Medication Safety & Prescribing
I

Imprivata Drug Diversion Intelligence

Imprivata Drug Diversion Intelligence, sold as DDI and previously carrying the Imprivata FairWarning name, is the diversion monitoring counterpart to the Patient Privacy Intelligence product already indexed here. It is recorded separately under the same product scoping rule that governs that entry: Imprivata's wider business is healthcare identity and access management, which would not qualify on AI centrality, and this record covers the diversion product specifically. Both products descend from the FairWarning and Maize Analytics acquisitions and now sit inside the Imprivata Digital Identity Framework under access compliance.

The product monitors the controlled substance lifecycle from prescription through dispensing, preparation, administration, waste and removal, using machine learning to establish baseline behaviour for medication access and flag deviation from it, including peer comparison and out of hours activity. It ships more than 250 report types for compliance and audit, an investigation platform, and an optional monitoring services team. It has been sold in the United States for years and became available in Canada in March 2023.

One named technical capability is unlike anything else in this lane. OneRx is described as AI assisted technology that standardises medication names across disparate source systems. Inconsistent drug naming between the electronic health record, the dispensing cabinet and the pharmacy system is a mundane and genuinely destructive problem for this category, because a reconciliation engine cannot match what it cannot recognise, and this is the only vendor here that names the problem and ships something specific at it rather than treating clean input as a given.

The security and privacy position is the strongest in this lane. Imprivata holds ISO 27001 and ISO 27701 certifications issued by A LIGN, maintains a public trust and security page, and states a SOC 2 attestation alongside HIPAA governance. ISO 27701 is the privacy information management standard and is rare across this entire index, which matters for a product whose subject is the behaviour of named staff. Two things a buyer should confirm rather than assume: the certification announcement cites the 2013 revision of ISO 27001, which has since been superseded, so the transition to the current revision should be verified, and the published scope is described at company level without enumerating which products fall inside it.

The weakness is evidence. No outcome study, accuracy figure or named customer result was located. The only checkable third party measure found is a KLAS assessment reported in 2022 that scored Imprivata 70.1 in drug diversion monitoring, the lowest of the four vendors covered in that report and flagged there as resting on limited data. That figure is four years old and should not be treated as current, but nothing published since replaces it.

AI Health Index verifiedAugust 29, 2026
Compare Imprivata Drug Diversion Intelligence with other vendors
Founded
Headquarters
Waltham, Massachusetts, United States
Categories
medication-safety-and-prescribing, healthcare-cybersecurity
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
BB on AI CentralityThe model is the engine of a core module. The platform carries other value, but this capability does not exist without it.
Vendor Published

Detection is what the product is for and machine learning is named as the method in the vendor's own voice across product pages, a knowledge hub entry and a market expansion announcement, described as establishing baseline behaviour and norms for medication access and flagging deviation from them. The OneRx medication name standardisation component is also described as AI assisted, so models do work at two distinct points in the pipeline rather than one.

It sits below the top grade because a substantial part of what is sold alongside the model is conventional: more than 250 report types, an investigation case platform and an optional human monitoring services team, all of which would function on rules alone.

CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.
Vendor Published

The human decision point is designed in rather than assumed. Output routes into an investigation platform built for case handling, with alerting for immediate review and reporting for documentation, and an optional monitoring services team exists for organisations without the internal capacity to work the queue, which is an honest acknowledgement that the alerts require skilled labour to be worth anything.

What is not published is the operational detail that separates a good oversight model from a described one: no alerting threshold, no statement of what qualification the reviewer needs, and no description of what the reviewer is shown about why a given behaviour was surfaced.

CC on Model and Technology TransparencyThe architecture is described in general terms with nothing identified. Proprietary is asserted rather than explained.
Vendor Published

Mechanism is described at a useful level in places and left vague in others. Machine learning is named as establishing baseline behaviours and norms, with deviation, peer comparison and out of hours access given as example signals. OneRx is described concretely as AI assisted standardisation of medication naming across disparate source systems, which is a specific and checkable claim about a specific data problem rather than a slogan.

Against that, no model family, feature set, training population or performance measure is published for the detection model itself, so a buyer can follow what the system is doing without being able to ask how well it does it.

DD on Model Supply Chain DisclosureNothing establishes who else sits between a patient record and an answer.
Vendor Published

No model provider, framework or third party component is named for either the detection model or the OneRx normalisation layer. The trust page does disclose that the company applies AI assisted analysis internally within its own product security and development process, which is an unusual and welcome piece of transparency about how the software is built, and it says nothing about what powers the software once it runs. Nothing distinguishes capability inherited from the FairWarning and Maize Analytics acquisitions from capability built or licensed since.

DD on Clinical and Operational EvidenceNo named deployment and no performance claim a reader can check. A figure published with no source sits here rather than higher.
Third Party Estimated

This is the weakest part of an otherwise solid record. No outcome study, detection accuracy figure, false positive rate or named customer result was located for the diversion product. Adoption is asserted as widespread in the United States and a Canadian market entry was announced in March 2023, but neither is quantified.

The one checkable third party measure found is a KLAS assessment reported in 2022 placing Imprivata at 70.1 in drug diversion monitoring, the lowest of the four vendors covered and flagged in that report as resting on limited data. Four years is long enough that the figure should not be read as current, and the grade reflects the absence of anything published since rather than the score itself.

CC on AI Safety and PHI StewardshipGeneral assurances of privacy and security that do not answer the questions artificial intelligence raises: what is retained, what reaches a model, and what happens to it there.
Vendor Published

The best grade on this axis in the lane, earned on one disclosure nobody else makes. Imprivata publishes a retention period: controlled substance data is stored for three years to support lifecycle auditing, and the sibling privacy product carries the same three year archive commitment. Every other vendor graded here leaves retention entirely unstated, which means a buyer cannot establish how long behavioural records about their staff persist.

Combined with the ISO 27701 certification this is a real stewardship position rather than a claim. It stays at this grade because the central model question is still unanswered: nothing states whether customer transaction data trains models that persist beyond the tenant, or whether baselines are fitted per customer or across the installed base. A tenancy and training statement is the single disclosure that would move this to the band above.

Regulatory and Compliance
BB on HIPAA and BAA PostureBusiness associate status is stated and supported by a substantive privacy document, with the agreement or its scope not fully published. For a vendor outside the United States, an equivalent regime documented to this depth grades here.
Vendor Published

The strongest position in this lane, resting on a certification rather than an assertion. Imprivata holds ISO 27701, the privacy information management standard, alongside ISO 27001, and its trust page states the certified scope covers the processing of personally identifiable information and protected health information.

A privacy management system certified by an accredited third party is a materially different signal from the usual claim of HIPAA compliance, and it is directly on point for a product whose subject matter is the recorded behaviour of identified staff and patients. Business associate agreement terms and data ownership provisions remain unpublished and are settled in contract, which is what holds this below the top grade.

BB on Security Certifications and Trust CenterA recognised certification is named in the vendor own material without the artefact, or with a scope or renewal question the buyer has to raise. A certification has a scope and a clock, and both are part of this grade.
Vendor Published

The broadest credential set in this lane, held by a company whose core business is security. ISO 27001 and ISO 27701 certifications were issued by A LIGN, an accredited certification body named in the announcement, and a SOC 2 attestation and HIPAA governance are stated on a public trust and security page that a buyer can read without entering a sales process.

The page also describes current practice rather than a historical badge, including the defensive use of AI assisted analysis in their own product security and release process. Two specifics hold it below the top grade and both are checkable. The certification announcement cites the 2013 revision of ISO 27001, which has since been superseded, and no confirmation of transition to the current revision was located.

And the published scope is stated at company level without enumerating which products sit inside the certified management system, so a buyer cannot establish from public material that this product is covered.

CC on FDA and Regulatory StatusNo device claim is made and the product is scoped accordingly. Most administrative and operational products sit here and are not penalised for it, because this axis grades the appropriateness of the positioning rather than possession of a clearance.
Vendor Published

Monitoring software rather than a regulated device, so no clearance applies and none is claimed. Regulatory purpose is engaged directly rather than left implicit: the product ships more than 250 report types explicitly for compliance and audit, monitors the full controlled substance lifecycle in the form regulators ask about, and holds data for three years, which is a retention period aligned to audit rather than to convenience.

It stops below a higher grade because no statement of the company's own regulatory position was located, and nothing published guides customers on how output should be used in reporting to the Drug Enforcement Administration or a state board, which is where these findings routinely end up.

DD on AI Governance and Bias DisclosureNothing published on how model behaviour is governed or tested. Multilingual operation with no subgroup performance sits here when the vendor markets recognition quality as a strength, because a caller the system failed to understand leaves no complaint and no record.
Vendor Published

No governance statement, validation summary, false positive rate or bias analysis was located for a model that flags named clinicians for investigation. The gap is sharper here than elsewhere because of what the vendor does claim.

Its own product material states that the system protects staff from false accusations, which is a claim about the very failure mode this axis exists to examine, and nothing published quantifies how often the system is wrong or describes what protection consists of. Making the claim without the number invites exactly the scrutiny the number would answer.

The peer comparison and out of hours signals in use also carry the familiar distributional risk, concentrating attention on irregular schedules and high turnover units, and no examination of that distribution has been published.

DD on AI Liability and RecourseNothing published on what happens when the system is wrong.
Vendor Published

This vendor is the only one in the lane to name the harm and it still earns the floor grade, which is worth explaining. Its product material states that the system protects staff from false accusations, an acknowledgement that a wrongly flagged clinician is a real and foreseeable outcome, and no competitor here says as much. Nothing published describes what that protection consists of.

There is no statement of who owns the determination, whether a flagged individual is informed, what evidentiary weight a flag is intended to carry in an employment or licensure process, or how one is challenged and withdrawn. An unsupported protective claim cannot carry a grade on this axis, because reassurance without a mechanism is weaker for the person being flagged than plain silence would be.

Integration and Deployment
CC on EHR and Interoperability DepthIntegration is claimed through standards or a middleware layer with no system named and nothing to verify.
Vendor Published

The product analyses data from electronic health records, pharmacy management systems and dispensing systems, and reaches into electronic prescribing workflows, so the input surface spans clinical and pharmacy operations rather than dispensing cabinets alone. The existence of OneRx is itself indirect evidence of integration breadth, since a medication name normalisation layer is only necessary across genuinely heterogeneous sources.

No specific electronic health record or dispensing cabinet vendor is named, no source list is enumerated, and no integration method or effort is described, which is what holds the grade here rather than higher.

DD on Deployment Model and Data ResidencyNothing published about where the system runs or where the data rests.
Vendor Published

No hosting model, cloud provider, region or residency commitment was located for this product. The trust page notes that product availability varies by region and refers to cloud service enhancements, and the company announced Canadian availability as a distinct event in March 2023, which suggests regional deployment capability without stating one.

That suggestion is worth a buyer's question rather than a grade, and the specific question is whether Canadian customer data remains in Canada, since a separate market entry announcement is not a residency commitment. The sibling privacy product is documented as running inside the customer environment, and nothing establishes that the same is true here, so that architecture should not be assumed to carry across.

Commercial
DD on Commercial TransparencyNothing a buyer can establish before a sales conversation. A published pricing claim contradicted by evidence also grades here.
Vendor Published

No price, pricing page or basis of charge was located in two passes. The product appears in at least one software marketplace listing, which establishes that it is transacted through channel partners without revealing what it costs.

Nothing published indicates whether the optional Drug Diversion Monitoring Services team is included, priced separately or sold as a tier, which is a material question because it is the difference between buying software and buying an outsourced monitoring function.

CC on Setting and Specialty CoverageCoverage is claimed broadly without specifics, or stated clearly with nothing validating it yet.
Vendor Published

Coverage is described by lifecycle stage rather than by care setting, spanning prescription, dispensing, preparation, administration, waste and removal, with departments identified as higher risk singled out for monitoring and electronic prescribing workflows included in scope. Geographic coverage is documented across the United States and Canada with a dated market entry for the latter.

What is missing is the setting level breakdown the stronger records in this lane provide: nothing distinguishes acute inpatient from procedural, anaesthesia, retail, ambulatory or post acute deployment, and no facility count or segment profile is published.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Not published
Quotation. Enterprise software subscription within the Imprivata Digital Identity Framework, with an optional monitoring services team, and no published unit of charge. Not published. Business associate agreement terms are settled in contract. The company holds ISO 27701 certification stated to cover the processing of personally identifiable and protected health information, which speaks to the control environment rather than to the contractual terms. Not published. The product ingests electronic health record, pharmacy and dispensing data across heterogeneous systems, and the existence of the OneRx name standardisation layer implies meaningful source variation to be reconciled during onboarding. No implementation scope or figure is given anywhere public. Vendor Published

No price, pricing page or basis of charge was located across two passes. The product appears in at least one software marketplace listing, establishing that it transacts through channel partners without exposing a rate. The question a buyer should force early is the treatment of the Drug Diversion Monitoring Services team, which the vendor offers alongside the software: nothing published states whether it is bundled, tiered or separately contracted, and that distinction decides whether the purchase is a software licence or a partly outsourced monitoring function with an ongoing labour cost attached. A second question worth asking is whether pricing differs between the United States and Canada, since the Canadian offering was launched as a separate market entry in March 2023.