4 General requirements .gif)
4.1 Impartiality
Requirements of ISO 15189, impartiality, tools, threats
Requirements 1 to 9 (see also the quiz)
Quality is conformance to requirements. Philip Crosby
The 549 requirementsexplicit or implicit need or expectation (see also ISO 9000, 3.6.4) of ISO 15189 found in the sub-clauses of clauses 4 to 8 and Annex A are shown in Figure 4-1:

Figure 4-1. Requirements of ISO 15189
These requirementsexplicit or implicit need or expectation (see also ISO 9000, 3.6.4) enable a medical biology laboratory to:
- improve patient care
- better satisfy laboratory users
- prevent risks
- seize opportunities for improvement
- increase the efficiency of the management system
Impartiality is like beauty: it is up to others to judge it. – Eric Dupont-Moretti
Impartialityabsence of bias and absence of conflict of interest is a fundamental principle ensuring that analysis results are:
- objective (uninfluenced by conflicts of interest)
- reliable (based solely on scientific and technical criteria)
- transparent (free from bias linked to commercial, financial, or personal pressures)
The laboratory demonstrates its impartialityabsence of bias and absence of conflict of interest in all its activitiesset of tasks to obtain a deliverable, particularly regarding:
- medical analyses (diagnostics, screening)
- quality-related decisions (result validation, nonconformity management)
- relationships with stakeholders (staff, patients, referring physicians, suppliers)
Impartialityabsence of bias and absence of conflict of interest is a non-negotiable requirementexplicit or implicit need or expectation (see also ISO 9000, 3.6.4):
- all threats to impartiality are identified, documented and managed
- top management plays a central role in ensuring impartiality
- transparency and communication are essential to maintaining trust
Practical tools (code of conduct, ethics committee, conflict of interest register) help meet this requirementexplicit or implicit need or expectation (see also ISO 9000, 3.6.4). Every employee signs a Declaration of No Conflict of Interest on their first day of work (cf. annex 05). 
The laboratory identifies threatsuncertain event that could have a negative impact on the objectives to impartialityabsence of bias and absence of conflict of interest by:
- identifying situations where its impartiality could be compromised
- documenting these threats (in the risk register or a SWOT analysis report)
- assessing their severity (high, medium, or low risk)
Examples of threatsuncertain event that could have a negative impact on the objectives to impartialityabsence of bias and absence of conflict of interest:
| Threat (source of risk) | Concrete example | Potential impact | Mitigation measure |
| Conflict of interest | A laboratory employee is also a reagent supplier | Bias in reagent selection (favoritism) | Establish an independent purchasing committee to select suppliers |
| Commercial pressure | A client (e.g., a clinic) demands unrealistic turnaround times for results | Errors or unreliable results | Train staff to resist pressure and clearly communicate limitations |
| Personal relationships | A biologist has a family connection to a referring physician | Influence on result interpretation | Exclude the staff member concerned from analyses linked to that physician |
| Unfair competition | The laboratory offers preferential rates to certain clients | Unequal treatment of patients | Apply the same rates and turnaround times to all clients |
| Supplier influence | An equipment manufacturer offers perks (e.g., free training) | Biased equipment selection | Establish objective criteria for equipment selection (performance, cost) |
| Insurer pressure | A health insurer mandates testing protocols that do not comply with GLP | Unreliable results | Establish an independent committee to select insurers |
Examples of internal communication (posted on the premises):
"Our laboratory is committed to ensuring the impartiality of its analyses. Any conflict of interest must be reported to the Quality Manager."
A laboratory purchases reagents from a supplier whose sales director is a former employee of the laboratory.
• risk identified: conflict of interest (risk of favoritism in the selection of reagents). Severity: 4/5 (high risk to the quality of analyses)
• Documentation: the risk is recorded in the risk register
Mitigation measures:
• creation of an independent purchasing committee (comprising biologists and technicians)
• exclusion of the supplier in question from purchasing decisions
• transparent tendering process for all suppliers
• staff informed of the impartial purchasing procedure
• ethical guidelines displayed on the premises
- gifts from suppliers comply with the laboratory’s ethical rules
- a declaration of no conflict of interest is signed by every employe
- an ethics group oversees impartiality issues
- regular workshops featuring case studies on conflicts of interest, impartiality, and ethics
- the audit program includes auditing compliance with impartiality requirements
- no documentation regarding the analysis of impartiality-related risks
- limited analysis of impartiality-related risks (covering only management)
- absence of an ethics policy (no rules governing gifts and benefits)
- staff unable to define a conflict of interest
- no management commitment to impartiality
4.2 Confidentiality
Confidentiality, protection

You don’t entrust chickens to a fox. Estonian proverb
Confidentiality is an ethical and legal cornerstone for medical biology laboratories, as they handle sensitive health data (examination results, diagnoses, personal information) belonging to patientsperson from whom the sample is obtained, referring physicians and partners. Requirementsexplicit or implicit need or expectation (see also ISO 9000, 3.6.4) to be met include:
- protecting data against unauthorized access, leaks, or misuse
- guaranteeing patient rights (right to be forgotten, data access)
- complying with local and international regulations (GDPR in the EU, HIPAA in the United States, the Data Protection Act in France)
Top managementgroup or persons in charge of the organizational control at the highest level (see also ISO 9000, 3.1.1) makes a written commitment to ensure that all information (regarding patientsperson from whom the sample is obtained, referring physicians and results) is protected.
Example of a formal document outlining the confidentialityproperty of information accessible only to authorized persons (see also ISO 27000, 3.10) rules applied by the laboratory:
"Top management of [Name] Laboratory is committed to protecting the confidentiality of all medical and personal information in accordance with ISO 15189:2022 and the GDPR. Any unauthorized access or disclosure is strictly prohibited and subject to sanctions."
Example of a confidentialityproperty of information accessible only to authorized persons (see also ISO 27000, 3.10) matrix:
| Level | Examples | Protection measures |
| Public | Quality policy, organizational chart | Open access, public distribution |
| Internal | Internal procedures, audit reports | Personnel-only access, authentication |
| Confidential | Patient results, medical data | Encryption, restricted access, logging |
| Secret | Genetic data, HIV tests | Enhanced encryption, highly restricted access, regular auditi |
Personnel communication:
- mandatory training for all personnel (including temporary workers and external contractors) on:
- legal obligations (GDPR, medical confidentiality)
- internal confidentiality procedures
- penalties for noncompliance
- signing of a confidentiality agreement by each employee
Information protection includes the following measures:
- technical:
- data encryption
- secure storage
- organizational:
- information classification (public, internal, confidential, secret)
- logging of access to patient records
- securing of premises
- legal:
- GDPR compliance
- confidentiality agreements with external contractors
To secure access to its premises and IT systems, a laboratory implemented the following measures to comply with ISO 15189 requirements:
• physical access: personalized badges for all employees, restricted-access areas (server room, archives), logging (badge + camera)
• digital access: individual accounts for each employee, two-factor authentication for critical systems, automatic account deactivation after 3 failed login attempts
• access audit: monthly review of access logs to detect anomalies, automatic alerts for suspicious access (e.g., login from a foreign country)
- a confidentiality agreement is signed by all employees
- a designated person is responsible for GDPR compliance
- data protection includes the management of unauthorized access
- regular training on GDPR, medical confidentiality, and best practices
- access logs are monitored monthly
- secure destruction of data and documents
- screens visible to the public at the reception desk
- examination results announced aloud near the reception area
- a shared login ID used by several employees
- computers connected to the Laboratory Information System (LIS) left logged in without automatic locking
- disclosing sensitive results without verifying the exact identity of the person on the line
- documents containing personal data discarded in standard trash bins
4.3 Patient requirements
Patient requirements (needs and expectations), rights, communication

A doctor's skill lies in discovering an ailment in a patient that both of them can live with. Albert Willemetz
Each medical biology laboratory places the patientperson from whom the sample is obtained at the heart of its management systemset of processes allowing objectives to be achieved (see also ISO 9000, 3.5.3) in order to respect their rights, needs and expectations, while ensuring the safetyabsence of unacceptable risk, confidentialityproperty of information accessible only to authorized persons (see also ISO 27000, 3.10) and qualityaptitude to fulfill requirements (see also ISO 9000, 3.6.2) of the services provided.
The purpose of the "Manage patient rights" processactivities that transform inputs into outputs (see also ISO 9000, 3.4.1) is to safeguard patientperson from whom the sample is obtained well-being and safetyabsence of unacceptable risk and to ensure respect for patientperson from whom the sample is obtained rights, cf. annex 03, includes the requirementexplicit or implicit need or expectation (see also ISO 9000, 3.6.4) to inform patientsperson from whom the sample is obtained about:

- services offered (examination methods, turnaround times, costs)
- communication channels (website, waiting room signage, patient information leaflets)
- results (format, interpretation, periodic review, delivery methods)
- incidents affecting patients and actions taken
- patient rights:
- to information
- to informed consent:
- to access their data and results
- to rectification
- to protection
- to be forgotten
- to confidentiality
- to lodge a complaint
- laboratory obligations (confidentiality, quality, safety, non-discrimination)
- communication tailored to specific patient needs (elderly, disabled, non-English speakers)
Good communication practices:
- simple language:
- avoid medical jargon in patient-facing communications
- use adapted explanations (diagrams, infographics for results)
- accessibility:
- formats adapted for people with disabilities (Braille, audio, large print)
- translation for non-English speaking patients (Spanish, Arabic, depending on the local population)
- multiple communication channels:
- online patient portal (secure access to results)
- mobile app (notifications for results)
- dedicated patient service (telephone line or live chat)
- the laboratory informs patients of their rights, specifically:
- right of access to their data (results, medical records)
- right to rectification (correcting errors in their data)
- right to be forgotten (data deletion after the statutory retention period)
- right to consent (for genetic testing or research)
- right to lodge a complaint (in the event of an error or delay)
- the laboratory must inform patients in the event of:
- error in results (sample mix-up)
- significant delay (turnaround time exceeded by more than 48 hours)
- breach of confidentiality (data leak)
The laboratory identifies patientperson from whom the sample is obtained needs and expectations by:
- gathering patient feedback (satisfaction surveys, suggestion boxes, discussions)
- analyzing data to identify trends (excessive turnaround times, results that are difficult to understand)
- segmenting patients to tailor services (chronic patients, emergency cases, children)
Examples of responses to patientperson from whom the sample is obtained expectations:
- improving turnaround times:
- automation of routine examinations (hematology, biochemistry)
- workflow optimization (24/7 sample reception)
- clarifying results:
- explanatory sheets for complex examinations (genetic tests)
- interpretation by a biologist for abnormal results
- facilitating access:
- home sample collection for patients with reduced mobility
- extended hours for sample collection (early morning, weekends)
- personalizing care:
- specific protocols for chronic patients (regular monitoring for diabetics)
- tailored communication for children or the elderly
An audit at the laboratory revealed that some patients were dissatisfied with the transparency of public information.
Actions implemented:
• a dedicated patient webpage was launched: patients can view average result turnaround times, pricing and sample collection procedures; they can also complete a satisfaction survey
• explanatory leaflets made available in waiting rooms, detailing examination procedures, average turnaround times for routine analyses (blood glucose, liver function tests)and contact details for inquiries
Results:
• no complaints regarding public information at the subsequent audit
• patient satisfaction survey showed 98% positive response
- patient rights are fully upheld
- results communicated to patients are validated and traceable
- patient needs and expectations are identified and respected
- communication with patients is clear and accessible
- the complaints process is simple and accessible
- results sent without explanation
- turnaround time not communicated to patients
- information sheets too technical for patients
- lack of privacy during sample collection (partially open collection room)
- written consent not requested for sensitive tests (HIV test, genetic testing)
- patient not informed of common side effects (bruising, dizziness)
- language barriers unaddressed (non-French speakers or the hearing impaired)