Patient privacy monitoring software that finds the accesses that matter
Your clinical systems generate millions of PHI access events. A handful are inappropriate, and each one can become an OCR investigation. Haystack iS audits every access across every system, learns your organization's patterns, and surfaces only what deserves an investigator's time.
Privacy teams are asked to find a handful of inappropriate accesses inside millions of legitimate ones, using fragmented reports and rules that flag everything.
Fragmented audit logs
EHR, document management, PACS, labs, and HR systems each keep separate audit trails. Piecing together one incident means running separate reports across all of them.
False-positive overload
Legacy rules-based tools flag everything unusual in a busy hospital. Teams burn hours clearing legitimate accesses while genuine risk waits in the queue.
Self-access busywork
Employees viewing their own records are policy violations, not breaches, yet each one used to require manual follow-up. That time belongs on preventing OCR-reportable incidents.
How it works
How Haystack iS works
Monitor everything, flag only what matters, and automate the follow-up that used to consume your team.
01
Consolidates every audit trail
Audit data from EHRs, document management, labs, PACS, HR, and any system that logs PHI access flows into one unified event list. One audit covers all applications.
02
Scores events with Solomon Engines
The proprietary AI and machine learning framework learns your organization's access patterns and assigns each event a Risk Index, so auditors start with the highest-risk activity.
03
Classifies risk types
Co-worker access, self-access, same household or street, patient-is-employee, VIP and confidential patients, guarantor matches, and discharged-employee access, each with configurable scoring.
04
Automates follow-up with AVA
AVA contacts users about suspicious activity, sends questionnaires, re-scores events from the answers, escalates unanswered cases, and documents everything inside the platform.
Capabilities
The complete privacy monitoring program
Detection, investigation, documentation, and prevention in one platform.
Unified PHI monitoring
One event list across EHRs, document management, labs, PACS, HR, and more. No more separate reports.
Solomon Engines AI
Learns your access patterns and adapts as workflows change, cutting false positives over time.
Risk Index scoring
Every event scored by identified risk types so auditors triage by quantified risk, not guesswork.
Risk type intelligence
Co-worker, self-access, same household, VIP, guarantor, and discharged-employee access detection.
AVA follow-up automation
Questionnaires sent, responses evaluated, incidents escalated or closed automatically by rule.
Manager's Portal
Manager reviews assigned, tracked, and documented in-platform. No phone tag, no email chains.
Dynamic forensics
User and patient access reports, geographic proximity mapping, and full investigation history.
Watchlist monitoring
Flag VIP patients or staff under review for elevated monitoring anywhere they appear.
Social media monitoring
Tracks employee-patient social connections, a disclosure vector most tools ignore.
OCR-compliant documentation
Breach determinations, safeguards, corrective actions, and notifications in structured, exportable records.
Predictive training intelligence
Spot access-pattern spikes ahead of time and schedule targeted training 30-90 days out.
800+ vendor integrations
Open-standard audit import consumes data from virtually any system, with 180+ vendors supported.
Real-world results
Measured by the systems that run it
Outcomes below come directly from the product whitepapers, with named organizations.
WVU Medicine
One platform for a 23-hospital system
West Virginia's largest health system and largest private employer, an iatricSystems partner for over 14 years.
WVU Medicine's privacy team ran separate audit reports across clinical systems, EHRs, document management, and labs, auditing reactively when suspicion arose. Haystack iS consolidated the entire audit workflow into one platform with comprehensive, proactive coverage. AVA now handles self-access workflows, with co-worker and family access reviews next.
A northern Nevada healthcare leader with 1,200+ providers and 375,000 Epic MyChart users.
Comprehensive auditing of thousands of daily PHI accesses was impossible manually, and self-access follow-up consumed the team. With Haystack iS, Renown monitors the full daily volume systematically. AVA virtually eliminated manual self-access follow-up, and the team now schedules targeted training 30 to 90 days ahead of predicted access spikes.
providers across the health system
1,200+
days of predictive training lead time
30-90
In their words
"It used to take us a lot longer to review multiple audit logs, because we had to run separate reports for everything. With Haystack, we can run one audit for all our applications, which cuts down on the review and gives us a better picture of what's going on."
Miranda BrownEnterprise Privacy Manager, WVU Medicine
"The feature that's reduced our workload the most has been AVA."
Brian ColonnaDirector of Compliance, Renown Health
"Before we had AVA, we would need to connect with users manually for self-access. It was so time consuming to have to follow up with every individual, knowing that these aren't even real HIPAA violations. AVA gathering that information instead has significantly reduced our workload, and lets our team focus on preventing what could be a true OCR breach."
Nicole GaarenstroomCompliance Coordinator, Renown Health
"Now we can start getting ahead of things. If we see a spike in say family snooping around the holidays, we can schedule educational sessions 30 days or 90 days out to avoid that spike."
Brian ColonnaDirector of Compliance, Renown Health
"We have a terrific support team. It's not like a typical hospital and vendor relationship. They're like our co-workers."
Miranda BrownEnterprise Privacy Manager, WVU Medicine
Swipe for more
Integrations and security
Works with what you already run
With 800+ vendor integrations across 200+ implementations and an open-standard audit file import spec, Haystack iS consumes audit data from virtually any system that produces it. If a system is not yet supported, iatricSystems builds the integration with you.
Epic
Cerner
MEDITECH
Allscripts
athenahealth
PACS systems
Lab systems
HR platforms
Document management
Active Directory
Open audit-file import
OCR-ready exports
Product questions
Haystack iS FAQ
How does Haystack iS reduce false positives?
Solomon Engines, the platform's AI and machine learning framework, is trained on your organization's specific access patterns and learns the difference between normal workflow variation and genuinely suspicious behavior. It also limits false negatives: AVA follow-up verifies flagged events so real cases are not lost while noise is filtered out.
Can it automate self-access cases?
Yes. AVA identifies self-access events, contacts the employee with a targeted questionnaire by email or SMS, evaluates the response, re-scores the event, and closes or escalates it by rule. Renown Health reports AVA virtually eliminated manual self-access follow-up.
Does Haystack iS produce OCR-ready investigation documentation?
Every investigation captures risk summaries, breach determinations, affected demographics, safeguards, corrective actions, and notification records in a structured, auditable format that meets OCR compliance standards, with PDF export for regulatory submissions.
Which systems can feed audit data into Haystack iS?
Haystack iS supports 180+ vendors and thousands of data feeds spanning EHRs, PACS, pharmacy, HR, labs, and document management, including Epic, Cerner, MEDITECH, Allscripts, Kronos, Workday, and Active Directory. An open-standard audit file import spec covers virtually any system that generates an audit file.
How is this different from HIPAA compliance software?
Policy and training platforms manage documents, attestations, and checklists. Haystack iS is patient privacy monitoring software: it continuously audits actual PHI access activity across your clinical systems, detects inappropriate access, and documents investigations. The two categories solve different problems.
Can department managers participate in investigations?
Yes. The built-in Manager's Portal assigns reviews to managers with priority levels, due dates, and activity logs, and captures every touchpoint inside the platform instead of email threads and spreadsheets.