Home/Security & Compliance
Security & compliance

Built to protect data — and speed procurement

TSB is PHI-minimal by design: name, email and phone only. Encryption in transit, in-region hosting options and a record of health-authority privacy and security reviews since 2018 help your privacy and IT teams say yes faster.

Trusted across 69 BC labs · 3.89M+ visits · 816K+ patient references (as of 10 Sep 2026)

A clinician reviews the TSB admin dashboard securely on a tablet
Encrypted
In transit
PHI held
Minimal by design
How we protect data

Privacy-first, by architecture

Security isn't a setting bolted on afterward — it's how the platform is built.

PHI-minimal by design

Name, email and phone only. No health numbers, requisitions, results or diagnoses.

Encrypted in transit

TLS on every connection, hashed credentials and strict access controls.

In-region data residency

Canadian and U.S. hosting options, confirmed in writing per deployment, to support BC health authority requirements under FIPPA and other provincial requirements.

Aggregate-only analytics

No patient names and no staff surveillance — insights measure flow, not people.

Role-based access

People see only what their role needs, with login and activity logging.

PIA & security review support

Privacy Impact Assessment and Security Threat and Risk Assessment processes supported at BC health authorities since 2018.

Track record

Reviewed by the people who have to say yes

What the platform has been through, with dates. We publish what we can evidence and nothing more.

In production since 2018

Live with BC public health authorities since 2018, across 69 active labs.

PIA & STRA processes since 2018

Privacy Impact Assessment and Security Threat and Risk Assessment processes supported at four BC health authorities.

Privacy schedule executed, 2020

A Provincial Health Services Authority privacy protection schedule executed under contract.

Penetration tested, 2024

Independent third-party penetration test completed under a National Research Council IRAP cyber-resilience mandate.

No known privacy breach involving the platform since launch. TSB HealthCare is designed to support HIPAA, PIPEDA and FIPPA.

Clinician using the TSB admin panel
For IT & privacy teams

Fewer blockers between you and go-live

Because the flow layer is PHI-minimal and hosting is in-region, the questions that usually stall healthcare deals have answers ready.

  • PHI-minimal architecture reduces breach surface and review scope.
  • Data residency in Canada or the United States for BC health authority requirements under FIPPA and other provincial requirements.
  • Secure integration with your LIS and EMR, least-privilege by default.
  • Documentation ready for PIA, security questionnaires and procurement.
Security & compliance

Built for the standards you answer to

Privacy and security aren’t bolted on — they’re how the platform is architected, so IT and privacy teams can say yes faster.

HIPAA
Designed to support
PIPEDA
Designed to support
FIPPA
Designed to support
Encryption in transit
TLS, hashed credentials
Data residency
Canada & U.S. options
PIA & STRA support
BC health authorities, since 2018
Penetration tested
Independent, 2024
Accessibility
WCAG 2.1 AA target

TSB HealthCare is designed to support HIPAA, PIPEDA and FIPPA. Data-residency options are confirmed per deployment. See security & compliance

Questions, answered

Frequently asked questions

Does TSB store protected health information (PHI)?
TSB is PHI-minimal by design. The booking and flow layer holds name, email and phone, plus login logs. It does not hold health numbers, requisitions, results or diagnoses.
Is TSB HealthCare HIPAA compliant?
There is no certification for HIPAA, PIPEDA or FIPPA. TSB is designed to support all three: PHI-minimal data, encryption in transit, role-based access and documentation for your review. It has supported health-authority PIA and STRA processes in Canada since 2018.
Where is our data stored?
In-region hosting options are available for Canadian and U.S. customers and are confirmed in writing as part of onboarding.
Can you support a Privacy Impact Assessment (PIA)?
Yes — we have supported PIA and security review processes at four BC health authorities since 2018 and provide architecture details, data-flow documentation and questionnaire answers.
Has the platform been independently tested?
Yes. An independent third-party penetration test was completed in 2024 under a National Research Council IRAP cyber-resilience mandate.
Has there been a privacy breach?
No. There has been no known privacy breach involving the platform since it went into production in 2018.
Do you track staff or patients?
No. Analytics are aggregate-only, with no patient-name tracking and no staff surveillance.

Bring your privacy team

We'll walk your IT and privacy stakeholders through the architecture and answer the security questionnaire — book a 30-minute session.

Trusted by Leading Health Organizations
Vancouver Coastal Health Fraser Health Interior Health Provincial Health Services Authority Providence Health Care and more…