Home/Security & Compliance
Security & compliance

Built to protect data — and speed procurement

TSB is designed to run without holding protected health information. That, plus encryption and U.S. & Canadian data residency, helps your privacy and IT teams say yes faster.

Trusted by care teams across 68+ sites · 739K+ patients served

A clinician reviews the TSB admin dashboard securely on a tablet
Encrypted
In transit & at rest
PHI in flow layer
None by design
How we protect data

Privacy-first, by architecture

Security isn't a setting bolted on afterward — it's how the platform is built.

No PHI in the flow layer

The platform is designed to operate without storing protected health information.

Encrypted end to end

Data is encrypted in transit and at rest, with strict access controls.

U.S. & Canadian data residency

Data kept in-region to support FIPPA and provincial requirements.

Aggregate-only analytics

No patient names and no staff surveillance — insights measure flow, not people.

Role-based access

People see only what their role needs, with audit trails throughout.

PIA & procurement support

Documentation and answers to speed Privacy Impact Assessments and security review.

Clinician using the TSB admin panel
For IT & privacy teams

Fewer blockers between you and go-live

Because the flow layer avoids PHI and keeps data in-region, the questions that usually stall healthcare deals have answers ready.

  • No-PHI architecture reduces breach surface and review scope.
  • U.S. & Canadian data residency for FIPPA and provincial requirements.
  • Secure integration with your LIS and EMR, least-privilege by default.
  • Documentation ready for PIA, security questionnaires and procurement.
Security & compliance

Built for the standards you answer to

Privacy and security aren’t bolted on — they’re how the platform is architected, so IT and privacy teams can say yes faster.

HIPAA
U.S. health data
PIPEDA
Canada federal privacy
FIPPA
Provincial privacy
AES-256 encryption
In transit & at rest
Data residency
U.S. & Canada, in-region
WCAG 2.1 AA
Accessible by design
SOC 2 Type II
Confirm status
Verify
ISO 27001
Confirm status
Verify

TSB HealthCare is architected to support these frameworks; formal certifications and data-residency options are confirmed per deployment. See security & compliance

Questions, answered

Frequently asked questions

Does TSB store protected health information (PHI)?
The flow layer is designed to operate without holding protected health information, which reduces risk and speeds privacy review and procurement.
Is TSB HealthCare HIPAA compliant?
TSB is architected to support HIPAA (U.S.) as well as PIPEDA and FIPPA (Canada), with encryption in transit and at rest and role-based access.
Where is our data stored?
TSB supports U.S. & Canadian data residency, keeping data in-region to meet FIPPA and provincial requirements.
Can you support a Privacy Impact Assessment (PIA)?
Yes — we provide architecture details, data-flow documentation and answers to speed your PIA and security review.
Do you track staff or patients?
No. Analytics are aggregate-only, with no patient-name tracking and no staff surveillance.

Bring your privacy team

We'll walk your IT and privacy stakeholders through the architecture and answer the security questionnaire — book a 30-minute session.

Trusted by Leading Health Organizations
Vancouver Coastal Health Fraser Health Interior Health Provincial Health Services Authority Providence Health Care and more…