916.542.1368 info@webpathlab.com

WebPathLab is HIPAA Compliant

In the event of a catastrophic disaster, be it flood, fire, hurricane, or earthquake, your data will not only remain safe, but accessible from any internet capable device so you can continue working as soon as possible. Additionally the system has strict security measures to prevent access from un-authorized users, hackers, and ransomware attacks. 

How Secured is WebPathLab?

WebPathLab Security and Compliance Overview

WebPathLab is designed as a secure, cloud-based Laboratory Information System (LIS) that prioritizes the protection of electronic protected health information (ePHI) in compliance with HIPAA Security Rule requirements, including technical safeguards for access control, audit controls, encryption, and transmission security.

Access Control and Authentication
Written procedures and defined access privileges ensure that authenticated users are restricted to only those functions and data necessary to fulfill their job responsibilities, adhering to the principle of least privilege.

The system provides comprehensive instructions—via detailed written documentation and interactive demos—for Laboratory Managers to securely assign, modify, or revoke user access, as well as to monitor and track user activity.

Role-based access control (RBAC) supports multiple privilege levels based on user roles and responsibilities. Permissions are granular, extending to individual pages, modules, and actions within the LIS, preventing unauthorized access or modification of ePHI.

Data Protection and Encryption
All data is encrypted in transit using industry-standard protocols (including 128-bit or higher encryption compatible with HIPAA expectations).

Data is hosted in a HIPAA-compliant data center on Amazon Web Services (AWS), a leading provider with over 100 HIPAA-eligible services and robust security certifications. A valid digital certificate (SSL/TLS) is verifiable at any time by clicking the padlock icon in the browser URL.

Daily automated backups ensure data availability and support disaster recovery, with all backups maintained under the same stringent security controls.

Audit Trails and Monitoring
WebPathLab maintains comprehensive audit trails that log every keystroke and database interaction, including:

  • The specific page and field affected,
  • The username of the performing user,
  • A precise timestamp.

This granular logging applies to every case and supports HIPAA-required audit controls for recording and examining system activity involving ePHI, enabling proactive monitoring, incident detection, and regulatory reporting.

Physical and Network Security
As a fully cloud-hosted solution, the LIS does not reside on laboratory premises, eliminating on-site physical security risks. All servers are managed within AWS’s secure, multi-layered infrastructure featuring:

  • Dual firewalls and advanced network protections to defend against unauthorized access, hackers, and ransomware.
  • Strict authentication requirements for all access attempts.
  • Automatic account lockout after five consecutive failed login attempts to mitigate brute-force attacks.

These features collectively safeguard system integrity, confidentiality, and availability while aligning with HIPAA technical safeguards and best practices for anatomic pathology laboratories.

What is HIPAA?

HIPAA is part of the TITLE 45 of the Code of Federal Regulations (45 CFR) sections 160, 162 and 164, as published by the US Department of Health and Human Services.

To view an electronic copy of the Code of Federal Regulations, Title 45 – Public Welfare; sections 160, 162 and 164, click here. This website is provided by the National Archives and Records Administration.

Key sections are:

164.306 Security Standards, General Rules
164.308 Administrative Safeguards

Issues of special interest to the US Dept. of Human Health and Services are recovery of data under a disaster recovery plan, protection of data from theft or unauthorized use, and security policies and procedures.

This publication is HIPAA 101 for Health Care Providers, and it was published by the US Dept of Health and Human Services.

For further helpful resources, visit hhs.gov or  cap.org.

Phone: 916.542.1368

FAX: 866.875.3915

Email: info@webpathlab.com

101 Parkshore Dr. Folsom, CA 95630

MODULAR SOLUTIONS

  • Anatomic Pathology
  • GYN Cytology
  • HL7 Engine
  • Management Reports
  • Auto Image Uploader
  • Remote Print
  • GU Auto Organ Map
  • Specimen Tracking
  • TC/PC
  • Molecular

Contact Us

Address

101 Parkshore Dr
Folsom, CA 95630

Phone: 916.542.1368

Fax: 866.875.3915

Email: info@webpathlab.com

WebPathLab Inc. • HIPAA Compliant • All Rights Reserved