Healthcare Cybersecurity
B

Bluesight

Medication intelligence platform whose ControlCheck product, formerly Bluesight for Controlled Substances, is the market share leader in drug diversion detection. Founded 2011 as Kit Check, rebranded to Bluesight in December 2022, based in Alexandria, Virginia, led by co founder and chief executive Kevin MacDonald and backed by Thoma Bravo. The diversion product connects data from automated dispensing cabinets, electronic medical records and other systems to deliver a 100 percent audit of dispense, administration, waste and return records for controlled substances, flagging discrepancies for review so pharmacy staff investigate real issues rather than manually reconciling records. The stated technical approach is notably specific: unsupervised machine learning with continuous learning, identifying anomalous patterns in clinician behaviour. The company's own explanation of why is the clearest articulation of the AI necessity argument in this category, and it is candid about what it replaces: simple statistics such as standard deviations and averages have proven inadequate against diverters who have become adept at covering their tracks, because diversion patterns are often visible only when many variables are compared simultaneously and evaluated against other patterns. Reported Best in KLAS three years running, with more than 100 million medication transactions tracked and over 1,000 US and Canadian hospitals using Bluesight solutions. Deployment is deliberately low friction: the platform runs on a HIPAA-compliant cloud, leverages existing reports and multiple data delivery options rather than requiring complex integrations, and one health system implemented across 10 hospitals in a reported 33 days with minimal IT involvement.

Updated 29 August 2026. The company has grown substantially by acquisition and has folded each acquired brand into its own product line rather than operating it as a standing brand: Medacist in 2023, Sectyr in 2024, and Protenus in January 2025. The patient privacy monitoring product now sold as PrivacyPro is the former Protenus platform, and Bluesight's own announcements refer to it as previously Protenus. In the 2025 Best in KLAS report ControlCheck scored 86.1 in the drug diversion monitoring category and the patient privacy product scored 94.3, among the highest scores recorded in that ranking. The suite now runs to six products: ControlCheck, PrivacyPro, KitCheck for radio frequency identification kit and tray inventory, CostCheck for drug spend, 340BCheck for covered entity compliance which was rebuilt on Sectyr technology and relaunched in April 2026 with a 100 percent transaction audit, and ShortageCheck for shortage forecasting. Prism Assistant, the first product on a new artificial intelligence platform, arrived in 2026 and carries no located governance or model disclosure.

Indexed in cybersecurity for the diversion and privacy products specifically, applying the product-scoping rule: the inventory, spend and 340B products are pharmacy operations tools rather than security. Medication safety and prescribing is carried as a secondary category because ControlCheck is a direct comparator to the diversion analytics sold inside the BD Pyxis and Omnicell dispensing estates, and a buyer comparing those three should find all of them.

AI Health Index verifiedAugust 29, 2026
Compare Bluesight with other vendors
Founded
2011
Headquarters
Alexandria, Virginia, United States
Website
bluesight.com
Categories
healthcare-cybersecurity, healthcare-admin-automation, medication-safety-and-prescribing
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
AA on AI CentralityThe artificial intelligence is the product. Remove the model and there is nothing left to sell.
Vendor Published

Graded on the diversion product per the product-scoping rule. The AI necessity argument is explicit and well made by the company itself: simple statistics such as standard deviations and averages are inadequate against diverters who conceal their activity, because diversion patterns are visible only when many variables are compared simultaneously and evaluated against other patterns.

Unsupervised machine learning with continuous learning is the stated method, which is the technically appropriate choice given diversion is a rare, evolving and deliberately concealed behaviour with no reliable labelled training set. Note the wider Bluesight suite includes RFID inventory and purchasing optimisation products where AI is less central; this grade covers ControlCheck.

BB on Autonomy and Oversight ModelThe oversight structure is described and one part is missing, commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

Detection and triage feeding human investigation, correctly positioned given that an alert here is a suspicion about a named clinician.

The company frames the product as an early warning system giving pharmacy directors control of discrepancy identification, with exception reports focusing attention on important discrepancies and automatic tracking of resolutions to produce a complete audit trail. It also explicitly supports building a diversion prevention programme with clinically driven workflows and cross departmental cooperation, which is an honest acknowledgement that the software is one component of a human governance process rather than the process itself.

Graded B rather than A because no alert precision or false positive rate is published, and in a product generating suspicion about individuals that is the number that matters most.

AA on Model and Technology TransparencyWhat is under the hood is named: proprietary or adapted foundation models identified, training data characterised, and versioning and update practice published so a buyer knows when the system changed.
Vendor Published

The strongest methodological transparency of any vendor in this category, and unusual anywhere in the index. The company published a substantive explanation of the data science behind the product, naming the technique as unsupervised machine learning, describing what it does as separating signal from noise across many simultaneous variables to reveal subtle behavioural differences among staff, and stating plainly why the simpler statistical approaches it replaces fail.

Naming unsupervised learning specifically, rather than saying AI, tells a technically literate buyer a great deal about how the system behaves, including that it surfaces outliers rather than matching known diversion signatures. Explaining the limits of the prior art is a form of candour most vendors avoid.

CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

One deployment choice narrows the surface deliberately and no party is named. The company states it leverages existing reports and multiple data delivery options rather than requiring complex data integrations and approvals, which reduces both the integration surface and the number of directly connected systems, and data minimisation achieved by design rather than by retention policy is the more durable form.

That is a real architectural position and it is unusual to see it stated as a selling point rather than as a limitation. What the platform nonetheless holds is worth naming precisely, because it is two sensitive categories joined: medication administration records linked to identifiable patients, and the behavioural profile of identifiable staff derived from them.

A diversion detection system is necessarily a staff monitoring system, and the employee record it constructs is not something the employee sees. On enumeration there is nothing beyond a stated compliant cloud: no provider named, no sub processor list, no retention policy and no statement on whether customer data trains the models, which matters for an unsupervised method whose baseline is learned from observed behaviour. Ask which cloud, for a sub processor list, for retention on the staff behavioural profiles specifically, and whether one customer's data informs another's baselines.

BB on Clinical and Operational EvidenceNamed deployments with dated outcome figures and enough method to test them, or published research short of independent validation.
Third Party Estimated

Strong third party and scale evidence, though no published detection performance. Best in KLAS three years running for the diversion product, which is independent customer-sourced research, alongside market share leadership, more than 100 million medication transactions tracked, and over 1,000 US and Canadian hospitals using Bluesight solutions.

Named deployments include OhioHealth across 10 hospitals and Children's Hospital of the King's Daughters across 20 operating rooms, with the OhioHealth implementation reported to have produced diversion investigations. Graded B rather than A because no published data quantifies detection performance, meaning diversion events identified that manual reconciliation would have missed, nor any false positive rate. Scale of transactions audited is a coverage measure, not an efficacy measure, and the index applies that distinction consistently.

BB on AI Safety and PHI StewardshipCategorical commitments are published, such as no training on customer data, without the retention schedule or the safety engineering behind them.
Vendor Published

Runs on a stated HIPAA-compliant cloud platform, and the deployment design is deliberately in a way worth crediting: the company states it leverages existing reports and multiple data delivery options rather than requiring complex data integrations and approvals, which reduces both the integration surface and the volume of directly connected systems. The platform nonetheless processes medication administration records linked to identifiable patients and identifiable staff. Graded B rather than A because no published retention policy or statement on model training use was located.

Regulatory and Compliance
BB on HIPAA and BAA PostureBusiness associate status is stated and supported by a substantive privacy document, with the agreement or its scope not fully published. For a vendor outside the United States, an equivalent regime documented to this depth grades here.
Vendor Published

HIPAA-compliant cloud platform stated directly, with the company noting patient data is secured without requiring complex data integrations and approvals. Graded B rather than A because no BAA terms were located in published form.

CC on Security Certifications and Trust CenterControls are described with an outside check behind them, such as independent penetration testing on a stated cadence, but no attestation against a recognised framework.
Vendor Published

Converted from Not Rated. No independent attestation was located, consistent with every vendor this index holds in the category.

No SOC 2 of either type, no HITRUST, no ISO 27001, no trust centre and no penetration testing statement was retrieved.

The holding here is narrower than the privacy monitoring platforms graded alongside it and no less sensitive. Medication intelligence requires ingesting controlled substance transaction data from automated dispensing cabinets, pharmacy systems and administration records, tied to the individual staff members who withdrew, wasted and administered each dose. That is a complete account of which named clinicians handled which controlled substances, when, and in what quantities, across an institution.

Two things follow. It is directly useful to anyone seeking to divert without detection, because it maps exactly where reconciliation is weak. And it is employment sensitive in a way clinical data is not, since the subject of the record is a member of staff rather than a patient, and the consequence of exposure is professional rather than medical.

The standing finding across this category now holds after individual checks on seven vendors: companies whose product is assessing whether others are secure or compliant do not evidence their own posture.

Ask for the attestation and period, and for the retention and access controls over staff level transaction data.

BB on FDA and Regulatory StatusThe pathway is stated and in progress, or a clearance is named without the vintage and scope a buyer needs to match it to the product on offer.
Vendor Published

Converted from Not Rated. The prior scoping was correct and the product's relationship to the governing regime is direct rather than incidental.

No device pathway applies. What governs is the Controlled Substances Act and the recordkeeping obligations that follow from it, and the company frames the product against them explicitly, describing the closing of gaps in the controlled substance record as a fundamental component of remaining compliant. State pharmacy and nursing board reporting duties attach when diversion is substantiated.

That framing is accurate and it is the reason this grades above a bare scoping note. Federal recordkeeping requires a complete and reconcilable account of controlled substance movement, and the practical failure mode in a hospital is not refusal to keep records but gaps that nobody reconciles because the volume defeats manual audit. A product that closes those gaps is discharging the obligation rather than reporting on it.

The exposure worth naming is the same one this pass has flagged for every diversion and privacy monitoring vendor. A substantiated finding can end a clinician's career and trigger a mandatory report to a licensing board. The consequence lands on an individual, and the vendor supplies the evidence. Nothing published describes what accuracy standard applies before escalation or what recourse the accused has.

Ask what precedes a substantiated finding, and what the false positive rate is on cases escalated to board reporting.

CC on AI Governance and Bias DisclosureResponsible artificial intelligence is committed to in policy language with no evaluation behind it. Most of the index sits here.
Third Party Estimated

No governance framework, subgroup analysis or bias evaluation located, and the concern mirrors Protenus. This is workforce surveillance analysing behavioural patterns of named clinicians, where an alert can trigger investigation, employment action, licensure board referral or criminal referral.

Unsupervised anomaly detection carries a specific version of this risk: it flags statistical outliers, and a clinician whose legitimate practice differs from their peer group, through specialty, shift pattern, patient acuity or working in a small unit where peer comparison is thin, may be flagged for being unusual rather than for diverting.

The company's own citation that roughly one in ten healthcare providers is using or abusing drugs sets a high prior that could compound over-investigation. No published fairness evaluation or false accusation rate was located.

CC on AI Liability and RecourseMechanisms exist that let someone challenge an output, such as audit trails, source traceability or review before commit, with nothing standing behind the output and no route for the harmed party.
Vendor Published

Naming the technique is doing real work here, and it is worth explaining why it counts as a limitation disclosure rather than only as transparency. The company published a substantive explanation of the data science, naming the method as unsupervised machine learning, describing it as separating signal from noise across many simultaneous variables to reveal subtle behavioural differences among staff, and stating plainly why the simpler statistical approaches it replaces fail.

Naming unsupervised learning specifically tells a technically literate buyer how the system behaves without any further disclosure: it surfaces outliers rather than matching known diversion signatures, which means it can catch novel patterns and equally that being statistically unusual is itself the trigger. A nurse whose practice differs legitimately, through shift pattern, unit, patient mix or simply working differently, is exactly the profile such a method surfaces.

Explaining the limits of the prior art is also a form of candour most vendors avoid. Held at C because nothing measures it. No precision figure, false positive rate or validation was located, and the affected party is a named clinician: a flag initiates a diversion investigation, an allegation that suspends and ends careers, attaching to someone with no access to the model and no route to see what triggered it. Ask for precision at the operating threshold, and what an investigated employee is entitled to see.

Integration and Deployment
AA on EHR and Interoperability DepthNamed bidirectional integrations with major record systems, verifiable in marketplace listings or integration documentation, with evidence the connection runs in production.
Third Party Estimated

Integration is the product's precondition and it is executed with unusually low friction. The platform connects automated dispensing cabinets, electronic medical records and other systems to reconcile the full dispense, administration, waste and return chain, which requires bridging pharmacy and clinical systems that rarely share a view.

The company states it leverages existing reports and multiple data delivery options so health systems onboard quickly with minimal IT involvement, and the OhioHealth deployment across 10 hospitals in a reported 33 days is concrete evidence rather than a claim. Achieving that speed across a multi-hospital system in an integration-heavy domain is a genuine differentiator.

AA on Deployment Model and Data ResidencyDeployment options, residency and tenant isolation are all documented, including where data rests and which processing crosses a border.
Third Party Estimated

Cloud platform explicitly designed to avoid the integration burden that stalls deployments in this category, using existing reports and flexible data delivery rather than requiring bespoke interfaces and approvals. Demonstrated at speed with a 10-hospital rollout in a reported 33 days with minimal IT involvement, which is exceptional for a system touching both dispensing cabinets and EMRs. No data residency disclosure located, the only qualification.

Commercial
CC on Commercial TransparencyNo price is published and the posture is discoverable: a buyer can establish how the product is sold and what drives the cost before contacting the vendor. Most of the index sits here.
Vendor Published

No pricing published and no pricing basis disclosed. The suite structure adds complexity, since ControlCheck sits alongside RFID inventory management and purchasing optimisation products, and how those are bundled or licensed separately is not public.

BB on Setting and Specialty CoverageCoverage is named with validation behind part of it.
Third Party Estimated

Deep across the controlled substance chain rather than broad across security. Covers the full custody path from purchase through dispense, administration, waste and return, spanning pharmacy and patient care areas including operating theatres, deployed across more than 1,000 US and Canadian hospitals. Serves pharmacy, nursing and compliance functions.

Graded B rather than A because within this index's cybersecurity category the coverage is a single risk domain, medication diversion, without the privacy monitoring breadth of Protenus or the multi-asset scope of the device security vendors.

Comparisons

Compared With

Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.

Head to head

Vendors the index assesses as direct competitors to Bluesight for the same buyer.

Adjacent comparisons

Products a buyer researches alongside Bluesight that do a different job: a different category, a different layer of the stack, or a specialist scope. These pages exist to settle whether the comparison is real before it settles which one to pick.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Not published
Undisclosed. Suite structure means ControlCheck may be licensed separately from RFID inventory and purchasing products; confirm before comparing. Third Party Estimated

No pricing published and no pricing basis disclosed. The suite structure is the complication a buyer must resolve first: ControlCheck for diversion detection sits alongside RFID-enabled inventory management and medication purchasing optimisation within the Medication Intelligence portfolio, and whether these are licensed separately, bundled, or priced as a platform is not public.

A health system wanting diversion detection alone should confirm it can buy that without the pharmacy operations products, and one wanting the full suite should establish whether bundling changes the economics materially. Likely scaling factors are facility count, bed count or medication transaction volume, and given the platform has tracked more than 100 million transactions, transaction-based pricing would behave very differently from per-facility at a large system.

Two points strengthen the buyer's position here relative to the rest of this category. First, deployment cost should be genuinely low: the company states it uses existing reports and multiple data delivery options rather than requiring complex integrations, evidenced by a 10-hospital implementation in a reported 33 days with minimal IT involvement, so the internal IT effort that inflates total cost in most healthcare security purchases is smaller.

Second, Best in KLAS recognition three years running for the diversion product provides independent leverage in negotiation and a clear comparator against Protenus, which won Best in KLAS 2023 in the same category. Buyers evaluating both should note they overlap on diversion but diverge on privacy monitoring, which Protenus covers and Bluesight does not.