The Taxonomy

Features

Every vendor in the AI Health Index is assessed against fifteen capability axes in four groups. Each axis carries a letter grade and a source basis, and each is gradeable from public artifacts: vendor documentation, trust centers, regulatory databases, EHR marketplace listings, and published research.

How grades read

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check.

A
Verifiable evidence at the top of this axis under the AI Health Index grading framework. Named, dated, and checkable by an outsider without contacting the vendor.
B
Substantive disclosure with a real gap. Enough for a buyer to act on, short of the artifact that would settle the question.
C
The claim is made and the documentation behind it is not published, or the coverage is standard and silent on the questions this axis asks.
D
Nothing published on this axis that a buyer can check, or a claim that cannot be tested. A D under the AI Health Index grading framework records an absence far more often than a defect, and absence is dated: it means not located in public sources on the date shown.

Grades are not aggregated into a composite score. An AI Health Index grade reflects the assessed strength of the vendor’s disclosure and evidence on that axis, not a comparison to other vendors. A low grade is dated: it records what was located in public sources on the verification date shown on the vendor profile, and vendors that publish more are regraded. See the Methodology for verification standards.

01 — AI Capability

AI Centrality

Whether artificial intelligence is the product itself, the engine of a core module, or a feature layer on a platform whose value stands without it. This axis is how a reader distinguishes an AI-native product from a platform with AI capabilities. The index includes companies across the full range.

How the whole index grades on this axis

Autonomy and Oversight Model

What the AI is permitted to do (draft, decide, or act) and how rigorously the vendor discloses its human oversight structure: escalation thresholds, supervision, override paths. Grades disclosure rigor, not autonomy itself. High autonomy with a documented oversight model can grade well; any autonomy with no disclosed oversight grades poorly.

How the whole index grades on this axis

Model and Technology Transparency

Disclosure of what is under the hood: proprietary models versus fine-tuned foundation models, training data claims, model cards, versioning and update practices.

How the whole index grades on this axis

Model Supply Chain Disclosure

Who else is in the chain between a patient record and an answer, and on what terms. Whether the model provider is named rather than described, whether subprocessors are enumerated, what retention and training terms govern data once it reaches them, and whether the vendor has published the terms it negotiated rather than the provider’s default posture. The strongest records answer the question structurally rather than contractually: the artefact is obtainable, or identifiers are removed before any model sees them, or the transfer does not occur at all.

How the whole index grades on this axis

Clinical and Operational Evidence

The strength of evidence behind performance and outcome claims, from peer-reviewed prospective multi-site validation at the top of the scale down to outcome percentages published with no methodology. Vendor-reported statistics are recorded as vendor-reported and never restated as independent results.

How the whole index grades on this axis

AI Safety and PHI Stewardship

How the vendor handles protected health information across the AI lifecycle, including use in training, retention, and de-identification, along with safety engineering disclosures such as guardrails, hallucination mitigation, and safety event reporting.

How the whole index grades on this axis
02 — Regulatory and Compliance

HIPAA and BAA Posture

Business Associate Agreement availability, the tier at which the BAA applies, and subprocessor disclosure. The specific BAA tier fact is recorded in the vendor pricing record; this axis grades the overall posture and disclosure quality.

How the whole index grades on this axis

Security Certifications and Trust Center

SOC 2 Type II, HITRUST, and ISO 27001 status, verified through public trust centers wherever possible, along with security incident disclosure practices.

How the whole index grades on this axis

FDA and Regulatory Status

Whether the product is FDA cleared or authorized as a Software as a Medical Device, operating under enforcement discretion, or positioned as non-device clinical decision support, verified against the FDA public databases. Grades clarity and appropriateness of regulatory positioning, not possession of clearance; products for which clearance is not applicable are not penalized.

How the whole index grades on this axis

AI Governance and Bias Disclosure

Substantive responsible AI commitments: published model cards, decision support transparency attributes for EHR-embedded tools, bias and fairness evaluations with stated methodology, third-party AI audits.

How the whole index grades on this axis

AI Liability and Recourse

What happens when the system is wrong, and who can do anything about it. Whether an error rate is published with its method and denominator rather than an unfalsifiable claim of accuracy, whether limitations and abstention behaviour are stated, and whether any warranty, indemnity or remediation commitment attaches. The axis weighs the route available to the affected person, who in much of this market is a patient or a clinician rather than the customer, and who frequently has no way to learn a determination was made about them at all.

How the whole index grades on this axis
03 — Integration and Deployment

EHR and Interoperability Depth

Integration maturity with major EHR systems: native workflow embedding, SMART on FHIR applications, HL7 interfaces, or standalone operation, verified against EHR marketplace listings and integration documentation where available. For lanes where EHR integration is not the relevant surface, the axis is assessed against the relevant surface or marked not applicable.

How the whole index grades on this axis

Deployment Model and Data Residency

Documented deployment options (cloud, virtual private cloud, on-premises) along with United States data residency commitments and tenant isolation disclosures.

How the whole index grades on this axis
04 — Commercial

Commercial Transparency

Whether a buyer can learn what the product costs and how it is priced without a sales engagement: published tiers, published pricing basis, self-serve trial availability. Specific figures are recorded in the vendor pricing record, with estimates labeled as estimates. Vendors that publish no pricing are recorded as Contact the vendor and graded on what a prospective buyer can establish before making contact; a failing grade is reserved for published pricing claims contradicted by evidence.

How the whole index grades on this axis

Setting and Specialty Coverage

Clarity about where the product is validated to operate (ambulatory, inpatient, emergency, behavioral health, post-acute, home) and specialty coverage where relevant. Narrow coverage clearly stated grades well; the measure is clarity and validation, not breadth.

How the whole index grades on this axis