Most open loops can wait.
A few will hurt someone.

Vivantal reads a de-identified record inside your browser, clears every follow-up that a published guideline already covers, and ranks what is left by how much it matters. Each finding arrives with the rule that produced it.

271 open loops across 80 charts · 79 critical and unaddressed · the other 192 can wait one mark per open loop · bundled synthetic cohort · the figures the roster reports
0M

US adults are estimated to experience an outpatient diagnostic error every year. The information needed to catch most of them was already in the chart.

Singh H, Meyer AND, Thomas EJ. The frequency of diagnostic errors in outpatient care. BMJ Qual Saf, 2014. Illustrative of the problem space, not a claim about any specific population.

Raw export to reasoned worklist.

Five stages, all of them running on your own machine: de-identified locally, compiled into one coded record, then read by named rules you can open and inspect.

  1. 01

    De-identify locally

    HIPAA Safe Harbor identifiers stripped and dates shifted on your machine. Raw PHI never moves.

  2. 02

    Understand & code

    CSV, FHIR, HL7 or C-CDA mapped by meaning, then coded to LOINC and RxNorm.

  3. 03

    Compile

    One canonical record. Every field carries its value, its confidence and its source of truth.

  4. 04

    Reason

    Deterministic engines read time, source authority, patient baseline and clinical relationships.

  5. 05

    Rank, cite & learn

    Each finding links to the exact event and the rule that fired. Dismiss one and it stays gone.

Every finding shows its work.

Open any finding and you get the rule that produced it, the event that triggered that rule, the guideline it rests on, the confidence attached to it, and the reason it survived suppression.

Critical

Potassium 6.4 mmol/L resulted 817 days ago and never acknowledged.

Hyperkalaemia in the critical range with no documented response.

Rule
unacknowledged_critical_result
Triggered by
LAB · 2777-1 · K 6.4 mmol/L · flag H
Source of truth
Inpatient result feed rank 1 of 4
Guideline
Critical value callback policy — result requires documented acknowledgement
Confidence
0.94 clinical signal × record reliability
Not suppressed
No acknowledgement event, no repeat draw, patient still active

Illustrative worked example · drawn from the bundled synthetic cohort

One record, read every way.

Seven deterministic readings of the same canonical record. Every one is a named, auditable rule.

Open loops

Walks the timeline for follow-ups that were never closed — unacknowledged abnormal results, incomplete referrals, imaging recommendations that went nowhere.

Potassium critical (6.4) resulted 817 days ago — never acknowledged.

Reasoning across time

Knows the monitoring cadence a drug expects and whether it is being met, and reads each lab's trajectory across visits — the slow slide a single result hides.

Warfarin on file 240 days — INR expected ~monthly, last drawn 180 days ago.

Abnormal for this patient

Judges each value against the patient's own baseline and rate of change, not just the population reference range.

Creatinine 1.25 is in range, but doubled from this patient's 0.6 — an AKI signal.

Source of truth

Ranks every fact by the authority of its source — inpatient and pharmacy MAR outrank an outside record or patient recall — and reconciles what disagrees.

Lisinopril: patient-reported 10 mg vs pharmacy MAR 20 mg — trust the MAR.

Clinical relationships

Reasons over an ontology of drugs, classes and conditions — therapeutic duplication, interacting co-prescriptions, a diagnosis whose expected work-up is missing.

Atrial fibrillation on file with no anticoagulation.

Is follow-up fair?

Measures how often an actionable finding actually gets closed for each subgroup — race, insurance, language, sex, age — with a significance test to separate signal from noise.

Medicaid patients close 51% of findings vs 74% reference — p < 0.001.

Data you can trust

Scores each record's reliability with itemised reasons, puts a confidence on every finding, and remembers what you dismiss so it stops re-raising it.

Record reliability 73% — −12% (3 labs missing units), −8% (1 undated event).

Example findings · bundled synthetic cohort

The record never leaves the tab.

Not a policy. An architecture — and one you can verify in about thirty seconds with your own network tab.

Your browser
De-identificationSchema inferenceCoding · LOINC / RxNorm All 10 reasoning enginesRanking & suppressionExport
no patient data crosses this line
Network
Sign-in tokenAggregate counts for team dashboards

Read the output before you trust it.

Every chart below is drawn from real engine output on the bundled cohort, or is stamped as an illustrative worked example. We do not fabricate clinical figures.

The whole system, one surface.

Every engine, tool and guarantee. Drag to move the camera; click any node to open it.

Load a cohort. Look for yourself.

Eighty synthetic patients with realistic gaps, every engine live. Or start an account and land in the patient builder.

One compiler, three teams.

Patient safety, health equity, and the informatics teams who own the data underneath both — all three questions live in one record.

Quality & safety

Catch the follow-ups that slipped

Every open loop across a panel — unacknowledged criticals, overdue monitoring, worsening trends — ranked by severity and confidence.

Example finding · synthetic demo data
"Creatinine 1.25 is in range, but doubled from this patient's 0.6 — an AKI signal."
Open the open-loop roster →
Health equity

Measure whether follow-up is fair

Closure rates by race, insurance, language, sex, and age — with a significance test on the gap.

Example finding · synthetic demo data
"Medicaid patients close 49% of findings vs 90% for the reference group — p = 0.0008."
Open the equity audit →
Informatics & data

Make any export analyzable

Messy CSV, Epic/Cerner dumps, FHIR, HL7, C-CDA — schema inferred, coded to LOINC and RxNorm, on-device.

Example · synthetic demo data
"Understood 98% · coded 41 concepts · saved template 'Epic Clarity Lab Export'."
See how it's verified →

One record, the gaps made visible.

Years of visits, mostly fine. Vivantal pulls out only what needs a human — coded, confidence-scored, and linked to the exact event.

What it flags in a single record

unacknowledged_resultA high calcium of 12.9 was resulted and never acknowledged — possible hypercalcemia left unworked.
baseline_deviationCreatinine 1.25 sits inside the reference range but has doubled from this patient's own baseline — a KDIGO acute-kidney-injury threshold.
monitoring_overdueWarfarin needs INR roughly monthly; the last INR was 180 days ago — monitoring has lapsed.
provenance_conflictThe med list shows lisinopril 10 mg (patient-reported) vs 20 mg (pharmacy MAR) — reconcile to the more authoritative source.
therapeutic_duplicationTwo statins are active at once — likely duplication across visits or clinicians.
condition_care_gapAtrial fibrillation is on the problem list with no anticoagulation on file.

Deterministic. Auditable. Yours to verify.

No model, no black box. Every finding comes from a named rule or an explicit statistic you can check by hand.

Step 01

Load a record

Demo cohort, a patient you build, or your own de-identified export — CSV, FHIR, HL7, C-CDA. Stays in your browser.

Step 02

Understand & code

Schema inferred by content, columns mapped by meaning, concepts coded to LOINC and RxNorm — into one canonical record.

Step 03

Reason across it

Deterministic engines read for open loops, monitoring lapses, trends, source conflicts, and subgroup disparities.

Step 04

Confirm, explain & act

Every finding links to the exact event and explains itself. Verify, export a worklist, dismiss false positives for good.

A sample of the reasoning rules

unacknowledged_resultAn abnormal or critical lab result with no documented acknowledgement in the record.
imaging_followup_openAn imaging study whose report recommends follow-up that never occurred.
referral_incompleteA referral placed but never completed, ranked by how long it's been open.
medication_unmonitored · monitoring_overdueA narrow-index drug started without its monitoring lab, or a monitoring cadence that has since lapsed (e.g. warfarin without a recent INR).
abnormal_trend · baseline_deviationA value worsening across visits, or an in-range value that has deviated materially from the patient's own baseline.
provenance_conflictThe same fact recorded differently by two sources of differing authority — reconciled to the more authoritative one.
therapeutic_duplication · condition_care_gapTwo agents of one class active at once, or a coded diagnosis whose expected work-up is missing.

The equity method

closure rateFor each subgroup, the share of actionable findings that actually got closed.
two-proportion z-testCompares each group to the best-performing one; surfaces gaps unlikely to be chance.
four-fifths ruleFlags any group closing at under 80% of the reference rate — a standard disparity threshold.
min-N guardCohorts too small for a reliable signal are reported honestly as "not enough data," never as false headlines.
The Vivantal Transcriptor

How raw records become safe, analyzable data.

Before a single record reaches the lenses, it passes through the Transcriptor — an open de-identification step that runs entirely on the authorized user's own machine. It reads a raw record, transcribes it into Vivantal's structured event format, removes the direct HIPAA Safe Harbor identifiers, and shifts dates per patient (intervals preserved). Nothing identifiable ever leaves the device, because there is no server to send it to.

Raw record · on your machine
Jane Doe · DOB 03/14/1958
MRN 40192 · 555-0114
Potassium 6.4 mmol/L — critical
Cardiology referral — open
Transcriptor · local
parse events
remove identifiers
shift dates
assign de-id code
emit review report
De-identified · ready to analyze
Patient P-2847 · F · 65+
K⁺ 6.4 — critical, not acked
Referral — open 8mo
→ 3 open loops detected
You stay in control the entire time. The Transcriptor produces a candidate de-identified file plus a review report; you and your IRB confirm it meets the legal standard before analysis. Vivantal contributes the software — you keep custody of your data. See Trust & safety for the full architecture.
No cohort loaded
What this demo does and does not prove
The data
80 synthetic patients. Gaps and disparities were deliberately planted.
What it proves
The rules are deterministic and not hand-tuned to one cohort — re-roll the set and they still fire.
What it does not
Clinical accuracy. That needs real records and an independent clinician. We have not done that work.
Where it runs
Entirely in your browser. Load your own de-identified records at any time.
No cohort loaded
Load the demo cohort, or upload your own de-identified records, to begin.

Does follow-up depend on who the patient is?

Equal findings should get equal action. This audit measures, for each subgroup, how often an actionable finding gets closed — then compares each group to the best-performing one. A gap that survives a significance test is a disparity worth investigating, not noise.

Load a cohort first
Switch to the Cohort tab and load data; the equity audit runs on the same records.

Where does this record contradict itself?

Fragmented care produces conflicts no single clinician sees: interacting medications, a drug continued against a lab that contraindicates it, duplicated work-ups. This lens reads each record and surfaces those contradictions for a pharmacist or clinician to resolve.

Who is sliding, one normal-looking result at a time?

A value that moves from normal toward danger across several visits is invisible in any single result. This lens trends each repeated measurement and flags the patients whose trajectory is heading the wrong way — before it becomes a crisis.

What if you fixed it? Model the intervention before you run it.

Drag the sliders to simulate closing care gaps across this cohort, and watch the numbers recompute instantly. Take the projected result to leadership — before you've spent a dollar. Runs entirely in your browser.

Why do these gaps keep happening?

Root-cause analysis normally takes weeks of committee meetings. This mines patterns across the whole cohort in seconds — surfacing the systemic causes behind your open loops, ranked by how much each contributes. No patient data leaves your browser; only event types, timing, and categories are analyzed.

The Mirror — how do you compare to the rest of the country?

Your safety and equity performance, side by side with published-literature benchmarks — each source cited. These are literature reference ranges, not a live national percentile. Computed in your browser, no data transmitted.

Oracle — who fails next, and why.

A forward-looking triage layer. Oracle ranks who's most likely to have a care gap turn into a real failure, and shows exactly which signals put them there. Deterministic and explainable — never a black box. Computed in your browser.

Autopilot — your morning brief, ready to act on.

A local agent runs on your machine on the schedule you set — reads the practice, ranks what matters, and drafts the next move, so a prioritized brief is waiting when you arrive. Nothing sends until a human approves. Everything is computed in your browser — no patient data leaves the device.

Network — how your practice compares, without sharing a single record.

The long-term vision: a privacy-preserving benchmark across participating clinics that learns only from anonymous aggregates — never patient data. Your metrics below are real and computed locally. There is no clinic-to-clinic benchmark here — no clinic has contributed data. What you see compared against is cited published literature and real CMS open data, labelled as such wherever it appears.

Research & quality-improvement tool — not a diagnostic device. Vivantal analyzes record completeness and follow-up patterns and surfaces process gaps for human review. It does not diagnose, and every finding is a transparent, rule-based flag a clinician should verify. Demo data is fully synthetic; no real patient information is used. Disparity figures are illustrative of the method, not claims about any real population.
Welcome — start here. Build a record from a few clinical facts below, then hit Analyze this patient to open it live in the demo. Nothing you enter is identifiable, and it never leaves your browser.
Build a patient

Turn a few clinical facts into an analyzable record.

Add events one at a time — a lab, a referral, an imaging study, a medication. Each becomes a row. When the record is built, analyze it directly or export it to load into the cohort tools.

No identifying information. This builder never asks for names, dates of birth, or medical record numbers. Each record gets a de-identified code, and you only enter demographic categories and clinical events. Everything stays in your browser — nothing is sent anywhere.

Paste a note — we'll build the events Starter

Paste a clinical note, discharge summary, or referral letter. Vivantal parses it into structured events on your device — no cloud, no AI service, nothing sent anywhere. Every extracted medication and lab is checked against the offline clinical vocabulary before it's added.

Add an event

Pick a type, fill the fields, add it to the record.

Patient (categories only)
When the event occurred.
Leave blank if no monitoring is required.
Working recordRL-0001
No events yet
Add a lab, referral, imaging study, or medication from the left to start building this record.

Vivantal never compromises patient privacy.

Protecting patient data isn't a policy we promise — it's an architecture we can't violate. Here's exactly how, in plain terms, and the rules we hold ourselves to.

The one rule we never break

Protected health information is never compromised. Vivantal does not receive, store, or transmit identifiable patient data — ever. There is no server in our analysis pipeline to send data to. Everything runs in your browser, on your machine. You can't leak what you never receive, and we never receive it.

Protection by architecture, not by promise.

No server, no transmission

The entire engine is JavaScript running inside your browser tab. Records you load are processed locally and never sent anywhere. Disconnect from the internet entirely and Vivantal still works.

De-identified data only

Vivantal is designed for data that's already de-identified. A separate, open converter — which runs on your machine, never ours — removes the direct HIPAA Safe Harbor identifiers and shifts dates per patient before any record reaches the app.

No tracking, no telemetry

No analytics, no advertising pixels, and no marketing trackers — and our fonts are self-hosted, so no font CDN ever sees you. The only network calls carry your sign-in and, for team accounts, the aggregate counts behind your dashboard — how many records you processed and how many critical findings, never a patient record. Your records themselves are analyzed entirely on your device and never uploaded.

Fully auditable

Because Vivantal is deterministic and open, anyone can verify these claims: open your browser's network tab and watch zero data leave the page. Nothing hidden in a model or a server you can't inspect.

Don't take our word for it — verify it in 30 seconds

1. Open your browser's developer tools (F12 or ⌥⌘I) and switch to the Network tab. 2. Load the demo, build a patient, or run the Transcriptor. 3. Watch the request list: the app's own files load once, and then zero outbound requests carry your records. Signed in, you'll also see calls that save your account's audit counts — record and finding totals, never a patient record.

Open the engine. Our analysis rules and the de-identification logic are deterministic and meant to be read, not trusted blindly. We're publishing the de-identification engine and a method/security whitepaper so anyone — clinicians, IRBs, security reviewers — can audit exactly what it does.

The rules we hold ourselves to

We only support use on data the user is already authorized to access, under their own approval such as an IRB protocol. Vivantal grants no access to data — it only analyzes what a user may already handle.
De-identification happens on the authorized user's machine, before any record reaches Vivantal — never on our side, because we have no side that touches data.
We treat an automated tool as an aid, not a certification. The converter produces a candidate de-identified file plus a review report, and states clearly that the user and their IRB must confirm it meets the legal standard.
×
We never ingest identified patient data into anything our team controls. No "upload your chart and we'll clean it" — that would mean PHI touching our systems, and we will not build it.
×
We never claim more than is true. Vivantal surfaces process gaps for human review. It does not diagnose, and we say so everywhere.

How real data is handled — and why it stays safe

01
Authorized access
A clinician with lawful access to their own data, under their IRB approval.
02
Local de-identification
They run the open converter on their machine; identifiers are stripped before anything leaves.
03
IRB review
They and their IRB confirm the de-identification meets the legal standard.
04
Local analysis
The clean file is loaded into Vivantal — which also runs locally.
At no point does identifiable patient data reach the Vivantal team. We contribute software; the authorized user keeps custody of their data the entire time. That's what makes the privacy commitment true by construction, not just asserted.
Research & quality-improvement tool — not a diagnostic device. Vivantal analyzes record completeness and follow-up patterns and surfaces process gaps for human review. It does not diagnose. Use on real patient data requires the user's own lawful access, de-identification on their machine, and institutional review.

Medicine's blind spots are an engineering problem.

Three co-founders, one conviction: the most preventable harm hides in the gaps between events — and you can make those gaps visible without a black box.

How we build
  • Every finding traces to a named rule or an explicit statistic — no black box.
  • The clinical rules and thresholds are inspectable, not hidden.
  • Analysis runs in your browser; no patient data ever leaves the device.
Neeraj Movva
Co-founder · Clinical rules & validation
Works on the open-loop ruleset and the clinical reasoning behind Vivantal's deterministic engines. Best first point of contact for research collaboration, IRB partnerships, and clinical validation.
Aditya Raut
Co-founder · Engineering & equity method
Works on engineering, the equity-audit methodology, and data architecture — focused on making the analysis rigorous, reproducible, and genuinely deployable.
Sathvik Loke
Co-founder · Web app & de-identification
Works on the web application, the in-browser analysis engine, and the de-identification tooling that keeps patient data on the user's own machine.
Clinical / informatics advisor
Advisor — we're actively recruiting
We're actively recruiting a clinical advisor. If you're a clinician or informaticist interested in validating our methodology, we'd love to talk — contact@vivantal.com.

From prototype to pilot.

Vivantal today is a working prototype validated on synthetic data. The path forward is real: validating the open-loop rules with clinicians, testing the method on de-identified institutional data under review, and adding lenses onto the same spine. The goal is a tool quality and equity teams reach for, then trust.

Real quotes only — this space is reserved for a genuine pilot user or advisor.
Pilot slot open
Reserved for a genuine, attributable quote.
Pilot slot open
Reserved for a named pilot or partner.
Partner slot open

An honest note: we have not published testimonials or pilot partners here because we will not invent them. This section is scaffolding, ready for real quotes and named collaborations as pilots begin. If you'd like to be one, reach us at partnerships@vivantal.com.

Meet the team.

Three co-founders — clinical informatics, engineering, and health-equity methodology. If you're a clinician, researcher, or institution, reach the right person below.

Neeraj Movva
Co-founder · Clinical informatics

Owns the open-loop ruleset and clinical reasoning. Best first contact for research collaboration, IRB partnerships, and clinical validation.

  • Designed the open-loop detection rules and severity model
  • Leads outreach to clinical collaborators
neeraj@vivantal.com
Aditya Raut
Co-founder · Engineering & health equity

Works on engineering, the equity-audit methodology, and data architecture — focused on making the analysis rigorous, reproducible, and genuinely deployable.

  • Built the equity-audit engine and significance testing
  • Designed the data schema and validation pipeline
aditya@vivantal.com
Sathvik Loke
Co-founder · Engineering

Works on the web application, the in-browser analysis engine, and the de-identification tooling that keeps patient data on the user's own machine.

  • Built the in-browser cohort tools and interface
  • Developed the local de-identification converter
sathvik@vivantal.com
General & best place to reach us
contact@vivantal.com

For anything that isn't directed at a specific person — questions, introductions, or just to say hello — this reaches the whole team.

Partnerships

For institutions and health-equity teams interested in piloting Vivantal.

partnerships@vivantal.com
Outreach

For press, talks, and general inquiries about the project.

outreach@vivantal.com
Sales

For questions about deploying Vivantal in a clinical quality or patient-safety setting.

sales@vivantal.com

Vivantal is a research and quality-improvement tool, not a diagnostic device, and the hosted demo uses only synthetic data. We never receive, store, or transmit patient information.

De-identify a record — without it ever leaving your browser.

Runs entirely on this device — no server, nothing transmitted. Removes the direct Safe Harbor identifiers and shifts dates per patient to preserve intervals. Date-shifting deviates from Safe Harbor's year-only rule, so confirm the output under your chosen standard with your privacy office or IRB.

Local only. This tool makes zero network requests. Open your browser's Network tab and watch — nothing leaves the page.
Free to use — no account needed. It all runs on your device. Optionally to save your column mappings and settings across devices.

Raw note · on your machine

De-identified · safe to analyze

Your de-identified text appears here.
Drop a CSV / TSV / JSON export, or click to choose
Vivantal-format JSON, or a flat CSV of clinical events. Columns are auto-mapped when named like Vivantal fields (or common Epic columns).
Rehydrate — turn a Vivantal action list back into addressed letters, locally

Paste the action manifest Vivantal produced. It is keyed by pseudonym and contains no identifiers. It is joined against your key on this machine. Nothing is uploaded, and Vivantal never learns who these patients are.

This is a candidate de-identification, not a certification. Automated de-identification is not, by itself, sufficient under HIPAA. You — and your IRB, or a qualified statistician under Expert Determination — must review the report and confirm the output meets HIPAA Safe Harbor before the data is used or shared. Only run this on data you are already authorized to handle. The tool redacts machine-detectable identifiers and, in strict mode, drops any note it can't verify is clean.
The Vivantal Autopilot

Walk in to a brief, not a backlog.

A local agent runs on the schedule you set — reads every chart, scores who fails next, and drafts the outreach. You arrive to a ranked brief. Every draft awaits a human.

A schedule you install

Set it to run before clinic opens — the brief is waiting when you arrive.

Autopilot is a local command-line agent. You install it on a schedule once — a macOS LaunchAgent, a Linux systemd timer, or a Windows Task (templates in deploy/schedule/) — and then you don't babysit it. It runs locally, on the records you already have; the analysis takes seconds. The timeline below is an example schedule — you choose the times.

11:00 PM

Ingests the day

New labs, referrals, imaging, meds — de-identified on your device the moment they load. No upload, no cloud.

2:00 AM

Walks every timeline

Every engine traces each patient's record — open loops, monitoring gaps, worsening trends, source conflicts, and silent deterioration.

4:00 AM

Scores who fails next

The Oracle ranks who's most likely to fail next — and records exactly which signals drove it.

5:30 AM

Drafts the moves

Outreach messages and clinician tasks, written and queued — waiting for a human yes.

7:00 AM

Hands you the brief

You open Vivantal to a ranked list and a stack of ready drafts waiting for review. First coffee, first save.

What lands on your desk

A co-pilot, not a dashboard.

Ranked brief

The list is already sorted.

Severity, Oracle risk, and how long a loop has festered — fused into one priority order. The patient who needs you most is at the top of every run.

Explainable Oracle

Every score, defended.

No black box. Each risk number decomposes into the exact signals behind it — critical findings, contradictions, days open.

Approval-gated

Nothing sends itself.

Autopilot drafts. A human approves. Then it becomes a tracked task. The AI never acts alone — by design.

Email digest

An aggregate digest you can enable.

Optionally have the aggregate brief mailed to your team on each scheduled run — counts and trends only, never a patient row.

Task queue

From flag to closed.

Approved items flow through To-do → In progress → Done, with a live completion bar for the whole practice.

The line we won't cross

Patient data never leaves the building.

Every score, every draft, every rank is computed in your browser. The only thing that can ever leave — and only if you ask — is an anonymous aggregate: a count, a rate, a trend. No names. No MRNs. No records. That isn't a policy. It's the architecture.

0
patient records uploaded
100%
on-device computation
18
HIPAA identifiers stripped locally

Walk in tomorrow to a practice that already did its rounds.

Autopilot is part of Team and above. A research/QI tool — not a diagnostic device. Demo runs on synthetic patients.

Error 404

This page slipped through the gaps.

Fittingly for a tool about missing follow-ups — the page you're looking for isn't here. Let's get you back on track.

Under validation

Vivantal is a research prototype under active validation.

It is not for sale, and not for clinical use. We are focused on proving the method against real records with clinical partners before we price anything. Pricing will return when there is a validated result to stand behind.

The live demo is open to everyone, no account required. To follow the validation work or reach us, write to partnerships@vivantal.com.

Docs — data formats, the lenses, and the Transcriptor.

Load your own de-identified records, understand what each lens checks, and read a de-identification report. All processing is local.

Getting started

Live demoOpen the demo to run every reasoning engine on 80 synthetic patients — no account, no upload.
Build a patientUse Build a patient to hand-enter events and analyze one record.
Upload recordsIn the demo, choose Upload records (JSON/CSV). Files run through the Transcriptor's identifier pre-scan first (see below).

Canonical record schema

A cohort is a JSON array of patient records. Each record holds demographic categories (never identifiers) and an events array.

patient_idOpaque code (e.g. RL-90DCD86A74). Not a name or MRN.
age / sex / race / insurance / primary_languageCategory values used by the equity lens. Ages over 89 are aggregated to 90.
events[]Each event: date (YYYY-MM-DD), type (lab · imaging · referral · medication · vital · encounter), name, and optional value, unit, ref_low, ref_high, flag, status, requires_monitoring, acknowledged, text.

Accepted inputs: this JSON shape, or a flat CSV of event rows with a patient_id column. The 18-field column mapper handles unfamiliar Epic/Cerner column names. Sample files: sample.csv · sample.json — 10 synthetic, already-de-identified patients (names are opaque codes; nothing real).

De-identification reference (the Transcriptor)

Mapped-field scrubIdentifiers inside kept clinical fields (e.g. a name typed into a referral description) are redacted.
Free-text scrubNotes have the 18 identifier categories removed; in strict mode a note with an unverifiable residual name is dropped and flagged.
Residual safety-netA final scan over the output flags anything identifier-shaped that slipped through — a silent miss becomes a loud "review this."
Dropped columnsUnrecognized columns are dropped by default (safe) and listed so you can confirm none were needed.
Malformed rowsRows with more fields than the header (likely an unescaped comma) are skipped and counted — never silently misaligned.
Date shiftingDates are shifted per patient — the real calendar date is hidden and the intervals your analysis needs are preserved. Shifting differs from Safe Harbor's remove-all-dates-but-year rule; confirm your standard with your privacy office.

The review report lists identifiers removed, columns dropped, rows skipped, items flagged for human review, and the residual-scan result. Output is a candidate de-identification — you and your IRB confirm it. See Trust & safety.

Troubleshooting

"No patient_id column"In the mapper, point the patient_id field at your MRN/record-id column.
Rows skippedA value contains an unescaped comma. Quote that field in the export, or fix the row.
Empty analysisRecords need at least one event with a type or name.
Browser supportAny current Chrome, Edge, Firefox, or Safari. Works offline after first load.

Straight answers to the questions people actually ask.

Is my patient data safe?

Yes — by architecture, not by promise. The analysis and de-identification run entirely in your browser. Records you load are never uploaded; there is no server in the analysis pipeline to send them to. Open your browser's network tab and watch: zero outbound requests carry your patient records.

Is it free?

Yes. Vivantal is a research prototype under active validation — it is free to run in your browser and is not being sold. Pricing will return once the method is validated with clinical partners.

Is this a diagnostic tool?

No. Vivantal is a research and quality-improvement tool. It surfaces process gaps for a qualified human to review. It does not diagnose, and every finding is a transparent rule a clinician must verify.

Can I use it on real patient data?

Only data you're authorized to handle, and only after de-identifying it (the Transcriptor helps, locally). The output is a candidate de-identification your IRB confirms. The hosted demo uses only synthetic data.

Does it need an internet connection?

Only to load the page the first time. After that the demo, builder, and Transcriptor work offline — further proof the work is local.

What does an account add?

Optional convenience: saved clinical thresholds, audit history, and compliance reports. Your account never stores patient data — only settings and counts.

Which browsers are supported?

Any current version of Chrome, Edge, Firefox, or Safari.

Is it a black-box AI?

No. Every finding comes from a named, deterministic rule or an explicit statistic you can check by hand. There is no model. See How it works.

The terms this site uses, in one line each.

Open loop
An event whose required follow-up never happened — an unacknowledged abnormal result, an incomplete referral, a medication started without its monitoring lab.
Closure rate
The share of actionable findings in a group that actually got closed (followed up). The equity lens compares closure rates across subgroups.
De-identification
Removing identifiers so data can no longer be tied to a specific person. Vivantal uses "de-identify" as the term of record.
Anonymization
Often used loosely for de-identification, but implies irreversibility. We say "de-identify," which under HIPAA has a specific legal meaning.
Safe Harbor
A HIPAA de-identification method (45 CFR 164.514(b)(2)) requiring removal of 18 categories of identifiers and no actual knowledge of residual re-identification risk.
PHI
Protected Health Information — individually identifiable health information covered by HIPAA.
The 18 identifiers
The categories Safe Harbor removes: names, geographic detail below state, dates finer than year, phone/fax, email, SSN, MRN, and other unique numbers, URLs, IPs, biometrics, photos, and more.
QI
Quality Improvement — systematic effort to improve care processes and outcomes. Vivantal is a QI/research tool.
IRB
Institutional Review Board — the body that reviews and approves research involving human subjects, including whether de-identification is adequate.
BAA
Business Associate Agreement — a HIPAA contract governing a vendor that handles PHI. See Terms.
Transcriptor
Vivantal's local de-identification engine — it turns a raw record into a de-identified one on your device.

What's changed, dated and honest.

Real entries only — no invented history. Dates are approximate to the work, not a release calendar.

Navigation

Full site navigation & resources

Every page is now reachable via real links (Product, Resources, Company menus), an expanded footer sitemap, and new Docs, FAQ, Glossary, and Changelog pages.

Trust

Trust & privacy overhaul

Self-hosted fonts (zero third-party requests), corrected privacy claims, Privacy Policy and Terms pages, security headers and CSP, SEO metadata, and cited statistics.

Engine

De-identification hardening

Kept-field scrubbing, a residual safety-net scan over the final output, month-name date parsing, malformed-row detection, and an interactive column mapper for unfamiliar exports.

Feature

The Transcriptor, in-browser

A local de-identifier (note and file modes) ported from the desktop converter, running entirely on-device.

Account

Signed in. Your settings and audit history live on this device.

Care-gap thresholds

Tune the engine to how your practice works. Changes apply immediately to the next analysis. These are preferences, not patient data — nothing here is PHI.

Referral open limitFlag a referral as high-severity after it's been open this many days.
days
Monitoring gap limitFlag a medication's missing monitoring lab as high-severity after this many days.
days
Critical escalationA value past its reference bound by more than this fraction of the normal range escalates to critical.
× range
Minimum subgroup sizeAn equity subgroup needs at least this many actionable findings before a disparity is reported.
findings

Per-lab cutoffs Custom

Override the high/low bound for a specific test — for example, flag HbA1c high at 7.0 instead of the lab's default.

Team thresholds Team

Keep your whole team analyzing against the same clinical thresholds. An admin publishes the settings above as the team default; members apply them in one click.

No team thresholds published yet.

Custom rules Practice

Define your own care-gap rules on top of the built-in engines — e.g. "flag any referral to cardiology still open after 30 days." Matches show on each patient. Up to 5 rules.

Audit trail

A timestamped record of every audit you've run — counts only, never patient data. This is the evidence a clinic shows its insurer or regulator to prove gaps are being actively monitored.

No audits logged yet
Run your first audit — open the demo, then load or generate a cohort. It's recorded here automatically.

Analytics Admin

Aggregate usage across all Vivantal accounts. Counts only — no patient data exists on our servers, so none can appear here.

Loading analytics…

Members Admin

Everyone with a Vivantal account. Membership and roles are non-PHI; patient data never leaves each person's own machine. Only the owner can change roles.

Invite teammates Team

Add teammates by email. When they sign up with that address, they join your organization automatically.

Report branding Institution

Put your organization's name and logo on the compliance report. Stored on this device — nothing is uploaded.

Organization nameShown as the report subject and header.
LogoPNG, JPG or SVG — appears top-left of the report.

Generate a compliance report

Produce a branded, timestamped PDF summarizing your audit activity — the document a clinic hands to HHS or its malpractice insurer. Built entirely in your browser from metadata only.

No patient data appears in the report — counts and dates only.

Plans & feature explorer Owner / Admin

See exactly what every plan includes, and switch your own view to any plan to use its features live. This changes only what you see — it doesn't affect your real subscription or other members.

Billing

Your plan and payment are managed by Stripe. Update your card, view invoices, or cancel anytime.

You're on the Free plan.

Clear this device

Wipe your account, settings, and audit history from this browser. Use this on a shared or public computer when you're done. This can't be undone — you'll need your recovery phrase to get back in elsewhere.

Delete my account

Permanently delete your Vivantal account, settings, and audit history from our servers, and free your email address to sign up again later. This can't be undone. No patient data is stored server-side — only your account and counts-only audit history.

Don't take our word for it — verify it.

A live self-audit runs in your browser: the enforced CSP, a de-identification proof, what's stored on this device, and what we don't claim.

Running live self-audit…
Vivantal never compromises patient privacy.
Runs in your browser · no data ever leaves your machine

Settings

Preferences for how Vivantal looks and behaves on this device. These are saved on your machine only.

High contrastStronger text and border contrast for readability.
Reduce motionMinimize animations and transitions.
Show privacy reminderDisplay the privacy notice on first load.
Default analysis thresholds

Applied to the demo and to any record you load. Signed-in users can save custom thresholds to their account.

days
days
Privacy

Vivantal stores account info and preferences in your browser only. No patient data is ever sent anywhere.

Sign in

Your clinical thresholds and audit history, on every device you use.

New here?

Create your account

Free to start. Once you verify, we drop you straight into the patient builder so you can build a record and open it in the demo. Your patient data never touches our servers — only your settings sync.

Already have an account?

Check your email

We sent a confirmation link to your inbox. Click it to verify your account. This tab will sign you in automatically once you do. If you don't see it, check spam.

Waiting for verification…

Welcome to Vivantal

Account verified. Signing you in…

Reset your password

Enter your email and we'll send you a link to set a new password.

Set a new password

Choose a new password: at least 9 characters, with a capital letter, a number, and a symbol.