LLabInboxBack to portal

How LabInbox protects results

Simple for patients. Layered underneath.

Medical-result delivery needs more than a login screen. LabInbox uses separate controls for identity, staff access, uploaded files, storage, delivery, and audit evidence.

Patient access

  • A short-lived one-time code is sent only to a number already linked by the center.
  • Requests are rate-limited and designed not to reveal whether a number has a result.
  • Results stay in private storage and are checked again when viewed or downloaded.

Diagnostic-center access

  • Staff accounts are invitation-only and require a second authentication factor.
  • Each role receives only the access it needs, and inactive centers or staff are denied.
  • Uploads require an explicit confirmation that the patient's number was checked.
  • A wrong-number report lets verified staff revoke the result, lock the linked inbox, end its sessions, cancel unsent alerts, and start private-file deletion.

PDF safety

  • New files enter a private quarantine before patients can see them.
  • Files are checked for size, type, structure, encryption, and known malware.
  • The original is preserved, a safer preview is generated, and cryptographic hashes detect later changes.
  • A failed or altered file is withheld rather than delivered.

Privacy and operations

  • Phone numbers are protected separately for matching and recovery.
  • PDF links are private and short-lived; responses cannot be cached by browsers or search engines.
  • Important actions create append-only audit records.
  • Production launch requires incident response, backup recovery, access review, privacy approval, and independent testing.

Report a security concern

Do not send a patient name, mobile number, result, screenshot, or PDF by ordinary email. The production security contact is still pending and must be configured before live use.

No premature security claim

These controls have passed the local automated workflow. They are not a certification. Protected staging, an independent penetration test, and formal owner sign-off remain launch requirements.

LabInbox
PrivacySecurity