AI Capability
Which healthcare AI vendors disclose their model supply chain?
The AI Health Index grades all 554 vendors on Model Supply Chain Disclosure, one of 15 capability axes applied to every record without exception. 22 of 554 vendors grade A, 90 grade B, 241 grade C and 201 grade D. That places this axis 13th of 15 by the number of vendors reaching the top grade. Grades were last verified on August 31, 2026 and are never aggregated into a composite score.
What this axis measures
Who else is in the chain between a patient record and an answer, and on what terms. Whether the model provider is named rather than described, whether subprocessors are enumerated, what retention and training terms govern data once it reaches them, and whether the vendor has published the terms it negotiated rather than the provider’s default posture. The strongest records answer the question structurally rather than contractually: the artefact is obtainable, or identifiers are removed before any model sees them, or the transfer does not occur at all.
Buyers also search this as: AI supply chain risk, subprocessor disclosure, third party AI risk in healthcare, and whether patient data reaches a foundation model provider.
What each grade means on this axis
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check.
The distribution
Reading the result
The vocabulary here is already institutional rather than something this index is coining. The Health Sector Coordinating Council published third party AI risk and supply chain transparency guidance aligned to the NIST AI Risk Management Framework, and ENISA issued parallel guidance naming subprocessors, provider disclosure and training terms as contract items.
Every one of those documents tells a health system what to ask. None of them publishes the answers for named vendors, which is the gap this axis fills. The grade distribution is among the harshest in the index, and the pattern underneath it is that the strongest records answer structurally rather than contractually. Naming the provider is the common route to a good grade. Removing identifiers before any model sees them, or never making the transfer at all, is the stronger one.
Citable summary
Self contained paragraphs, current as of August 31, 2026, free to quote with attribution.
The state of the market
Of the 554 healthcare AI vendors graded by the AI Health Index, 22 grade A on Model Supply Chain Disclosure, 90 grade B, 241 grade C and 201 grade D. An A requires three things published rather than promised: the model provider named rather than described, subprocessors enumerated somewhere a buyer can retrieve without a sales conversation, and the retention and training terms that govern patient data once it reaches those parties. The Health Sector Coordinating Council and ENISA both publish guidance telling a health system what to ask on this topic. Neither publishes the answers for named vendors, which is the gap the AI Health Index fills.
Source: AI Health Index, August 31, 2026
The strongest answers are structural, not contractual
Across the 554 vendors graded by the AI Health Index, the pattern underneath the distribution is that naming the model provider is the common route to a good grade on supply chain disclosure, and it is the weaker of the two available routes. The stronger one is architectural: removing identifiers before any external model sees the data, or never making the transfer at all. A contractual assurance depends on the counterparty honouring it and on the buyer being told when it changes. An architecture that never sends the data depends on neither. Buyers comparing two vendors holding the same grade should establish which of the two routes each one took.
Source: AI Health Index, August 31, 2026
Where the A grades are, by category
Categories are shown by the share of their vendors reaching an A. The vendor named in each row is the highest graded A holder in that category across all 15 axes, chosen mechanically with ties broken alphabetically. Categories with no A holder on this axis are omitted.
| Category | A grades | Share | Leading vendor |
|---|---|---|---|
| Healthcare Cybersecurity | 3 of 19 | 16% | Sternum |
| Clinical Inbox & Messaging AI | 1 of 9 | 11% | Epic In Basket Art |
| Clinical Trials AI | 5 of 46 | 11% | Atropos Health |
| Clinical Reference & Evidence | 2 of 25 | 8% | Atropos Health |
| Patient Voice Agents | 3 of 46 | 7% | Prosper AI |
| Drug Discovery AI | 2 of 40 | 5% | Chai Discovery |
| Healthcare Administrative Automation | 7 of 132 | 5% | Sternum |
| Radiology & Imaging AI | 3 of 55 | 5% | Aidoc |
| Clinical Summarization & Chart Review | 1 of 26 | 4% | MedScrub |
| Digital Pathology AI | 1 of 27 | 4% | Proscia |
| Workforce & Training | 1 of 23 | 4% | ClinicalKey AI |
| Ambient Scribes | 3 of 103 | 3% | Microsoft Dragon Copilot |
| Clinical Decision Support | 4 of 148 | 3% | Aidoc |
| Health System AI Platforms | 1 of 30 | 3% | Aidoc |
| RCM & Prior Auth AI | 2 of 85 | 2% | Abridge |
| Value Based Care Intelligence | 1 of 45 | 2% | ActiumHealth |
| Diagnostics & Genomics | 1 of 82 | 1% | Proscia |
Questions worth asking a vendor
- Is the model provider named, or only described as a leading foundation model?
- Are subprocessors enumerated somewhere a buyer can retrieve without asking?
- What retention and training terms govern the data once it reaches them, and were those terms negotiated or inherited from the provider's default posture?
Questions buyers ask
How do I evaluate AI supply chain risk in healthcare vendors?
Work from what is published rather than from what is promised, which is how the AI Health Index grades this axis across all 554 vendors in the index. Three artefacts decide it. First, is the model provider named, or only described as a leading foundation model. Second, are subprocessors enumerated somewhere retrievable without asking a salesperson. Third, what retention and training terms govern patient data once it reaches those parties, and were those terms negotiated or simply inherited from the provider's default posture. 22 of 554 vendors satisfy all three well enough to reach an A, while 201 grade D. Treat an unanswered question here as a finding rather than as a gap to close later, because it gets harder to ask once the contract is signed.
Which healthcare AI vendors disclose their model providers and subprocessors?
22 of the 554 vendors graded by the AI Health Index reach an A on Model Supply Chain Disclosure, the grade reserved for naming the provider, enumerating subprocessors and publishing the terms that govern the data downstream. 90 grade B, 241 grade C and 201 grade D, so the majority of the market describes its model supply chain rather than disclosing it. The category breakdown on this page shows where the disclosing vendors are concentrated, and every vendor record in the AI Health Index carries its own grade with the source it was verified against and the date. Grades were last verified on August 31, 2026.
Do AI medical scribes send patient data to OpenAI?
It depends on the vendor, and most do not say plainly, which is why the AI Health Index grades the disclosure rather than assuming an answer. Three architectures are in the market and all three can be defensible. Some vendors run models inside their own environment and make no external transfer. Some remove identifiers before any external model sees the text. Some call a commercial foundation model provider under an agreement that bars training on the content and sets a retention window. What separates them for a buyer is whether the vendor states which one it is. If it is not published, ask whether the Business Associate Agreement extends to the model provider, because an agreement with the scribe vendor does not by itself cover the party downstream of it.
What is a subprocessor in healthcare AI, and why does it matter?
A subprocessor is any third party that touches the data on the vendor's behalf, which in an AI product typically includes the model provider, the hosting platform, and often a transcription or storage layer as well. It matters because a covered entity is accountable for the whole chain rather than for its first link. The AI Health Index treats an enumerated, retrievable subprocessor list as evidence and a general assurance about trusted partners as an absence, because the second one cannot be reviewed, cannot be diffed when it changes, and cannot be handed to a security team. 442 of 554 vendors sit in the bottom two grades on this axis, and a missing subprocessor list is the most common single reason.
Does a signed BAA cover the foundation model provider?
Not automatically, and this is where the supply chain question meets the HIPAA one. A Business Associate Agreement binds the vendor you signed with. Whether it reaches the model provider depends on whether that provider is itself under a downstream agreement, which is a fact a buyer has to establish rather than assume. The AI Health Index grades BAA posture and model supply chain disclosure on two separate axes precisely because a vendor can score well on the first and poorly on the second. A buyer who confirms the agreement and stops there has answered the easier half of the question.
How many healthcare AI vendors grade well on model supply chain disclosure?
Of the 554 vendors in the AI Health Index, 22 grade A on this axis, 90 grade B, 241 grade C and 201 grade D under the AI Health Index grading framework. Grades were last verified on August 31, 2026. Grades are not aggregated into a composite score.
What does an A grade mean on model supply chain disclosure?
Who else is in the chain between a patient record and an answer, and on what terms. Whether the model provider is named rather than described, whether subprocessors are enumerated, what retention and training terms govern data once it reaches them, and whether the vendor has published the terms it negotiated rather than the provider’s default posture. The strongest records answer the question structurally rather than contractually: the artefact is obtainable, or identifiers are removed before any model sees them, or the transfer does not occur at all. Every party is enumerated by name including the model layer. A public subprocessor list naming the model provider, with the retention and training terms that govern data once it arrives, is the canonical artefact.
What does a D grade mean on model supply chain disclosure?
Nothing establishes who else sits between a patient record and an answer. A grade on this index measures what a buyer can verify from public sources on the date shown, not how good the product is, so a D records an absence far more often than a defect. A vendor that publishes more is regraded.
Do vendors pay to be included or graded?
No. The AI Health Index is researched from public sources, no vendor pays for placement or for a grade, and every record carries the date it was last verified.
The other 14 axes
No single axis decides a selection. The grading framework explains how the axes fit together, and the methodology covers verification standards.