Back

Privacy Policy

Last Updated:

At MyPathoLabs, your privacy and the security of your data are our highest priorities. This Privacy Policy outlines how we collect, use, process, and protect your information, particularly regarding the handling of sensitive health and laboratory data. By using the MyPathoLabs platform, you agree to the practices described in this policy.

1. Information We Collect

We collect information to provide, improve, and secure our Laboratory Information System (LIS). The types of data we collect include:

  • Account Information: Name, email address, password, laboratory details, and billing information when you register for an account.
  • Protected Health Information (PHI): Patient names, ages, genders, contact details, medical histories, test results, and diagnostic reports processed through our platform.
  • Usage Data: Information on how you interact with our platform, including IP addresses, browser types, access times, and activity logs.

2. How We Use Your Information

We use the collected information for the following purposes:

  • To operate, maintain, and provide the features of the MyPathoLabs platform.
  • To facilitate the secure storage, retrieval, and transmission of laboratory reports and patient data.
  • To ensure compliance with global healthcare data protection regulations, including HIPAA and GDPR.
  • To monitor and analyze usage and trends to improve user experience.
  • To communicate with you regarding updates, security alerts, and support matters.

3. Data Security and HIPAA Compliance

We implement enterprise-grade security measures designed to protect your data against unauthorized access, alteration, disclosure, or destruction. Our platform is designed to assist you in meeting compliance requirements such as the Health Insurance Portability and Accountability Act (HIPAA) in the United States and similar worldwide regulations.

  • Encryption: All data is encrypted in transit using TLS/SSL and at rest using industry-standard AES-256 encryption.
  • Access Controls: We employ strict Role-Based Access Control (RBAC) ensuring that only authorized personnel have access to sensitive information.
  • Audit Logs: Comprehensive system logging is maintained to track access and modifications to PHI.

4. Data Sharing and Disclosure

We do not sell, rent, or trade your personal information or PHI. We may share information only in the following limited circumstances:

  • Service Providers: With trusted third-party vendors who assist us in operating our platform (e.g., cloud hosting providers) under strict Business Associate Agreements (BAAs) or data processing agreements.
  • Legal Requirements: If required to do so by law, court order, or to protect the rights, property, or safety of MyPathoLabs, our users, or others.

5. Data Retention

We retain your account information and patient data for as long as your account is active or as needed to provide you services, comply with our legal obligations, resolve disputes, and enforce our agreements. Upon account termination, data can be exported and will subsequently be securely deleted in accordance with our data retention policies.

6. Your Rights

Depending on your location, you may have rights under local laws (such as GDPR or CCPA) to access, correct, delete, or restrict the processing of your personal data. If you wish to exercise these rights, please contact our privacy team.

7. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.

8. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact our Data Protection Officer at pranshuvramani@gmail.com.

© 2026 MyPathoLabs. All rights reserved.