Data Security
Last updated: 4 October 2026
MyLabScope is operated by Digital Health Innovations Ltd (“DHI,” “MyLabScope,” “we,” “us,” or “our”).
Protecting laboratory, patient, healthcare-provider, and business information is an important part of how we design and operate the MyLabScope platform. We use technical, administrative, and organisational safeguards intended to protect information against unauthorised access, disclosure, alteration, loss, or misuse.
This Data Security statement should be read together with our Privacy Policy and Terms of Use.
1. Our Security Approach
MyLabScope processes sensitive healthcare and laboratory information, and we apply security controls that we consider appropriate to that information. These controls are designed to cover access control, the protection of information while it is transmitted and stored, platform availability, monitoring, backups, and limiting access to authorised users.
2. Access Controls
Access to information on MyLabScope is restricted according to account type, role, and the permissions assigned to each user. Users are intended to see only the information their role requires.
Laboratories, hospitals, and other organisations using MyLabScope are responsible for giving access only to their authorised staff and for assigning roles and permissions appropriately.
3. Authentication and Account Protection
Each user is responsible for protecting their own login credentials. This includes using a strong password that is not used elsewhere, keeping passwords private, protecting the devices used to access MyLabScope, signing out of shared or public devices, and reporting any suspected unauthorised access to their account as soon as possible.
4. Protection of Data in Transit
MyLabScope uses encrypted web connections, including HTTPS/TLS, to protect information transmitted between supported user devices and the MyLabScope platform.
5. Cloud Infrastructure and Data Storage
MyLabScope operates using cloud-based infrastructure provided by third-party service providers. Access to production infrastructure and to stored information is restricted to authorised personnel and to service providers who require it for legitimate purposes connected with providing, maintaining, and supporting the platform.
6. Laboratory and Patient Information
In providing the service, MyLabScope may process information such as:
- patient identification and contact information
- laboratory test orders
- test results and reports
- appointment information
- laboratory and provider information
- payment and transaction records
- system and audit information
- communications required to provide the service
This information is not intended for public disclosure. It is made available only to the users, organisations, and recipients authorised to receive it.
7. Data Controller and Data Processor Responsibilities
Laboratories, hospitals, and other organisations that use MyLabScope to manage their patients’ information may act as data controllers for that information. When MyLabScope processes information on their behalf, MyLabScope may act as a data processor.
Organisations remain responsible for obtaining any consent required from their patients and for ensuring that patient information is collected and used lawfully.
8. Result Access and Delivery
MyLabScope supports the authorised creation, management, approval, and delivery of laboratory results. Supported delivery channels may include:
- the MyLabScope platform and mobile app
- PDF reports
- SMS
- approved messaging services
- other supported communication methods
Laboratories and users are responsible for confirming that a patient’s contact information is correct before sending results or other sensitive information.
9. Third-Party Service Providers
MyLabScope may use third-party service providers to help operate the platform, including providers of:
- cloud infrastructure
- payment processing
- SMS and messaging
- monitoring
- communications
- other technology services
These providers are intended to receive only the information they need to perform their services for MyLabScope.
10. Payment Information
Payments on MyLabScope may be processed by authorised third-party payment providers. Where a payment provider directly processes card or banking information, MyLabScope does not need to store complete card details.
11. Monitoring and System Security
MyLabScope may use technical and operational monitoring to help detect suspicious activity, investigate suspected unauthorised access, troubleshoot failures, detect misuse of the platform, and maintain platform performance.
12. Software and Infrastructure Maintenance
Applications, infrastructure, libraries, dependencies, and security controls may be updated from time to time to address defects, vulnerabilities, reliability, and security.
13. Backups and Recovery
MyLabScope uses operational backup and recovery processes intended to support continuity of the service and to reduce the risk of permanent data loss.
No information system can guarantee that loss or disruption will never occur.
14. Service Availability
MyLabScope makes commercially reasonable efforts to keep the platform available. Availability commitments, where they apply, are governed by our Terms of Use.
15. Employee and Administrative Access
Access by MyLabScope staff to sensitive information is limited to authorised personnel with a legitimate business reason, such as customer support, administration, troubleshooting, security, and compliance.
16. Data Retention and Deletion
How long information is kept is governed by our Privacy Policy, applicable legal obligations, operational requirements, and legitimate business needs.
17. Security Incident Response
Suspected security incidents may be investigated, contained, mitigated, and documented. Where applicable law requires it, incidents will be reported to the appropriate authorities and to affected parties.
18. User and Laboratory Responsibilities
Security is shared between MyLabScope and the people and organisations who use it. Users and laboratories should:
- protect their passwords
- not share accounts
- remove access for former staff promptly
- review staff roles and permissions regularly
- use trusted devices and networks
- verify recipient information before sending results
- protect downloaded or printed reports
- report suspicious activity promptly
19. Data Protection
MyLabScope handles personal information in accordance with our Privacy Policy and applicable Nigerian data-protection requirements, including the Nigeria Data Protection Act 2023 where applicable.
20. Reporting a Security or Privacy Concern
If you believe your account or information has been accessed without authorisation, or you have a security or privacy concern, please contact us:
- Security, Privacy and Compliance: compliance@mylabscope.com
- General Support: support@mylabscope.com
21. Changes to This Data Security Statement
We may update this Data Security statement as our services, technology, legal obligations, and security practices evolve. The “Last updated” date at the top of this page shows when it was last changed.