Open loops
Walks the timeline for follow-ups that were never closed — unacknowledged abnormal results, incomplete referrals, imaging recommendations that went nowhere.
Potassium critical (6.4) resulted 817 days ago — never acknowledged.
Vivantal reads a de-identified record inside your browser, clears every follow-up that a published guideline already covers, and ranks what is left by how much it matters. Each finding arrives with the rule that produced it.
US adults are estimated to experience an outpatient diagnostic error every year. The information needed to catch most of them was already in the chart.
Singh H, Meyer AND, Thomas EJ. The frequency of diagnostic errors in outpatient care. BMJ Qual Saf, 2014. Illustrative of the problem space, not a claim about any specific population.
Five stages, all of them running on your own machine: de-identified locally, compiled into one coded record, then read by named rules you can open and inspect.
HIPAA Safe Harbor identifiers stripped and dates shifted on your machine. Raw PHI never moves.
CSV, FHIR, HL7 or C-CDA mapped by meaning, then coded to LOINC and RxNorm.
One canonical record. Every field carries its value, its confidence and its source of truth.
Deterministic engines read time, source authority, patient baseline and clinical relationships.
Each finding links to the exact event and the rule that fired. Dismiss one and it stays gone.
Open any finding and you get the rule that produced it, the event that triggered that rule, the guideline it rests on, the confidence attached to it, and the reason it survived suppression.
Potassium 6.4 mmol/L resulted 817 days ago and never acknowledged.
Hyperkalaemia in the critical range with no documented response.
unacknowledged_critical_resultLAB · 2777-1 · K 6.4 mmol/L · flag HIllustrative worked example · drawn from the bundled synthetic cohort
Seven deterministic readings of the same canonical record. Every one is a named, auditable rule.
Walks the timeline for follow-ups that were never closed — unacknowledged abnormal results, incomplete referrals, imaging recommendations that went nowhere.
Potassium critical (6.4) resulted 817 days ago — never acknowledged.
Knows the monitoring cadence a drug expects and whether it is being met, and reads each lab's trajectory across visits — the slow slide a single result hides.
Warfarin on file 240 days — INR expected ~monthly, last drawn 180 days ago.
Judges each value against the patient's own baseline and rate of change, not just the population reference range.
Creatinine 1.25 is in range, but doubled from this patient's 0.6 — an AKI signal.
Ranks every fact by the authority of its source — inpatient and pharmacy MAR outrank an outside record or patient recall — and reconciles what disagrees.
Lisinopril: patient-reported 10 mg vs pharmacy MAR 20 mg — trust the MAR.
Reasons over an ontology of drugs, classes and conditions — therapeutic duplication, interacting co-prescriptions, a diagnosis whose expected work-up is missing.
Atrial fibrillation on file with no anticoagulation.
Measures how often an actionable finding actually gets closed for each subgroup — race, insurance, language, sex, age — with a significance test to separate signal from noise.
Medicaid patients close 51% of findings vs 74% reference — p < 0.001.
Scores each record's reliability with itemised reasons, puts a confidence on every finding, and remembers what you dismiss so it stops re-raising it.
Record reliability 73% — −12% (3 labs missing units), −8% (1 undated event).
Example findings · bundled synthetic cohort
Not a policy. An architecture — and one you can verify in about thirty seconds with your own network tab.
Every chart below is drawn from real engine output on the bundled cohort, or is stamped as an illustrative worked example. We do not fabricate clinical figures.
Every engine, tool and guarantee. Drag to move the camera; click any node to open it.
Eighty synthetic patients with realistic gaps, every engine live. Or start an account and land in the patient builder.
Patient safety, health equity, and the informatics teams who own the data underneath both — all three questions live in one record.
Every open loop across a panel — unacknowledged criticals, overdue monitoring, worsening trends — ranked by severity and confidence.
Closure rates by race, insurance, language, sex, and age — with a significance test on the gap.
Messy CSV, Epic/Cerner dumps, FHIR, HL7, C-CDA — schema inferred, coded to LOINC and RxNorm, on-device.
Years of visits, mostly fine. Vivantal pulls out only what needs a human — coded, confidence-scored, and linked to the exact event.
| unacknowledged_result | A high calcium of 12.9 was resulted and never acknowledged — possible hypercalcemia left unworked. |
| baseline_deviation | Creatinine 1.25 sits inside the reference range but has doubled from this patient's own baseline — a KDIGO acute-kidney-injury threshold. |
| monitoring_overdue | Warfarin needs INR roughly monthly; the last INR was 180 days ago — monitoring has lapsed. |
| provenance_conflict | The med list shows lisinopril 10 mg (patient-reported) vs 20 mg (pharmacy MAR) — reconcile to the more authoritative source. |
| therapeutic_duplication | Two statins are active at once — likely duplication across visits or clinicians. |
| condition_care_gap | Atrial fibrillation is on the problem list with no anticoagulation on file. |
No model, no black box. Every finding comes from a named rule or an explicit statistic you can check by hand.
Demo cohort, a patient you build, or your own de-identified export — CSV, FHIR, HL7, C-CDA. Stays in your browser.
Schema inferred by content, columns mapped by meaning, concepts coded to LOINC and RxNorm — into one canonical record.
Deterministic engines read for open loops, monitoring lapses, trends, source conflicts, and subgroup disparities.
Every finding links to the exact event and explains itself. Verify, export a worklist, dismiss false positives for good.
| unacknowledged_result | An abnormal or critical lab result with no documented acknowledgement in the record. |
| imaging_followup_open | An imaging study whose report recommends follow-up that never occurred. |
| referral_incomplete | A referral placed but never completed, ranked by how long it's been open. |
| medication_unmonitored · monitoring_overdue | A narrow-index drug started without its monitoring lab, or a monitoring cadence that has since lapsed (e.g. warfarin without a recent INR). |
| abnormal_trend · baseline_deviation | A value worsening across visits, or an in-range value that has deviated materially from the patient's own baseline. |
| provenance_conflict | The same fact recorded differently by two sources of differing authority — reconciled to the more authoritative one. |
| therapeutic_duplication · condition_care_gap | Two agents of one class active at once, or a coded diagnosis whose expected work-up is missing. |
| closure rate | For each subgroup, the share of actionable findings that actually got closed. |
| two-proportion z-test | Compares each group to the best-performing one; surfaces gaps unlikely to be chance. |
| four-fifths rule | Flags any group closing at under 80% of the reference rate — a standard disparity threshold. |
| min-N guard | Cohorts too small for a reliable signal are reported honestly as "not enough data," never as false headlines. |
Before a single record reaches the lenses, it passes through the Transcriptor — an open de-identification step that runs entirely on the authorized user's own machine. It reads a raw record, transcribes it into Vivantal's structured event format, removes the direct HIPAA Safe Harbor identifiers, and shifts dates per patient (intervals preserved). Nothing identifiable ever leaves the device, because there is no server to send it to.
Equal findings should get equal action. This audit measures, for each subgroup, how often an actionable finding gets closed — then compares each group to the best-performing one. A gap that survives a significance test is a disparity worth investigating, not noise.
Fragmented care produces conflicts no single clinician sees: interacting medications, a drug continued against a lab that contraindicates it, duplicated work-ups. This lens reads each record and surfaces those contradictions for a pharmacist or clinician to resolve.
A value that moves from normal toward danger across several visits is invisible in any single result. This lens trends each repeated measurement and flags the patients whose trajectory is heading the wrong way — before it becomes a crisis.
Drag the sliders to simulate closing care gaps across this cohort, and watch the numbers recompute instantly. Take the projected result to leadership — before you've spent a dollar. Runs entirely in your browser.
Root-cause analysis normally takes weeks of committee meetings. This mines patterns across the whole cohort in seconds — surfacing the systemic causes behind your open loops, ranked by how much each contributes. No patient data leaves your browser; only event types, timing, and categories are analyzed.
Your safety and equity performance, side by side with published-literature benchmarks — each source cited. These are literature reference ranges, not a live national percentile. Computed in your browser, no data transmitted.
A forward-looking triage layer. Oracle ranks who's most likely to have a care gap turn into a real failure, and shows exactly which signals put them there. Deterministic and explainable — never a black box. Computed in your browser.
A local agent runs on your machine on the schedule you set — reads the practice, ranks what matters, and drafts the next move, so a prioritized brief is waiting when you arrive. Nothing sends until a human approves. Everything is computed in your browser — no patient data leaves the device.
The long-term vision: a privacy-preserving benchmark across participating clinics that learns only from anonymous aggregates — never patient data. Your metrics below are real and computed locally. There is no clinic-to-clinic benchmark here — no clinic has contributed data. What you see compared against is cited published literature and real CMS open data, labelled as such wherever it appears.
Add events one at a time — a lab, a referral, an imaging study, a medication. Each becomes a row. When the record is built, analyze it directly or export it to load into the cohort tools.
Paste a clinical note, discharge summary, or referral letter. Vivantal parses it into structured events on your device — no cloud, no AI service, nothing sent anywhere. Every extracted medication and lab is checked against the offline clinical vocabulary before it's added.
Pick a type, fill the fields, add it to the record.
Protecting patient data isn't a policy we promise — it's an architecture we can't violate. Here's exactly how, in plain terms, and the rules we hold ourselves to.
Protected health information is never compromised. Vivantal does not receive, store, or transmit identifiable patient data — ever. There is no server in our analysis pipeline to send data to. Everything runs in your browser, on your machine. You can't leak what you never receive, and we never receive it.
The entire engine is JavaScript running inside your browser tab. Records you load are processed locally and never sent anywhere. Disconnect from the internet entirely and Vivantal still works.
Vivantal is designed for data that's already de-identified. A separate, open converter — which runs on your machine, never ours — removes the direct HIPAA Safe Harbor identifiers and shifts dates per patient before any record reaches the app.
No analytics, no advertising pixels, and no marketing trackers — and our fonts are self-hosted, so no font CDN ever sees you. The only network calls carry your sign-in and, for team accounts, the aggregate counts behind your dashboard — how many records you processed and how many critical findings, never a patient record. Your records themselves are analyzed entirely on your device and never uploaded.
Because Vivantal is deterministic and open, anyone can verify these claims: open your browser's network tab and watch zero data leave the page. Nothing hidden in a model or a server you can't inspect.
1. Open your browser's developer tools (F12 or ⌥⌘I) and switch to the Network tab. 2. Load the demo, build a patient, or run the Transcriptor. 3. Watch the request list: the app's own files load once, and then zero outbound requests carry your records. Signed in, you'll also see calls that save your account's audit counts — record and finding totals, never a patient record.
Open the engine. Our analysis rules and the de-identification logic are deterministic and meant to be read, not trusted blindly. We're publishing the de-identification engine and a method/security whitepaper so anyone — clinicians, IRBs, security reviewers — can audit exactly what it does.
Three co-founders, one conviction: the most preventable harm hides in the gaps between events — and you can make those gaps visible without a black box.
Vivantal today is a working prototype validated on synthetic data. The path forward is real: validating the open-loop rules with clinicians, testing the method on de-identified institutional data under review, and adding lenses onto the same spine. The goal is a tool quality and equity teams reach for, then trust.
An honest note: we have not published testimonials or pilot partners here because we will not invent them. This section is scaffolding, ready for real quotes and named collaborations as pilots begin. If you'd like to be one, reach us at partnerships@vivantal.com.
Three co-founders — clinical informatics, engineering, and health-equity methodology. If you're a clinician, researcher, or institution, reach the right person below.
Owns the open-loop ruleset and clinical reasoning. Best first contact for research collaboration, IRB partnerships, and clinical validation.
Works on engineering, the equity-audit methodology, and data architecture — focused on making the analysis rigorous, reproducible, and genuinely deployable.
Works on the web application, the in-browser analysis engine, and the de-identification tooling that keeps patient data on the user's own machine.
For anything that isn't directed at a specific person — questions, introductions, or just to say hello — this reaches the whole team.
For institutions and health-equity teams interested in piloting Vivantal.
partnerships@vivantal.comFor questions about deploying Vivantal in a clinical quality or patient-safety setting.
sales@vivantal.comVivantal is a research and quality-improvement tool, not a diagnostic device, and the hosted demo uses only synthetic data. We never receive, store, or transmit patient information.
Runs entirely on this device — no server, nothing transmitted. Removes the direct Safe Harbor identifiers and shifts dates per patient to preserve intervals. Date-shifting deviates from Safe Harbor's year-only rule, so confirm the output under your chosen standard with your privacy office or IRB.
Paste the action manifest Vivantal produced. It is keyed by pseudonym and contains no identifiers. It is joined against your key on this machine. Nothing is uploaded, and Vivantal never learns who these patients are.
A local agent runs on the schedule you set — reads every chart, scores who fails next, and drafts the outreach. You arrive to a ranked brief. Every draft awaits a human.
Autopilot is a local command-line agent. You install it on a schedule once — a macOS LaunchAgent, a Linux systemd timer, or a Windows Task (templates in deploy/schedule/) — and then you don't babysit it. It runs locally, on the records you already have; the analysis takes seconds. The timeline below is an example schedule — you choose the times.
New labs, referrals, imaging, meds — de-identified on your device the moment they load. No upload, no cloud.
Every engine traces each patient's record — open loops, monitoring gaps, worsening trends, source conflicts, and silent deterioration.
The Oracle ranks who's most likely to fail next — and records exactly which signals drove it.
Outreach messages and clinician tasks, written and queued — waiting for a human yes.
You open Vivantal to a ranked list and a stack of ready drafts waiting for review. First coffee, first save.
Severity, Oracle risk, and how long a loop has festered — fused into one priority order. The patient who needs you most is at the top of every run.
No black box. Each risk number decomposes into the exact signals behind it — critical findings, contradictions, days open.
Autopilot drafts. A human approves. Then it becomes a tracked task. The AI never acts alone — by design.
Optionally have the aggregate brief mailed to your team on each scheduled run — counts and trends only, never a patient row.
Approved items flow through To-do → In progress → Done, with a live completion bar for the whole practice.
Every score, every draft, every rank is computed in your browser. The only thing that can ever leave — and only if you ask — is an anonymous aggregate: a count, a rate, a trend. No names. No MRNs. No records. That isn't a policy. It's the architecture.
Autopilot is part of Team and above. A research/QI tool — not a diagnostic device. Demo runs on synthetic patients.
Fittingly for a tool about missing follow-ups — the page you're looking for isn't here. Let's get you back on track.
It is not for sale, and not for clinical use. We are focused on proving the method against real records with clinical partners before we price anything. Pricing will return when there is a validated result to stand behind.
The live demo is open to everyone, no account required. To follow the validation work or reach us, write to partnerships@vivantal.com.
Load your own de-identified records, understand what each lens checks, and read a de-identification report. All processing is local.
| Live demo | Open the demo to run every reasoning engine on 80 synthetic patients — no account, no upload. |
| Build a patient | Use Build a patient to hand-enter events and analyze one record. |
| Upload records | In the demo, choose Upload records (JSON/CSV). Files run through the Transcriptor's identifier pre-scan first (see below). |
A cohort is a JSON array of patient records. Each record holds demographic categories (never identifiers) and an events array.
| patient_id | Opaque code (e.g. RL-90DCD86A74). Not a name or MRN. |
| age / sex / race / insurance / primary_language | Category values used by the equity lens. Ages over 89 are aggregated to 90. |
| events[] | Each event: date (YYYY-MM-DD), type (lab · imaging · referral · medication · vital · encounter), name, and optional value, unit, ref_low, ref_high, flag, status, requires_monitoring, acknowledged, text. |
Accepted inputs: this JSON shape, or a flat CSV of event rows with a patient_id column. The 18-field column mapper handles unfamiliar Epic/Cerner column names. Sample files: sample.csv · sample.json — 10 synthetic, already-de-identified patients (names are opaque codes; nothing real).
| Mapped-field scrub | Identifiers inside kept clinical fields (e.g. a name typed into a referral description) are redacted. |
| Free-text scrub | Notes have the 18 identifier categories removed; in strict mode a note with an unverifiable residual name is dropped and flagged. |
| Residual safety-net | A final scan over the output flags anything identifier-shaped that slipped through — a silent miss becomes a loud "review this." |
| Dropped columns | Unrecognized columns are dropped by default (safe) and listed so you can confirm none were needed. |
| Malformed rows | Rows with more fields than the header (likely an unescaped comma) are skipped and counted — never silently misaligned. |
| Date shifting | Dates are shifted per patient — the real calendar date is hidden and the intervals your analysis needs are preserved. Shifting differs from Safe Harbor's remove-all-dates-but-year rule; confirm your standard with your privacy office. |
The review report lists identifiers removed, columns dropped, rows skipped, items flagged for human review, and the residual-scan result. Output is a candidate de-identification — you and your IRB confirm it. See Trust & safety.
| "No patient_id column" | In the mapper, point the patient_id field at your MRN/record-id column. |
| Rows skipped | A value contains an unescaped comma. Quote that field in the export, or fix the row. |
| Empty analysis | Records need at least one event with a type or name. |
| Browser support | Any current Chrome, Edge, Firefox, or Safari. Works offline after first load. |
Yes — by architecture, not by promise. The analysis and de-identification run entirely in your browser. Records you load are never uploaded; there is no server in the analysis pipeline to send them to. Open your browser's network tab and watch: zero outbound requests carry your patient records.
Yes. Vivantal is a research prototype under active validation — it is free to run in your browser and is not being sold. Pricing will return once the method is validated with clinical partners.
No. Vivantal is a research and quality-improvement tool. It surfaces process gaps for a qualified human to review. It does not diagnose, and every finding is a transparent rule a clinician must verify.
Only data you're authorized to handle, and only after de-identifying it (the Transcriptor helps, locally). The output is a candidate de-identification your IRB confirms. The hosted demo uses only synthetic data.
Only to load the page the first time. After that the demo, builder, and Transcriptor work offline — further proof the work is local.
Optional convenience: saved clinical thresholds, audit history, and compliance reports. Your account never stores patient data — only settings and counts.
Any current version of Chrome, Edge, Firefox, or Safari.
No. Every finding comes from a named, deterministic rule or an explicit statistic you can check by hand. There is no model. See How it works.
Real entries only — no invented history. Dates are approximate to the work, not a release calendar.
Every page is now reachable via real links (Product, Resources, Company menus), an expanded footer sitemap, and new Docs, FAQ, Glossary, and Changelog pages.
Self-hosted fonts (zero third-party requests), corrected privacy claims, Privacy Policy and Terms pages, security headers and CSP, SEO metadata, and cited statistics.
Kept-field scrubbing, a residual safety-net scan over the final output, month-name date parsing, malformed-row detection, and an interactive column mapper for unfamiliar exports.
A local de-identifier (note and file modes) ported from the desktop converter, running entirely on-device.
Signed in. Your settings and audit history live on this device.
Tune the engine to how your practice works. Changes apply immediately to the next analysis. These are preferences, not patient data — nothing here is PHI.
Override the high/low bound for a specific test — for example, flag HbA1c high at 7.0 instead of the lab's default.
Keep your whole team analyzing against the same clinical thresholds. An admin publishes the settings above as the team default; members apply them in one click.
Define your own care-gap rules on top of the built-in engines — e.g. "flag any referral to cardiology still open after 30 days." Matches show on each patient. Up to 5 rules.
A timestamped record of every audit you've run — counts only, never patient data. This is the evidence a clinic shows its insurer or regulator to prove gaps are being actively monitored.
Aggregate usage across all Vivantal accounts. Counts only — no patient data exists on our servers, so none can appear here.
Everyone with a Vivantal account. Membership and roles are non-PHI; patient data never leaves each person's own machine. Only the owner can change roles.
Add teammates by email. When they sign up with that address, they join your organization automatically.
Put your organization's name and logo on the compliance report. Stored on this device — nothing is uploaded.
Produce a branded, timestamped PDF summarizing your audit activity — the document a clinic hands to HHS or its malpractice insurer. Built entirely in your browser from metadata only.
See exactly what every plan includes, and switch your own view to any plan to use its features live. This changes only what you see — it doesn't affect your real subscription or other members.
Your plan and payment are managed by Stripe. Update your card, view invoices, or cancel anytime.
Wipe your account, settings, and audit history from this browser. Use this on a shared or public computer when you're done. This can't be undone — you'll need your recovery phrase to get back in elsewhere.
Permanently delete your Vivantal account, settings, and audit history from our servers, and free your email address to sign up again later. This can't be undone. No patient data is stored server-side — only your account and counts-only audit history.
A live self-audit runs in your browser: the enforced CSP, a de-identification proof, what's stored on this device, and what we don't claim.