>
Quintessentia Network logo QuintessentiaNetwork Inc.
AI Automation · Industry

For clinics & dental practices

The administrative paperwork around care — intake forms, referral letters, benefits verification, recalls — automated with health information kept inside a region you name. Administrative scope only. Nothing clinical.

Your front desk is
a data-entry desk.

A new patient fills in a form. Someone retypes it into the practice-management system. A referral arrives by fax or PDF and someone reads it, decides urgency, and books accordingly. A benefits check means logging into a portal, keying a policy number, and writing the result somewhere. A recall list gets worked by hand until the phone rings.

Every one of those is a person moving information between two systems that do not speak. It is also, for most practices, the reason the front desk cannot absorb another two hundred patients without another hire.

We do not touch clinical decision-making, triage severity, diagnosis or anything that shapes care. That boundary is in the statement of work, and it is not negotiable at any price.

The deciding question

Health information does not get to leave quietly

If you are a health information custodian in Ontario, PHIPA governs what your service providers may do with patient information. In Quebec, Law 25 adds its own requirements around transfers outside the province. In the United States, a vendor handling protected health information is a business associate and that relationship needs a signed agreement before any data moves.

None of that is satisfied by a vendor who cannot tell you which country processes the data. A great many AI development firms — including well-reviewed ones — operate from a single office on another continent, and their contracting entity is registered there too. That is a perfectly legitimate business. It is a poor fit for a patient chart.

We are incorporated in Ontario. We deploy into a Canadian region, a U.S. region, your own cloud tenancy, or hardware in your own building — your choice, named in the agreement.

Read our data commitments in full

What we will not claim

  • We are not SOC 2 certified and not ISO 27001 certified. We say so on every page where it matters.
  • There is also no such thing as a "HIPAA-certified" vendor. What exists is a signed business associate agreement plus a set of Security Rule controls you can inspect. Anyone selling you a HIPAA certificate is selling you a document with no issuer.
  • Your own counsel and privacy officer should review any arrangement before patient information moves. We will give them the architecture in writing to review — that is what the assessment produces.
Scope

What we automate — and what stays human

Administrative movement of information. Not care, not triage, not anything a clinician is accountable for.

01

New-patient intake

Completed forms — typed, handwritten, scanned or photographed — read and written into your practice-management system, with anything uncertain held in a review queue rather than guessed. Health history fields are transcribed, never interpreted.

02

Referral intake

Inbound referrals from fax, email or portal parsed for the administrative facts: referring provider, patient identifiers, requested service, stated timeframe, attachments present. Routed to the right list. Clinical urgency is assessed by your staff, not by us.

03

Benefits & coverage paperwork

Coverage details pulled from the documents patients supply and reconciled against what your system already holds, so discrepancies surface before the appointment instead of at the desk.

04

Recalls & unbooked follow-ups

The list of patients due for recall, assembled and prioritised from your own records, with outreach drafted for a human to review and send. A person always sends anything a patient will read.

05

Document filing

Incoming correspondence, lab paperwork and third-party forms identified, matched to the right chart and filed — with an audit record of every match so a wrong filing can be traced and undone.

Explicitly out of scope: diagnosis, triage severity, treatment recommendation, clinical note generation, and any output presented to a patient as clinical advice. If you want those, we are the wrong firm and we will say so on the first call.

Pricing

The same published prices as everything else

Prices in Canadian dollars, verified 23 August 2026. An advisory hour is CAD $195; fixed-scope advisory engagements start at CAD $4,500; minimum build engagement is CAD $9,500.

Start here
Automation Readiness Assessment — $12,500 (credited in full against a build within 90 days). Includes the data-residency and privacy memo your privacy officer will want to read before anything is built.
The build
From $26,000 for one document type across two intake sources; $48,000 for three types with separate rule sets and a full review queue.
Running it
$2,400 or $4,800 a month, hosted in your chosen region — or in your own tenancy at no hosting fee, which is what most clinics with a privacy officer end up choosing.

Full scope, inclusions and written exclusions →

Honest advice

When you should not buy this

  • When your practice-management vendor already ships it. Several major platforms now include digital intake forms that write straight into the chart. If yours does and you are still retyping, the answer is a configuration afternoon, not a build. Ask them first — we would rather you did.
  • Single-location practices under roughly 500 documents a month. The arithmetic does not clear our minimum. A digital form product at a few hundred dollars a month will serve you better.
  • When you have no privacy officer and no appetite to appoint one. Someone has to own the residency decision and the retention policy. If nobody will, the project stalls at the first review — and it should.
  • When what you actually want is clinical. Ambient scribing and note generation are a real and fast-moving category with specialist vendors. That is not us.
FAQ

Questions worth asking first

The questions a privacy officer asks first. If yours is not here, bring it to the first call.

Does any of this touch clinical decisions?

No. We do not touch clinical decision-making, triage severity, diagnosis or anything that shapes care — that boundary is in the statement of work, and it is not negotiable at any price. Diagnosis, triage severity, treatment recommendation, clinical note generation and any output presented to a patient as clinical advice are explicitly out of scope. On an inbound referral, clinical urgency is assessed by your staff, not by us.

Where does patient information actually live?

In a place you choose and we name in the agreement: a Canadian region, a U.S. region, your own cloud tenancy, or hardware in your own building. We are incorporated in Ontario. Our Canadian regions are AWS ca-central-1 (Montreal) or Azure Canada Central (Toronto), which is our default for work involving personal health information under PHIPA.

Are you SOC 2 or ISO 27001 certified?

No. We are not SOC 2 certified and not ISO 27001 certified, and we say so on every page where it matters. If your procurement process requires either certification from every vendor, we will not pass it today — and we would rather you learn that here than three meetings in.

Can a vendor be "HIPAA certified"?

No — there is no such thing as a "HIPAA-certified" vendor, and anyone selling you a HIPAA certificate is selling you a document with no issuer. What exists is a signed business associate agreement plus a set of Security Rule controls you can inspect. In the United States, a vendor handling protected health information is a business associate, and that relationship needs a signed agreement before any data moves.

What does it cost to start?

The Automation Readiness Assessment is $12,500, credited in full against a build within 90 days, and it includes the data-residency and privacy memo your privacy officer will want to read before anything is built. An advisory hour is CAD $195; fixed-scope advisory engagements start at CAD $4,500; minimum build engagement is CAD $9,500. Prices are in Canadian dollars, verified 23 August 2026.

Bring your privacy officer to the first call

The residency and retention questions decide the architecture, so they are worth settling before anyone writes code. The assessment produces the memo they will want to review.

See the assessment