MetaclinicMetaclinic

Diagnostic data infrastructure

A result is data.
Access is metadata.

Metaclinic automates the administrative decision and reports on the clinical outcome. One signed report, and nine parties with a claim on part of it: the ordering clinician, the referring practice, the consulting specialist, the coder, the payer, counsel, the registry, the research sponsor, and the patient.

Every result, to everyone entitled to it — decided in advance, on a stated legal basis, and recorded the moment it happens.

A single beam of white light entering one face of a milled steel block and leaving the other separated into many distinct ribbons of blue, each a different width, fanning apart and running off the frame.
One result in. Every release out, already scoped to whoever is entitled to it.
23 released by default 39 conditional on something specific 19 withheld, with the reason stated all 81 decisions →

A laboratory result is finished. Its job is not.

the premise

The test was performed correctly and the report is right. Everything after that is a delivery problem, a scoping problem, and an evidence problem — handled by whatever happens to sit in the seam between the laboratory information system, the practice's EHR, the billing vendor, and a fax machine. Almost every expensive failure in diagnostics happens in that second half, and it is nobody's product.

Failure one

The result is a document

Filed as a PDF, it cannot be trended, thresholded, coded from reliably, or split so one party sees part of it and another does not. That choice is made at intake and everything downstream inherits it.

Failure two

Access is a role, not a relationship

Give a consulting specialist a role and they keep it after the consult, across every patient in the tenant. The relationship was one case for three weeks. The permission should have been too.

Failure three

The patient is treated as a request queue

Direct patient access has been required of laboratories since 2014 and delay without a defined exception has been information blocking since 2021. Most systems still model it as a favor with a turnaround time.

A broad sheet of cool blue light meeting one face of a milled aluminium plate and emerging from the other as a single narrow ribbon with hard edges.
The same light on both sides. The geometry decides how much of it leaves.

One result, released nine ways

the shape of the thing

The same issued report becomes nine different disclosures, because nine parties are entitled to different parts of it on different authority. That is not a workflow with nine steps. It is one object, scoped nine ways, at the moment it is asked for.

One result, released nine ways A single issued laboratory result enters a scoping aperture and leaves as nine separate disclosures, one per stakeholder. Each slot in the aperture is open in proportion to the data classes released to that stakeholder by default, and the counts beside each destination are the same numbers as the release matrix. issued result Patient7 released · 2 conditionalOrdering clinician6 released · 3 conditionalConsulting specialist0 released · 6 conditionalReferring practice5 released · 3 conditionalBilling and coding3 released · 5 conditionalAttorney of record1 released · 4 conditionalPayer and UM1 released · 6 conditionalPublic health0 released · 5 conditionalResearch sponsor0 released · 5 conditional
Scoped per class, per stakeholder, and per state. Every number here is read from the release matrix: each slot opens in proportion to what that stakeholder receives by default, line weight carries the same count, and a dashed line means nothing is released until a condition is met.

Adding one stakeholder adds nine decisions

the network effect, stated honestly

This is the part that compounds. A tenth stakeholder does not add one relationship to the model, it adds nine — one per class of data, each needing an answer that is defensible on its own. That is why the rules are written down and generated from one file rather than decided per integration, and it is why the answer to “can they see it” is never a shrug.

Every connection between a data class and a stakeholder Nine classes of diagnostic data on the left and nine kinds of stakeholder on the right. 23 connections are released by default and drawn solid, 39 are conditional and drawn dashed, and 19 are withheld and are not drawn at all. The same numbers appear in the release matrix. RequisitionDiscrete resultsNarrative reportImages and slidesMolecular and genomicPart 2 substance useState-protectedCharge and lien ledgerRaw interface messagePatientOrdering clinicianConsulting specialistReferring practiceBilling and codingAttorney of recordPayer and UMPublic healthResearch sponsor
23 connections released by default, 39 conditional on something specific. The 19 withheld are the lines that are not drawn.

Every source is a relationship with a spec

hl7 v2 · fhir r4 · tefca

Diagnostic data crosses organizations that share no identity system, no code set, and no incentive to make it easy. The integration surface is a graph, and the posture toward each edge is different.

ConnectionDirectionHowWhat to know
Laboratory information systemsSourceHL7 v2.5.1 ORU^R01 over TLS or SFTP, plus a FHIR R4 read where the LIS supports it. Orders return as ORM or OML.GPS LIS is a first-class source. Every other LIS is treated as a stranger with a spec, which is the correct posture.
Electronic health recordsSource and destinationSMART on FHIR app launch for in-workflow access, US Core profiles for read, and Bulk FHIR export for panel-level pulls.Certified EHRs must expose a standards-based API. When one does not, that is a finding, not an integration problem.
Reference and send-out laboratoriesSourceResult-only interfaces reconciled back to the originating accession, so a send-out returns to the case it left.The failure mode is an orphaned molecular result nobody bills and nobody reads. Reconciliation is the whole job.
National networksSource and destinationQuery and retrieve through a designated QHIN under TEFCA, including individual access services for patient-initiated requests.Useful for prior results and outside history. Not a substitute for a direct interface where volume is predictable.
Health data aggregatorsSourceNormalized clinical and lab feeds from a network aggregator, used to fill in outside results in weeks rather than quarters.Fastest path to coverage, thinnest control over data quality. Use it to start, replace it where the volume justifies a direct build.
Direct secure messagingDestinationDirect addresses for practices with no interface and no API, because a surprising number of destinations are still an inbox.Lowest common denominator, and the one that keeps a rollout on schedule.
Patient endpointsDestinationPortal, patient-facing FHIR API with a registered third-party app, and a full electronic export on request.Patient-directed transmission to a third party is a distinct path with its own record, not a shortcut around authorization.
Payers and clearinghousesDestinationClaims and attachments out, remittance and adjudication back, reconciled against the charge that produced them.This is where Metaclinic already lives. Diagnostic data access makes the claim defensible instead of merely submitted.

How a connection goes live

Multi-tenant, and the interesting part is the doors

org · suborg · role · grant

Multi-tenant usually means isolation: every customer in a sealed box. Diagnostic data does not work that way. A laboratory reports to a practice, the practice consults a specialist at another organization, a delegated biller codes the case, a firm holds a lien, and the patient stands outside all of them holding a legal right to the whole thing.

So the model has four layers — organization, sub-organization, role, and grant — and only the last one crosses a boundary. A grant is an edge attached to a case or a matter with an expiry on it. There is no standing permission to look at another tenant's data, enforcement has a floor in the database rather than only in application code, and support access is a break-glass event that notifies the affected tenant when it happens.

one specimen, nine release events
14:02
Specimen received
Accession created, requisition parsed, order matched to the referring practice tenant.
Laboratory tenant
14:03
Patient identity linked
Probabilistic candidate held for review rather than auto-merged. A false link is a disclosure to the wrong person.
Cross-tenant identity
09:41
Result verified and released to the ordering clinician
Discrete values mapped to LOINC, reference interval carried from the performing laboratory.
Laboratory tenant → practice tenant
09:41
Released to the patient
Same moment, no administrative hold. Plain-language summary generated above the report, never in place of it.
Patient identity
09:41
Ordering clinician notified of the abnormal flag
So the conversation happens quickly. Notification and open state are both recorded.
Practice tenant
09:44
Coder opens the report
Final diagnosis and specimen list visible. Slide images are not, because coding does not require them.
Billing tenant
11:20
Consulting specialist granted the case
One case, twenty-one days, expiring on a date rather than on a promise.
Grant across tenants
16:08
Firm requests records on the matter
Authorization parsed. Chemistry and pathology released; the Part 2 toxicology result is withheld and the omission is reported by name.
Firm tenant
16:08
Disclosure recorded
Requester, purpose, basis, classes released, classes withheld, and the result version current at release.
Audit record

The tenancy modelThe full release model

The patient is not a stakeholder to be managed

42 cfr 493.1291(l) · 45 cfr 164.524

A laboratory subject to CLIA has been required to give a patient copies of their completed test reports since 2014, and the HIPAA exception that used to shield laboratories is gone. The engineering question is no longer whether to release. It is how to release something a person can actually use.

Results go to the patient when they are final and identity is verified, with no waiting period built in to give a clinician time to call first. A plain-language summary sits above the report and never replaces it. Reference intervals and flags travel with every value, sourced from the performing laboratory. Corrections are surfaced as corrections with the prior value visible. And the ordering clinician is notified the moment a critical or malignant result is released, so the call happens fast — which is the real answer to the hard case, not a delay.

Patient access in detail

What we are, legally, and what follows from it

45 cfr 171 · 42 cfr part 2

Metaclinic is a business associate of the laboratories and practices it serves, under an agreement with each of them. The information blocking rules reach the providers it serves, and the platform is built to the standard those rules set rather than to the minimum a vendor could argue for.

Nothing is withheld without naming the exception that allows it

Where a request is not fulfilled, the reason is recorded against a named exception — preventing harm, privacy, security, infeasibility, health IT performance, content and manner, fees, licensing, or the exchange framework. A refusal without a recorded exception is a violation with extra steps.

How release decisions are madePatient access

Which stakeholder is currently asking you for data you cannot easily give them?

That is the useful first conversation, and it is a short one. Bring the laboratories, the practices, and the thing that breaks today.

Book a 30-minute call service@meta.clinic Read the release model first