LabgnosticEQA
LabgnosticEQA enables healthcare EQA/PT laboratories to submit their EQA programme results securely and electronically to the EQA provider. The requests and results are processed via a single interface to LabgnosticEQA.
Features
- Integrate with any other organisation on the network
- Automation of EQA results delivery to any EQA provider
- Quantitative EQA results
- View the status of shipments with sample tracking
- Cloud-hosted, regularly updated and highly available
- Complex EQA programmes structures
- Test code upload and auto-mapping
Benefits
- EQA workflow that mimics the normal patient testing workflow
- Zero transcription errors
- Time saved in the lab
- In-lab task management - “what needs doing today?”
- EQA work resource planning - “upcoming EQA work”
- Auditing and evidencing of EQA activity
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 7 4 0 3 2 8 1 5 5 2 7 3 9 2
Contact
X - LAB LIMITED
Commercial Department
Telephone: 07787656851
Email: enquiries@x-labsystems.co.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- N/A
- System requirements
- N/A - we cater for the buyers requirements.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Online ticketing support is provided 9:00 and 17:30 Monday to Friday, excluding Bank holidays. Within these hours the tickets are responded to as follows:
1) Urgent severity - Before the start of the next Business Day;
2) High severity - Before the end of the next Business Day;
3) Medium - 2 Business Days;
4) Low - 3 Business Days - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
-
We provide one standard support level for the LabgnosticEQA service. This support model applies to all customers equally and is designed to ensure consistent service quality, transparency, and fair use. Support, maintenance, and general software upgrades are included as part of the contracted service.
Support includes:
- Access to a service desk during Normal Business Hours
- Incident management, service requests, and change requests handled in line with ITIL principles
- Defined incident severity levels with documented target resolution times
- Planned maintenance management
- Access to out-of-hours third-line engineering support triggered via automated monitoring (no customer-initiated service desk outside Normal Business Hours).
Customers are provided with a named Account Manager, who acts as the primary commercial and service liaison. This role supports onboarding coordination, service reviews, and future service expansion planning. Technical support is delivered via the service desk and specialist engineering teams as required - Support available to third parties
- No
Onboarding and offboarding
- Getting started
- X-Lab prides itself on excellent customer service with each of our LabgnosticEQA customers assigned a dedicated Account Manager. The Account Management team is an integral part of the organisation and works closely with the Onboarding and Support team as part of the wider Customer Success function. The Account Managers work closely with the Sales team and are introduced to new LabgnosticEQA customers during the sales process. Prior to customers' onboarding to the LabgnosticEQA service, we ensure a contract is agreed and that all labs joining the network comply with information governance (in the form of a Data Protection Agreement). The Account Manager will work closely with the customer to maintain engagement, agree a utilisation plan, deal with any escalations, communicate service developments, and continually review the customer experience. We provide a welcome pack containing a high-level overview of what to expect during the LabgnosticEQA onboarding process (including supporting documentation, prerequisites, required stakeholders, key milestones, and a bespoke onboarding plan. Training and support are offered online however there is scope for training to be delivered onsite. Testing scripts are provided to the customer to validate testing ahead of sign off and cutover into production.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- Other
- Other documentation formats
-
- Word
- Excel
- End-of-contract data extraction
- We don't explicitly extract/remove data when a contract ends. We have a Retention Policy which is available on request. Data is removed from the production system after 4 months by default and will be removed from the archive after a further 2 years. Customers can reduce their retention period for production to a shorter period (we recommend no less than ~1 month, but this could be shorter if required). Upon request from an exiting customer a final data extract can be provided. This is a complex process as we would need to obtain agreement from all third party organisations that hold data sharing agreements with the off-boarding customer.
- End-of-contract process
- LabgnosticEQA customers usually renew their contract at the end of the subscription term. Should a customer decide to end the contract, the termination terms form part of the contractual documentation. The dedicated Account Manager would work with the customer to ensure any outstanding invoices have been paid and would facilitate an off-boarding plan with the relevant teams. The tasks carried out by the X-Lab team include the deletion of the connection profiles, the decommissioning of the Customer VPN and the removal of web access configuration. The team would be required to wait until the archive period elapses and delete the laboratories. End users would need to be removed from the Service desk and CRM system. Users would also need removing from any service communications. The customers would be expected to liaise with other LabgnosticEQA partners to communicate and manage the process, although the team at X-Lab could assist and advise where necessary.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Onboarding/Offboarding documents are accessible for customers to read in PDF format. If a document is shared requesting information or for collaboration documents are shared as ODF. Documents can also be shared in HTML format. All of our document formats are accessible across all devices including documents containing logos, images, and charts, and can be printed or stored by recipients.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Interactions with LabgnosticEQA are either through a set of user interfaces, or via connections to Laboratory Information Management systems (LIMs). LabgnosticEQA has a number of interfaces for common LIMs systems used by pathology labs that have been developed to LIMS vendor's HL7 interface specifications. There is also a LIMS type-agnostic specification available that connecting customers are able to develop to if a vendor specific module is not available.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The service is accessed via a browser based user interface.
- Accessibility testing
- None.
- API
- Yes
- What users can and can't do using the API
- LabgnosticEQA relies on APIs to function, allowing service users to send requests and get results from any other system on the network. Most systems are integrated via HL7 over MLLP, but support also exists for connecting via S3, or over SFTP, FTP or FTPS.
- API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
- LabgnosticEQA is built to scale horizontally and vertically making best use of available managed cloud services. Given the nature of the service providing a network of customers together, no guarantee can be made that an abnormally high load from one customer would not affect another.
Analytics
- Service usage metrics
- Yes
- Metrics types
- On request we can provide performing & referring transaction volumes for each customer, and can provide more detailed analysis (e.g. turnaround times or transaction volumes segmented by test type and partner lab) on request. This would require work from Engineers to provide.
- Reporting types
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Test configuration data can be exported from the application in JSON format on a per test basis. Order and Results data can not be exported from the system by the users, but they are exported/delivered outbound to LIMs systems via a selection of formats and protocols.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- HL7
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON
- HL7
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- We aim to ensure that the service is available throughout the Subscription Term for 99.7% of the time. There is currently no mechanism for refunds.
- Approach to resilience
- We use Azure's cloud native redundancy and resilience tooling to ensure our platform is spread over multiple data centres and regions within the UK.
- Outage reporting
- Update banners via the service desk and email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Public key authentication (including by TLS client certificate)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Azure AD group membership with conditional access and MFA.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Currently under going certification for ISO 27001.
- Information security policies and processes
- We employ a suite of ~20 information security policies and have built our ISO27001 ISMS policies as part of phase 1 of our audit.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We ensure that security requirements are captured as far left in the SDLC as possible to ensure we have resources to appropriately remediate. All changes are developed using pair programming, and scanned for static code analysis including infrastructure as code static analysis (policy-as-code)
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerabilities identification is done by our vulnerability management tool and reported back every 6 hours. Vulnerabilities are then logged automatically as tickets for the respective team to remediate within our SLAs, with reporting on adherence to SLAs fed up to senior management.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Logging from endpoints, IaaS , PaaS, SaaS tools are ingested by our SIEM and monitored by our SOC on a 24/7 basis with proactive threat hunting activities conducted monthly.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Our incident management approach is holistic as part of our risk management and BC/DR management approach. All suspected or confirmed security incidents are reported to the GRC team & SLT who triage and follow the predefined playbooks for various common incidents. Any live incidents have a PIR conducted with the Lessons Learned captured and remediated within SLAs. Incident Reports are provided to the customer within 48 hours of closure of the incident.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Scottish Wide Area Network (SWAN)
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 3%
- Between £500,001 and £1,000,000
- 6%
- Between £1,000,001 and £2,500,000
- 9%
- Between £2,500,001 and £5,000,000
- 12%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- E940d951-581e-4e45-9cfd-61a86de643d4
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- F16f8b35-62c2-4efd-9490-bdf7ea61050e
- Other security certifications
- Yes
- Any other security certifications
- Data Security and Protection Toolkit
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-