Search Health Tests
i-screen logo

Who Should You Trust With Your Health Data?

2 September 2026Brad Ryan Chief AI Officer

Health testing has never been easier to buy. Order online, take a cheek swab, pee in a cup or roll up your sleeve, and a few weeks later a slick app tells you something about your biology. The category has exploded, and that is mostly a good thing. More people paying attention to their health earlier is exactly the outcome we have been pushing for over the last 11 years.

But there is a question that gets skipped in the rush, and it is the most important one you can ask before you hand over a sample.

Who is looking after this data, and what happens to it after the results are processed?

Your health data is not like other data. A leaked email address is an inconvenience. Your genome, your blood chemistry, your hormone profile and your gut microbiome are deeply personal, and in some cases predictive of things you have not experienced yet. Your DNA is permanent and you can't change your DNA the way you change a password.

So before you choose who to test with, here is what to look for.

The 7 questions to ask a health testing company

These are the questions we would want asked of us, and that we think you should ask of anyone offering to analyse your biology.

1. Where is my health data physically stored?

At i-screen, your data is held in your own country. We run a separate environment for each market: Australian data in an Australian environment, Singapore data in a Singapore environment, United Kingdom data in a United Kingdom environment. These are separate systems with separate databases, not partitions of one global platform. Your records are not commingled with another country's.

Why this matters: "the cloud" is not actually where your data is stored. Data lives in a data centre, in a country, under that country's laws. If your results are processed and stored offshore, they can fall under legal regimes that have nothing to do with the protections you have at home.

Those laws are genuinely different by country, which is the point. Australian customers are protected by the Privacy Act 1988 and the Australian Privacy Principles. United Kingdom customers are protected by the UK GDPR and the Data Protection Act 2018. New Zealand customers are protected by the Privacy Act 2020 and its Information Privacy Principles, including the Health Information Privacy Code. Singapore customers are protected by the Personal Data Protection Act. Keeping each market's data in its own environment is what lets i-screen apply the right one of those policies to your data, rather than the most convenient one.

Running four environments costs more than running one. We do it because data protection law is national, and the cleanest way to respect four countries' rules about their citizens' health information is to keep that information in the country it belongs to, rather than moving it somewhere convenient and papering over the difference with legal agreements.

We will be straight about the one exception. New Zealand customers are served from a dedicated New Zealand environment that is currently hosted in Australia rather than NZ. It is a separate environment with separate data, but it is physically in Australia, and New Zealand privacy law has specific rules about that, which we follow. We would rather tell you plainly than round it up to a neater claim.

If you want to know where your records sit, ask us. We can answer precisely. That is a question worth putting to any provider.

2. Can I see everything you hold on me, and can I have it deleted?

Yes to both, and both are documented processes rather than something we do as an exception. You can request a full copy of the personal information we hold about you, and you can request deletion. Our Privacy Policy sets out how.

There is one nuance we will explain. Clinical records carry minimum retention periods set by law, so "delete everything now" is not something any legitimate health provider can offer you. The period is not the same in every country, and the one that applies to you is the one in your market.

| Where you are | Minimum retention period | Where that comes from | | --- | --- | --- | | Australia | 7 years from your last service, or until you turn 25 if you were a child at the time | Health Records Act 2001 (Vic) and the equivalent state health records legislation | | United Kingdom | 8 years after your last test or appointment, or until your 25th birthday if you were a child at the time | The NHS Records Management Code of Practice, the recognised standard for health records in the UK | | New Zealand | 10 years, starting the day after we last provided you a service | Health (Retention of Health Information) Regulations 1996 | | Singapore | 6 years from your last consultation, or until you turn 24 if you were a child at the time | Licence conditions on the retention of patient health records, made under the Healthcare Services Act 2020 |

It's worth noting how much that varies by region. The same set of results would be kept for six years in Singapore and ten years in New Zealand. It is a good illustration of why a generic "we comply with health records law" is a weak answer from any provider operating in more than one country, and why we at i-screen would rather show you how we treat your data in each region specifically.

What happens in practice is the same in all four. When you ask us to delete your account we deactivate it immediately, stop all communications, remove your identifying details from customer-facing systems, and then securely destroy the underlying clinical record once the retention period above expires.

The rights themselves also vary a little by market. Access and correction exist everywhere we operate. United Kingdom customers additionally have the erasure and other rights that come with the UK GDPR, and can escalate to the Information Commissioner's Office if they are not satisfied with how we handle a request.

If a provider cannot tell you where your data sits, how long they keep it, or how to get a copy, that should be a red flag.

3. Who is actually running the laboratory test?

We use accredited laboratories in every market we operate in, and every panel is mapped to the laboratory best placed to run those specific tests.

The analysis is only ever as good as the laboratory doing it, so this is worth checking properly. Each country runs its own accreditation scheme, and the relevant one depends on where your sample is analysed.

| Where you are | What our laboratories hold | | --- | --- | | Australia | NATA accreditation to ISO 15189, assessed by the National Association of Testing Authorities | | United Kingdom | UKAS accreditation to ISO 15189, assessed by the United Kingdom Accreditation Service | | New Zealand | IANZ accreditation to ISO 15189, assessed by International Accreditation New Zealand, with one partner additionally meeting the national pathology accreditation standard | | Singapore | Licensed by the Ministry of Health under the Healthcare Services Act, and accredited by the College of American Pathologists for high-complexity clinical pathology |

ISO 15189 is the international standard specifically for medical laboratories. It covers technical competence, quality management and the integrity of the result, which is a higher bar than a general quality certification.

Two things about that table are worth drawing out.

First, NATA, UKAS and IANZ are all signatories to the ILAC Mutual Recognition Arrangement, the international agreement under which accreditation bodies recognise each other's assessments. So an accredited laboratory in Auckland and an accredited laboratory in London are being held to the same international standard, not to whatever each country decided was good enough.

Second, Singapore's clinical laboratory regime works differently: our laboratory there is licensed by the Ministry of Health and accredited by the College of American Pathologists (CAP), rather than carrying a local ISO 15189 accreditation. That is the accurate description, so that is what we publish.

A small number of highly specialised assays, such as fatty acid profiling and pharmacogenomics, are run by dedicated laboratories rather than general pathology providers. Where a specialist laboratory sits outside a national medical accreditation scheme, we require continuous participation in recognised international external quality assurance programmes, which is the mechanism by which a laboratory's results are independently checked against peer laboratories worldwide on an ongoing basis. Where the specialist laboratory is in the United States, that includes CLIA certification. We would rather tell you which mechanism applies, rather than describe everything as "accredited" and leave you to assume they are all the same thing.

The labs we work with have been carefully chosen and these lab partnerships were not formed overnight. They have been built by working alongside our laboratories year after year, sample after sample, through method changes, reference range updates, edge cases, and the occasional result that needed a phone call rather than an email. That is how you come to understand a laboratory's processes well enough to trust them with someone's health.

It is also why a new provider cannot simply buy this. Laboratory capacity is available to anyone with a purchase order. Earned trust between a testing company and its laboratories is not, and it is the difference between a result being processed and having the confidence that a result is right and will be delivered on time.

4. Who reviews my blood test results before I see them?

A qualified health professional reviews and approves every result before it reaches you, and there is a documented record of who reviewed what.

i-screen operates under its own medical governance, led by our Medical Director, with a clinical team and a formal Clinical Governance Framework behind it. That framework covers how results are reviewed and approved, how critical results are escalated and communicated, what reference ranges we apply and on what basis, how interpretive content is written and controlled, and who signs off on changes.

This is where the gap between providers is widest. Generating a report is trivial. Having qualified clinicians accountable for what that report says is not.

5. If AI is used on my results, how is it controlled?

Most of what you read in an i-screen result is not generated by AI at all. The clinical interpretation comes from a rules engine our clinical and science teams built and maintain, so the same inputs always produce the same output and every statement traces back to a source. We use AI for the summaries and scorecards that sit on top of that, the prompts behind them are controlled and auditable, and a clinician approves the output before it reaches you.

That distinction matters. Generative models are good at turning dense pathology into language you can act on, and the wrong tool for deciding what your results mean, because you cannot audit a sentence that was invented on the spot. So we do not use them for that. We have written separately about how we use AI at i-screen.

On your data: we do not sell your identifiable health information, and we do not give your personal health information to third parties to train their AI models. We do use de-identified data to improve our own reference ranges and interpretation. Our Privacy Policy also allows us to use de-identified data for research and to provide it to research partners, including on a commercial basis, under contracts that prohibit any attempt to re-identify it. You have the ability to opt out from having your de-identified data included if you prefer.

The question is not whether a company uses AI. It is whether they have put guardrails around it, and you do not have to take anyone's word for what good looks like. Australia's guidance for AI adoption, the OECD principles New Zealand adopted, the United Kingdom's five cross-cutting principles, Singapore's governance frameworks and the United States NIST framework were written separately and landed on the same five things.

| Principle | What it means | | --- | --- | | Accountability | A named human is answerable for what the AI does | | Transparency and explainability | You should be told AI is involved, and the basis for what it says should be inspectable | | Fairness | The system should not produce discriminatory outcomes | | Reliability and safety | It should work, be tested, and be monitored over time | | Human oversight and contestability | A qualified person reviews the output, and you can challenge it |

That is a checklist you can use on anyone, including us. Ours: our Clinical Governance Framework names who is accountable for AI-generated content, with our Medical Director above it. We publish how we use AI, and the prompts behind our interpretations are controlled and auditable. A clinician reviews and approves output before release, and if you think something is wrong, raise it and a human will look at it.

Fairness is the hardest of the five, so we would rather be specific than claim it solved. The material our interpretations draw on is clinically supported rather than scraped from the open internet, and we use your health profile, your age, sex, ethnicity and your own test history, to tailor what you are told where that is appropriate and possible. Reference ranges are set by our clinical and science teams in alignment with the laboratory running each specific test, rather than applied generically. The limits are real as well: generative models carry bias from the data they were trained on, and demonstrating fairness rather than asserting it needs evidence we are still building.

Two of those five have become the dividing line for regulators rather than a nice-to-have: whether a qualified human can independently review what the AI produced, and whether you are told AI was involved at all. Not how sophisticated the model is. Whether its work can be checked.

None of this makes us special. It makes us checkable, which is the more useful property.

6. What stops my data being breached?

Encryption in transit and at rest, multi-factor authentication, role based access control, ongoing penetration testing by an independent security firm, secure development practices, backup and disaster recovery, and a documented breach response plan.

Every company will tell you they take security seriously. The meaningful question is what they have actually built, and what each of those things is for.

Encryption means data taken is unreadable. Multi-factor authentication means a stolen password on its own does not get anyone in. Role based access control means our own staff can only reach what their job requires, rather than being able to browse the database. Penetration testing means we pay specialists to try to break in before someone else does, and we fix what they find.

There is also a structural answer, and it is the reason question 1 matters more than it first appears. Each market runs in its own separate environment, so a compromise of one does not expose the others. A provider running a single global system has no such containment: one breach reaches every customer they have.

We would rather not pretend a breach is impossible, because no system is immune and any company claiming otherwise is not being straight with you. So what matters next is how quickly we would know and how contained it would be. Access is logged and monitored, and our response plan is written and documented rather than something we would improvise on the day. If a breach ever did put you at serious risk, we are legally required to tell you and to notify the regulator in your country, and we would.

We are also working through a formal certification programme, including ISO 27001 for information security, SOC 2, and GDPR alignment for our UK and European customers. Certification is a multi-year discipline rather than a badge you buy, and we will tell you where we are up to as each one completes.

7. Are your reviews verified, and what do the bad ones say?

i-screen holds more than 2,300 verified customer reviews with an average rating of 4.78 out of 5. 96% are 4 or 5 stars, and 94% of reviewers wrote something rather than just clicking a rating.

Here is the part worth understanding, and it is another thing you can check rather than take on faith.

Our reviews are collected by Feefo, which is invitation-only. Feefo invites customers after a real, completed transaction, and only those verified customers can leave a review. Anonymous submissions are not possible. That is a meaningful difference from open review platforms where anyone can post about a company they have never bought from, and where fake reviews are posted in the millions each year.

So when you read an i-screen review, you are reading someone who actually ordered a test, gave a sample, and got a result. Every review carries a "Feefo Verified" marker. Reviews are voluntary and we do not incentivise them.

What the reviews show

| Metric | Figure | | --- | --- | | Verified reviews | 2,300+ | | Average rating | 4.78 out of 5 | | Rated 4 or 5 stars | 96% | | Reviewers who wrote comments, not just a rating | 94% | | Collection method | Feefo, invitation-only, verified customers only |

Figures at the time of writing. Our live review feed is on our website and on Feefo, updated continuously.

We also read the bad ones

A 4.78 average means we do not get it right every time, and we would rather be straight about that than pretend otherwise.

We categorise every review below five stars into themes and track them, because that is where the useful information is. Those review categories drive product and operational work and input into how we write and review interpretive content.

That is worth asking any provider too. Not "do you have good reviews", but "what do your worst reviews say, and what did you do about them?" A company that cannot answer the second half is not really using its feedback.

And the question almost nobody asks: how do you keep up when the rules change?

We maintain a per-market view of what applies to us and what is coming, reviewed quarterly, and where a market is clearly heading somewhere we build to the stricter position early rather than waiting for the deadline.

Almost nobody asks this one, and it may be the most revealing question of the lot.

The rules governing AI in healthcare are changing faster than almost any area of regulation, and they are changing differently in every country. In the past 12 months alone:

  • Australia announced it will legislate mandatory national AI standards and established a new Office of AI, and South Australia called a Royal Commission into AI that will examine health
  • The United Kingdom's medicines and healthcare regulator published the findings of a national commission on regulating AI in healthcare, including a call for evidence that 760 people and institutions responded to, with recommendations due shortly
  • Singapore published refreshed AI in healthcare guidelines, including a section specifically about direct-to-consumer services like ours
  • New Zealand extended its privacy notification rules

A provider operating in a single country can perhaps afford to react. We operate in Australia, New Zealand, the United Kingdom and Singapore, which means four regulators, four sets of privacy law and four medical device regimes.

Two examples of building early: Australia's automated decision-making transparency rules commence in December 2026 and we built to that standard ahead of the date. The European rules requiring you to be told when you are interacting with an AI took effect in August 2026, and we apply that everywhere rather than only where it is compulsory.

We also participate rather than only comply. Where governments and regulators consult on how health AI should be governed, we put our operating experience on the record, because rules written without input from the people running these systems tend to miss the mark.

None of that is glamorous, and it is a permanent cost rather than a project that finishes. But the alternative is a provider who was compliant on the day they launched and has not looked since, and from the outside you would have no way of telling the two apart.

Why 11 years and 147,000 customers matters for data security

More than 147,000 people have tested with i-screen across 11 years in service. We have completed over 1.1 million health tests, and more than 4,000 practitioners use our platform to support their patients. A large proportion of those customers have come back and tested again, and more than 2,300 have left a verified review.

We say that for one reason: time is the only thing that proves a company can be trusted with data.

11 years means every result we have ever issued is still auditable. It means we have operated through changes in privacy law, cloud security expectations and clinical guidance, and adapted each time. It means our clinical governance has been built and refined against real cases rather than drafted for a funding round. It means our laboratory relationships are measured in years, not contracts.

It also means we hold a longitudinal view of health data that only accumulates with time, which is precisely what makes repeat testing more valuable each time you do it.

New entrants can match a price or offer a pretty interface. What they cannot compress is track record. A company that launched last quarter has not yet had to answer a regulator, manage a critical result at 9pm on a Friday, migrate a decade of records, or prove that its access controls work. We have.

There is also a harder question worth sitting with. If a testing company is funded to grow fast by investors and priced to undercut the market, where does the money eventually come from? Health data is valuable, and the pressure to monetise it does not usually announce itself in the marketing campaign.

We have built our business by providing our customers quality health test information for eleven years. What we do and do not do with your data is set out above and in our Privacy Policy. You do not have to take our word for it, you can check it.

Prioritising the handling of your health data

i-screen's first company value is accuracy and privacy above all else. It sits above growth and above speed on purpose, because in this business the two are not separable. Data you cannot trust is not accurate, and results you cannot verify are not safe.

So test. Test annually, ideally, because the whole point of screening is catching things while they are still easy to deal with. But choose deliberately:

  • Ask where your data lives, and which country's law therefore protects it
  • Ask which accreditation their laboratory holds in your country, and who assessed it
  • Ask who reviews your results
  • Ask which parts of your result an AI model wrote, and who checked it
  • Ask who is accountable when something is wrong
  • Ask what the retention period is in your country, and what happens to your record when it runs out
  • Ask which regulator they would have to notify if something went wrong
  • Ask whether their reviews are verified, and what the bad ones say
  • Ask how they keep up when the rules change

We are comfortable being asked all of it.

If you have questions about how we handle your data, our team is at info@i-screen.com.au, and our Privacy Policy is available on our website.

Image of Brad Ryan Chief AI Officer
Brad Ryan Chief AI Officer

Brad Ryan is the Chief AI Officer at i-screen, where he leads the company’s AI strategy across products, operations, and customer experience. Before joining i-screen in 2026, Brad spent over five years at Amazon Web Services (AWS) as the APJ Data and AI Partner Lead, helping organisations across Asia Pacific and Japan adopt data, analytics, and machine learning at scale. Prior to AWS, he spent 25 years at Accenture, most recently as Managing Director leading AI capability across ANZ and APAC. Brad holds a Bachelor of Commerce from Deakin University and is a Graduate of the Australian Institute of Company Directors (GAICD).

You may also be interested in

human-ai-960x760
How We Use AI at i-screen
15 April 2026Brad Ryan Chief AI Officer
Read more
woman wearable data blog feature
How We Protect Your Data at i-screen
1 June 2025Yansen Sudharsono (MIS)
Read more