Solia Direct

Security & data integrity

Healthcare infrastructure requires more than good design.

Solia Direct separates consumer experiences from laboratory systems while applying access, encryption, provenance and environment-specific controls to patient data, orders and results.

Platform architecture

Platform control model

  • TransportTLS in transitPlatform control
  • StorageEncryption at restPlatform control
  • AccessRole-scoped accessPlatform control
  • TenancyLaboratory isolationProduction-configured
  • EventsAudit loggingProduction-configured
  • ResultsResult provenancePlatform control

How to read this page

Platform control
Implemented in the underlying platform and applied to every environment.
Production-configured
Configured and enforced for each production laboratory environment.
Environment / Program-specific
Dependent on laboratory requirements, Program, integrations, hosting, retention policy or contract.

Regulatory & compliance scope

Exactly where HIPAA, CLIA, CAP and SOC 2 apply.

Solia Direct is designed to support HIPAA-regulated laboratory workflows through deployment-specific safeguards and review. CLIA certification and CAP accreditation always remain with the laboratory — the distinctions below define what must be validated before Production and what stays with you.

HIPAA

Designed to support HIPAA-regulated workflows.

Production use of PHI requires deployment-specific safeguards, vendor and subprocessor review, data-flow review, and completion of applicable contractual requirements before activation. Solia Direct does not claim HIPAA certification or universal compliance independent of that deployment review.

Business Associate Agreements

Conditional prerequisite where required.

Where a Business Associate Agreement is required, an executed agreement and validated production configuration are prerequisites before PHI is used in Production. Applicability and contractual requirements are determined for each deployment.

CLIA

Designed to support CLIA-certified laboratories.

CLIA certification is held by the laboratory, not by Solia Direct. The platform is designed to support CLIA-certified laboratory operations through validated interfaces, result integrity controls and auditable data handling, while the laboratory retains responsibility for its certification and clinical validation.

CAP

Designed to support CAP-accredited laboratories.

CAP accreditation likewise remains with the laboratory. Solia Direct supports accreditation workflows with traceable result provenance, version history for corrected or amended results, and controlled change management across integrations.

SOC 2

Not currently attested.

Solia Direct does not claim SOC 2, HITRUST or other independent attestations that have not been completed. Current control posture is described on this page and can be reviewed with your security team during diligence.

Subprocessors & infrastructure

Reviewed during diligence.

Infrastructure providers and subprocessors relevant to a production deployment — including hosting, storage and communication services — are documented and can be reviewed during security and implementation diligence. Subprocessor scope is agreed per deployment.

Controls

The controls behind every laboratory deployment.

Each control below states whether it is a platform control, configured for each Production environment, or dependent on the connected environment and Program.

Platform architecture
Data

Encryption

Data is protected in transit using TLS and encrypted at rest within configured platform storage. Transport and storage protection apply to patient, order and result records handled by the platform.

Status: Platform control

Access

Role-scoped access

Authentication, session handling and row-level authorization scope what laboratory, administrative and operational roles can read or change.

Status: Platform control

Isolation

Laboratory isolation

Records are scoped to a laboratory identifier throughout the data model. Production environments are configured with laboratory-scoped data boundaries and access rules for that laboratory's patients, orders and results.

Status: Production-configured

Governance

Auditability

Security-relevant administrative, access and system events can be logged and retained according to the requirements agreed for each production deployment.

Status: Production-configured

Clinical

Result provenance

The laboratory remains the authoritative source. Solia Direct receives, structures and presents results, preserves source metadata, maintains version history and distinguishes corrected or amended versions rather than redefining the underlying clinical result.

Status: Platform control

Integrations

Controlled integrations

Laboratory APIs, LIS / LIMS interfaces, HL7 / FHIR feeds and third-party services are explicitly configured per environment and Program with credentials scoped to the narrowest required permissions.

Status: Environment / Program-specific

Production security review

What happens before a laboratory goes live.

Every Production environment is reviewed against the data flows, integrations and obligations that apply to that laboratory.

  1. 01

    Data flows

    Identify patient data, PHI where applicable, order data, laboratory results, operational data and every external system connection in scope.

  2. 02

    Access & isolation

    Configure laboratory boundaries, roles, permissions, authentication and environment access for the deployment.

  3. 03

    Integrations

    Scope LIS / LIMS interfaces, laboratory APIs, HL7 / FHIR exchanges and third-party services, including credentials and required permissions.

  4. 04

    Operational controls

    Configure the applicable auditability, monitoring and retention requirements documented for the deployment.

  5. 05

    Launch review

    Validate the production configuration against the agreed requirements before go-live.

Additional production controls

Topics covered during security diligence.

Authentication & session management
Authenticated access and managed sessions for administrative and operational users, with consumer authentication included only where the supported deployment enables it.
Environment separation
Non-production and production environments are kept separate, with synthetic data used for demonstration environments.
Data retention & deletion
Retention and deletion behavior is agreed per deployment against laboratory policy and applicable obligations.
Access review
Administrative and integration access is reviewed as part of deployment readiness and ongoing configuration changes.
Monitoring, backup & recovery
Monitoring, backup and recovery arrangements are agreed and configured for the production deployment as applicable. No recovery objectives or guarantees are claimed here.
Subprocessor & infrastructure review
Infrastructure and subprocessors relevant to a production deployment can be reviewed during security and implementation diligence.

Principles

Principles for handling laboratory data.

01

The laboratory owns the clinical record.

Solia Direct is a consumer layer on top of your systems. Reports, reference ranges and clinical interpretation stay with the laboratory.

02

Least privilege by design.

Access for services, integrations and operational roles is scoped to the permissions required for their function.

03

No claims we cannot support.

We describe only controls that are implemented today or documented as production deployment requirements — never attestations that have not been independently completed.

Production environments undergo an environment- and Program-specific security and compliance review based on applicable data flows, integrations, hosting, access requirements and contractual obligations. Before PHI is used in Production, applicable HIPAA safeguards and Business Associate requirements must be validated and any required agreement executed.

Solia Direct does not claim SOC 2, HITRUST or other independent attestations that have not been completed. Infrastructure and subprocessors relevant to a production deployment can be reviewed during security and implementation diligence.

Review Solia Direct with your security team.

We can walk through the platform control architecture, integration model, data boundaries and production deployment requirements.