IT and cybersecurity for Clinical & Diagnostic Labs

You are held to CLIA + CAP inspection; HIPAA + signed BAA – and, like most firms your size, you are expected to meet it without anyone in-house whose job it is to own it. We run the IT and the security program so the obligation is actually covered, not just acknowledged.

Where we usually start: PHI breach + silently failing HL7 interfaces.

If this sounds familiar

“A breach here isn’t an outage – it’s patient data, mandatory notification, and possibly the end of the practice.”

Results are PHI. A lab of 60 people carries HIPAA exposure that dwarfs its balance sheet, and the owner knows it.

“If an interface stops, results stop reaching physicians and nobody may notice for hours.”

HL7/FHIR feeds to referring EHRs fail silently. Unmonitored interfaces are the single most common cause of a clinical incident that traces back to IT.

“One person understands our LIS and its interfaces. If they leave, I’m in serious trouble.”

The LIS Analyst is an undocumented single point of failure, and the owner has usually already lost sleep over it.

Who this is for

Typical size: 20–250 (sweet spot 30–120), revenue $5M–$60M. If that is roughly you, the rest of this page will land.

What working with us looks like

A named team that knows your stack, monitoring and patching that happens whether or not anyone chases it, and a written security program kept current – with the evidence to back it up when a client, an auditor or an insurer asks. We report to the Medical Director / Managing Partner (+ Lab Manager, Compliance Officer), not to a ticket queue.

Talk to us

Call 206-850-1496 or email mhasse@itwerx.net and we will set up a short call – no audit, no pitch deck, just a conversation about what you have and what is worrying you.