Regulatory and Compliance
Which healthcare AI vendors hold SOC 2, HITRUST or ISO 27001?
The AI Health Index grades all 554 vendors on Security Certifications and Trust Center, one of 15 capability axes applied to every record without exception. 61 of 554 vendors grade A, 120 grade B, 300 grade C and 73 grade D. That places this axis 8th of 15 by the number of vendors reaching the top grade. Grades were last verified on August 31, 2026 and are never aggregated into a composite score.
What this axis measures
SOC 2 Type II, HITRUST, and ISO 27001 status, verified through public trust centers wherever possible, along with security incident disclosure practices.
Buyers also search this as: SOC 2 for healthcare AI, HITRUST certified vendors, ISO 27001, trust centers, and security questionnaires.
What each grade means on this axis
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check.
The distribution
Reading the result
This is the axis buyers check first and learn least from, because certification is close to a licence to operate in this market rather than a differentiator. The grade separation comes from verifiability instead: whether the certification can be confirmed at a public trust center without an email exchange, and whether it is current rather than historical.
The more revealing half is incident disclosure. Certifications describe controls at a point in time. How a vendor behaved when something went wrong describes the controls in practice, and vendors that publish that history are making a costly signal that a badge does not.
Where the A grades are, by category
Categories are shown by the share of their vendors reaching an A. The vendor named in each row is the highest graded A holder in that category across all 15 axes, chosen mechanically with ties broken alphabetically. Categories with no A holder on this axis are omitted.
Questions worth asking a vendor
- Can the certification be verified at a public trust center right now, and what is its date?
- What is in scope, since a certification covering the corporate environment is not the same as one covering the product?
- Has the vendor disclosed any security incident, and what did that disclosure look like?
Questions buyers ask
How many healthcare AI vendors grade well on security certifications and trust center?
Of the 554 vendors in the AI Health Index, 61 grade A on this axis, 120 grade B, 300 grade C and 73 grade D under the AI Health Index grading framework. Grades were last verified on August 31, 2026. Grades are not aggregated into a composite score.
What does an A grade mean on security certifications and trust center?
SOC 2 Type II, HITRUST, and ISO 27001 status, verified through public trust centers wherever possible, along with security incident disclosure practices. Certifications named with their type and version and presented as retrievable artefacts, usually through a trust portal a buyer can open without asking.
What does a D grade mean on security certifications and trust center?
Controls are asserted with nothing independent behind them, or nothing is published. Read the note before concluding anything: this is the grade most often corrected on a second pass, because assurance material frequently sits on a parent domain or inside an old announcement rather than on the product pages. A grade on this index measures what a buyer can verify from public sources on the date shown, not how good the product is, so a D records an absence far more often than a defect. A vendor that publishes more is regraded.
Do vendors pay to be included or graded?
No. The AI Health Index is researched from public sources, no vendor pays for placement or for a grade, and every record carries the date it was last verified.
The other 14 axes
No single axis decides a selection. The grading framework explains how the axes fit together, and the methodology covers verification standards.