Infrastructure for signed screening reports

The infrastructure behind signed clinical reports.

Lumepath builds the platform that turns laboratory results into clinician-signed screening reports and privacy-safe workforce insight — under the clinic's rules, in the patient's language, delivered through partners who know the market.

Fail-closed by constructionNothing reaches a patient before a doctor releases it
Privacy in the data modelOpaque references; employer views in groups of ten or more
Versioned, signed lineageEvery report traces to the template edition and the person who signed
Signet

Intake, Hold, Compose, Deliver.

A screening programme is a pipeline with a doctor in the middle. Signet is the reporting platform for clinician-signed screening results. It is not a medical device and not SaMD. We do not claim FDA, CE, clinical validation or clinical approval. Clinical judgement stays with a named clinician. Partners licence it and put their own name on it.

Signet pipeline details →

Every admitted record gets a signed receipt and an opaque reference. Unmatched rows are quarantined, not guessed. Manual fallback is CSV only — never XLSX.

  • Signed receipt + opaque reference
  • Quarantine unmatched rows
  • CSV only — never XLSX

Four fail-closed rules hold incomplete, invalid, mismatched or critical work. Held reports wait for a person. A critical value never auto-delivers.

  • Four hold cases
  • Clinician sign-off ladder
  • Repeat-safe bulk release

Versioned clinic templates become sealed PDFs with verifiable lineage. SPECIMEN until a named clinician releases. AI assists the review queue — it does not replace release.

  • Version-pinned templates
  • Sealed PDF + verifiable code
  • Named clinician release

One-use patient links. Employer aggregates refuse groups below k ≥ 10. Clinic write-back only when bound and licensed.

  • Patient portal + SMS or email
  • k ≥ 10 employer views
  • Write-back when bound and licensed
How it works

From specimen to signed report, with a person at every gate.

The path below is the one a real result takes. Solid lines carry every report; the dotted arc is the only path that skips the individual review, and only a report that passed every hold rule may take it.

release-run · todayone doctor signs in advance · a person sends
Pipeline: laboratory results enter intake, pass the four hold rules, go to a clinician for sign-off, are released, and are delivered to the patient, the employer aggregate, and a contracted clinic receipt when in scope. Reports that pass every hold rule may skip the individual review; a critical value never does. LaboratoryHL7 · lab/clinic feed Intakereceipt · opaque ref Hold rulescases 1–3 · critical held → clinician Sign & releaseMCR-signed · sealed PDF passed every rule · auto-ready Patientone-use + code Cliniccontracted receipt Employergroups of 10+ only query / re-pull when the feed is late
every report · receipted at each hopauto-ready · skips individual review only after every hold rule passes· a critical value never takes the dotted arc
Held-report rules

What the system refuses to do on its own.

Automation is only trustworthy where it knows when to stop. These four conditions hold a report for a clinician, every time, regardless of volume.

Case 1Incomplete panel

A test the package promised is missing from the result set.

Case 2Invalid unit or range

The laboratory's unit or reference range does not match the marker's definition.

Case 3Mismatched test code

A local code cannot be mapped to a known marker with confidence.

Case 4Critical value

A result inside the clinic's critical band. Flagged by the lab, decided by the clinician.

Principles

Three invariants.

Privacy is structural, not a setting

Opaque references; identity never travels in a URL. Employer surfaces are computed server-side and refuse any group under the privacy floor — k ≥ 10 absolute floor; raiseable by the tenant, never lowerable. It is not a default.

Fail closed

Each portal boots only if its route census matches its contract. Nothing is shown before release; an unbound source fails closed into a hold — never a sample.

Auditable by design

Every report carries its template edition, the signing clinician and a sealed digest. Intake, release and delivery are receipted — operators answer "what happened" from the record.

Security

What a security review asks.

Built-as-is answers for the controls partners ask first. Keys, identity, receipts and assurance detail live on Trust.

Data residency
Each deployment’s data at rest stays in the region its clinics are regulated in. The first deployment keeps Singapore clinical data in Singapore. Other regions are chosen with the tenant.
Patient access
A one-use link plus a code sent by SMS or email. No account to create, no password, and no identifier in the URL — patients are addressed by opaque reference. A patient cannot see a report before a clinician has released it.
Employer views
Computed server-side and refused for any group below the privacy floor — k ≥ 10 absolute floor. It is not a default. A tenant can raise the floor. Nothing can lower it, including us.
Report integrity
Generation is determined only by the inputs, the content version and the engine version: no clock, no randomness, no external call in the clinical path. A released report regenerates byte-identical, so a later alteration cannot hide.
Portal isolation
Each portal is its own origin with its own host-scoped session cookie. Facades boot only if route census matches contract. One portal cannot reach another’s routes or session.

Certifications follow deployments: we name a framework only when a deployment has been audited against it. Full control surface, residency exceptions and questionnaire answers: Trust.

White-label

Lumepath builds the platform. Partners bring it to market.

Signet is licensed, not retailed. A delivery partner takes the whole platform, puts its own name, logo and wording on every surface, and owns the relationship with the clinics and employers it serves. We stay behind it: the pipeline stays ours to keep correct. Hold rules, signed lineage and the privacy floor are platform invariants. Branding, templates and integrations are set per partner.

Signet
one stack, four stages

A workspace for the clinic team, a private report for each patient, an aggregate for the employer, and a partner operations console (jointly configured on first licences; full self-serve ops console as product direction). Each surface carries the partner’s brand, the clinic’s templates and the patient’s language.

First deployment
A Singapore screening provider, under its partner’s brand
Region
Singapore · clinical data stays in-region
Posture
First deployment is PDPA-scoped; no report body leaves unsigned. Other tenants follow the law of their region
Talk to us about a licence
Company

A small team, building the boring parts properly.

Lumepath Inc. builds infrastructure for clinician-signed screening reports for partners worldwide. Signet is not a medical device. Partners own clinic and employer relationships. We do not sell to patients, and we do not hold data we were not asked to process. Data stays in the region its clinics are regulated in — first deployment: Singapore.

Lumepath Inc.hello@lumepath.ai
Data stays in regionFirst deployment: Singapore clinical data stays in Singapore; other regions chosen with the tenant
Owner-operated platformLumepath owns the platform; delivery partners are registered and scoped
Regulated-grade engineeringClosed route contracts, signed lineage, receipted side effects
Contact

Building a screening programme, or a platform for one?

We work with delivery partners; clinics and laboratories are reached through partner channels. Write to us and a founder will reply.

hello@lumepath.ai