Last updated: July 31, 2026
RivalQuest Health ("we", "us", "our") is a private-pay service that helps Canadian patients arrange diagnostic imaging at facilities in the United States and consultations with specialist physicians. To do that, we collect and handle personal health information.
This policy describes our information practices in plain language: what we collect, how we use it, where it is stored, who we share it with, how we protect it, and the rights and choices you have. We handle your personal health information in accordance with Ontario's Personal Health Information Protection Act (PHIPA).
Our Privacy Officer is responsible for our privacy practices and is your contact for any question, access request, correction request, or complaint. You can reach the Privacy Officer at support@rivalhealth.ca.
We do not sell your information. We do not use it for third-party advertising. We do not run third-party analytics or tracking scripts on this site.
Your records live on Amazon Web Services (AWS) infrastructure in the Canada (Central) region: our application database, our encrypted file storage (protected with an encryption key that we control), our sign-in service, and our email-sending service all reside in Canada. Data is encrypted in transit and at rest.
Our public website pages (marketing content, pricing, this policy) are delivered through a content delivery network with servers in North America and Europe so pages load quickly. Only public website content travels through that network — your health information never does. When you use the portal, your records come directly from our Canadian servers over an encrypted connection.
All of our systems run on Amazon Web Services in the Canada (Central) region, as described under "Where your information is stored" above: the database holding your records, the encrypted storage holding your documents, the sign-in service holding your account credentials, and the service that sends our emails. AWS processes this information on our behalf, in Canada.
This is the core of what we do, and the most significant disclosure. When you submit an imaging request, we send the U.S. imaging facility what it needs to perform your scan: your name, date of birth, contact details, the type of scan and body part, the reason for the exam, and your referral. When you request a specialist consultation, your request and the medical history or imaging documents you attach are sent to the U.S.-based specialist.
We only do this with your explicit consent, recorded when you join and confirmed with each request. Once a U.S. provider receives your information, it is handled under U.S. law (primarily HIPAA) and the provider's own records policies rather than PHIPA, and it may in some circumstances be accessible to U.S. authorities in ways that differ from Canadian law. U.S. providers keep their own records according to their own legal obligations — deleting your information from RivalQuest Health does not remove it from their files.
Diagnostic imaging requires a referral from a Canadian physician. We fax the requisition we prepare to your referring physician for review and signature, and your imaging report is also sent to that physician, who is your primary contact for follow-up care.
Requisitions and results move between us, physicians, and imaging facilities by fax. We use SRFax, a Canadian fax service provider, to send and receive these documents. Faxed documents (which include health information) pass through and are held by SRFax in Canada as part of providing that service.
Payments are processed by Stripe. The billing details you enter in the payment form — your name, card number, and billing address — go directly to Stripe as the payment processor and are handled under Stripe's own security certifications. Separately from what you enter, we attach a limited set of request details to the payment: your account identifier (a random code, not your name or email), the type of exam being paid for (for example "MRI"), and a service description; for membership payments, the plan and its duration. Stripe is a U.S. company, so this payment information is processed and stored in the United States. This transfer is part of the cross-border consent you provide.
We send transactional email (account setup, payment re-authorization requests, and "you have an update" notices) through Amazon's email service in Canada. Notification emails are deliberately minimal: they tell you that an update or message is waiting and never include your health details, which stay in the secure portal.
Messages sent through the public contact form are emailed to our support address, which currently uses a third-party mail-forwarding service (ImprovMX) to relay messages to the mailbox we read. Your contact-form message therefore transits that forwarding service and remains in our support mailbox as our record of the conversation. This is why we ask you not to include health information in the contact form — signed-in members should use secure messaging instead.
When you look up your referring physician while filling in a request, the name (and optionally postal code) you type is checked against the College of Physicians and Surgeons of Ontario's public register to find a match. The search is logged on your account. Only the physician details you typed are sent — none of your health information.
We may disclose information where PHIPA or another law permits or requires it — for example, in response to a court order.
Because sending your health information to U.S. providers is central to the service, we treat that consent carefully:
We keep your records while your account is open so we can coordinate your care and show you your history. You are in control of two deletion paths, described under "Your rights" below. When records and documents are deleted, they are removed from our live systems immediately, and residual copies in our backup and recovery layer clear within 90 days. Audit logs and consent records are kept even after health records are deleted — they are the accountability trail PHIPA expects us to maintain, and they record events (who accessed what, and when), not the content of your health records. Where a law requires us to keep a record for a minimum period, we keep it for that period. Records already in the hands of your physician or a U.S. provider are governed by their retention obligations, not ours.
We do not use advertising cookies, third-party analytics, or tracking pixels. The browser storage we use ourselves is the per-tab session storage that keeps you signed in while a tab is open; it is cleared when the tab closes. One exception to note: on payment screens, Stripe's own payment script runs and may set its own cookies, which Stripe uses for fraud prevention as described in Stripe's privacy policy.
When we change this policy, we will post the new version here with an updated date. If a change is significant — a new type of disclosure, a new processor handling health information — we will notify you and, where the change affects a consent you have given, ask you to review and accept the updated notice before it applies to you.
Privacy Officer, RivalQuest Health — support@rivalhealth.ca. We will respond to access requests, correction requests, and complaints as PHIPA requires.