RFP radarCarepatron
AssessmentsRCMP, Request for Information for an Electronic Occupationa…

Assessment

RCMP, Request for Information for an Electronic Occupational Health Record System (WS5899493094)

No bid1 Nov · 31dscore 38
BuyerRoyal Canadian Mounted Police (RCMP), contracting through Public Works and Government Services Canada (PSPC)
WhereCA
SolicitationWS5899493094
Written1 Oct
Due1 Nov
Recommendation: do not bid

Second pass, after the 28 September review closed unresolved. The RFI itself is still unreadable without an SAP Ariba account. That no longer matters, because the question the review was waiting on has now been answered from two public sources and from our own claims library. The answer is no.

Recommendation: do not bid. Let it lapse. I have recorded a SKIP so it stops returning to the queue.

The check, answered

The check was: confirm Canadian data residency and Protected B hosting. Three facts close it, and none of them needed the RFI.

RCMP ADM 390 "Medical, Health and Wellness", covers "general health, medical, dental and wellness services for employees" and states: "This information is categorized as Protected B." The listed document types include treatments, referrals, medical assessments, immunization records and counselling. Source: RCMP-specific Classes of Records, rcmp.ca, read 1 October 2026.

sovereignty states: "The GC has published the Direction for Electronic Data Residency, which sets out the Canadian residency requirements for data at the Protected B, Protected C and Classified levels. These requirements are embedded in recent updates to the Treasury Board Policy on Management of Information Technology (section 6.2.7)." Source: canada.ca, GC White Paper: Data Sovereignty and Public Cloud, read 1 October 2026.

and Europe, and we cannot commit to a customer-selectable data region (known-gap-no-data-residency-choice). The published sub-processor list names AWS hosting in the US, Australia and Europe, and Google Cloud hosting in the US and Singapore (compliance-subprocessors). There is no Canadian region on either list.

Be clear about what this is and is not. I have not read the RFI, so I am not quoting a mandatory requirement from the solicitation. I am matching the buyer's own published classification of these exact records against the buyer's own published hosting rule for that classification. That is an inference, but a short and well-evidenced one, and it points the same way regardless of how the RFI is worded.

Protected B hosting is a second, separate barrier. Canadian Centre for Cyber Security assessment of the cloud service is the normal route, and nothing in the library speaks to it: [VERIFY: has Carepatron ever been assessed by the Canadian Centre for Cyber Security, or hosted Government of Canada Protected B data under any contract?]

What the buyer is buying, in more detail than we had

Worth recording, because the 28 September note read this as an HR records system and that read was too harsh.

The RCMP runs 11 Occupational Health Services offices across Canada. The teams are clinical: physicians titled Health Services Officers, Health Services Nurses, psychologists and administrative support. The services are periodic health assessments to confirm fitness for duty, disability management and accommodation, and psychological health screening. Regular members are assessed every three years, more often in high-risk positions. Source: Occupational Health Services, rcmp.ca, read 1 October 2026.

That is assessment, documentation, scheduling and case management delivered by clinicians in an outpatient setting. It sits nearer our core product than the commodity codes suggest. On size it also reads better than assumed: clinical staff users in the tens across 11 offices, with roughly the RCMP's employee population as client records, and unlimited clients is a positive for us rather than a cost.

What it still is not: there is no insurance billing or claims dimension, and the records are employer-held fitness-for-duty files rather than client-pays clinical care. The commodity codes point the same way, tagging software, human resources software, content management, data management and query, and cloud-based software as a service. No health code appears.

What changed since 28 September

Amendment 001, dated 29 September 2026. The visible change is the closing-time correction already recorded last time. Two details are new to our record:

  • The notice now carries a fifth UNSPSC code, 81162000 Cloud-based software as a service, alongside the four the 28 September note listed. I cannot tell whether the amendment added it or the earlier pass recorded four of five, because state.db overwrites the stored row on each fetch rather than versioning it.
  • Expected contract end date is 31 December 2028, which the earlier note did not have. An RFI carrying a contract end date suggests a real procurement runway behind it.

Neither changes the recommendation.

Routes tried today

The 28 September note tried the CanadaBuys page, the Ariba anonymous preview, our four portal accounts, and a web search. I repeated the first two and added the rest.

  1. CanadaBuys notice, by curl. Read in full. Metadata only, one-paragraph description.
  2. CanadaBuys open data CSV, the full openTenderNotice bulk file. This is the complete structured record and it carries no attachment or document field. It is where the contract end date and the fifth commodity code came from.
  3. Ariba Discovery anonymous preview, rendered with Firecrawl. Renders, and states the block: "The full Request for Information (RFI) and attachments can only be accessed and downloaded when logged into your SAP Ariba account and you have filled out your Government of Canada profile."
  4. Five aggregator mirrors, all new this pass: Govly, MERX, canadatenders.ai, EveryBid and mcloco. Every one carries the CanadaBuys metadata and none carries the document. canadatenders.ai states it outright: "Documents available: No" and "No public attachments are linked from this record yet." Govly adds NAICS 541511 and 541512. MERX shows no documents tab for this notice.
  5. Our four portal accounts, being BidNet Direct, NYS Contract Reporter, Virginia eVA and InstantMarkets. None federates to Ariba or CanadaBuys.
  6. SAP Ariba registration. Not attempted, deliberately. It submits Carepatron legal and tax details on a Government of Canada supplier profile, which is your call and not mine.

The document is not publicly available by any route I can reach. That is now confirmed across eight independent sources rather than assumed.

Why I am not drafting the request email

The standing rule is that when the public-records route is the last one left, I name the contact and draft the request for you to send. I am not doing that here, and the reason is that getting the document would not change the answer.

Even with the RFI in hand, we could not respond. Responses go through Ariba, and so does the Event Messages board that carries both the questions channel and every amendment. The account gates reading, asking and answering alike. So the email would buy us a document we could not act on, in pursuit of a bid we would lose on residency.

The contact is on file if you want it anyway: Aleksandra Karpik, Contracting authority, PSPC, [email protected]. Buying organisation is the RCMP, 73 Leikin Drive, Ottawa.

The score

38, down from 48.

Product fit and size fit both moved up once I read what RCMP Occupational Health Services actually does. Winnability and feasibility moved further down, and they dominate. We cannot meet the residency rule that governs these records, and we cannot read, question or answer the solicitation without an account you have not authorised. Below 45 is a SKIP under the rubric, so the verdict is recorded as SKIP rather than left open.

What would change the call

One thing: a Carepatron AWS Canada region, or any contractual commitment to Canadian data residency. That would reopen Government of Canada work generally, not just this notice. Worth knowing whether it is on the infrastructure roadmap, but that is a product question for another day, not a reason to hold this file open.

The separate question of whether Carepatron registers on SAP Ariba as standing infrastructure for Canadian federal tenders is still open from the 28 September note. My view is unchanged and now firmer: the residency gap makes Government of Canada procurement a poor market for us until that gap closes, so the account is not worth opening for this reason alone.

Machine-written first pass against the verified claim library. Not reviewed by a person unless the status says so.