We write the policies that keep client health information safe — and keep you compliant with BC's PIPA and Canada's PIPEDA.
Intune, Purview and Defender configured to lock down devices, encrypt data in transit, and catch breaches before they spread.
Clear, practical device policies for contractors and BYOD staff — password rules, encryption, screen locks.
A step-by-step plan for the day you hope never comes, so your team knows exactly who to call.
Keep client data on Canadian soil and retained for exactly as long as regulations require.
Move off fragile spreadsheets onto secure, auditable systems that scale with your practice.
We map your tools, data flows, and gaps against PIPA/PIPEDA.
Policies and safeguards sized to your practice, not a hospital system.
We configure Microsoft 365, devices, and workflows with your team.
Annual audits keep you compliant as regulations and your practice evolve.
Sitka Labs is built to work the way small healthcare practices do: one point of contact, plain-language guidance, and solutions sized to small clinics — not enterprise IT.
Meet the team →We helped a Vancouver-based occupational therapy practice move off a managed-partner Microsoft plan, harden device compliance for a fully remote contractor team, and stand up a breach response plan — closing gaps identified during a security review.
Read the case study →
Book a free 30-minute consultation. We'll review your current setup and outline where the risks are.
Vancouver, BC, Canada · hello@sitkalabs.ca