Vendor Review: Stratosphere PACT (Proof & Attestation Compliance Toolkit)
Reviewed by: Huan Chin | Chief Technology Officer at Blue Meadows Health & Rehabilitation
What PACT Actually Is
Worth being precise about this up front, since it matters for anyone evaluating the product: Stratosphere’s core PACT platform is a general-purpose compliance-evidence infrastructure — it hashes, anchors, and cryptographically verifies records so that audit trails become tamper-evident, regardless of industry or use case. It’s built for HIPAA, SOC 2, and similar regulated environments broadly, not specifically for skilled nursing or medication data.
What made PACT relevant to us specifically is a medication-reconciliation plugin that Stratosphere offers at no additional cost on top of the core attestation platform. The plugin supplies the domain logic — matching Epic medication orders and administration events against pharmacy return/destruction records — while the underlying PACT infrastructure guarantees that once that reconciliation output is generated, it can’t be quietly altered later. In other words: the plugin does the matching, the core platform proves nobody touched the results afterward. That combination is what solved our problem.
Why We Chose PACT
Every skilled nursing operator with more than a couple of facilities knows the particular pain of a medication audit. It isn’t the clinical care that keeps you up at night — it’s proving, on paper, that the care happened the way the record says it happened. We manage hundreds of nurses and CNAs across multiple buildings, and medication administration records and pharmacy return/destruction logs have always lived in systems that were never designed to talk to each other.
Before PACT, reconciling eMAR administration data against what pharmacies reported as returned, wasted, or destroyed was a manual, spreadsheet-driven exercise. Our compliance team would pull Epic eMAR reports, cross-reference them against pharmacy recollection logs (often PDFs or faxes), and manually flag discrepancies — controlled substances charted as administered but unaccounted for in return counts, or vice versa. A single audit cycle could consume a compliance analyst’s time for two to three weeks, and the process was inherently error-prone since it depended on manual matching of patient, drug, dose, and timestamp across disconnected sources.
We found PACT through Epic’s Partner program while researching medication diversion and reconciliation tools. What sealed it wasn’t just that the reconciliation plugin was free — it was that the results it produces sit on top of a genuinely independent attestation layer. An auditor doesn’t have to take our compliance team’s word that a reconciliation report is accurate and unaltered; the cryptographic verification does that work.
The Problem PACT Solves
Our core problem was gap detection at scale, with an added credibility problem: even a well-built internal reconciliation report is still “our own spreadsheet” from an auditor’s perspective. PACT addresses both halves:
- The plugin answers the operational question — was every controlled substance dispensed to a unit either administered, wasted with a witness, or returned to the pharmacy? Are there administration records with no corresponding order, or orders with no administration and no return?
- The core platform answers the trust question — can we prove this reconciliation record, and the underlying Epic events it’s built from, haven’t been modified since they were generated?
That second piece turned out to matter more than we initially expected. Auditors are increasingly skeptical of internally generated compliance reports precisely because they’re editable after the fact. A hash-anchored, independently verifiable record closes that gap.
Integration Experience
Integration was one of the smoother vendor onboardings we’ve had with an Epic-connected third party, and being part of Epic’s Partner program clearly helped — Stratosphere’s team already understood Epic’s HL7 interface conventions rather than needing our environment explained from scratch.
The process:
- Our Epic interface team worked with Stratosphere to define a subset of HL7 message types and events relevant to medication ordering, administration, and pharmacy return workflows.
- We configured Epic to route only those specific messages/events to PACT’s interface engine, rather than a full data feed — important to us both for bandwidth and for minimizing our data exposure footprint.
- The reconciliation plugin was enabled alongside the core attestation service at no extra licensing cost, and Stratosphere’s implementation team handled message mapping on their end.
- We validated a test batch of messages before going live.
There was no need for custom middleware or a separate interoperability engine — the HL7 feed configuration lived entirely within our existing Epic interface tooling. Total time from contract signature to live data flow was measured in weeks, not months, which is unusual for anything touching medication data in Epic.
Results
Since implementation, the impact has been concentrated exactly where we needed it — audit preparation time, discrepancy detection, and the defensibility of what we hand an auditor:
- Audit prep time dropped substantially. Work that took a compliance analyst weeks of manual cross-referencing is now a matter of running a reconciliation report and reviewing flagged exceptions.
- Earlier detection of discrepancies. Reconciliation gaps surface close to when they occur, giving facility administrators a chance to investigate and document explanations while context is still fresh, rather than months later during a retrospective audit.
- More defensible documentation. We can now produce a cryptographically attested reconciliation trail instead of an internally-built spreadsheet — a real difference in credibility when sitting across the table from a state surveyor.
- A shift in posture internally, from “prove nothing went wrong” during an audit to “here’s our ongoing, independently verifiable reconciliation process.”
Caveats Worth Noting
In the interest of a balanced review: the reconciliation plugin’s output is only as good as pharmacy-side data quality and timeliness. If a pharmacy partner is slow to report returns or destruction, the plugin will (correctly) flag a gap that isn’t actually a compliance failure — just a lag. We built a short grace-period buffer into our internal review process to avoid chasing false positives in the first few months.
It’s also worth being clear about scope: PACT addresses reconciliation, detection, and evidentiary integrity — not prevention. It doesn’t stop diversion or documentation errors from happening; it makes them visible faster and makes the resulting record harder to dispute. And because the reconciliation logic is a plugin rather than Stratosphere’s core offering, it’s worth confirming directly with Stratosphere whether it will remain free long-term or is currently offered as an adoption incentive for the core attestation platform.
Overall, for a multi-facility SNF operator running Epic and struggling with medication reconciliation during audits, PACT solved a specific, expensive, recurring problem for us with minimal integration overhead — and did it in a way that improved not just our internal process but the credibility of what we present externally.