Imprivata Drug Diversion Intelligence
Imprivata Drug Diversion Intelligence, sold as DDI and previously carrying the Imprivata FairWarning name, is the diversion monitoring counterpart to the Patient Privacy Intelligence product already indexed here. It is recorded separately under the same product scoping rule that governs that entry: Imprivata's wider business is healthcare identity and access management, which would not qualify on AI centrality, and this record covers the diversion product specifically. Both products descend from the FairWarning and Maize Analytics acquisitions and now sit inside the Imprivata Digital Identity Framework under access compliance.
The product monitors the controlled substance lifecycle from prescription through dispensing, preparation, administration, waste and removal, using machine learning to establish baseline behaviour for medication access and flag deviation from it, including peer comparison and out of hours activity. It ships more than 250 report types for compliance and audit, an investigation platform, and an optional monitoring services team. It has been sold in the United States for years and became available in Canada in March 2023.
One named technical capability is unlike anything else in this lane. OneRx is described as AI assisted technology that standardises medication names across disparate source systems. Inconsistent drug naming between the electronic health record, the dispensing cabinet and the pharmacy system is a mundane and genuinely destructive problem for this category, because a reconciliation engine cannot match what it cannot recognise, and this is the only vendor here that names the problem and ships something specific at it rather than treating clean input as a given.
The security and privacy position is the strongest in this lane. Imprivata holds ISO 27001 and ISO 27701 certifications issued by A LIGN, maintains a public trust and security page, and states a SOC 2 attestation alongside HIPAA governance. ISO 27701 is the privacy information management standard and is rare across this entire index, which matters for a product whose subject is the behaviour of named staff. Two things a buyer should confirm rather than assume: the certification announcement cites the 2013 revision of ISO 27001, which has since been superseded, so the transition to the current revision should be verified, and the published scope is described at company level without enumerating which products fall inside it.
The weakness is evidence. No outcome study, accuracy figure or named customer result was located. The only checkable third party measure found is a KLAS assessment reported in 2022 that scored Imprivata 70.1 in drug diversion monitoring, the lowest of the four vendors covered in that report and flagged there as resting on limited data. That figure is four years old and should not be treated as current, but nothing published since replaces it.
Capability Axes
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read
Detection is what the product is for and machine learning is named as the method in the vendor's own voice across product pages, a knowledge hub entry and a market expansion announcement, described as establishing baseline behaviour and norms for medication access and flagging deviation from them. The OneRx medication name standardisation component is also described as AI assisted, so models do work at two distinct points in the pipeline rather than one.
It sits below the top grade because a substantial part of what is sold alongside the model is conventional: more than 250 report types, an investigation case platform and an optional human monitoring services team, all of which would function on rules alone.
The human decision point is designed in rather than assumed. Output routes into an investigation platform built for case handling, with alerting for immediate review and reporting for documentation, and an optional monitoring services team exists for organisations without the internal capacity to work the queue, which is an honest acknowledgement that the alerts require skilled labour to be worth anything.
What is not published is the operational detail that separates a good oversight model from a described one: no alerting threshold, no statement of what qualification the reviewer needs, and no description of what the reviewer is shown about why a given behaviour was surfaced.
Mechanism is described at a useful level in places and left vague in others. Machine learning is named as establishing baseline behaviours and norms, with deviation, peer comparison and out of hours access given as example signals. OneRx is described concretely as AI assisted standardisation of medication naming across disparate source systems, which is a specific and checkable claim about a specific data problem rather than a slogan.
Against that, no model family, feature set, training population or performance measure is published for the detection model itself, so a buyer can follow what the system is doing without being able to ask how well it does it.
No model provider, framework or third party component is named for either the detection model or the OneRx normalisation layer. The trust page does disclose that the company applies AI assisted analysis internally within its own product security and development process, which is an unusual and welcome piece of transparency about how the software is built, and it says nothing about what powers the software once it runs. Nothing distinguishes capability inherited from the FairWarning and Maize Analytics acquisitions from capability built or licensed since.
This is the weakest part of an otherwise solid record. No outcome study, detection accuracy figure, false positive rate or named customer result was located for the diversion product. Adoption is asserted as widespread in the United States and a Canadian market entry was announced in March 2023, but neither is quantified.
The one checkable third party measure found is a KLAS assessment reported in 2022 placing Imprivata at 70.1 in drug diversion monitoring, the lowest of the four vendors covered and flagged in that report as resting on limited data. Four years is long enough that the figure should not be read as current, and the grade reflects the absence of anything published since rather than the score itself.
The best grade on this axis in the lane, earned on one disclosure nobody else makes. Imprivata publishes a retention period: controlled substance data is stored for three years to support lifecycle auditing, and the sibling privacy product carries the same three year archive commitment. Every other vendor graded here leaves retention entirely unstated, which means a buyer cannot establish how long behavioural records about their staff persist.
Combined with the ISO 27701 certification this is a real stewardship position rather than a claim. It stays at this grade because the central model question is still unanswered: nothing states whether customer transaction data trains models that persist beyond the tenant, or whether baselines are fitted per customer or across the installed base. A tenancy and training statement is the single disclosure that would move this to the band above.
The strongest position in this lane, resting on a certification rather than an assertion. Imprivata holds ISO 27701, the privacy information management standard, alongside ISO 27001, and its trust page states the certified scope covers the processing of personally identifiable information and protected health information.
A privacy management system certified by an accredited third party is a materially different signal from the usual claim of HIPAA compliance, and it is directly on point for a product whose subject matter is the recorded behaviour of identified staff and patients. Business associate agreement terms and data ownership provisions remain unpublished and are settled in contract, which is what holds this below the top grade.
The broadest credential set in this lane, held by a company whose core business is security. ISO 27001 and ISO 27701 certifications were issued by A LIGN, an accredited certification body named in the announcement, and a SOC 2 attestation and HIPAA governance are stated on a public trust and security page that a buyer can read without entering a sales process.
The page also describes current practice rather than a historical badge, including the defensive use of AI assisted analysis in their own product security and release process. Two specifics hold it below the top grade and both are checkable. The certification announcement cites the 2013 revision of ISO 27001, which has since been superseded, and no confirmation of transition to the current revision was located.
And the published scope is stated at company level without enumerating which products sit inside the certified management system, so a buyer cannot establish from public material that this product is covered.
Monitoring software rather than a regulated device, so no clearance applies and none is claimed. Regulatory purpose is engaged directly rather than left implicit: the product ships more than 250 report types explicitly for compliance and audit, monitors the full controlled substance lifecycle in the form regulators ask about, and holds data for three years, which is a retention period aligned to audit rather than to convenience.
It stops below a higher grade because no statement of the company's own regulatory position was located, and nothing published guides customers on how output should be used in reporting to the Drug Enforcement Administration or a state board, which is where these findings routinely end up.
No governance statement, validation summary, false positive rate or bias analysis was located for a model that flags named clinicians for investigation. The gap is sharper here than elsewhere because of what the vendor does claim.
Its own product material states that the system protects staff from false accusations, which is a claim about the very failure mode this axis exists to examine, and nothing published quantifies how often the system is wrong or describes what protection consists of. Making the claim without the number invites exactly the scrutiny the number would answer.
The peer comparison and out of hours signals in use also carry the familiar distributional risk, concentrating attention on irregular schedules and high turnover units, and no examination of that distribution has been published.
This vendor is the only one in the lane to name the harm and it still earns the floor grade, which is worth explaining. Its product material states that the system protects staff from false accusations, an acknowledgement that a wrongly flagged clinician is a real and foreseeable outcome, and no competitor here says as much. Nothing published describes what that protection consists of.
There is no statement of who owns the determination, whether a flagged individual is informed, what evidentiary weight a flag is intended to carry in an employment or licensure process, or how one is challenged and withdrawn. An unsupported protective claim cannot carry a grade on this axis, because reassurance without a mechanism is weaker for the person being flagged than plain silence would be.
The product analyses data from electronic health records, pharmacy management systems and dispensing systems, and reaches into electronic prescribing workflows, so the input surface spans clinical and pharmacy operations rather than dispensing cabinets alone. The existence of OneRx is itself indirect evidence of integration breadth, since a medication name normalisation layer is only necessary across genuinely heterogeneous sources.
No specific electronic health record or dispensing cabinet vendor is named, no source list is enumerated, and no integration method or effort is described, which is what holds the grade here rather than higher.
No hosting model, cloud provider, region or residency commitment was located for this product. The trust page notes that product availability varies by region and refers to cloud service enhancements, and the company announced Canadian availability as a distinct event in March 2023, which suggests regional deployment capability without stating one.
That suggestion is worth a buyer's question rather than a grade, and the specific question is whether Canadian customer data remains in Canada, since a separate market entry announcement is not a residency commitment. The sibling privacy product is documented as running inside the customer environment, and nothing establishes that the same is true here, so that architecture should not be assumed to carry across.
No price, pricing page or basis of charge was located in two passes. The product appears in at least one software marketplace listing, which establishes that it is transacted through channel partners without revealing what it costs.
Nothing published indicates whether the optional Drug Diversion Monitoring Services team is included, priced separately or sold as a tier, which is a material question because it is the difference between buying software and buying an outsourced monitoring function.
Coverage is described by lifecycle stage rather than by care setting, spanning prescription, dispensing, preparation, administration, waste and removal, with departments identified as higher risk singled out for monitoring and electronic prescribing workflows included in scope. Geographic coverage is documented across the United States and Canada with a dated market entry for the latter.
What is missing is the setting level breakdown the stronger records in this lane provide: nothing distinguishes acute inpatient from procedural, anaesthesia, retail, ambulatory or post acute deployment, and no facility count or segment profile is published.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
Not published
|
Quotation. Enterprise software subscription within the Imprivata Digital Identity Framework, with an optional monitoring services team, and no published unit of charge. | Not published. Business associate agreement terms are settled in contract. The company holds ISO 27701 certification stated to cover the processing of personally identifiable and protected health information, which speaks to the control environment rather than to the contractual terms. | Not published. The product ingests electronic health record, pharmacy and dispensing data across heterogeneous systems, and the existence of the OneRx name standardisation layer implies meaningful source variation to be reconciled during onboarding. No implementation scope or figure is given anywhere public. | Vendor Published |
No price, pricing page or basis of charge was located across two passes. The product appears in at least one software marketplace listing, establishing that it transacts through channel partners without exposing a rate. The question a buyer should force early is the treatment of the Drug Diversion Monitoring Services team, which the vendor offers alongside the software: nothing published states whether it is bundled, tiered or separately contracted, and that distinction decides whether the purchase is a software licence or a partly outsourced monitoring function with an ongoing labour cost attached. A second question worth asking is whether pricing differs between the United States and Canada, since the Canadian offering was launched as a separate market entry in March 2023.