Medication Safety & Prescribing
D

DetectRx (iatricSystems)

DetectRx is the drug diversion counterpart to Haystack iS, the iatricSystems patient privacy product already indexed here, and is recorded separately under the same product scoping rule. Released in May 2022 by iatricSystems of Ponce Inlet, Florida, a healthcare technology company with more than three decades of integration work behind it, it evaluates dosing activity in near real time using what the company describes plainly as machine learning combined with expert written rules.

The signal set is the most clinically interesting in this lane. Alongside the usual medication and reconciliation patterns and off shift or off location behaviour, DetectRx analyses patient pain scores. That is a genuinely different idea from anything else graded here. Every other product in this category reasons about the diverter; pain scores reason about the patient left behind, on the logic that a withheld dose shows up as pain that never resolves. Nobody else in this lane names it. The product draws from three system classes, the electronic health record, automated dispensing cabinets and timekeeping, and presents events risk ranked in a management dashboard.

The second distinctive component is AVA, the Advanced Virtual Assistant shared with the privacy product. AVA triggers alerts, requests information and tracks responses against predefined parameters, and the company states the product responds automatically according to customised settings. In the sibling privacy record, AVA is documented as initiating a questionnaire directly with the user whose access was flagged, before a human has reviewed the case. Whether DetectRx does the same to a clinician suspected of drug theft is not stated in any published material located here, and it is the single most consequential open question about this product. The two situations are not equivalent. Being asked to explain a record you opened is an inconvenience; being contacted by an automated system about suspected controlled substance theft, before any person has looked at the case, is something else.

The deployment evidence is named and checkable. Renown Health in northern Nevada implemented DetectRx in 2024, with its director of accreditation and regulation and its vice president of quality and patient safety both quoted, and reports moving from five risk factors monitored through manual monthly reports to twenty four monitored through the product. Peterson Health is named through its director of pharmacy. Worth reading carefully: twenty four risk factors is a measure of how much is now watched, not of how much was caught, and no detection rate, accuracy figure or case outcome has been published.

AI Health Index verifiedAugust 29, 2026
Compare DetectRx (iatricSystems) with other vendors
Founded
Headquarters
Ponce Inlet, Florida, United States
Categories
medication-safety-and-prescribing, healthcare-cybersecurity
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
BB on AI CentralityThe model is the engine of a core module. The platform carries other value, but this capability does not exist without it.
Vendor Published

Detection is the product and the method is named in the vendor's own voice as machine learning combined with expert written rules, a hybrid the company states openly rather than presenting everything as a model. That candour is worth noting because it is the second record in this lane to describe itself that way, and both are more accurate about their architecture than the vendors claiming pure artificial intelligence.

It sits below the top grade for the same reason it earns this one: rules do a meaningful share of the work, and the surrounding investigation dashboard and reporting would function without a model at all.

DD on Autonomy and Oversight ModelNo oversight structure is published. An absolute claim that the system does not err grades here too, because a buyer who believes it will not build the review step that would catch a failure.
Vendor Published

A human decision point exists and the vendor is explicit that investigators should be spending their time on decisions. The problem sits before that point. AVA triggers alerts, requests information and tracks responses against predefined parameters, and the company states the system responds automatically according to customised settings, which places an automated action ahead of human review rather than after it.

In the sibling privacy product this component is documented as initiating a questionnaire directly with the flagged user. Nothing published states whether DetectRx does the same to a clinician suspected of controlled substance theft, and no threshold, scope limit or description of what the contacted person is told was located. An automated outreach capability whose boundaries are undefined, attached to an accusation this serious, is what carries the grade. Establishing whether AVA contacts suspected staff directly in this product is the first question to put to the vendor.

CC on Model and Technology TransparencyThe architecture is described in general terms with nothing identified. Proprietary is asserted rather than explained.
Vendor Published

The mechanism is described with real specificity. The method is named as machine learning plus expert written rules, the source systems are identified as the electronic health record, dispensing cabinets and timekeeping, evaluation is stated to run in near real time as feeds arrive, and events are presented risk ranked.

The signal list is the most informative in this lane and includes one nobody else names: patient pain scores, which inverts the usual approach by looking for the consequence of diversion in the patient record rather than only for the behaviour of the diverter. Against that, no model family, feature weighting, training population or performance measure is published, and the repeated false positive reduction claim is offered without a number.

DD on Model Supply Chain DisclosureNothing establishes who else sits between a patient record and an answer.
Vendor Published

No model provider, framework or third party component is named for either the detection model or the AVA automation layer, and nothing distinguishes capability built in house from capability licensed. AVA is presented as proprietary and shared across the company's privacy and diversion products, which tells a buyer the component is reused internally and nothing about what it is built on.

CC on Clinical and Operational EvidenceNamed customers, or vendor reported percentages with no method, denominator or reference standard. Scale of use is recorded here and is not treated as evidence of benefit.
Vendor Published

Deployment evidence is named, dated and attributable, which is more than most here manage. Renown Health in northern Nevada implemented the product in 2024 with its director of accreditation and regulation and its vice president of quality and patient safety both speaking on record, and Peterson Health is named through its director of pharmacy. The published figure is that Renown moved from five risk factors monitored via manual monthly reports to twenty four monitored through the product.

That number needs reading carefully, because it measures how much is now watched rather than what was found, and an input measure presented alongside customer names can easily be mistaken for a result. No detection rate, accuracy figure, false positive rate or case outcome has been published, which is what holds this at the middle band rather than higher.

DD on AI Safety and PHI StewardshipNothing published on how protected information moves through the system.
Vendor Published

Nothing published addresses whether customer data trains models beyond the tenant, how long behavioural records about named staff are retained, or what happens to them at contract end. The timekeeping feed sharpens this. A model that knows when a clinician was scheduled, when they were present and what they administered is building a continuous record of an identified employee's working life, and the absence of any retention or training statement leaves a hospital unable to tell its own staff how long that record persists or what else it is used for.

Regulatory and Compliance
DD on HIPAA and BAA PostureNo statement of status and no privacy document that reaches the product.
Vendor Published

No business associate agreement position, data ownership statement or description of protected health information handling was located across two passes, for a product that reads the electronic health record, dispensing records and staff timekeeping data together. The combination is what makes the silence consequential.

Joining clinical records to a named employee's shift pattern produces a dataset about that person which neither source system holds on its own, and nothing published establishes who owns it, how it is governed, or what contractual terms attach to it.

DD on Security Certifications and Trust CenterControls are asserted with nothing independent behind them, or nothing is published. Read the note before concluding anything: this is the grade most often corrected on a second pass, because assurance material frequently sits on a parent domain or inside an old announcement rather than on the product pages.
Vendor Published

Two dedicated passes found no certification, attestation, trust portal or security page for this product or for the company. This is a small vendor and the absence is unsurprising, but the consequence for a buyer is concrete rather than theoretical. The product ingests clinical records, controlled substance transactions and employee timekeeping data and joins them, and there is no third party assurance of any kind covering how that is held.

Health systems that require a security attestation from vendors handling protected health information should establish what exists before evaluating anything else here, because nothing public answers the question.

CC on FDA and Regulatory StatusNo device claim is made and the product is scoped accordingly. Most administrative and operational products sit here and are not penalised for it, because this axis grades the appropriateness of the positioning rather than possession of a clearance.
Vendor Published

Monitoring software rather than a regulated device, so no clearance applies and none is claimed. Regulatory alignment is stated more concretely than in most records here: the product is described as configurable to meet Joint Commission standards and Core Measures, which names a specific accreditor's requirements rather than gesturing at compliance generally, and AVA output is explicitly framed as producing documentation for regulatory purposes.

It stops below a higher grade because no statement of the company's own regulatory position was located, and nothing guides customers on how findings should be handled in reporting to the Drug Enforcement Administration or a state board of pharmacy.

DD on AI Governance and Bias DisclosureNothing published on how model behaviour is governed or tested. Multilingual operation with no subgroup performance sits here when the vendor markets recognition quality as a strength, because a caller the system failed to understand leaves no complaint and no record.
Vendor Published

No governance statement, validation summary or false positive rate was located, and the last of those is a specific gap rather than a general one. Reducing false positives is a claim this vendor makes repeatedly, at one point described as drastic, and no figure anywhere supports it. The signals in use also point the distributional risk in an identifiable direction.

Off shift and off location behaviour, evaluated against timekeeping data, will attach most readily to float pool staff, agency workers, night shifts and anyone whose schedule is irregular by the nature of their job rather than by intent. No examination of who the model actually flags has been published.

DD on AI Liability and RecourseNothing published on what happens when the system is wrong.
Vendor Published

No published position on responsibility, challenge or remedy, and this record has a specific reason to want one. The vendor states that AVA output provides documentation for human resources purposes, which means the product is explicitly designed to feed an employment process about a named individual.

Nothing published describes what standard of evidence the output is meant to meet before it enters that process, whether the employee is told a model generated it, what weight it should carry against them, or how a wrong flag is withdrawn once it is in an HR file. Building the evidentiary artefact and saying nothing about the rights of the person it describes is the gap here.

Integration and Deployment
CC on EHR and Interoperability DepthIntegration is claimed through standards or a middleware layer with no system named and nothing to verify.
Vendor Published

Three source system classes are named for this product, the electronic health record, automated dispensing cabinets and timekeeping, and reaching into workforce scheduling data is a genuine extension beyond what most competitors describe.

The parent company has documented integration breadth elsewhere, spanning a large number of named electronic health record and clinical system vendors, but that breadth is published for the sibling privacy product rather than for this one, and it is not assumed to carry across.

On what is published for DetectRx specifically, no electronic health record or dispensing cabinet vendor is named, no integration method is described, and three source classes is a narrower documented input surface than the strongest records in this lane.

DD on Deployment Model and Data ResidencyNothing published about where the system runs or where the data rests.
Vendor Published

No hosting model, cloud provider, region or residency commitment was located in two passes. The product is described as evaluating data as feeds are received, which implies a persistent service consuming source system extracts, and nothing establishes where that service or the resulting data sits.

The company's heritage is in on premises healthcare integration work, so both hosted and customer resident architectures are plausible, and a buyer cannot currently tell which applies from anything published.

Commercial
DD on Commercial TransparencyNothing a buyer can establish before a sales conversation. A published pricing claim contradicted by evidence also grades here.
Vendor Published

No price, pricing page or basis of charge was located in two passes. The company does publish a product brochure as a downloadable document, which is modestly more than several competitors offer and contains no commercial terms.

Nothing indicates whether the product is licensed per facility, per bed or per monitored clinician, and nothing describes whether AVA is included in the base product or priced as an addition, which matters because the automation is the differentiator rather than an accessory.

CC on Setting and Specialty CoverageCoverage is claimed broadly without specifics, or stated clearly with nothing validating it yet.
Vendor Published

The two named customers span a useful range, a large multi site health system in Nevada and a smaller regional organisation, which suggests the product scales in both directions without the vendor claiming so. Configuration to Joint Commission standards and Core Measures is stated explicitly, which ties coverage to a recognised accreditation framework rather than to a self defined checklist.

What is absent is any breakdown by care setting: nothing distinguishes inpatient from procedural, anaesthesia, retail or ambulatory deployment, no facility count is given for the product, and the three source system classes it reads imply a hospital footprint without the vendor defining one.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Not published
Quotation. Enterprise software subscription sold direct by iatricSystems, with no published unit of charge. Not published. No business associate agreement position or tiering was located across two passes. Not published. The product requires feeds from three system classes including timekeeping, and the named customer account describes a configuration effort worked through jointly with the vendor, so implementation is evidently substantive and is not itemised anywhere public. Vendor Published

No price, pricing page or basis of charge was located. A downloadable product brochure is published, which is more commercial material than several competitors offer and contains no terms. Two questions are worth forcing early with this vendor specifically. First, whether AVA is included in the base product or priced separately, since the automation is the differentiator rather than an add on and its treatment determines what the core licence actually buys.

Second, what the timekeeping integration costs to establish, because workforce systems sit outside the clinical estate and are usually owned by a different department with its own approval path, which tends to convert an integration line item into a project.