DetectRx (iatricSystems)
DetectRx is the drug diversion counterpart to Haystack iS, the iatricSystems patient privacy product already indexed here, and is recorded separately under the same product scoping rule. Released in May 2022 by iatricSystems of Ponce Inlet, Florida, a healthcare technology company with more than three decades of integration work behind it, it evaluates dosing activity in near real time using what the company describes plainly as machine learning combined with expert written rules.
The signal set is the most clinically interesting in this lane. Alongside the usual medication and reconciliation patterns and off shift or off location behaviour, DetectRx analyses patient pain scores. That is a genuinely different idea from anything else graded here. Every other product in this category reasons about the diverter; pain scores reason about the patient left behind, on the logic that a withheld dose shows up as pain that never resolves. Nobody else in this lane names it. The product draws from three system classes, the electronic health record, automated dispensing cabinets and timekeeping, and presents events risk ranked in a management dashboard.
The second distinctive component is AVA, the Advanced Virtual Assistant shared with the privacy product. AVA triggers alerts, requests information and tracks responses against predefined parameters, and the company states the product responds automatically according to customised settings. In the sibling privacy record, AVA is documented as initiating a questionnaire directly with the user whose access was flagged, before a human has reviewed the case. Whether DetectRx does the same to a clinician suspected of drug theft is not stated in any published material located here, and it is the single most consequential open question about this product. The two situations are not equivalent. Being asked to explain a record you opened is an inconvenience; being contacted by an automated system about suspected controlled substance theft, before any person has looked at the case, is something else.
The deployment evidence is named and checkable. Renown Health in northern Nevada implemented DetectRx in 2024, with its director of accreditation and regulation and its vice president of quality and patient safety both quoted, and reports moving from five risk factors monitored through manual monthly reports to twenty four monitored through the product. Peterson Health is named through its director of pharmacy. Worth reading carefully: twenty four risk factors is a measure of how much is now watched, not of how much was caught, and no detection rate, accuracy figure or case outcome has been published.
Capability Axes
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read
Detection is the product and the method is named in the vendor's own voice as machine learning combined with expert written rules, a hybrid the company states openly rather than presenting everything as a model. That candour is worth noting because it is the second record in this lane to describe itself that way, and both are more accurate about their architecture than the vendors claiming pure artificial intelligence.
It sits below the top grade for the same reason it earns this one: rules do a meaningful share of the work, and the surrounding investigation dashboard and reporting would function without a model at all.
A human decision point exists and the vendor is explicit that investigators should be spending their time on decisions. The problem sits before that point. AVA triggers alerts, requests information and tracks responses against predefined parameters, and the company states the system responds automatically according to customised settings, which places an automated action ahead of human review rather than after it.
In the sibling privacy product this component is documented as initiating a questionnaire directly with the flagged user. Nothing published states whether DetectRx does the same to a clinician suspected of controlled substance theft, and no threshold, scope limit or description of what the contacted person is told was located. An automated outreach capability whose boundaries are undefined, attached to an accusation this serious, is what carries the grade. Establishing whether AVA contacts suspected staff directly in this product is the first question to put to the vendor.
The mechanism is described with real specificity. The method is named as machine learning plus expert written rules, the source systems are identified as the electronic health record, dispensing cabinets and timekeeping, evaluation is stated to run in near real time as feeds arrive, and events are presented risk ranked.
The signal list is the most informative in this lane and includes one nobody else names: patient pain scores, which inverts the usual approach by looking for the consequence of diversion in the patient record rather than only for the behaviour of the diverter. Against that, no model family, feature weighting, training population or performance measure is published, and the repeated false positive reduction claim is offered without a number.
No model provider, framework or third party component is named for either the detection model or the AVA automation layer, and nothing distinguishes capability built in house from capability licensed. AVA is presented as proprietary and shared across the company's privacy and diversion products, which tells a buyer the component is reused internally and nothing about what it is built on.
Deployment evidence is named, dated and attributable, which is more than most here manage. Renown Health in northern Nevada implemented the product in 2024 with its director of accreditation and regulation and its vice president of quality and patient safety both speaking on record, and Peterson Health is named through its director of pharmacy. The published figure is that Renown moved from five risk factors monitored via manual monthly reports to twenty four monitored through the product.
That number needs reading carefully, because it measures how much is now watched rather than what was found, and an input measure presented alongside customer names can easily be mistaken for a result. No detection rate, accuracy figure, false positive rate or case outcome has been published, which is what holds this at the middle band rather than higher.
Nothing published addresses whether customer data trains models beyond the tenant, how long behavioural records about named staff are retained, or what happens to them at contract end. The timekeeping feed sharpens this. A model that knows when a clinician was scheduled, when they were present and what they administered is building a continuous record of an identified employee's working life, and the absence of any retention or training statement leaves a hospital unable to tell its own staff how long that record persists or what else it is used for.
No business associate agreement position, data ownership statement or description of protected health information handling was located across two passes, for a product that reads the electronic health record, dispensing records and staff timekeeping data together. The combination is what makes the silence consequential.
Joining clinical records to a named employee's shift pattern produces a dataset about that person which neither source system holds on its own, and nothing published establishes who owns it, how it is governed, or what contractual terms attach to it.
Two dedicated passes found no certification, attestation, trust portal or security page for this product or for the company. This is a small vendor and the absence is unsurprising, but the consequence for a buyer is concrete rather than theoretical. The product ingests clinical records, controlled substance transactions and employee timekeeping data and joins them, and there is no third party assurance of any kind covering how that is held.
Health systems that require a security attestation from vendors handling protected health information should establish what exists before evaluating anything else here, because nothing public answers the question.
Monitoring software rather than a regulated device, so no clearance applies and none is claimed. Regulatory alignment is stated more concretely than in most records here: the product is described as configurable to meet Joint Commission standards and Core Measures, which names a specific accreditor's requirements rather than gesturing at compliance generally, and AVA output is explicitly framed as producing documentation for regulatory purposes.
It stops below a higher grade because no statement of the company's own regulatory position was located, and nothing guides customers on how findings should be handled in reporting to the Drug Enforcement Administration or a state board of pharmacy.
No governance statement, validation summary or false positive rate was located, and the last of those is a specific gap rather than a general one. Reducing false positives is a claim this vendor makes repeatedly, at one point described as drastic, and no figure anywhere supports it. The signals in use also point the distributional risk in an identifiable direction.
Off shift and off location behaviour, evaluated against timekeeping data, will attach most readily to float pool staff, agency workers, night shifts and anyone whose schedule is irregular by the nature of their job rather than by intent. No examination of who the model actually flags has been published.
No published position on responsibility, challenge or remedy, and this record has a specific reason to want one. The vendor states that AVA output provides documentation for human resources purposes, which means the product is explicitly designed to feed an employment process about a named individual.
Nothing published describes what standard of evidence the output is meant to meet before it enters that process, whether the employee is told a model generated it, what weight it should carry against them, or how a wrong flag is withdrawn once it is in an HR file. Building the evidentiary artefact and saying nothing about the rights of the person it describes is the gap here.
Three source system classes are named for this product, the electronic health record, automated dispensing cabinets and timekeeping, and reaching into workforce scheduling data is a genuine extension beyond what most competitors describe.
The parent company has documented integration breadth elsewhere, spanning a large number of named electronic health record and clinical system vendors, but that breadth is published for the sibling privacy product rather than for this one, and it is not assumed to carry across.
On what is published for DetectRx specifically, no electronic health record or dispensing cabinet vendor is named, no integration method is described, and three source classes is a narrower documented input surface than the strongest records in this lane.
No hosting model, cloud provider, region or residency commitment was located in two passes. The product is described as evaluating data as feeds are received, which implies a persistent service consuming source system extracts, and nothing establishes where that service or the resulting data sits.
The company's heritage is in on premises healthcare integration work, so both hosted and customer resident architectures are plausible, and a buyer cannot currently tell which applies from anything published.
No price, pricing page or basis of charge was located in two passes. The company does publish a product brochure as a downloadable document, which is modestly more than several competitors offer and contains no commercial terms.
Nothing indicates whether the product is licensed per facility, per bed or per monitored clinician, and nothing describes whether AVA is included in the base product or priced as an addition, which matters because the automation is the differentiator rather than an accessory.
The two named customers span a useful range, a large multi site health system in Nevada and a smaller regional organisation, which suggests the product scales in both directions without the vendor claiming so. Configuration to Joint Commission standards and Core Measures is stated explicitly, which ties coverage to a recognised accreditation framework rather than to a self defined checklist.
What is absent is any breakdown by care setting: nothing distinguishes inpatient from procedural, anaesthesia, retail or ambulatory deployment, no facility count is given for the product, and the three source system classes it reads imply a hospital footprint without the vendor defining one.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
Not published
|
Quotation. Enterprise software subscription sold direct by iatricSystems, with no published unit of charge. | Not published. No business associate agreement position or tiering was located across two passes. | Not published. The product requires feeds from three system classes including timekeeping, and the named customer account describes a configuration effort worked through jointly with the vendor, so implementation is evidently substantive and is not itemised anywhere public. | Vendor Published |
No price, pricing page or basis of charge was located. A downloadable product brochure is published, which is more commercial material than several competitors offer and contains no terms. Two questions are worth forcing early with this vendor specifically. First, whether AVA is included in the base product or priced separately, since the automation is the differentiator rather than an add on and its treatment determines what the core licence actually buys.
Second, what the timekeeping integration costs to establish, because workforce systems sit outside the clinical estate and are usually owned by a different department with its own approval path, which tends to convert an integration line item into a project.