Medication Safety & Prescribing
M

MedAware

MedAware is an Israeli company whose platform monitors prescribing for medication related risk using machine learning rather than the rule libraries that conventional medication decision support runs on. It was founded in 2012 after a nine year old asthma patient died because his physician selected the wrong drug from an electronic prescribing dropdown, an error no interaction rule was written to catch because the prescription was internally consistent and simply belonged to the wrong patient.

The engine applies outlier detection over longitudinal and real time patient data, an approach the company compares to fraud detection in financial services, and flags prescriptions that are anomalous for this particular patient rather than prescriptions that violate a predefined rule. Products span prescribing error detection, evolving adverse drug event monitoring, and an algorithm that identifies patients at risk of opioid use disorder.

The platform runs continuously rather than only at the moment of ordering, and delivers into existing systems through vendor agnostic APIs, an athenahealth Marketplace listing and, at Ballad Health from 2024, natively inside an Epic pharmacy workflow. MedAware is unusual in this index for the independence of its evidence base, which was produced largely by investigators at Brigham and Women's Hospital and Harvard Medical School and published in JAMIA and the Joint Commission Journal on Quality and Patient Safety, and equally unusual for how little it publishes about its own compliance, security and governance posture.

AI Health Index verifiedAugust 2, 2026
Compare MedAware with other vendors
Founded
2012
Headquarters
Ra'anana, Israel
Categories
medication-safety-and-prescribing, clinical-decision-support
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
AA on AI CentralityThe artificial intelligence is the product. Remove the model and there is nothing left to sell.
Vendor Published

The model is the product. MedAware exists because rule based interaction checking could not catch the error that motivated its founding, a correctly written prescription issued to the wrong patient, and the engine works by outlier detection over longitudinal patient data rather than by evaluating predefined rules.

Independent researchers writing in PLOS One describe it as the first commercial system for preventing prescription errors using machine learning, which is a third party characterisation rather than a vendor claim. The published mechanism spans statistical outlier detection through deep learning with neural networks, with different algorithms applied to different error types, and the company compares the approach to fraud detection in financial services.

David Bates of Brigham and Women's Hospital states the distinction in the vendor's own marketing, saying that because it is not rule based the system represents a paradigm shift. Remove the machine learning and no product remains.

BB on Autonomy and Oversight ModelThe oversight structure is described and one part is missing, commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

Output is an alert to a prescriber or a pharmacist and the system never acts on a medication itself, so a licensed human stands between every model output and every patient. Two published numbers make the oversight picture unusually legible for this category: an alert burden of roughly 1.6 percent of medical orders, and a prescriber behaviour change rate the company puts above 40 percent.

Alert burden matters more here than sensitivity, because the defining failure of medication decision support is the alert that fires so often it is dismissed, and a vendor willing to publish that denominator is answering the question the category actually turns on. The company also describes a standing human layer, with its own data analysts and clinical teams reviewing and refining the tools and combining the algorithms with statistical and clinical review.

Held below the top grade because the threshold at which an alert fires is not published, the size and scope of that review layer is not described, and no escalation path is published for an alert nobody acts on.

CC on Model and Technology TransparencyThe architecture is described in general terms with nothing identified. Proprietary is asserted rather than explained.
Third Party Estimated

The model family is named at a high level, unsupervised outlier detection with algorithms ranging from statistical methods to deep learning with neural networks, which is more than several competitors in this category disclose. The limit is documented by an outside group rather than inferred.

Researchers publishing an independent prescription error detection study in PLOS One record that the MedAware report does not provide information about the machine learning process, and attribute that omission to commercial reasons.

Published material names no features, no training population, no alerting threshold, no calibration and no drift monitoring concept, which is a conspicuous gap for a system whose entire premise is that normal prescribing patterns shift over time and that anomaly is defined against them. The move that changes this grade is a model description detailed enough for a third party to characterise where the system degrades.

DD on Model Supply Chain DisclosureNothing establishes who else sits between a patient record and an answer.
Vendor Published

Nothing identifies any party in the chain: no hosting arrangement, no sub processor list, and no retention, de identification or minimum necessary scoping was located in two passes, against a platform that ingests longitudinal and real time patient data including prescriptions, laboratory results and demographics, runs continuously rather than only at the point of ordering, and in at least one deployment operates natively inside the customer's pharmacy workflow.

That is a broad and persistent view of the record rather than a query at a moment. The training question carries more weight here than for most vendors and it is a clinical question as much as a privacy one. An outlier detection method works by comparing a prescription against patterns learned from a population, so what that population consists of determines what counts as anomalous, and a model learned largely on one health system's prescribing may flag differently in another with different case mix or formulary.

Nothing states whether customer data contributes to model development across institutions, whether models are institution specific or shared, or whether a customer can decline. A cross border question sits alongside it, since the company operates from one jurisdiction while processing United States protected health information, and nothing published addresses transfer or processing location. Ask what population the models learn from, whether your data joins it, and where processing occurs.

BB on Clinical and Operational EvidenceNamed deployments with dated outcome figures and enough method to test them, or published research short of independent validation.
Third Party Estimated

The evidence base was produced mainly by investigators who do not work for the company, which is rare in this category. A Harvard Medical School group publishing in JAMIA screened five years of electronic health record data and found that in a 300 chart sample roughly 75 percent of alerts validly identified potential medication errors, three quarters of those being potentially life threatening.

Rozenblum and colleagues in the Joint Commission Journal on Quality and Patient Safety generated alerts retrospectively across 747,985 patients at Brigham and Women's Hospital and Massachusetts General Hospital, reviewed a random 300 alert sample and reported 79.7 percent clinically valid, 68.2 percent that the existing decision support system would not have flagged, and an extrapolated 1.3 million dollars in avoided direct costs.

Separate work validated the opioid use disorder algorithm against two expert opinions on more than 649,000 outpatient records at above 93 percent accuracy, and Sheba Medical Center has published its own validation. Three things hold this at B. The pivotal studies generated alerts retrospectively rather than firing them prospectively, so validity and behaviour change are not measured in the same design. There is no randomised or controlled evaluation.

And David Bates, an author within this literature, also appears as an endorsing quote in the vendor's marketing, which is disclosed here rather than treated as disqualifying. A prospective evaluation in which the alerts actually fired would move this to A.

CC on AI Safety and PHI StewardshipGeneral assurances of privacy and security that do not answer the questions artificial intelligence raises: what is retained, what reaches a model, and what happens to it there.
Vendor Published

The platform ingests longitudinal and real time patient data including prescriptions, laboratory results and demographics, runs continuously rather than only at the point of ordering, and in at least one deployment operates natively inside the customer's Epic pharmacy workflow. That is a broad and persistent view of the record.

Published material describes what the system does with the data clinically without describing what happens to the data operationally, and two retrieval passes over the vendor's own site and news archive located no retention period, no de identification practice, no minimum necessary scoping and no statement of whether customer data contributes to model development across institutions.

That last question carries more weight here than for most vendors, because an outlier detection method depends on comparing a prescription against patterns learned from a population, so what the population consists of is a substantive clinical question and not only a privacy one. An Israeli company processing United States protected health information also raises a cross border handling question that nothing published addresses.

Regulatory and Compliance
DD on HIPAA and BAA PostureNo statement of status and no privacy document that reaches the product.
Vendor Published

This grade describes what a buyer can retrieve before contact, not what exists contractually. A business associate agreement almost certainly governs the Ballad Health and athenahealth deployments, since neither would be possible without one. What is absent is any public expression of it.

Two retrieval passes over the vendor's own site, technology page and news archive surfaced no HIPAA statement, no BAA terms, no execution path, no subprocessor list and no compliance or legal page of any kind. The bar being missed is one that peers in the same market have cleared, since several vendors in this index publish at least an assertion of HIPAA compliance and one publishes the full text of its business associate agreement at an open URL. Scope stated plainly: the site is small and no privacy policy surfaced in either pass, so this reflects published posture and should be revisited if a compliance page appears.

DD on Security Certifications and Trust CenterControls are asserted with nothing independent behind them, or nothing is published. Read the note before concluding anything: this is the grade most often corrected on a second pass, because assurance material frequently sits on a parent domain or inside an old announcement rather than on the product pages.
Vendor Published

Retrieval across the vendor's own material surfaced no SOC 2 attestation of either type, no HITRUST certification, no ISO 27001, no trust centre, no penetration testing cadence and no vulnerability disclosure policy. The nearest thing to external assurance is commercial rather than published.

Listing in the athenahealth Marketplace and native operation inside an Epic pharmacy workflow both imply that a partner conducted a security review, and Becton Dickinson is an investor, but a partner's private diligence is not something a buyer's security team can read. For a product that sits inside the pharmacy workflow of an acute care health system and holds a continuous view of prescribing data, this is the widest gap in the record and the fastest one to close.

CC on FDA and Regulatory StatusNo device claim is made and the product is scoped accordingly. Most administrative and operational products sit here and are not penalised for it, because this axis grades the appropriateness of the positioning rather than possession of a clearance.
Vendor Published

MedAware markets no FDA clearance and none was located, which is consistent with a product that alerts a clinician rather than computing a dose or acting on a patient. Advisory medication risk alerting is the territory the Cures Act exclusion for non device clinical decision support was written to cover, so operating without clearance is a legitimate position rather than a deficiency. The gap is that the company states no position anywhere.

Vendors in this category are currently split between products cleared as Class II software because they compute a dose and products publicly asserting the exclusion, with the boundary between them the subject of an active petition to the agency, so a compliance function needs to know which reading applies before deployment. Graded C because only the absence of an articulated regulatory position counts against the record, not the absence of a clearance the product does not appear to need.

DD on AI Governance and Bias DisclosureNothing published on how model behaviour is governed or tested. Multilingual operation with no subgroup performance sits here when the vendor markets recognition quality as a strength, because a caller the system failed to understand leaves no complaint and no record.
Vendor Published

The pointed absence is subgroup performance. Retrieval located no reporting of accuracy by age, sex, race, ethnicity, insurance status or site, no bias assessment, no model governance documentation and no statement of how the system is monitored for degradation after deployment.

This weighs more heavily than the grade alone conveys, because one of the company's products scores patients for risk of opioid use disorder, and the lack of subgroup analysis is precisely the criticism peer reviewed informatics literature has levelled at the most widely deployed opioid risk score in the United States. A vendor whose whole argument is that its science is better than the incumbent's is unusually well placed to publish the subgroup analysis the incumbent has not. That is the specific ask to put to them, and answering it would move this grade further than anything else on this record.

DD on AI Liability and RecourseNothing published on what happens when the system is wrong.
Peer Reviewed Publication

The opacity here is documented by an outside party rather than inferred, which is unusual and makes the finding firmer than most. Researchers publishing an independent prescription error detection study record that the vendor's report does not provide information about the machine learning process, and attribute the omission to commercial reasons.

From the vendor, the model family is named at a high level as unsupervised outlier detection spanning statistical methods to neural networks, and nothing else: no features, no training population, no alerting threshold, no calibration and no warranty, indemnity or remediation commitment. One absence is conspicuous rather than ordinary because it contradicts the product's own premise.

This is an anomaly detector, so its entire logic is that a prescription is judged against learned patterns of normal prescribing, and normal prescribing shifts as formularies, guidelines and practice change. A system built on that premise needs a concept of drift and a way of monitoring for it, and no drift monitoring is described anywhere. Without it a buyer cannot tell whether the alerting behaviour they validated at go live is the behaviour they have two years later.

The failure direction that matters is also silent: a missed dangerous prescription generates no alert and therefore no artefact. Ask what the alerting threshold is, how drift is monitored and reported, and what the false negative rate is against a reviewed sample.

Integration and Deployment
BB on EHR and Interoperability DepthNamed systems with read access or one directional writing, or standards support with named deployments behind it.
Vendor Published

Integration is named and confirmed by customers rather than asserted. At Ballad Health the acute care pharmacy team began operating MedAware natively inside an Epic pharmacy workflow in October 2024, described as the first deployment of its kind, following a partnership announced in July 2023 and confirmed on the health system's own newsroom.

The platform is listed in the athenahealth Marketplace and integrated with athenaOne, a partnership with Allscripts dates to 2018, and a collaboration with Baxter extends the same safety layer toward infusion devices. Delivery is through vendor agnostic APIs designed to sit inside multiple partner ecosystems.

Held at B because no FHIR conformance statement or public API documentation was located, the Allscripts relationship is eight years old with no current confirmation, and the named live footprint is small relative to the breadth the vendor agnostic framing implies.

CC on Deployment Model and Data ResidencyA single hosted option with location implied rather than committed.
Vendor Published

Published material describes where the product appears to a clinician, inside an Epic pharmacy workflow or an athenahealth practice, but not where it runs. Retrieval located no hosting model, no cloud region, no data residency commitment, no on premise option and no statement of whether processing occurs inside the customer's environment or on vendor infrastructure.

Headquarters in Israel with a United States commercial presence makes the residency question concrete rather than theoretical for a health system privacy office, and it is the kind of question that surfaces late in procurement when it is expensive to answer. Graded C rather than lower because the deployments are named and confirmed by the customers themselves, which establishes that the integration path works in production even though its shape is undocumented.

Commercial
DD on Commercial TransparencyNothing a buyer can establish before a sales conversation. A published pricing claim contradicted by evidence also grades here.
Vendor Published

Pricing is entirely undisclosed. Retrieval located no price, no unit, no pricing mechanism, no contract shape and no implementation fee guidance. The asymmetry is worth naming because the same vendor participates in a peer reviewed cost analysis and publicises an extrapolated 1.3 million dollars in avoided direct healthcare costs from that work.

Publishing a return while publishing nothing about the cost side of that return is a recurring pattern in this index and it is graded the same way wherever it appears. Stating a pricing basis alone, whether per bed, per prescriber or per order, would move this grade without disclosing a negotiated rate.

BB on Setting and Specialty CoverageCoverage is named with validation behind part of it.
Vendor Published

Coverage spans several settings rather than one. Inpatient acute care is confirmed by the Ballad Health pharmacy deployment, ambulatory care by the athenahealth Marketplace listing and by the Brigham and Women's and Massachusetts General outpatient datasets that produced the evidence base, and the company publishes material aimed at deprescribing in post acute and long term care.

Because the method is outlier detection over prescribing data rather than a condition specific model, specialty coverage follows the data rather than a defined indication list, which is a genuine breadth advantage over rule libraries that must be authored per drug class.

Held at B because the named live customer base is small, the geographic footprint is limited to the United States and Israel, and paediatric performance is not separately addressed even though the founding case that motivated the company was a child.

Comparisons

Compared With

Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Undisclosed
Not published Not published Not published Vendor Published

No price, unit or pricing mechanism was located across two retrieval passes over the vendor's own site and news archive, and no implementation or integration fee guidance is published. Contracting appears to run through direct enterprise sale to health systems, with a second route through the athenahealth Marketplace whose commercial terms are also unpublished.

The asymmetry worth flagging to a buyer is that the vendor participates in a peer reviewed cost analysis and publicises an extrapolated 1.3 million dollars in avoided direct healthcare costs, so a return figure is in the public record while the cost of obtaining it is not. Ask for the pricing basis first, since per bed, per prescriber and per order economics produce very different totals for the same deployment.