Security

How Book Lab protects patient information

Book Lab takes the booking and hands it straight to your practice management software. It keeps no copy. There is no patient database, no offshore processing and no third-party calendar holding your patients' details. This page explains how that works, in plain English.

Where does a booking actually go?

A patient fills in the booking form on your booking page. Book Lab checks the details are valid, then writes the appointment directly into your practice management software. That's the whole journey. The appointment sits in your appointment book alongside the ones reception entered by hand, and your practice software takes over from there.

What does Book Lab store?

Nothing. Each booking is validated, passed on and gone. Zero retention is a design rule, not a setting: there is no database in the platform to store patient details in. If you ever change plans or leave, there is no data to migrate or ask us to delete, because we never had it.

Who can see patient details?

Your team, inside your practice software, under the access controls you already manage. Book Lab's connection does two things: it checks appointment availability and it creates bookings. It has no endpoint for reading patient records, notes or history, so patient information cannot be browsed or exported through it. Each practice's integration credentials sit in their own encrypted vault, separate from every other practice.

Does data leave New Zealand?

No. Bookings are health information under the NZ Health Information Privacy Code 2020, and Book Lab treats them that way: collect the minimum, retain nothing, and keep processing in a New Zealand data centre.

What happens when something breaks?

If a booking can't reach your practice software, the patient sees an honest message asking them to phone the practice. Nobody gets a confirmation for an appointment that doesn't exist. We'd rather lose a booking than fake one.

How is the platform tested?

We attack it ourselves, continuously. Book Lab uses the latest AI-driven security testing to probe the platform around the clock, the way a real attacker would, proving what's exploitable instead of guessing. A traditional penetration test happens once a year and starts ageing the day the report lands. Ours never sleeps. Testing is included in every plan, never sold as an extra. The site you're reading now runs with a strict content security policy and makes no third-party requests at all.

Security questions practices ask us

Does Book Lab store patient records?

No. Book Lab keeps no patient database. Each booking is validated, passed to your practice management software and gone. Patient records live only in your practice software, protected by its access controls.

Is Book Lab compliant with the NZ Health Information Privacy Code?

Book Lab is built around the Health Information Privacy Code 2020 principles: collect the minimum information needed to make a booking, retain none of it, and keep processing in New Zealand.

Can Book Lab staff see our appointment book?

No. Book Lab's connection can check appointment availability and create bookings. It has no endpoint for reading patient records, notes or history, so patient information cannot be browsed or exported through it.

Where is Book Lab hosted?

Booking data is processed in a New Zealand data centre. Health information does not leave the country.

Does the booking page use tracking cookies?

No. Booking pages run without advertising trackers or analytics cookies. Your patients are not the product.

Get started

Ready to secure your bookings?

Tell us which practice management software you run and we'll take it from there.

Or email hello@booklab.co.nz