Domain Atlas / Behavioral-health & crisis triage
ODMAP overdose spike alerts on a drug-enforcement-housed store
In 2025 ODMAP's pre-set county thresholds - a rolling 24-hour count against a threshold each agency sets or accepts, recommended by the system as two standard deviations above the county's own previous 90-day mean, a deterministic rule rather than a machine-learning model - fired 74,805 advisory spike-alert notifications from 498,003 suspected, unconfirmed overdose events that only about 1,362 of its 5,605 approved agencies actually submitted; these figures are self-published by the program in its own annual report and manuals, and ODMAP states its data are suspected, incomplete, not a system of record, and should not be generalized beyond participating agencies.[3]
What happened
ODMAP (the Overdose Detection Mapping Application Program) is a nationwide, population-level overdose spike-alerting network. It matters to the Atlas precisely because it is the opposite of an individual scoring tool: it records aggregate, unnamed, suspected overdose events and produces no per-person risk number. It was developed and is hosted by the Washington/Baltimore High Intensity Drug Trafficking Area (W/B HIDTA), a federal program administered by the Office of National Drug Control Policy, and launched as a pilot in January 2017. Public safety and public health agencies - law enforcement, fire, EMS, hospitals, and public health entities - enter suspected overdose events into one shared national store (the ODMAP database and National Map) by manual mobile or web entry or by automated API feed, with 30 statewide APIs in place by the end of 2025.
The algorithm is a deterministic threshold rule, not machine learning. A county is treated as in a spike when suspected-overdose submissions meet or exceed a pre-set threshold within a rolling 24-hour window; the October 2025 training manual states the system-recommended threshold precisely as two standard deviations above the mean of the county's previous 90 days of data, updating every 90 days, and an agency administrator may instead set a manual value. Crossing the threshold emits advisory email and text spike-alert notifications to subscriber lists. Critically, an agency can configure alerts on neighboring counties as an explicit anticipatory early warning - in the program's own words, "if a spike in overdoses occurs in a neighboring area, officials can anticipate a spike in their area and prepare" - so a local count exceedance propagates preparation signals across jurisdictional edges without any predictive model. Alerts continue while the count stays above threshold and a closing notification is sent when the spike ends; the spike-alert overview also notes that the system does not alert a user when the threshold itself has changed.
Nearly every quantitative figure comes from the program grading its own homework, and is reported here as self-published. The 2025 Annual Report counts 5,605 approved agencies and more than 37,700 approved users at the end of 2025, 3,398,381 total incidents reported since 2016, and 498,003 suspected overdose events in 2025 alone (an average of 1,364 entered daily), from which the county thresholds fired 74,805 spike-alert notifications. The same report documents a large gap between enrollment and active reporting: only 1,362 of the 5,605 approved agencies - roughly 24 percent - actually submitted events in 2025, so coverage is spatially uneven by construction. Statewide institutionalization is substantial: the report counts 37 states with a statewide strategy, of which 14 have legislation or policy and 16 have a data-entry or statewide strategy, alongside 30 statewide APIs, and in August 2025 an Illinois law extended existing requirements toward reporting overdoses through ODMAP. In June 2025 Senator Raphael Warnock publicly urged ONDCP to preserve funding and resourcing for ODMAP and the HIDTA priorities more broadly - a documented funding-preservation advocacy push, carried as that rather than as an asserted funding threat.
The standing controversy is a contested question of link authority on the shared store, and both sides of it are in the program's own documents. The operating policies (Rev. Sept 2022) simultaneously state that ODMAP "is neither an intelligence sharing database, nor a pointer index records system" and that data are the submitting agency's property, while also granting the HIDTA permission to use the data "as the HIDTA sees fit pursuant to the goals of ODMAP," including combining it with data from other databases that the HIDTA manages and creating "law enforcement and public health products." Both clauses ship together because both are in the source. A 2024 peer-reviewed stakeholder study found users valued the data integration for targeted intervention but identified divergent data-privacy standards between the public health and public safety sectors and a need for clearer cross-sector data-sharing guidance; an ONDCP-funded 2022 legal guidance document exists specifically to help hospitals and EMS navigate HIPAA when reporting, evidence that health-side reporting into an enforcement-housed store required dedicated legal scaffolding. A 2025 peer-reviewed critical analysis in Medical Anthropology Quarterly assesses ODMAP and the National Overdose Response Strategy as "collaborative surveillance technologies" and argues the law-enforcement and public-health integration risks racialized surveillance and the criminalization of people who experience overdose. That argument is a scholarly critique and a documented governance tension, not a documented misuse incident, and is presented here as contested.
Two more facts complete the honest picture. First, ODMAP's own disclaimer states that events are suspected and unconfirmed, that agencies define their own reporting criteria, that the data set is incomplete and is not a system of record, and that analyses "should not be generalized" beyond participating agencies - so the alert stream carries self-declared measurement noise of unknown magnitude, and no public statistic on spike-alert accuracy or on the outcomes of alert-triggered response exists to bound it. Second, for 2026 the team announced a partnership with a research organization to explore predictive-analytic options and a new interactive dashboard, so the currently rule-based system has an announced but not-yet-deployed predictive extension; on the public record ODMAP should not be described as predictive or machine learning in the present tense. It is deliberately distinct from the Atlas's patient-level scoring cell, which scores identified patients from prescription histories: ODMAP records unnamed, aggregate, suspected overdose events and never issues a per-person score.
The sociotechnical reading
Most cells in the Atlas turn on a model: how accurate the score is, who checks it, whether the human can override it. ODMAP is the cell where that whole frame does not apply, and the mismatch is the lesson. The algorithm is a rolling count against a threshold - arithmetic a spreadsheet could do - and there is no individual being scored, so there is almost nothing to govern on the model node itself. Sharpening the detector buys nothing; the threshold is already exact. What that reveals, by subtraction, is that the entire governance surface of a population-level alerting system sits on its links, not its model: which agencies may read a shared signal, what that signal may be combined with, where it may be sent, and whether the measurement is ever independently checked. Move the AI off the individual and onto the aggregate, and the questions do not disappear - they migrate from the score to the wiring.
Read as a system map, three link properties carry the whole case. The first is where the store lives. A public-health surveillance signal is housed inside a federal drug-enforcement program, and that single hosting decision is what places a law-enforcement read edge on the same store as the public-health one. The program's policies try to hold both truths at once - the store is "neither an intelligence sharing database, nor a pointer index" and yet may be used "as the HIDTA sees fit," combined with other databases it manages for "law enforcement and public health products" - and the contested critique in the literature attaches to exactly that link structure, not to the threshold rule. Housing is authority: where a shared signal is stored decides who is allowed to read it, and no amount of model governance touches that. The second is the self-referential baseline. The threshold is recomputed from the store's own trailing ninety days, so a system's sensitivity is set by its own reporting behavior - a county that under-reports quietly lowers its future alert sensitivity, the baseline can shift without notifying anyone, and coverage itself (only about a quarter of approved agencies actually submitted events in 2025) becomes a governed, spatially uneven quantity rather than a given. A surveillance network built this way can go blind precisely where reporting is thinnest, and it will not announce that it has. The third is dissemination by design: the early-warning value comes from the neighbor edge and from wide subscription, but the same design sends alerts to subscribers who "do not need to be ODMAP users," in tension with the policy that says distribution should stay within eligible agencies - so the signal leaks outward by construction, exactly as it is meant to propagate.
The distinct lesson the Atlas draws here is that when the algorithm is a simple threshold on a shared count, safety stops being a property of the model and becomes a property of the links - and the most decisive of those links is the store's housing, because where a signal is kept determines who may read it and what it may be joined to. That reframes what governance even means for this cell. It is not a better model or a human-in-the-loop over a decision; it is authorizing every connection into and out of the store (which feeds enter, which reads are permitted, which copies may leave), marking a self-reported and self-referential count as the estimate it is rather than the fact it looks like, governing the sideways neighbor-edge and cross-sector propagation so an early warning does not become a contagion of its own error, and standing up the two things the program has never had: an independent evaluation of whether the alerts are even right, and an independent check on who reads the shared store and what it is combined with. Every figure in this case is the program's self-report, so the honest posture is doubled caution: the numbers are unaudited, the alerts' accuracy is unmeasured, and the served people who experience overdose are not in this reading at all. No overdose, mortality, or clinical outcome is computed from anything here; a spike alert, a threshold, or a reported event is an aggregate institutional signal, never a person, and the racialized-surveillance concern is carried as a contested critique of the link structure, never as a quantified harm.
The concepts used in this reading are defined in the Field Guide; the governance responses live in the Practice Library. The model organization for this case can be stress-tested in the PAN Lab.