FDB (First Databank)
FDB, formerly First Databank, supplies the drug knowledge that sits underneath most medication decisions made in the United States. Its databases are embedded in the majority of hospitals, physician practices and pharmacies, which means that when a prescribing system warns about an interaction, a dose ceiling or a contraindication, the content behind that warning is frequently this company's rather than the software vendor's. It is owned by Hearst and part of Hearst Health, the same group that owns Zynx Health.
The asset is human curated: clinical editors maintain the content and the company's stated credibility rests on rigorous quality control and clinical expertise rather than on any model. What makes the record current rather than historical is a deliberate repositioning. In October 2025 FDB opened pilot integrations of a Model Context Protocol server, and on 31 March 2026 it made FDB MedProof MCP generally available, described as the first such server purpose built for agent driven medication decision support, letting other companies' AI agents and language models query clinically validated drug knowledge in patient specific context rather than answering from training data.
Two further products were previewed in March 2026 and are not yet generally available: FDB Script Agent, which turns a spoken clinical conversation into a structured prescription for physician review, and FDB VerifyAssist, an inpatient pharmacy order verification assistant. The company is positioning itself as the grounding layer beneath other people's medication AI.
Capability Axes
This grade describes the mechanism and understates the company's importance to medication AI, so both should be read together. The asset is a drug knowledge base maintained by human clinical editors, and the company's own credibility claim rests on rigorous quality control and clinical expertise rather than on any model.
The generally available agentic product, a Model Context Protocol server released in March 2026, is an interface: it lets other companies' agents and language models query that curated content in patient specific context, which is a genuinely useful piece of infrastructure and is not itself artificial intelligence.
Two products that would change this grade were previewed in March 2026 and are not yet generally available, an agent converting spoken clinical conversations into structured prescriptions and an inpatient order verification assistant. The strategic position matters more than the grade: a company supplying the knowledge that other people's medication agents reason over shapes what those agents are able to say, without operating a model itself.
The company's own products are framed conservatively, with the prescription agent producing orders explicitly for physician review and the verification product named as an assistant rather than a decision maker. The interesting oversight question is structural and belongs to the protocol server rather than to either product.
When a vendor supplies grounding knowledge to another company's agent, it controls the accuracy of the content and controls nothing about how the agent uses it: whether warnings are surfaced or summarised away, whether contraindications are weighted appropriately, whether an agent presents a synthesis with more confidence than the source supports.
Accountability for a harmful recommendation built on correctly supplied drug knowledge is not addressed in any public material from either side of that relationship. Buyers integrating this server should establish contractually who is answerable for what, because the question will arrive eventually and is easier to settle in advance.
Editorial rigour is the company's central claim and its process is not published. Retrieval located no description of how content is derived from labelling, literature and regulatory sources, no stated review cadence, no error or correction rate, no versioning or change history a customer could audit, and no account of how conflicting evidence is adjudicated when sources disagree.
For a curated knowledge base the editorial methodology is the equivalent of a model card, and its absence matters more as the content moves from a screen a pharmacist reads to a server an agent queries at machine speed. Nothing was located describing the protocol server's tool schema, the granularity at which knowledge is returned, or any evaluation of how faithfully downstream agents represent what it supplies. Graded C rather than lower because the content itself is inspectable in use by the clinicians who rely on it daily.
Ubiquity is not evidence and this index grades the two separately by standing practice. The company's databases are embedded in the majority of American hospitals, physician practices and pharmacies, which is the deepest market penetration of any vendor in this category and demonstrates decades of successful commercial and technical execution.
Retrieval located no peer reviewed evaluation of the content's accuracy, no published study of outcomes attributable to its warnings, no measurement of how its alerting contributes to the override rates that define this segment, and no evaluation of the newly released protocol server.
That last absence is the notable one, since a product enabling agents to answer medication questions at scale invites an obvious evaluation, namely whether agents grounded on it give safer answers than agents that are not, and that comparison would be straightforward for the company to commission.
The traditional business involves licensing reference content rather than handling patient data, which is a structurally low risk position. The protocol server changes that, because it is described as serving drug knowledge in patient specific context, which means patient medication and clinical details reach the server in order for the response to be tailored.
Retrieval located no statement of what patient context is transmitted, whether it is retained, whether queries are logged, or whether query patterns inform product development, and those are the first questions a health system's privacy office will ask about any agentic integration. The prescription automation product raises the same issue more acutely, since converting a recorded clinical conversation into a structured order involves audio and its transcription. Publishing a data flow description for the agentic products would resolve most of this axis.
Two retrieval passes located no privacy rule statement, no business associate agreement terms, no execution path and no compliance page. Scope is worth stating: the company's historical position as a content licensor to software vendors meant its contracts ran to those vendors rather than to covered entities, so a published business associate agreement may genuinely not have been necessary for most of its history.
That changes with products that receive patient context directly, and the transition from content supplier to agentic service provider is exactly the moment when the contracting posture should be restated publicly. A health system integrating the protocol server should establish whether it contracts with this company directly or through its existing software vendor, because the answer determines who its business associate actually is.
Retrieval located no service organisation controls report, no HITRUST certification, no ISO 27001, no trust centre, no penetration testing cadence and no vulnerability disclosure programme. The gap is more consequential here than the grade alone suggests because of what was launched.
Protocol servers that expose tools to language models carry a category of risk that conventional data licensing does not, including prompt injection through returned content, tool result manipulation and unintended data exposure through agent context, and these are actively discussed security concerns for the standard itself rather than speculative ones.
A company that has positioned itself as the trusted grounding layer for medication agents is the party best placed to publish how it addresses them, and nothing addressing agent specific security was located.
No device clearance was located and none has historically been expected, since supplying drug reference content to software vendors places the regulatory obligation on those vendors rather than on the content supplier. The newer products complicate that settled position in ways worth watching.
Software that converts a spoken conversation into a structured prescription order, and software that assists with inpatient pharmacy order verification, sit closer to the line than a reference database does, and the boundary in this category is defined by whether a clinician can independently review the basis of the output. An agent that summarises drug knowledge into a recommendation may be harder to review than the underlying reference entry the clinician would otherwise have read. The company publishes no regulatory position on either new product, and both are in preview, so this is a question to ask before adoption rather than a criticism of a shipped product.
Retrieval located no bias assessment, no coverage analysis and no governance documentation. The exposure specific to this company is unusual and deserves naming precisely: it is concentration rather than discrimination. When one curated knowledge base supplies the drug content used by most prescribing systems in a country, and now also grounds the agents built on top of them, any gap, error or editorial judgement in that content propagates everywhere at once, and no downstream vendor is positioned to detect it because they all draw on the same source.
Diversity of sources is a safety property, and this market has very little of it. That is a structural observation about the segment rather than an accusation about this company's editorial quality, which by reputation is high, and it is precisely why the editorial methodology and correction record should be public.
This is the deepest distribution of any vendor in this category and arguably in this index. The company's drug databases are embedded within the healthcare information systems used by the majority of American hospitals, physician practices and pharmacies, with additional integration across life sciences and health systems, which means the content reaches the point of care through hundreds of separate software products rather than through one.
The protocol server extends that reach into a new integration mode, providing a standard interface that reduces the custom development previously required and is described as available in patient specific context across major record systems. A vendor whose content is already inside a buyer's existing systems presents an adoption path with almost no integration cost, which is a structural advantage no competitor in this lane can match.
Delivery has historically been content licensing embedded inside customers' own systems, which places hosting and residency questions with those customers rather than with this company, a clean arrangement that answers most of this axis by design.
The protocol server changes the model to a hosted service the company operates, and retrieval located no named hosting provider, no region, no residency commitment, no availability or latency commitment and no description of behaviour when the service is unreachable.
That last point deserves attention for anyone building on it, because an agent whose grounding source becomes unavailable either fails visibly or falls back to answering from its own training data, and which of those happens is an architectural decision a buyer should make deliberately rather than discover.
No price, unit, pricing basis, contract shape or implementation fee was located for the databases or for the newer agentic products. The commercial structure is worth understanding even without figures, because most healthcare organisations already pay for this content indirectly, bundled inside the licence of whichever prescribing or pharmacy system they run, and may not know what portion of that fee it represents or what rights it carries.
An organisation now considering direct integration of the protocol server should establish whether existing content licences extend to agentic access or whether that is a separate commercial arrangement, since the same knowledge consumed through a new interface is exactly the situation where licensing terms are ambiguous and expensive to resolve after deployment.
Coverage is effectively universal within its market. The content spans the drug supply rather than a therapeutic area, and reaches acute hospital care, ambulatory practice, retail and institutional pharmacy, life sciences and payer settings, so there is no prescribing context in which it is absent. The newer products deliberately address both ends of the workflow, with prescription automation aimed at ambulatory practice and order verification aimed at inpatient pharmacy.
Held at B rather than higher because the footprint is essentially United States and Canadian, because the two products that would extend coverage into new workflows remain in preview rather than general availability, and because the company's reach is mediated through other vendors' software, so what any individual clinician actually sees depends on choices those vendors made.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
Undisclosed
|
Not published, content is typically licensed through software vendors rather than directly | Not published | Not published | Vendor Published |
No price, unit, pricing basis, contract shape or implementation fee was located for the drug databases or for the newer agentic products. The structural point matters more than the missing number: most healthcare organisations already pay for this content indirectly, bundled inside the licence fee of whichever prescribing, pharmacy or record system they run, and typically cannot see what portion of that fee it represents or what usage rights it conveys.
The question to resolve before building anything is whether an existing content licence, held by the organisation or by its software vendor, extends to agentic access through the protocol server, or whether that is a separate commercial arrangement with separate terms. Consuming the same knowledge through a new interface is precisely the case where licensing language is ambiguous, and it is far cheaper to settle before an integration exists than after one is in production.