Sector dossier

Run your pathology lab on IT that leaves the analysers alone

Your instrument PCs cannot be patched, your LIMS interfaces fail silently, and your turnaround time is a clinical commitment. We build around all three.

Cyber Essentials aligned · UKAS ISO 15189 & DSPT aware · we do not touch validated instruments

Sector
Private pathology & diagnostic laboratories
Applies to
London & Greater London
Last reviewed

Sector evidence

Standards and requirements to consider

Standards and requirements

  • UKAS accreditation to ISO 15189
  • UK GDPR & DPA 2018 (special category)
  • NHS DSPT (where NHS data or contracts apply)
  • HTA licensing (where relevant material is stored)
  • Cyber Essentials / Plus (voluntary or contractual)

Systems we support

  • LIMS / LIS platforms such as Clinisys or Sunquest
  • Analyser interfaces over HL7 v2 and ASTM
  • Interface middleware and result routing
  • Digital pathology and whole-slide imaging
  • Cold-chain and freezer alarm monitoring

What firms bring to us

  • Analyser-attached PCs running vendor-locked, out-of-support Windows that cannot be patched or re-imaged without invalidating the method
  • A LIMS interface dropping quietly — results stop routing and nobody notices until a clinician chases
  • Turnaround time commitments that make an hour of downtime a clinical problem, not an inconvenience
  • Evidencing IT controls at UKAS assessment — access records, audit trails, change control and document control
  • Whole-slide imaging files measured in gigabytes per slide, on a network built for spreadsheets
  • Handling patient identifiable data as special-category data under UK GDPR, across requesting clinicians, couriers and reporting

ISO 15189

The standard UKAS accredits medical laboratories against

Special category

Status of patient test data under UK GDPR

24/7

Operating pattern most diagnostic labs run to

What makes a laboratory different

A pathology lab is easy to mistake for a normal business that happens to own expensive equipment. That assumption is where the trouble starts.

In an ordinary office, the right answer to an out-of-date PC is to patch it. In a laboratory, the PC bolted to the side of an analyser is part of a validated method. Updating it can invalidate that validation and, in some cases, void vendor support. A well-meaning engineer running Windows Update across the estate is not a maintenance task here — it is an incident.

The same inversion runs through everything. Turnaround time is a clinical commitment, so downtime has a patient at the end of it. Results move over interfaces that fail without symptoms. Storage is dominated by imaging that grows relentlessly and can never be deleted. And the whole thing is assessed against ISO 15189 by an assessor who will ask who had access, what changed, and how you know.

We provide managed IT support for private pathology and diagnostic laboratories. We start from how a lab actually runs, and from a clear view of what belongs to your instrument vendors.

Segment your instrument estate instead of patching it

This is the problem we are called about most, and the one where generic advice does the most damage.

A large share of analyser-attached PCs run an operating system that is out of support and locked by the vendor. You cannot patch them without risking revalidation. You cannot easily replace them. And they sit on the same flat network as email and the internet.

The answer is not to patch. It is to stop the unpatchable machine being reachable:

  • The instrument estate goes on its own network segment
  • Routing is explicit — instruments talk to the LIMS and the middleware, and to nothing else
  • No general internet access, no browsing, no email on instrument PCs
  • Monitoring on what is actually communicating, so anything unexpected is visible

None of this requires the vendor’s permission, because none of it changes the validated machine. It is the highest-value change most laboratories can make, and it is routinely missing.

Laboratory interfaces fail quietly

An analyser can run perfectly while its interface to the LIMS is dead. Samples process, results generate, and nothing arrives. The failure surfaces when a clinician chases a result that was never routed, by which point you are reconstructing hours of work.

We monitor the interfaces and the middleware carrying them — HL7 and ASTM connections, result routing, queue depth — so a dropped connection produces an alert within minutes. Where the fault is the analyser’s or the LIMS vendor’s, we take that up with them directly. You should not be the message-passing layer between two of your own suppliers.

Answer your assessor from records, not recollection

UKAS accreditation to ISO 15189 covers competence and quality across the laboratory, and parts of it land squarely on IT: control of access, control of records, control of change, and the integrity of the data behind a report.

We maintain the technical half of that evidence — access records and reviews, audit trails, change history and approvals, documented configuration, and backups that have been restore-tested rather than assumed. When an assessor asks who could see what and when it changed, the answer comes from a record.

To be precise about the boundary: your quality management system, your procedures and your representation at assessment all sit with your quality lead. What we do is make the IT questions answerable.

Test data protected to clinical standard

Patient test data is special-category personal data under UK GDPR and the Data Protection Act 2018 — a higher duty of care than ordinary business information, and it flows further than people expect: requesting clinicians, courier manifests, reporting portals, and the archive.

Where you hold NHS contracts or touch NHS systems, the Data Security and Protection Toolkit applies and is submitted annually. Where you do not, it is not legally required, and we will say so before you spend anything on it. UK GDPR applies either way, so the underlying controls are the same: access on a need-to-know basis, multi-factor authentication throughout, encryption at rest and in transit, and audit trails that record who accessed which record.

Cyber Essentials is voluntary, but increasingly written into NHS and pharmaceutical supply-chain contracts. If your commercial pipeline includes either, it is worth having before it is asked for.

Size storage to survive digital pathology

Whole-slide imaging changes the shape of a laboratory’s storage problem. A single slide can run to several gigabytes, the archive only ever grows, and retention obligations mean very little of it can be deleted.

We design for that explicitly — tiered storage so live cases stay fast while the archive stays affordable, backup windows that actually complete, and restore testing so retrieving a historic slide or report is routine. A backup you have never restored is a hope, not a plan; in a laboratory it is also a compliance gap.

Getting a 3am freezer alarm to a human

Laboratories do not stop at five. Support hours are scoped against your real operating pattern — overnight runs, weekend cover, and the specific alerts that must reach a human immediately.

Cold-chain and freezer monitoring belongs in that category. A -80 failure discovered in the morning is an archive lost. Those alarms are treated as incidents with a defined escalation path, not as another line in a monitoring dashboard nobody reads.

Exactly where our scope ends

We are direct about scope, because in a regulated laboratory a vague division of responsibility is itself a risk. We handle infrastructure, networking, segmentation, storage, backup, security and support. Your analyser and LIMS vendors own their applications and validations. Your quality lead owns the QMS. We set those boundaries out at the start and coordinate across them, so nothing falls into the gap between suppliers.

If you would like to talk through your instrument estate, your interfaces, or how your IT evidence would stand up at your next assessment, we are glad to discuss it in confidence.

Also relevant: healthcare IT support for the wider clinical picture, and IT support in London for pricing and response times.

When another approach fits better

If any of these describe you, we are glad to point you somewhere better suited.

  • You need us to configure, validate or modify analyser software itself — that is your vendor's responsibility and we will not touch it.
  • You want a provider who will patch the instrument estate on a standard schedule. We segment it instead, deliberately.
  • You are looking for someone to write or validate your quality management system. We supply the technical evidence; the QMS is yours.
  • Your laboratory sits outside the UK regulatory perimeter — our compliance work is built around UKAS, the DSPT and UK GDPR.
Last reviewed , and maintained by the Nerdster engineering team.

What you get from us

Segment the instrument estate instead of patching it

Analyser PCs are frequently locked to an old, unsupported Windows build by the vendor's validation. Patching them is not an option, so we remove the exposure a different way — putting the instrument estate on its own segmented network with tightly controlled routing, so an unpatchable PC is not also an internet-reachable one. It is the single biggest gap we find when we take on a laboratory.

Hear about a dropped LIMS interface before a clinician does

Analyser-to-LIMS interfaces fail quietly. The analyser keeps running, results stop arriving, and the first symptom is a phone call. We monitor the interfaces and the middleware that carries them, so a dropped connection raises an alert rather than a complaint — and we work alongside your LIMS and analyser vendors rather than between you and them.

Answer the UKAS IT questions from records

ISO 15189 expects control over access, records and change. We maintain the technical side of that evidence — who has access to what, when it changed, who approved it, and that backups have actually been restored — so the IT questions at assessment are answered from records rather than recollection.

Size storage for whole-slide imaging, not spreadsheets

Digital pathology changes the arithmetic: a single whole-slide image can run to several gigabytes, and the archive only grows. We design storage and backup around that reality, with restore testing, so retrieval of an historic slide or report is a routine operation rather than a project.

FAQ

Frequently asked questions

Our analysers run on old Windows versions the vendor will not let us update. What can you actually do?

This is the defining IT problem in a laboratory, and the answer is that you usually cannot fix it by patching. The instrument PC is part of a validated method; changing its operating system can require revalidation, and the vendor may withdraw support. So we do not patch it. We reduce the risk around it instead: the instrument estate goes on its own network segment with strictly controlled routing, no general internet access, no email, and monitoring on what talks to what. The unpatchable machine stays unpatched, but it stops being reachable from the places attacks actually come from. That is a far safer outcome than an update that puts your validation at risk, and it is work we can do without waiting on your instrument vendor.

Do you work on our LIMS?

We support the infrastructure your LIMS depends on — servers or cloud tenancy, networking, storage, backup, secure access and the interfaces that carry results — and we work alongside your LIMS vendor. We do not modify the application, its configuration or its validated workflows. Where an issue sits with the vendor we co-ordinate with them rather than leaving you to relay messages between two suppliers.

Will you help us through a UKAS assessment?

We supply the technical evidence, which is a defined and useful part of it. Access control records, audit trails, change history, backup and tested restores, and the documented configuration of the systems holding patient data are all things an assessor may ask about, and all things we can produce from records. What we do not do is write or own your quality management system, or represent you at assessment — that sits with your quality lead. Setting that boundary out at the start means everyone knows who is producing what when the assessment comes round.

Is the DSPT mandatory for a private laboratory?

It depends on your NHS exposure rather than your ownership. The Data Security and Protection Toolkit is required for organisations that access NHS patient data or systems, which in practice means labs holding NHS contracts or connected to NHS infrastructure. A wholly private laboratory with neither is not legally required to submit it. Every laboratory remains fully subject to UK GDPR and the Data Protection Act 2018 regardless, so we apply the same security baseline either way and set out clearly where your laboratory stands on the DSPT question.

What happens if the network fails mid-run?

That is the scenario we design against, because a lost run is repeat testing, wasted reagent and a delayed result rather than an inconvenience. Instrument networking is built with redundancy where it matters, analysers are not dependent on an internet connection to keep operating, and result routing buffers rather than discards when the LIMS is briefly unreachable. Where a genuine single point of failure exists and cannot be removed economically, we will show you where it is and what removing it would take, so it stays a decision you have made rather than something you find out during an incident.

Can you cover out-of-hours? Our lab does not stop at 5pm.

Yes, and it is worth agreeing the specifics rather than assuming. We scope support hours against your actual operating pattern — including overnight runs and weekend cover — and around the alarms that genuinely cannot wait, such as freezer and cold-chain monitoring. A -80 failure at 3am that nobody is told about is a sample archive lost, so those alerts are treated as incidents in their own right, not as monitoring noise.

Tell us what would make IT easier

Share what is causing problems or taking up time. Our London team replies during business hours.

We respond within 2 hours during business days. Your data is handled per our privacy policy.

Contact details

0330 043 7414

Mon-Fri 8am-6pm

[email protected]

We reply within 2 hours

71-75 Shelton Street

Covent Garden, London WC2H 9JQ

IT assessment

A review of your IT, your security posture and your compliance readiness, free of charge.

  • 30-minute consultation call
  • Infrastructure & security review
  • Compliance gap analysis
  • Custom recommendations report