BD Pyxis
This record covers BD's medication dispensing estate as sold to hospital pharmacy: the BD Pyxis family of automated dispensing systems and the BD HealthSight analytics layer that runs on top of it. Becton Dickinson as a whole is far too broad to grade on these axes, spanning syringes, catheters, surgical instrumentation and much else, so the parent is noted here rather than indexed. BD's own securities filings draw the same boundary this record does, separating the Dispensing quality management system from the Infusion quality management system that governs BD Alaris. Alaris sits outside this record.
The hardware is the Pyxis ES portfolio: MedStation ES dispensing cabinets with CUBIE pocket technology, Anesthesia Station ES for the operating room, MedBank countertop and restricted access stations for controlled substances and temperature sensitive stock, supply dispensing cabinets, and Med Link Queue and Waste for witnessed disposal. It reached BD through the $12 billion CareFusion acquisition in 2015 and is still manufactured by CareFusion 303, Inc. in San Diego.
The intelligence sits in BD HealthSight. Diversion Management is the substantive machine learning product. It draws on dispensing behaviour and the electronic medical record, compares an individual clinician against a dynamically selected peer group within the facility, produces an individual risk score, and names the behaviours that contributed to it, including overrides, cancelled transactions, and delays in dispensing, administering and wasting medication. It automates controlled substance reconciliation, flags discrepancies, and routes cases into an investigation workflow with assignment to named investigators. Inventory Optimization and the HealthSight Viewer complete the layer.
Two things make this record unusual and both belong in front of a buyer. The mechanism description is more specific than anything else in this lane, naming the signals and the comparison population rather than stopping at the phrase predictive analytics. And the regulatory and security record is documented in extraordinary detail, because securities law and coordinated vulnerability disclosure compelled it. A November 2024 FDA Warning Letter cites the dispensing quality system, and BD carried a $68 million liability for the response as of March 2026. Five cybersecurity advisories reached the Cybersecurity and Infrastructure Security Agency between 2018 and 2022. None of that is concealed, and a buyer here has more primary source material to work with than for any comparable product. What that material says is a separate question from how completely it is available, and the grades below keep the two apart.
Capability Axes
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read
The estate is dispensing hardware and the models are a layer above it. HealthSight Diversion Management is the substantive machine learning product and Inventory Optimization the second. Remove both and the Pyxis cabinets still dispense, reconcile and report across every installed hospital, because that is what they did for the two decades before the analytics existed. The grade describes where the models sit in the product rather than how good the automation is, and the same reading applies to the direct competitor in this lane.
The oversight design is described rather than implied, and it is careful. The model surfaces clinicians as areas of investigative focus rather than as findings, the behaviours contributing to a risk score are specified back to the user, and output is routed into a case workflow where a human investigator is assigned and documents the review.
Feature level explanation plus a named human decision point plus deliberately hedged output language is a stronger position than most vendors in this index hold, and BD reaches it without needing a governance document to say so. It falls short of the top grade because no threshold, escalation rule or reviewer qualification is published, so the strength rests on product design that a customer can see rather than on a commitment the vendor has made.
The mechanism is described with more specificity than anything else in this lane. Machine learning is named as the method, the input signals are enumerated rather than gestured at, covering overrides, cancelled transactions and delays in dispensing, administering and wasting, the comparison population is defined as a dynamically selected peer group, the output is an individual risk score, and the contributing behaviours are surfaced with it.
A buyer can form a real mental model of how a score arises. What is missing is any measure of whether it is right: no accuracy, precision, recall or false positive figure, no validation study and no description of how the model was trained or is monitored for drift.
No model provider, framework or third party analytics supplier is named for the machine learning in the analytics layer, and no distinction is drawn between capability built inside the medication management business and capability licensed from elsewhere.
The dispensing estate is the more informative half on supply chain generally, since the cybersecurity bulletins identify affected components at product version level, but that visibility covers the software estate rather than the models running on top of it.
The unusual feature of this record is that the substantial body of operational evidence is adverse and comes from the regulator rather than the vendor. The FDA Warning Letter of November 2024 documents more than 92,000 complaints of dispensing system malfunctions causing medication delivery delays, including reports of life threatening situations, 70 complaints of incorrect medication dispensed, and 111 open software defect tickets classified as catastrophic or severe.
On the vendor side the material is thin by comparison: a customer statement from University of Rochester Strong Memorial Hospital on inventory labour, and a category level statistic that 68 percent of medication errors occur during administration. The C reflects that a buyer can actually find out how this product behaves in the field, at a level of detail no marketing page would supply. It should not be read as a favourable finding.
One detail here is better than the lane norm and worth crediting: the peer group a clinician is scored against is stated to be dynamically selected within the facility, which implies the comparison population is the customer's own staff rather than a pooled cross customer model. That is a specific and checkable scoping claim. Everything around it is unaddressed.
Whether dispensing and behavioural data trains models that persist beyond the tenant, what retention applies to the hosted analytics, and whether a departing customer's data is destroyed are not covered anywhere published. Extending the peer group statement into an explicit training and retention commitment is the single change that would move this grade.
Protected health information appears in the published material almost entirely as something that was at risk. Two coordinated disclosures in 2022 describe default and hardcoded credentials on specific Pyxis products, both scored 8.8 of 10, with the stated consequence being privileged access to the file system and to electronic protected health information.
Against that, no business associate agreement position, no data ownership statement and no security certification covering the dispensing estate were surfaced by two passes. Acknowledging that a vulnerability could expose protected health information is a responsible disclosure practice and is not a posture on how that information is handled in normal operation, which is what this axis asks for.
Two findings pull in opposite directions and the grade sits between them. The disclosure apparatus is genuinely mature: BD runs a public product security bulletin, publishes affected product lists it commits to updating, gives interim mitigations, and voluntarily reports through the Cybersecurity and Infrastructure Security Agency coordinated disclosure programme, to the FDA, and through the Health Information Sharing and Analysis Center.
Few vendors in this index operate anything comparable. The record that apparatus documents is poor: five advisories in five years, default credentials and hardcoded credentials on specific products both scored 8.8 of 10 with electronic protected health information as the stated exposure, and four cybersecurity items among the software defects the FDA classified as catastrophic or severe.
No third party certification such as HITRUST or a service organisation control report covering the dispensing estate was located in two passes. Telling buyers the truth about your weaknesses is worth real credit and is not a substitute for not having them.
The dispensing business is under an open FDA Warning Letter issued in November 2024 against the quality management system at the San Diego facility of CareFusion 303, Inc., citing the quality system regulation, medical device reporting, and the corrections and removals reporting requirements.
BD recorded a $68 million liability for the response as of March 2026 and reported in its filing for the quarter ended June 2026 that the commitments have been completed, while stating that the ultimate resolution and any further FDA action remain unknown. A separate consent decree covers the infusion business at the same site and is outside this record. The grade reflects an impaired and unresolved regulatory standing on the product itself. It should not be read as a disclosure failure, because the disclosure is complete, primary source and traceable quarter by quarter, which is more than most vendors in this index offer about anything.
No governance position, validation summary, false positive rate or appeal route was located for a model whose output is an individual clinician identified as higher risk for drug theft. That is the most consequential model output in this lane and the least governed.
The bias mechanism is concrete rather than theoretical: a score built from overrides, cancellations and timing delays will attach to the staff whose work is most interrupted, which tends to mean the busiest units, night shifts and the least senior clinicians, and a peer comparison inside one facility inherits whatever the local staffing pattern already is. Trade coverage of this category names false positives as the central risk precisely because they alienate clinicians, and nothing published tells a nurse how a score against them can be contested.
Nothing published addresses what happens when the model is wrong, and the exposure here has a named victim by design. A false diversion score attaches to an identified clinician and enters an investigation workflow that generates documentation about them, with employment and professional licensure consequences downstream.
There is no published statement of who owns the determination, what standard of evidence the score is meant to meet, whether the clinician is told they were scored, or how a score is challenged or withdrawn. The product is careful to call its output a focus for investigation rather than a finding, which is the right framing, and no commitment anywhere converts that framing into a recourse a clinician could actually use.
Integration is load bearing here rather than decorative. The analytics layer explicitly consumes the electronic medical record alongside dispensing data, which is what allows reconciliation between what was withdrawn and what was documented as administered, and that join is the product.
At the cabinet level the ES platform integrates with the pharmacy information system and with Active Directory for enterprise identity, and the HealthSight Viewer presents dispensing and infusion alerts together in one view. The grade stops below the top band because specific electronic medical record vendors and the depth of each integration are not named publicly.
The split between the two halves of the estate is clear: the cabinets and their servers are customer premises equipment and the analytics layer is described as hosted and cloud based. Beyond that the hosting is undefined. No cloud provider, no region, no residency commitment and no customer option to constrain any of it were located, which matters more here than usual because the hosted half is the half holding behavioural data about named clinicians. A buyer can tell which component sits where and cannot tell where the hosted one actually is.
No price is published for the cabinets, the analytics layer or the service contracts, and the estate is sold as a configured multi year enterprise agreement rather than a listed product. What the parent discloses is investor facing and arrives through securities filings, including the $68 million liability recorded for the warning letter response, which tells a shareholder what the remediation costs BD and tells a hospital nothing about what the system costs it.
The one commercially useful public detail is structural rather than numeric: the Security Module for automated patching and virus definition management is stated to be provided to all accounts rather than sold as an upgrade.
Coverage is broad and specified by care area rather than asserted in general. Inpatient units through MedStation ES, the operating room through Anesthesia Station ES with single access drawers for controlled substances, countertop and restricted access storage through MedBank for smaller sites and for temperature sensitive stock, medical supply management through the supply cabinet line, and multi facility enterprise deployment through the ES platform, with product surfaces maintained for international markets. It sits below the top grade because the depth is documented as product availability and workflow fit by setting rather than as measured performance within any specialty.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
Not published
|
Quotation. Configured enterprise agreement covering capital equipment, software subscription for the analytics layer, and multi year service contracts. | Not published. No business associate agreement position or tiering was located for either the dispensing estate or the hosted analytics layer. | Not published. Installation, enterprise integration and staff training are part of the configured agreement and are not itemised anywhere public. | Vendor Published |
No figure is published for the cabinets, the HealthSight analytics layer or the service contracts, and no distributor or reseller lists a price. The estate is sold as a configured enterprise agreement covering hardware, software, installation and multi year service, which makes any single number close to meaningless without the configuration behind it. Two structural details are public and useful.
The Security Module providing automated patching and virus definition management is stated to be supplied to all accounts rather than sold separately, which removes one common line. And the parent discloses in securities filings that it recorded $68 million in liability for the response to the November 2024 FDA Warning Letter on the dispensing quality system, which is a cost of remediation rather than a cost of ownership and should not be read as pricing information. A buyer pricing this estate is negotiating, not comparing published rates.