Array
OncoFirm™ / Technology / Connectivity

Pillar guide · Lab connectivity

Laboratory Information System (LIS) Connectivity for Point-of-Care Testing: Standards, Security and Data Quality

A point-of-care test is only as useful as the record it leaves behind. If a result is typed in by hand, filed to the wrong patient or never reaches the laboratory information system (LIS), the speed of the test is wasted. This guide explains how point-of-care results travel to the LIS and electronic health record in 2026, which standards and regulations apply, what the evidence says about connectivity, and how OncoFirm™ is designing its reader for it.

At a glance

Topic

Connecting point-of-care diagnostics to LIS, EHR and public-health systems

Main path

Reader → POC data manager (POCT01-A2) → LIS (HL7 v2.5.1) → EHR (FHIR R4)

Data that travels

LOINC-coded result, units, device, lot, operator, QC status

Key rules

FDA §524B cybersecurity, CLIA, ISO 15189:2022, HIPAA; EU IVDR

OncoFirm™ status

Reader connectivity in development; research use only

Key numbers

Why connectivity matters, in three numbers

0.5%of manually entered point-of-care glucose results had clinically significant transcription errors
85.7% → 97.1%share of point-of-care results visible to wards after connected reporting
59%integrity of lab data between analyzer and information system, per FDA's SHIELD initiative

Sources: Mays and Mathias, JAMIA 2019; Choi et al., Annals of Laboratory Medicine 2024; FDA SHIELD. Full citations below.

Definitions

What an LIS does, and how it differs from an EHR

  • Laboratory information system (LIS): receives orders, tracks specimens, captures analyzer results, applies verification rules and reference ranges, and releases reports.
  • Middleware and POC data managers: sit between instruments and the LIS. A POC data manager also manages operator certification, quality-control (QC) lockout and device status across many sites.
  • Electronic health record (EHR): the clinician-facing record where results are viewed alongside notes, orders and medications.
  • LIMS: a laboratory information management system, more common in research, manufacturing and public-health labs than in hospital diagnostics.

For the testing workflow these systems support, see what is biochemical diagnostics.

Why connect POC tests

What the evidence shows

  • Transcription errors: in a study where outpatient glucose results were both uploaded electronically and typed by staff, about 5 in 1,000 manual entries contained clinically significant errors.
  • Missing results: after a hospital connected its glucose meters, results visible to wards rose from 85.7% to 97.1%, and contradictory entries were eliminated. Before connection, 22–27% of test strips used had no matching recorded result (an upper bound, since it includes wasted strips).
  • Patient and operator checks: connected systems can block results with invalid patient or operator IDs before they are reported.
  • Reader consistency: in 1.49 million COVID-19 lateral flow reports, a digital reader found 25.49% more PCR-confirmed positives than people reading their own tests, and about twice as many at low viral load. That reader imaged visual strips; the comparison is an analogy for instrument-read tests, not evidence for any specific fluorescent reader.
What connectivity does not fix. Electronic transfer removes transcription and documentation errors. It does not correct a poor sample, an expired reagent or a test used for the wrong purpose, which is why operator training, QC and clinical pathways still matter.

How results travel

From reader to record: the connected architecture

How a point-of-care result travels to the LIS and EHRA point-of-care reader stores each result locally, with operator, QC, lot and device identifiers, and sends it using CLSI POCT01-A2 or a documented vendor protocol to a point-of-care data manager. The data manager enforces operator certification, QC lockout and patient identification, then sends results as HL7 version 2.5.1 messages to the laboratory information system. The LIS files the result to the electronic health record, which exposes it to apps through HL7 FHIR R4 and US Core. In public-health and low-resource programmes, results can also flow to platforms such as DHIS2 or OpenELIS. Every result should carry a LOINC code, standard units and device identifiers, and the reader should keep working offline when the network or LIS is down.HOW A POINT-OF-CARE RESULT REACHES THE RECORDPOC readerResult + QC + lotOperator, device IDOffline storePOC data managerOperator certificationQC lockoutPatient ID checkLISVerification, rulesReference rangesLab recordEHRClinician viewPatient portalApps via FHIRPOCT01-A2HL7 v2.5.1FHIR R4Public health · DHIS2 · OpenELISEvery result carries: LOINC (via LIVD) · units · device UDI · lot · operatorSecurity and resilience across every hopEncryption · authenticated users · signed updates · SBOM and patching (FDA §524B) · audit trail · offline store-and-forwardSimplified. Some devices connect directly to the LIS or through vendor middleware; protocols vary by vendor and site.

The typical hospital path for a point-of-care result. Each hop uses an established standard, and each result carries the identifiers that make it traceable and comparable.

  1. Capture. The reader records the result with operator ID, patient ID (ideally by barcode), QC status, reagent lot, device identifier and time stamp, and stores it locally.
  2. Manage. A POC data manager receives results, enforces operator certification and QC lockout, and monitors devices across sites.
  3. Report. Results pass to the LIS or directly to the EHR as HL7 v2.5.1 result messages, coded with LOINC.
  4. Share. Certified EHRs expose results to apps and other organizations through FHIR R4 and US Core; public-health programmes may receive them through platforms such as DHIS2.

Standards in 2026

The connectivity standards and where they stand

LayerStandardStatus, Oct 2026What it does
Device ↔ data managerCLSI POCT01-A22006 edition, archived but technically valid and FDA-recognized; no newer editionDevice messaging for results, QC, operator lists and lock/unlock commands; the data manager enforces the lockout rules
Instrument ↔ LIS (legacy)CLSI LIS01 / LIS02-A2 (formerly ASTM E1381/E1394)Archived, FDA-recognizedLow-level transport and record format still used by many analyzers
Instrument ↔ LIS (modern)IHE PaLM LAW (with IICC)Published profileHL7 v2.5.1-based analyzer workflow; IHE LPOCT covers point-of-care testing
LIS ↔ EHRHL7 v2.5.1 LOI / LRIUS lab orders and results guidesOrder and result messages between labs and EHRs
EHR ↔ apps and partnersHL7 FHIR R4, US CoreUSCDI v6 and US Core 9.0.0 approved for voluntary use from 29 Aug 2026; FHIR R6 still in ballotAPI access to results using DiagnosticReport and Observation resources
Test meaningLOINC, LIVD, SNOMED CT, UCUMLIVD published as an HL7 FHIR guideCodes and units that make results comparable across devices and sites

Version and status details were checked against standards-body and regulator pages; some implementation details, such as specific message trigger events, vary by vendor and site interface specifications.

Data quality and AI

Moving data is easy; making it comparable is not

FDA’s SHIELD initiative found that laboratory data keeps only about 59% of its integrity between the analyzer and the information system, and less across the full path, mainly because manufacturers and laboratories code the same test differently. Its pilot found 41% variability in how laboratories coded identical tests.

  • Code every result: a LOINC code, published by the manufacturer as an LIVD mapping, tells every receiving system what was measured.
  • Carry the context: units, method, device identifier and reagent lot let analysts separate true biological change from assay or lot effects.
  • Keep provenance: audit trails show who ran a test, on which device, after which QC event.
  • Govern secondary use: analytics and AI on diagnostic data require consent and privacy safeguards, validation on representative data and, for medical devices, FDA oversight. FDA's guidance on AI-enabled device software was still a draft (January 2025) as of October 2026.

Quantitative results, such as serial CEA or PSA values, are only trendable across sites when they are coded and traceable. See AI-driven biomarkers in precision diagnostics.

Regulation and security

Rules that apply to connected diagnostics

RequirementApplies toStatus, Oct 2026
FD&C Act §524B: SBOM, vulnerability plan, patchesManufacturers of networked devices with softwareIn force since 29 Mar 2023; FDA premarket cybersecurity guidance finalized 27 Jun 2025
Quality Management System Regulation (QMSR)Device manufacturersEffective 2 Feb 2026; incorporates ISO 13485:2016
IEC 62304, IEC 81001-5-1, ISO 14971Device software lifecycle, security and riskConsensus standards used in submissions
CLIA (42 CFR 493)US laboratories, including POC sites2023 rule fully effective; result reporting and QC records required
ISO 15189:2022Accredited laboratoriesAbsorbed ISO 22870 POC requirements; transition ended Dec 2025
HIPAA Security RuleCovered entities and business associatesUpdate proposed Jan 2025; final rule targeted for 2027
EU IVDR, NIS2, Cyber Resilience ActDevices and manufacturers in the EUNew devices need full IVDR certification; CRA excludes IVDR devices but can cover companion software
European Health Data SpaceEU health data exchangeIn force Mar 2025; lab results a priority category from Mar 2031

Designing for downtime

The Synnovis lesson: connectivity must fail safely

On 3 June 2024 a ransomware attack hit Synnovis, the pathology provider for several London NHS trusts. More than 10,000 appointments were cancelled, hospitals had to rely on O-negative blood while blood matching was impaired, costs exceeded £32 million and data on about 900,000 patients was stolen. A patient death was later linked to delays in blood results.

  • Offline first: a reader should keep testing, storing and displaying results when the network or LIS is down, then forward them when systems recover.
  • Downtime procedures: printed or on-screen results with unique identifiers, and reconciliation once systems return.
  • Least privilege and segmentation: devices should not be a route into hospital networks.
  • Patchability: signed software updates and a vulnerability disclosure process for the device's whole life.

Low-resource settings

Connectivity beyond the hospital

In global-health programmes, connected diagnostics help programmes as much as patients: remote monitoring of QC and operator errors, alerts when a device stops transmitting, stock tracking and faster return of results for follow-up. Open-source systems such as OpenELIS Global and DHIS2 are common endpoints, and FIND promotes interoperable digital companions for rapid tests. Store-and-forward over mobile networks matters where connectivity is intermittent. See the global need for affordable diagnostics and rapid testing for global health.

Evaluation checklist

Questions lab and IT teams should ask about any POC device

  1. Which interface does it support: POCT01-A2, a documented vendor protocol, HL7 v2.5.1 or FHIR? Is it validated with our data manager and LIS?
  2. Does the manufacturer publish LOINC mappings (LIVD) and units for every reported result?
  3. Can it enforce operator certification, QC lockout and barcode patient identification?
  4. What happens offline: how many results are stored, and how are they reconciled?
  5. Is there an SBOM, a vulnerability disclosure policy and a signed update process?
  6. What audit trail is kept, and how long are records retained to meet CLIA and accreditation requirements?

OncoFirm™ design

How OncoFirm™ is designing its reader for connectivity

The OncoFirm™ reader is intended to produce quantitative fluorescent lateral flow results, such as CEA and PSA, that arrive in the record as complete, coded and traceable data rather than as a number typed by hand.

Complete digital record

The reader is being designed to record each result with operator, patient ID, QC status, reagent lot, device ID, time stamp and audit trail. Digital readers

Standards-based export

Planned support for POCT01-A2 data-manager connectivity, HL7 v2.5.1 result messages and FHIR-based exchange, with LOINC mappings published in LIVD format. One reader, one strip

Security by design

Design objectives include encrypted transfer, role-based access, signed updates, an SBOM and a vulnerability management process aligned with FDA Section 524B. Platform

Offline-first and global

Store-and-forward operation for clinics with intermittent networks, with intended interfaces to public-health platforms. Point-of-care oncology

The OncoFirm™ reader, assays and connectivity features are in development. Capabilities described are design objectives, not validated performance. They have not been cleared or approved by the FDA or any other regulatory authority, are for research use only and are not for sale.

FAQ

Frequently asked questions

What is a laboratory information system (LIS)?

An LIS is the software a clinical laboratory uses to receive test orders, track specimens, capture results from analyzers, apply verification rules and reference ranges, and report results to clinicians, usually through the electronic health record (EHR).

How do point-of-care devices connect to the LIS?

Most hospitals route point-of-care devices through a POC data manager. The device sends results using the CLSI POCT01-A2 standard or a vendor protocol; the data manager checks operator certification, quality control and patient identity, then forwards results to the LIS or EHR, typically as HL7 version 2.5.1 messages.

Is HL7 FHIR replacing HL7 v2 for lab results?

Not yet. HL7 v2.5.1 remains the workhorse for device-to-LIS and LIS-to-EHR result messages in the United States. FHIR R4 with US Core profiles is how certified EHRs expose results to apps and other systems. FHIR R6 was still in ballot as of October 2026.

Why does LOINC coding matter?

LOINC codes tell receiving systems exactly which test was performed, so results from different devices and sites can be compared, trended and analyzed. FDA's SHIELD initiative reports that lab data keeps only about 59% integrity between analyzers and information systems, largely because of inconsistent coding. Manufacturers can publish suggested LOINC mappings in the LIVD format.

Does connecting point-of-care tests reduce errors?

Yes, for transcription-related errors. One study of outpatient point-of-care glucose testing found clinically significant transcription errors in about 5 of every 1,000 manually entered results; electronic transfer removes that step. Connectivity does not fix pre-analytical errors, such as a poor sample, or interpretation errors.

What cybersecurity rules apply to a connected diagnostic reader?

In the United States, a networked device with software is likely a 'cyber device' under Section 524B of the FD&C Act. Its premarket submission must include a software bill of materials, a plan to monitor and address vulnerabilities, and a process for updates and patches, as described in FDA's June 2025 cybersecurity guidance.

Is the OncoFirm™ reader connected to hospital systems today?

No. The OncoFirm™ fluorescent lateral flow reader and its connectivity features are in development. The capabilities described are design objectives; the system has not been cleared or approved by the FDA or any other regulatory authority, is for research use only and is not for sale.

Sources

References

  1. Clinical and Laboratory Standards Institute. POCT01-A2: Point-of-Care Connectivity; Approved Standard, 2nd ed. 2006. clsi.org/shop/standards/poct01/
  2. Clinical and Laboratory Standards Institute. LIS02-A2: Specification for Transferring Information Between Clinical Laboratory Instruments and Information Systems (formerly ASTM E1394). clsi.org/standards/products/automation-and-informatics/documents/lis02/
  3. HL7 International. HL7 Version 2.5.1 Implementation Guide: Laboratory Orders from EHR (LOI) and Lab Results Interface (LRI), US Realm. www.hl7.org/documentcenter/public/standards/dstu/v251_ig_laborders_r1_stu_r3_2018jun.pdf
  4. HL7 International. FHIR version history (R4, R5, R6 ballot). build.fhir.org/versions.html
  5. ASTP/ONC. Advancements in health IT: ONC's 2026 approved SVAP standards (USCDI v6, US Core 9.0.0). 2026. healthit.gov/blog/standards/advancements-in-health-it-oncs-2026-approved-svap-standards/
  6. IHE International. Pathology and Laboratory Medicine (PaLM) Technical Framework, including Laboratory Point Of Care Testing (LPOCT). www.ihe.net/uploadedFiles/Documents/PaLM/IHE_PaLM_TF_Vol2c.pdf
  7. IVD Industry Connectivity Consortium. Laboratory Analytical Workflow (LAW) profile. ivdconnectivity.org/law-profile/
  8. HL7 International. LOINC to Vendor IVD (LIVD) FHIR implementation guide. github.com/HL7/livd
  9. U.S. Food and Drug Administration. Systemic Harmonization and Interoperability Enhancement for Laboratory Data (SHIELD). www.fda.gov/medical-devices/diagnostic-data-program/systemic-harmonization-and-interoperability-enhancement-laboratory-data-shield
  10. Mays JA, Mathias PC. Measuring the rate of manual transcription error in outpatient point-of-care testing. J Am Med Inform Assoc. 2019;26(3):269–272 (AHRQ PSNet summary). psnet.ahrq.gov/issue/measuring-rate-manual-transcription-error-outpatient-point-care-testing
  11. Choi et al. Connected point-of-care glucose reporting and result accessibility. Ann Lab Med. 2024;44(1):103. www.annlabmed.org/journal/view.html?doi=10.3343%2Falm.2024.44.1.103
  12. UK Health Security Agency. Evaluation of a digital reader for COVID-19 lateral flow device results. November 2022. assets.publishing.service.gov.uk/media/6363de468fa8f505764b007b/LFD-digital-reader-november-2022.pdf
  13. U.S. Food and Drug Administration. Cybersecurity in medical devices (Section 524B and premarket guidance, June 2025). www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity
  14. 21 U.S.C. § 360n-2. Ensuring cybersecurity of devices (FD&C Act Section 524B). www.law.cornell.edu/uscode/text/21/360n-2
  15. Ropes & Gray. A QMSR state of mind: FDA adopts new inspection approach for medical devices. February 2026. www.ropesgray.com/en/insights/alerts/2026/02/a-qmsr-state-of-mind-fda-adopts-new-inspection-approach-for-medical-devices
  16. U.S. Food and Drug Administration. Artificial intelligence-enabled device software functions: lifecycle management and marketing submission recommendations (draft guidance). January 7, 2025. www.federalregister.gov/documents/2025/01/07/2024-31543/artificial-intelligence-enabled-device-software-functions-lifecycle-management-and-marketing
  17. Electronic Code of Federal Regulations. 42 CFR Part 493: Laboratory requirements (CLIA). www.ecfr.gov/current/title-42/chapter-IV/subchapter-G/part-493
  18. UKAS. ISO 15189:2022 transition update (incorporation of ISO 22870 point-of-care requirements). www.ukas.com/resources/resources/15189-transition-update/
  19. HIPAA Journal. New HIPAA regulations: status of the proposed HIPAA Security Rule update. www.hipaajournal.com/new-hipaa-regulations/
  20. European Commission. Q&A on the transitional provisions of the In Vitro Diagnostic Medical Devices Regulation (IVDR). health.ec.europa.eu/document/download/dfd7a1c6-f319-4682-9bac-77bef1165818_en?filename=mdr_qna-ext-ivdr.pdf
  21. Kennedys. The European Health Data Space is in force: implications for healthcare, medtech and life sciences. 2026. www.kennedyslaw.com/en/thought-leadership/article/2026/the-european-health-data-space-is-in-force-implications-for-healthcare-medtech-and-life-sciences/
  22. HIPAA Journal. Patient death linked to ransomware attack on pathology provider Synnovis. 2025. www.hipaajournal.com/patient-death-linked-to-ransomware-attack/
  23. Elizabeth Glaser Pediatric AIDS Foundation. Point-of-care connectivity issue brief. November 2018. pedaids.org/wp-content/uploads/2018/11/Point-of-Care-Connectivity-Issue-Brief-Nov-2018-English_Digital-1.pdf
  24. FIND. Digital health: connected diagnostics and data. www.finddx.org/what-we-do/cross-cutting-workstreams/digital-health/
  25. DHIS2 documentation. Integration concepts. docs.dhis2.org/en/implement/implementing-dhis2/integration-concepts.html
  26. OpenELIS Global. Open-source laboratory information system. openelis-global.org/

About this article. Written by the OncoFirm™ Scientific Team from standards-body publications, regulatory documents and peer-reviewed studies, all linked above, and reflecting public information as of 1 October 2026. Vendor-neutral: no laboratory software or middleware vendor reviewed or sponsored it. This update replaces an earlier version and separates current standards and evidence from OncoFirm™ design objectives. It is for education and is not legal, regulatory or medical advice. OncoFirm™ products are in development, have not been cleared or approved by the FDA and are not available for sale.

Talk to us about integration

Laboratory, informatics and IT teams interested in point-of-care connectivity for future validation studies can reach the OncoFirm™ team. Collaboration inquiry · Investor inquiry