting clinicians, courier manifests, reporting portals, and the archive.

Where you hold NHS contracts or touch NHS systems, the Data Security and Protection Toolkit applies and is submitted annually. Where you do not, it is not legally required — and we will say so rather than sell you a submission you do not owe. UK GDPR applies either way, so the underlying controls are the same: access on a need-to-know basis, multi-factor authentication throughout, encryption at rest and in transit, and audit trails that record who accessed which record.

Cyber Essentials is voluntary, but increasingly written into NHS and pharmaceutical supply-chain contracts. If your commercial pipeline includes either, it is worth having before it is asked for.

Storage That Survives Digital Pathology

Whole-slide imaging changes the shape of a laboratory’s storage problem. A single slide can run to several gigabytes, the archive only ever grows, and retention obligations mean very little of it can be deleted.

We design for that explicitly — tiered storage so live cases stay fast while the archive stays affordable, backup windows that actually complete, and restore testing so retrieving a historic slide or report is routine. A backup you have never restored is a hope, not a plan; in a laboratory it is also a compliance gap.

Out of Hours, and the Alarms That Cannot Wait

Laboratories do not stop at five. Support hours are scoped against your real operating pattern — overnight runs, weekend cover, and the specific alerts that must reach a human immediately.

Cold-chain and freezer monitoring belongs in that category. A -80 failure discovered in the morning is an archive lost. Those alarms are treated as incidents with a defined escalation path, not as another line in a monitoring dashboard nobody reads.

Working With Us

We are direct about scope, because in a regulated laboratory a vague division of responsibility is itself a risk. We handle infrastructure, networking, segmentation, storage, backup, security and support. Your analyser and LIMS vendors own their applications and validations. Your quality lead owns the QMS. We make those boundaries explicit at the start and coordinate across them rather than hiding behind them.

If you would like to talk through your instrument estate, your interfaces, or how your IT evidence would stand up at your next assessment, we are glad to discuss it in confidence.

Also relevant: healthcare IT support for the wider clinical picture, and IT support in London for pricing and response times.

Probably not us if

We would rather say so now than discover it three months in.

  • You need us to configure, validate or modify analyser software itself — that is your vendor's responsibility and we will not touch it.
  • You want a provider who will patch the instrument estate on a standard schedule. We segment it instead, deliberately.
  • You are looking for someone to write or validate your quality management system. We supply the technical evidence; the QMS is yours.
  • Your laboratory sits outside the UK regulatory perimeter — our compliance work is built around UKAS, the DSPT and UK GDPR.
Last reviewed , and maintained by the Nerdster engineering team.

How we support a laboratory

Instrument Estate Segmentation

Analyser PCs are frequently locked to an old, unsupported Windows build by the vendor's validation. Patching them is not an option, so we remove the exposure a different way — putting the instrument estate on its own segmented network with tightly controlled routing, so an unpatchable PC is not also an internet-reachable one. This is the single biggest gap we find in labs supported by generalist IT providers.

LIMS and Interface Monitoring

Analyser-to-LIMS interfaces fail quietly. The analyser keeps running, results stop arriving, and the first symptom is a phone call. We monitor the interfaces and the middleware that carries them, so a dropped connection raises an alert rather than a complaint — and we work alongside your LIMS and analyser vendors rather than between you and them.

Evidence for UKAS Assessment

ISO 15189 expects control over access, records and change. We maintain the technical side of that evidence — who has access to what, when it changed, who approved it, and that backups have actually been restored — so the IT questions at assessment are answered from records rather than recollection.

Storage and Backup Sized for Imaging

Digital pathology changes the arithmetic: a single whole-slide image can run to several gigabytes, and the archive only grows. We design storage and backup around that reality, with restore testing, so retrieval of an historic slide or report is a routine operation rather than a project.

FAQ

Frequently asked questions

Our analysers run on old Windows versions the vendor won't let us update. What can you actually do?

This is the defining IT problem in a laboratory and the honest answer is that you usually cannot fix it by patching. The instrument PC is part of a validated method; changing its operating system can require revalidation, and the vendor may withdraw support. So we do not patch it. We reduce the risk around it instead: the instrument estate goes on its own network segment with strictly controlled routing, no general internet access, no email, and monitoring on what talks to what. The unpatchable machine stays unpatched, but it stops being reachable from the places attacks actually come from. We would rather tell you that plainly than promise an update we cannot safely deliver.

Do you work on our LIMS?

We support the infrastructure your LIMS depends on — servers or cloud tenancy, networking, storage, backup, secure access and the interfaces that carry results — and we work alongside your LIMS vendor. We do not modify the application, its configuration or its validated workflows. Where an issue sits with the vendor we co-ordinate with them rather than leaving you to relay messages between two suppliers.

Will you help us through a UKAS assessment?

We supply the technical evidence, which is a defined and useful part of it. Access control records, audit trails, change history, backup and tested restores, and the documented configuration of the systems holding patient data are all things an assessor may ask about, and all things we can produce from records. What we do not do is write or own your quality management system, or represent you at assessment — that sits with your quality lead. Being clear about the boundary tends to make the working relationship better, not worse.

Is the DSPT mandatory for a private laboratory?

It depends on your NHS exposure rather than your ownership. The Data Security and Protection Toolkit is required for organisations that access NHS patient data or systems, which in practice means labs holding NHS contracts or connected to NHS infrastructure. A wholly private laboratory with neither is not legally required to submit it. Every laboratory remains fully subject to UK GDPR and the Data Protection Act 2018 regardless, so we apply the same security baseline either way and tell you honestly which obligations actually bite.

What happens if the network fails mid-run?

That is the scenario we design against, because a lost run is repeat testing, wasted reagent and a delayed result rather than an inconvenience. Instrument networking is built with redundancy where it matters, analysers are not dependent on an internet connection to keep operating, and result routing buffers rather than discards when the LIMS is briefly unreachable. Where a genuine single point of failure exists and cannot be removed economically, we will tell you where it is rather than let you discover it during an incident.

Can you cover out-of-hours? Our lab doesn't stop at 5pm.

Yes, and it is worth agreeing the specifics rather than assuming. We scope support hours against your actual operating pattern — including overnight runs and weekend cover — and around the alarms that genuinely cannot wait, such as freezer and cold-chain monitoring. A -80 failure at 3am that nobody is told about is a sample archive lost, so those alerts are treated as incidents in their own right, not as monitoring noise.

Talk to an engineer, not a call centre

Tell us what you need. A London-based engineer replies within 2 hours during business hours.

We respond within 2 hours during business days. Your data is handled per our privacy policy.

Contact details

0330 043 7414

Mon-Fri 8am-6pm

[email protected]

We reply within 2 hours

71-75 Shelton Street

Covent Garden, London WC2H 9JQ

Free IT Assessment

Get a comprehensive review of your IT infrastructure, security posture, and compliance readiness — completely free, no obligations.

  • 30-minute consultation call
  • Infrastructure & security review
  • Compliance gap analysis
  • Custom recommendations report
Replies the same business day

Ready to fix your IT?

Book a free 30-minute IT assessment. We'll review your setup, identify risks, and show you exactly what better IT looks like.

  • 30-day rolling contracts
  • No callout fees
  • Free assessment