Account, Pricing & Access

Account Security, 2FA, and Data

Your account controls access to your learning record, portfolio drafts, and any organisation you belong to. This article explains how to keep it secure and how to manage your data.

Changing your password

Open Account Settings → Security, enter a new password twice and click Update Password. Use a passphrase of at least 12 characters that you do not use anywhere else, and store it in a password manager.

If you signed up with Continue with Google or sign in through your institution, you do not have a PathologyLabTraining password; your Google account or institution manages it.

Resetting a forgotten password

Click Forgot password on the login page and enter your email. You will receive a reset link that is valid for a short time. If it does not arrive within a few minutes, check your spam folder; NHS mail servers sometimes filter it.

Changing your email address

You cannot change your email address yourself from Account Settings. The field is read-only and shows: "Email cannot be changed directly. Contact support if you need to update your email."

To change it:

  1. Email [email protected] from the email address currently on your account. This proves you control the existing inbox.
  2. Tell us the new address you want to use.
  3. We verify the request, confirm with the new address, and switch the account over.

If you have lost access to the current address (for example an old NHS account), write from any address and we will work through identity verification with you. That takes longer because we have to confirm you are the account holder.

If you sign in through your institution, your email is managed by them, not by us. Update it there first; we pick up the new address the next time you sign in.

Two-factor authentication (2FA)

Authenticator-app 2FA is currently used by platform administrators only. The 2FA panel under Account Settings → Security appears only for those accounts, so it is normal for the section to be absent on a standard account.

To harden a standard account today:

Sharing your training record with your organisation

If you belong to an organisation, Account Settings → Security has a Sharing your training record switch. It is off by default. Turned on, your organisation's administrators can see your name, last active date, modules attempted, number of attempts, recorded time and median score. They never see your answers, reflections or AI coach conversations. You can switch it off again at any time.

Exporting your data (GDPR)

Data export is not in Account Settings. It lives on the Data Protection page, linked from the site footer.

  1. Choose JSON or CSV.
  2. Click Request Data Export.
  3. The file downloads straight away, and we send an email confirming the export was made.

You can request one export per 24 hours. The file contains your profile, subscriptions and invoices, practice test results, AI coach sessions, training and CPD activity, organisation membership and invitations, newsletter preferences and consent records.

Deactivating or deleting your account

There are two paths. Both cancel any active subscription first, so no further payments are taken.

Before deleting, export anything you still need, and if you are an organisation administrator, hand the role to someone else first. See Your data and GDPR rights.

Suspected compromise

If you think someone else has signed into your account, change your password immediately from Account Settings → Security and email [email protected] so we can check the account with you.