Inpatient Deterioration & Risk Monitoring
A

AITRICS VitalCare

AITRICS is a Korean medical AI company whose AITRICS-VC (VitalCare) predicts patient deterioration from electronic medical record data. It is the first vendor in this category focused on the general ward rather than the ICU, which is a materially different detection problem: ward patients are observed intermittently rather than monitored continuously, so the model must work from sparse, irregularly timed measurements.

As marketed, VitalCare runs two deep learning models built on a bidirectional long short term memory architecture. VC-MAES predicts clinical deterioration events, defined as unplanned ICU transfer, cardiac arrest or in hospital death, within six hours. VC-SEPS predicts sepsis onset within four hours. The company also markets cardiac arrest prediction within 24 hours and, in the ICU, mortality prediction within six hours. Inputs are 19 parameters drawn from the EMR: six vital signs, 11 blood test results, level of consciousness and age.

The development and validation work is published as a medRxiv preprint. Models were derived on 357,009 adult general ward admissions at Yonsei Severance Hospital between 2013 and 2017, then externally validated on 22,073 admissions at National Health Insurance Service Ilsan Hospital. In external validation VC-MAES reached an AUROC of 0.918 against 0.834 for MEWS and 0.883 for NEWS, and VC-SEPS reached 0.941 against 0.559 for SOFA, 0.687 for qSOFA and 0.767 for NEWS. Both models held AUROC above 0.86 across all age and sex categories, which is the only published subgroup performance reporting located for any vendor in this category.

Regulatory footprint spans several jurisdictions, and the scopes differ in ways a buyer must read carefully. Korea's MFDS approved the deterioration prediction product for both general wards and intensive care. Hong Kong's Medical Device Division and Vietnam's Ministry of Health followed. The US clearance is materially narrower: 510(k) K240756, granted 23 July 2024 under 21 CFR 870.2300, describes software performing rule based calculation of conventional early warning scores including NEWS, MEWS and qSOFA, screening patients against predefined thresholds and displaying them on a dashboard. It is indicated solely for the general ward and is expressly not indicated for the ICU or operating rooms, and the submission required no clinical data. VitalCare is reported in use at more than 60 hospitals in Korea. Pricing is not published.

AI Health Index verifiedJuly 25, 2026
Compare AITRICS VitalCare with other vendors
Founded
Headquarters
Seoul, Republic of Korea
Website
aitrics.com
Categories
inpatient-monitoring, clinical-decision-support
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
AA on AI CentralityThe artificial intelligence is the product. Remove the model and there is nothing left to sell.
Regulatory Filing

The product AITRICS builds, publishes on and sells is a pair of deep learning models, and there is no ambiguity about it. The bidirectional LSTM architecture is named in the literature and the models are the entire value proposition. Strip them out and nothing saleable remains.

One caveat belongs here rather than buried, because it changes what a US buyer is actually getting. The device description in the US 510(k) K240756 describes software performing rule based calculation of conventional early warning scores, not the deep learning models. In its US cleared configuration as described to the FDA, the centrality of machine learning is much lower than this grade implies. See the FDA axis.

BB on Autonomy and Oversight ModelThe oversight structure is described and one part is missing, commonly the threshold at which the system stops or what happens after it is wrong.
Regulatory Filing

The US cleared indications for use carry two explicit published constraints: the software is not intended to replace bedside patient monitors or clinicians' clinical decision making, and it is restricted to the general ward and expressly not indicated for the ICU or operating rooms. A setting restriction written into the label is a stronger form of scope discipline than most vendors accept.

Nothing is auto actioned and there is no de escalation or low risk output of the kind that creates the invisible failure mode elsewhere in this category. Held below A because no operating threshold is published, no positive predictive value at that threshold is stated, no abstention or uncertainty behaviour is described, and nothing addresses what a clinician should do when the model and the conventional early warning score disagree, which is the practical question given the product displays both.

BB on Model and Technology TransparencyThe approach or the suppliers are named without the version and update discipline behind them.
Vendor Published

Strong disclosure of the kind this market rarely offers. The architecture is named, a bidirectional long short term memory network, which almost no vendor in this index does. Inputs are enumerated at 19 EMR parameters covering six vital signs, 11 blood tests, level of consciousness and age, with the published work specifying age, vital signs, laboratory results and Glasgow Coma Scale. Derivation and external validation cohorts are named with institutions, sizes and date ranges, and performance is reported with 95 percent confidence intervals and benchmarked against four conventional scores.

Held at B rather than A for three reasons: the study is a preprint and has not completed peer review, no calibration curves or feature attribution are published, and the company nowhere explains the gap between the deep learning models it publishes on and the rule based device described in its US clearance.

CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

The input footprint is bounded and stated, and one precedent on the record answers the training question in at least one direction. The system draws roughly nineteen defined elements covering vital signs, blood test results, level of consciousness and age over a standard interface and presents them in a browser, which is a materially smaller proposition than a product ingesting whole records and deserves crediting.

On training, the company's United States validation work used an academic health system's database to improve detection accuracy, which establishes that customer derived data has been used for model improvement in at least one arrangement rather than leaving it hypothetical. Whether anything comparable applies to a commercial deployment, and on what basis, is unstated. Jurisdiction is worth naming rather than treating as an absence.

The company is headquartered in a country operating one of the more demanding personal information regimes in the world, with specific provisions for sensitive health data and strict conditions on transfer abroad, so obligations attach that do not depend on what the company publishes in English.

With a footprint now spanning six jurisdictions, the questions are where processing occurs for each deployment, whether customer data crosses a border, and how the home regime interacts with the buyer's own. Ask all three, plus the retraining basis.

BB on Clinical and Operational EvidenceNamed deployments with dated outcome figures and enough method to test them, or published research short of independent validation.
Vendor Published

Substantial development and external validation, published with full conflict disclosure. Kim Y, Hahn S, Kim KJ et al., medRxiv 2025, doi 10.1101/2025.08.20.25334022, posted 24 August 2025. Derivation on 357,009 adult general ward admissions at Yonsei Severance Hospital 2013 to 2017, and external validation on 22,073 admissions at NHIS Ilsan Hospital. VC-MAES reached AUROC 0.918 (95 percent CI 0.909 to 0.927) against MEWS 0.834 and NEWS 0.883. VC-SEPS reached 0.941 (0.934 to 0.947) against SOFA 0.559, qSOFA 0.687 and NEWS 0.767. Conflicts are stated plainly: seven authors are AITRICS employees and two are founders serving as chief executive and chief research officer.

The gap is the one this category exists to name. The paper's own introduction identifies high false alarm rates and alarm fatigue as a principal barrier to clinical adoption, and then reports AUROC as its primary metric. AUROC is prevalence independent and tells a nurse nothing about how many false alarms they will see per shift. No positive predictive value, no alert burden per patient day and no median lead time are reported.

Also held at B because the work is a preprint, the external validation is single centre, and both cohorts are Korean with data now eight to thirteen years old.

CC on AI Safety and PHI StewardshipGeneral assurances of privacy and security that do not answer the questions artificial intelligence raises: what is retained, what reaches a model, and what happens to it there.
Vendor Published

No privacy policy, data processing statement, retention policy or training use disclosure was located.

What is known about the data path is narrow and now firmer. The system draws a defined and modest set of inputs from the record system, described as roughly nineteen elements covering vital signs, blood test results, level of consciousness and age, delivered over a standard interface and presented in a browser. A bounded input set is a smaller proposition than a product ingesting whole records, and it is worth crediting.

What governs at home is worth naming rather than treating as an absence. Korea operates one of the more demanding personal information regimes in the world, with specific provisions for sensitive health data and strict conditions on transfer abroad. A company headquartered there is subject to obligations that do not depend on what it publishes in English, and a buyer outside Korea should ask how those interact with their own.

The unanswered questions follow from the footprint, which now spans six jurisdictions. Where does processing occur for each deployment, does customer data cross a border, and is deployment data used to retrain or recalibrate models.

That last question has a concrete precedent on this record. The company's United States validation work used an academic health system's database to improve detection accuracy, which establishes that customer derived data has been used for model improvement in at least one arrangement. Establish whether anything comparable applies to a commercial deployment, and on what basis.

Regulatory and Compliance
CC on HIPAA and BAA PostureCompliance is claimed without the underlying document, or the published privacy notice covers the website rather than the service that handles patients.
Vendor Published

No statement on business associate agreements, execution terms, cost or subprocessor disclosure was located, and the earlier assessment's observation stands: the company holds a United States clearance while its posture under the domestic privacy rule appears untested in public.

The second pass refines that in a way worth stating, because it identifies what United States experience the company does have and why it is a different instrument.

The company's first United States relationship was a research collaboration with a major academic health system, entered several years before clearance, to validate the model against that system's clinical database. It has since established a United States office. So American patient data has very likely been processed, but under the arrangements research uses: institutional review, a data use agreement, and typically a limited or de identified dataset.

Those are not the instrument a hospital buyer needs. A business associate agreement governs a vendor providing a service on a covered entity's behalf, with different permitted uses, different breach obligations and no ethics committee in the path. A company whose domestic contracting experience is research based may be building that apparatus for the first time as it enters the market commercially.

So an early United States adopter should establish which entity contracts, whether it is the domestic office or the overseas parent, whether an agreement template exists, and how offshore access by development and support staff is documented.

Ask for the agreement, the contracting entity, and the offshore access position.

CC on Security Certifications and Trust CenterControls are described with an outside check behind them, such as independent penetration testing on a stated cadence, but no attestation against a recognised framework.
Vendor Published

A second pass again located no attestation, trust centre or report request path, and the earlier assessment's reading of the standards recorded in the United States submission is exactly right.

The second pass makes the point sharper by adding scale to it. This product now holds regulatory authorisations in six jurisdictions, and the company separately holds a medical device quality management system certification from its home regulator. Every one of those is an examination of safety, performance or quality management. Not one is an information security attestation.

That is the clearest illustration in this lane of the distinction this index keeps drawing. A company can be assessed six times by six national regulators and still have published nothing about how it protects the data its models run on, because that is not what any of those bodies examine. A buyer counting approvals as assurance is counting the wrong thing.

The deployment footprint makes the gap consequential rather than theoretical. The software is in use across dozens of hospitals in one country with authorisations across several others, so a single control failure would reach a large installed base across multiple legal regimes with different breach notification rules.

The home market regulator's quality certification is the closest analogue to a management system standard the company publishes, and it governs device quality rather than information security.

Ask for an information security certification, and whether one is held for the home market that has simply not been published in English.

BB on FDA and Regulatory StatusThe pathway is stated and in progress, or a clearance is named without the vintage and scope a buyer needs to match it to the product on offer.
Regulatory Filing

Genuine multi jurisdiction breadth, and a US clearance that does not cover the marketed product.

Korea's MFDS approved the deterioration prediction system for both general wards and intensive care. Hong Kong's Medical Device Division and Vietnam's Ministry of Health followed, with Indonesia and Malaysia stated as in progress.

The US clearance must be read in full. K240756, decision 23 July 2024, 21 CFR 870.2300 Cardiac Monitor, Class II, product code PLB, predicate K213335 Capsule Surveillance System. The filing's own device description states that AITRICS-VC receives vital signs and blood test results from the EHR and conducts rule based calculations for conventional early warning scores including NEWS, MEWS and qSOFA, screening patients against predefined thresholds and displaying them on a dashboard. The indications restrict it solely to the general ward and state expressly that it is not indicated for the ICU or operating rooms. The performance section states the device does not require clinical data, and none was submitted.

So the deep learning deterioration and sepsis prediction the company publishes on and sells elsewhere is not what the FDA cleared. Clearing a narrow predicate matched claim to enter a market and expanding later is ordinary and legitimate regulatory strategy, and this note is not an allegation of impropriety. It is a warning that the FDA clearance here is a claim about a rule based ward dashboard rather than about the machine learning models. Graded B rather than A for that mismatch and the absence of clinical data in the US submission, and not lower because the Korean approval of the machine learning product is substantive.

BB on AI Governance and Bias DisclosureA governance framework with named process behind it, such as certification to an artificial intelligence management standard, or material written for a customer own review committee to evaluate the product with.
Vendor Published

The first published subgroup performance reporting located for any vendor in this category, and it should be the benchmark others are asked to match. The validation work reports that both models maintained AUROC above 0.86 across all age and sex categories, which is a quantified subgroup floor rather than a statement of intent. Every other vendor assessed in this lane publishes nothing of the kind.

The larger exposure is transportability, and it is the sharpest version of this problem the index has encountered. Both models were derived and externally validated entirely in Korean cohorts on data from 2013 to 2017, and the product now holds US clearance with no published validation in any US population. The Epic Sepsis Model showed the same model's sensitivity falling from 33 percent at a Michigan academic centre to 14.7 percent at county emergency departments within a single country. A shift from Korean tertiary hospitals to the US care system, with different case mix, coding practice, laboratory conventions and ward staffing ratios, is a larger distributional change than that.

Subgroups are also age and sex only, with no race or ethnicity breakdown, which is understandable in a single country cohort and precisely why it does not transfer. No calibration by subgroup is reported.

CC on AI Liability and RecourseMechanisms exist that let someone challenge an output, such as audit trails, source traceability or review before commit, with nothing standing behind the output and no route for the harmed party.
Vendor Published

The published methodology is strong and an unexplained discrepancy sits underneath it, which is what holds this in the middle band rather than above. On the strong side: the architecture is named as a bidirectional long short term memory network, which almost no vendor in this index does, inputs are enumerated at nineteen record parameters covering vital signs, blood tests, level of consciousness and age, derivation and external validation cohorts are named with institutions, sizes and date ranges, and performance is reported with confidence intervals and benchmarked against four conventional scores.

Benchmarking against the scores a hospital already uses is the comparison a buyer actually needs, since the question is never whether a model is good but whether it beats what is on the wall. The discrepancy is the problem. The company nowhere explains the gap between the deep learning models it publishes on and the rule based device described in its United States clearance, and those are different artefacts with different failure modes and different validation needs.

A buyer cannot tell which one they are being sold, and this index has recorded the same class of failure where a vendor described its technology in two incompatible ways. The study is also a preprint that has not completed peer review, and no calibration or feature attribution is published. Ask which artefact is deployed in your jurisdiction, and for calibration on it.

Integration and Deployment
CC on EHR and Interoperability DepthIntegration is claimed through standards or a middleware layer with no system named and nothing to verify.
Regulatory Filing

Ingest is confirmed in the regulatory filing as EHR data over an HL7 feed, delivered to clinicians through a web browser, which is a verified fact rather than a marketing claim. Beyond that the disclosure is thin: no EHR vendor is named anywhere, there is no FHIR support described, no SMART on FHIR launch, no marketplace listing or partner review credential, and no outbound path for pushing scores back into other systems. An Azure Marketplace listing exists.

The counterweight, credited on the deployment axis rather than here, is that integration plainly works at scale in Korean hospitals; but nothing published tells a US buyer what integrating with Epic, Oracle Health or Meditech would involve.

BB on Deployment Model and Data ResidencyOptions and residency are stated with isolation or the processing path left open.
Vendor Published

Real scale in one market. VitalCare is reported in use at more than 60 hospitals in Korea, and named institutions appear consistently across independent symposium and conference reporting, including Seoul St Mary's, Gangnam Severance, Seoul National University Bundang, Yonsei Severance, NHIS Ilsan and Hallym University Chuncheon Sacred Heart. Delivery is browser based with an Azure Marketplace listing.

Held at B because no US deployment was identified despite the US clearance, no implementation timeline, resourcing or data feed prerequisite is published, and no data residency commitment is stated, which is a live question for a Korean vendor selling across Korea, Hong Kong, Vietnam and now the US.

Commercial
CC on Commercial TransparencyNo price is published and the posture is discoverable: a buyer can establish how the product is sold and what drives the cost before contacting the vendor. Most of the index sits here.
Vendor Published

No pricing published at any level: no rate card, no unit of pricing, no indicative band, and no implementation or integration fee. An Azure Marketplace listing exists but carries no published price. Standard for this category and behind the published ladders that earn a Commercial A elsewhere in this index.

BB on Setting and Specialty CoverageCoverage is named with validation behind part of it.
Regulatory Filing

The general ward focus is a genuine and useful position in a category that is otherwise ICU heavy. Ward deterioration is a harder detection problem than ICU deterioration for a reason worth stating: ICU patients are monitored continuously, while ward patients are measured intermittently, often every four to eight hours, so a ward model must work from sparse and irregularly timed observations. Every other vendor assessed in this lane is built around continuous critical care data streams.

Coverage is published with explicit limits, which is credited: adults, general ward, with ICU mortality prediction marketed under the Korean approval but expressly excluded from the US clearance.

Held at B because the ICU and ward claims differ by jurisdiction in a way the company does not clearly signpost, and because no paediatric or neonatal indication exists.

Comparisons

Compared With

Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Not published
Not published Not published Not published Vendor Published

No pricing published at any level. No rate card, no stated unit of pricing such as per bed, per ward or per monitored patient day, and no published implementation, integration or training fee. An Azure Marketplace listing exists but carries no published price.

The most important non price question for a US buyer is a scope question rather than a cost one, and it should be settled before any commercial discussion: the US 510(k) covers a rule based early warning score dashboard for the general ward only, expressly not the ICU, so establish in writing which product configuration is being quoted, whether the deep learning deterioration and sepsis models are included in a US deployment, and under what regulatory basis they would run.