Enterprise Healthcare Pledge: MyPathoLabs NEVER SELLS, RENTS, OR MONETIZES your personal data or Protected Health Information (PHI). Patient health data processed through our Platform is exclusively used to fulfill diagnostic workflows authorized by your diagnostic laboratory or healthcare provider.
At MyPathoLabs Technologies Inc. ("MyPathoLabs", "We", "Us", or "Our"), we maintain an unyielding commitment to the confidentiality, integrity, and privacy of all Protected Health Information (PHI), Sensitive Personal Data or Information (SPDI), and administrative user data processed across our multi-tenant diagnostic Laboratory Information System (LIS) (the "Platform").
1. Scope & International Compliance Frameworks
This Privacy Policy applies globally to all users, diagnostic laboratories, clinic administrators, medical staff, and patients accessing the Platform. Our data governance controls strictly align with worldwide legal standards:
- United States: Health Insurance Portability and Accountability Act (HIPAA), HITECH Act, California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA).
- European Union & United Kingdom: General Data Protection Regulation (EU GDPR 2016/679) and UK Data Protection Act 2018.
- India: Digital Personal Data Protection (DPDP) Act 2023, Information Technology Act 2000, and National Digital Health Mission (NDHM) sandbox guidelines.
- Global Standards: PIPEDA (Canada), LGPD (Brazil), and Privacy Act 1988 (Australia).
2. Categories of Information We Process
We process information under two distinct operational roles: as a Data Processor / Business Associate (on behalf of subscribing diagnostic laboratories) and as a Data Controller / Data Fiduciary (for laboratory administrator accounts and billing).
2.1 Protected Health Information (PHI) & Sensitive Patient Data
Processed strictly on behalf of and instructed by the subscribing laboratory (Data Controller):
- Patient Identification: Full Name, Date of Birth, Age, Gender, Unique Patient Identifier (PID), Government ID (where legally required/consented), Contact Number, Email Address.
- Clinical & Diagnostic Data: Doctor referrals, specimen IDs, test orders, diagnostic measurements, LOINC codes, reference ranges, pathologist digital signatures, and historical diagnostic reports.
2.2 Subscriber Account & Administrative Data
- Account Credentials: Laboratory name, license numbers, administrator name, business email, encrypted password hashes (Bcrypt with salt rounds ≥ 12), role designations, and billing details.
2.3 Telemetry, Security & Audit Logs
- System Telemetry: IP addresses, browser types, session tokens, audit logs of record modifications, system error logs, and Datadog performance metrics. All application logs automatically redact PII and PHI parameters.
3. Legal Basis for Processing (GDPR & DPDP Act 2023)
Under GDPR (Art. 6 & Art. 9) and the India DPDP Act 2023 (Sec. 6), we process data under the following valid legal bases:
- Performance of Contract: To operate the LIS platform and deliver diagnostic workflows requested by the subscribing laboratory.
- Compliance with Legal Obligations: Retaining medical records in adherence to statutory healthcare retention mandates and medical council guidelines.
- Explicit Consent: Where required by law, diagnostic laboratories obtain explicit informed consent from patients prior to submitting sample details to the Platform.
- Legitimate Interests: Maintaining platform cybersecurity, preventing fraudulent access, and monitoring system operational health.
4. Data Security Architecture & Technical Safeguards
MyPathoLabs implements enterprise-grade security infrastructure aligned with industry benchmarks (ISO 27001 / SOC 2 Type II control frameworks):
- Data Encryption in Transit: All data transmitted between user browsers, mobile interfaces, and Platform APIs is encrypted using TLS 1.3 / SSL with strong cipher suites.
- Data Encryption at Rest: Database tables, document stores, and backup archives are encrypted utilizing AES-256 bit hardware-level encryption.
- Role-Based Access Control (RBAC): Strict zero-trust permission models ensure laboratory staff only access data appropriate to their operational role.
- Audit Logging & Anonymization: Automated immutable audit logging records every read/write action on PHI. Telemetry integration via Datadog enforces client-side masking of sensitive query parameters.
5. HIPAA Business Associate Agreement (BAA) & Data Protection Addendum (DPA)
For US Covered Entities, MyPathoLabs executes standard Business Associate Agreements (BAAs) guaranteeing compliance with 45 CFR § 164.502(e) and § 164.504(e). For EU/UK/Indian entities, our standardized Data Processing Addendum (DPA) includes standard contractual clauses ensuring cross-border transfer protections.
6. Sub-processors & Third-Party Disclosures
We do not sell personal data. We disclose data only to vetted sub-processors bound by stringent contractual security obligations:
| Sub-processor |
Purpose |
Data Location |
Compliance |
| AWS / Google Cloud Platform |
Encrypted Cloud Hosting & Database Storage |
US / EU / India Regions |
HIPAA, SOC 2, ISO 27001 |
| Datadog Inc. |
Real-time Performance & Error Monitoring |
US / EU (Masked PII) |
HIPAA BAA Executed, SOC 2 |
| SendGrid / SMTP Providers |
Transactional Diagnostic Report Emails |
Global Edge Routing |
TLS Encryption Enforced |
7. Data Subject Rights & Data Principal Rights
Depending on your jurisdiction, data subjects (patients & users) possess comprehensive privacy rights under GDPR, DPDP Act 2023, and CCPA:
- Right to Access & Confirmation: Request confirmation of processing and obtain copies of stored personal health data.
- Right to Rectification & Correction: Correct incomplete or inaccurate diagnostic profile information.
- Right to Erasure / Right to be Forgotten: Request data deletion, subject to mandatory medical record statutory retention laws (which require preserving diagnostic records for 3 to 8 years depending on state/national medical council laws).
- Right to Data Portability: Export data in structured machine-readable formats (JSON/CSV/PDF).
- Right to Withdraw Consent: Revoke processing consent via the laboratory consent manager at any time.
8. Data Retention & Cryptographic Disposal
Patient health records are retained strictly in accordance with statutory medical retention laws applicable to the subscribing laboratory's jurisdiction. Upon expiration of mandatory retention periods or account termination, data undergoes multi-pass cryptographic erasure conforming to NIST SP 800-88 standards.
9. Cookies & Analytical Tracking
The Platform utilizes essential session cookies required for authentication, security token validation, and CSRF protection. We do NOT use third-party advertising cookies or cross-site behavioral tracking scripts.
10. Data Protection Officer (DPO) & Grievance Redressal Officer
In accordance with GDPR Art. 37 and Section 10 of the India DPDP Act 2023, MyPathoLabs has appointed a designated Data Protection & Grievance Redressal Officer to handle privacy inquiries and Data Subject Access Requests (DSAR):
Designated Data Protection & Grievance Redressal Officer
Name: Pranshu Patel (DPO & Compliance Lead)
Official DPO Email: pranshuvramani@gmail.com
Address: MyPathoLabs Data Governance Cell, Enterprise Tech Park, India / USA
Turnaround SLA for DSAR & Privacy Grievances: Within 15 business days (Maximum 30 days as per statutory requirements)