RCM & Prior Auth AI
A

Alaffia Health

Agentic AI for health plan claims operations, and the only payer side vendor in this lane: the buyer is the plan rather than the provider. Covers the full claims lifecycle across payment integrity, utilization management, and appeals. Proprietary optical character recognition digitizes unstructured itemized bills and medical records, agents extract and structure clinical facts and cross reference a claim against the complete patient record, clinical criteria, and policy guidelines, automating routine cases and prioritizing high value claims for human review. A generative assistant helps reviewers summarize records, source guidelines, and draft determination responses.

The company states it deliberately avoids black box denial algorithms: every recommendation carries a clinical rationale and traceable citations, and licensed clinicians validate and sign off. Maintains SOC 2 Type II, HIPAA, and HITRUST. Reports saving health plans more than $120 million, over 20 percent average savings on high cost facility claims, and go live in roughly 30 days. Founded 2020 by siblings TJ Ademiluyi and Adun Akanni; $55 million Series B in February 2026 led by Transformation Capital, bringing total funding above $73 million.

AI Health Index verifiedJuly 26, 2026
Compare Alaffia Health with other vendors
Founded
2020
Headquarters
New York, New York
Categories
rcm-and-prior-auth, healthcare-admin-automation
Indexed Products
Payment Integrity, Utilization Management, Appeals
Buyer Segments
Payer
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
AA on AI CentralityThe artificial intelligence is the product. Remove the model and there is nothing left to sell.
Vendor Published

Agents perform the review itself: OCR digitizes unstructured bills and records, models extract clinical facts and cross reference the claim against the full patient record and policy criteria. The human clinician validates a machine produced finding rather than conducting the review.

AA on Autonomy and Oversight ModelWhat the system may do and what it may not do are both published, with escalation thresholds, override paths and the conditions that route a case to a person.
Vendor Published

The most deliberate oversight position in the index, and it is a direct response to a live regulatory problem. The company states it avoids black box denial algorithms of the kind drawing regulatory backlash, grounds every insight in verifiable record data, attaches a clinical rationale and traceable citations to each recommendation, and keeps licensed clinicians at the point of validation and signoff.

In claims denial, where an opaque model decision has direct patient consequence and growing legal exposure, designing for defensibility rather than throughput is the correct answer and it is stated explicitly.

CC on Model and Technology TransparencyThe architecture is described in general terms with nothing identified. Proprietary is asserted rather than explained.
Vendor Published

Nothing published describes the models. No architecture, no accuracy or precision figures, no confidence threshold governing what is automated versus escalated, and no evaluation methodology.

The published numbers are commercial outcomes rather than model performance: more than $120 million in reported savings for health plans and more than 20 percent average savings on high cost facility claims. Those describe money recovered, not how often the system was right, and the two are not the same measurement. A recommendation that reduces a claim is recorded as a saving whether or not the reduction was correct, because the counterfactual is rarely tested.

The one genuine technical disclosure is the training boundary, that the platform learns only from the customer's own data and workflows. That tells a buyer where the model's inputs come from but nothing about what the model is or how well it performs.

BB on Model Supply Chain DisclosureSubstantial partial disclosure, or a chain that is structurally short: an in house build, a cleared model that cannot be quietly swapped, or a deployment where the transfer does not occur at all. Naming only the hosting provider sits at the top of this band rather than in A.
Vendor Published

Two commitments here are exactly what this axis asks for and are stated publicly rather than offered under agreement. Data is committed never to be shared with or used by third party models, and learning is stated to be per plan so inferences are not pooled across customers.

That second one is the pooling answer this segment almost never gives, and it matters most here because the customers are competing payers: a model that learned from one plan's determinations and served another would transfer commercially sensitive adjudication behaviour without either plan agreeing to it. Encryption in transit and at rest is stated with the strength named, and the security page carries the position publicly. Held below the top grade on three gaps.

No retention or deletion schedule is published for the medical records ingested during review, which have no ongoing purpose once a determination is made, so a defined purge is the obvious control and its absence is conspicuous. No sub processor list and no data classification policy.

And the managed services arm adds a question a pure software vendor does not face, since licensed clinicians employed by the vendor handle member records at scale, which makes personnel screening, access controls and staffing location live operational issues rather than theoretical ones. Ask for retention on ingested records, the sub processor list, and how the human review workforce is screened and where it sits.

BB on Clinical and Operational EvidenceNamed deployments with dated outcome figures and enough method to test them, or published research short of independent validation.
Vendor Published

Specific and falsifiable figures: more than $120 million in reported medical cost savings, over 20 percent average savings on high cost facility claims, return on investment above five times, review cycles compressed from weeks to days, and roughly 30 day implementation. Held back from A because the figures are vendor reported without published methodology or an independent audit, and savings attribution in payment integrity is notoriously difficult to isolate.

BB on AI Safety and PHI StewardshipCategorical commitments are published, such as no training on customer data, without the retention schedule or the safety engineering behind them.
Vendor Published

Unlike the credentialing vendors in this index, this is squarely protected health information. The platform ingests itemized bills and full medical records through its own optical character recognition and reasons over them against clinical criteria, so the data is patient data and HIPAA is the primary governing regime rather than a secondary one.

Strong points: an explicit commitment that data is never shared with or used by third party models, per plan learning so inferences are not pooled across customers, 256 bit encryption in transit and at rest, and a security page that states the position publicly.

Gaps worth pressing. No retention or deletion schedule is published for the medical records ingested during review, which have no ongoing purpose once a determination is made, so purging them is the obvious control. No subprocessor list. No data classification policy.

The managed services arm adds a question a pure software vendor does not face. Licensed clinicians employed by Alaffia handle member records at scale, which makes personnel screening, access controls and staffing location live issues rather than theoretical ones.

Regulatory and Compliance
BB on HIPAA and BAA PostureBusiness associate status is stated and supported by a substantive privacy document, with the agreement or its scope not fully published. For a vendor outside the United States, an equivalent regime documented to this depth grades here.
Vendor Published

Alaffia is unambiguously a business associate. It processes member claims and medical records on behalf of health plans, so the status follows from the work rather than from interpretation. It states HIPAA adherence publicly and maintains a dedicated security page.

One precision problem is worth naming, because it is the disclosure failure this index finds most often, appearing here in a new form. The company's own pages say it adheres to SOC 2 Type II, HIPAA and HITRUST security standards. Adhering to a standard is a weaker statement than holding a certification, and the HITRUST level is not named anywhere on its own site. The level is material: i1 is a fixed control set certified for one year, while r2 is the tailored, risk based, two year certification, and a buyer told only HITRUST would reasonably assume the latter.

The level is findable, but only through a third party. Alaffia's compliance platform published a customer account naming HITRUST i1 specifically, with a stated plan to progress from i1 to r2. Credited on that basis and attributed, since it is the audit partner rather than a competitor comparison site.

Held at B because no business associate agreement is published, no role statement appears in its own words, and no review cadence is stated.

BB on Security Certifications and Trust CenterA recognised certification is named in the vendor own material without the artefact, or with a scope or renewal question the buyer has to raise. A certification has a scope and a clock, and both are part of this grade.
Vendor Published

SOC 2 Type II, HIPAA, and HITRUST all stated, the appropriate certification set for a vendor handling payer claims and clinical records. Held back from A because no public trust center with control level detail or named audit dates was retrieved.

CC on FDA and Regulatory StatusNo device claim is made and the product is scoped accordingly. Most administrative and operational products sit here and are not penalised for it, because this axis grades the appropriateness of the positioning rather than possession of a clearance.
Vendor Published

Graded against the regime that actually governs this work rather than against the FDA, which has no jurisdiction here. Payment integrity and utilization management support is administrative and financial review, not diagnosis or treatment, so no clearance exists to hold.

The governing regime is accreditation plus the 2026 payer rules. URAC Health Utilization Management accreditation covers exactly what Alaffia does, since eligibility turns on determining medical necessity, peer clinical review and appeals. NCQA runs a parallel Utilization Management Accreditation for organisations performing full scope utilization management under contract. Alongside those sit the CMS interoperability and prior authorization requirements effective January 2026 and the state laws now restricting AI driven coverage determinations.

Alaffia is eligible rather than exempt. Its managed services arm puts its own licensed clinicians into the review, which is the delegated entity side of the line, not the software side. No URAC or NCQA accreditation was located across two differently phrased searches. That matters more than a missing certificate usually would, because URAC operates a modular approach under which an accredited partner relieves the plan of conducting its own delegation oversight. The accreditation would transfer into the customer's audit position, and its absence leaves that oversight with the plan.

BB on AI Governance and Bias DisclosureA governance framework with named process behind it, such as certification to an artificial intelligence management standard, or material written for a customer own review committee to evaluate the product with.
Vendor Published

Earns the B on traceability surfaced to the reviewer rather than on published testing. Every recommendation carries a clinical rationale and source citations that link back to the underlying medical records and policy documents, so the reviewer can check the reasoning against the evidence rather than accepting a score. The company states that all AI generated recommendations are validated by licensed clinicians, and that it implements governance controls tailored to each customer's requirements. It positions itself explicitly against black box denial algorithms, which in this category is a meaningful stance rather than a slogan.

What is missing is the evidence layer. No bias testing, no subgroup results, no accuracy or error rates, and no false positive rate on claims the system flags for reduction.

That gap has a specific shape here that it does not have in clinical tools. This system recommends paying less. A false positive is a wrongly reduced or denied claim, and the person who absorbs it is a patient or a provider, neither of whom is the customer. Exposure would run on claim characteristics such as facility type, documentation quality and coding patterns, all of which track the resourcing of the place a patient happened to receive care. Ask for the flag rate and whether it varies by facility type.

DD on AI Liability and RecourseNothing published on what happens when the system is wrong.
Vendor Published

Nothing published describes the models: no architecture, accuracy or precision figures, confidence threshold governing what is automated versus escalated, evaluation methodology, or warranty, indemnity or remediation commitment. The one genuine technical disclosure is the training boundary, that the platform learns only from the customer's own data and workflows, which tells a buyer where the model's inputs come from and nothing about what the model is or how well it performs.

The published numbers are commercial outcomes covering total savings for health plans and average savings on high cost facility claims, and the gap between those and accuracy is unusually consequential in this domain rather than merely technical.

A recommendation that reduces a claim is recorded as a saving whether or not the reduction was correct, because the counterfactual is almost never tested: the provider either accepts the reduction, in which case it is booked as a win, or appeals, in which case the cost of appealing filters which errors ever surface.

So the headline figure measures the system's effect on payment, not its correctness, and a payment integrity model that is systematically too aggressive would produce a larger number rather than a smaller one. The affected party is a provider, and behind them a member whose claim was reduced. Ask what proportion of reductions are appealed, what proportion of appeals succeed, and the precision of the clinical criteria matching.

Integration and Deployment
CC on EHR and Interoperability DepthIntegration is claimed through standards or a middleware layer with no system named and nothing to verify.
Vendor Published

This axis has to be read differently on the payer side. Alaffia does not connect to electronic health records and has little reason to. The systems that matter to its buyer are claims platforms, utilization management systems and clearinghouses, and the meaningful question is which of those it connects to.

None is named. The company states that integration into existing systems is seamless with no disruption to operations or workflow changes, and reports go live in about 30 days, but publishes no named claims platform, no clearinghouse, no utilization management system and no reference to the standard transaction formats that govern this exchange.

What is disclosed is the ingestion side, and it is genuinely capable: proprietary optical character recognition that digitises unstructured itemized bills and medical records, which is the hard part of this problem because the source documents arrive as scans rather than structured data. That is a document handling strength rather than an interoperability one. A buyer should ask for named integrations with its own claims stack before treating the 30 day figure as applicable.

BB on Deployment Model and Data ResidencyOptions and residency are stated with isolation or the processing path left open.
Vendor Published

The distinctive claim is a boundary rather than a location. Alaffia states that plan data stays in the plan's environment, is never shared with or used by third party models, and that the platform learns only from that plan's own workflows, so what the system infers is specific to the customer rather than pooled. Data is encrypted in transit and at rest with 256 bit encryption. Implementation is reported at about 30 days.

A per tenant learning boundary is a real architectural commitment and few vendors on the payer side state one this plainly.

What is not published is the residency itself. No hosting provider is named, no region or data centre location is stated and there is no subprocessor list. There is also a tension a buyer should resolve directly: the managed services arm has Alaffia's own licensed clinicians working in the platform daily on the plan's claims, which is difficult to reconcile with data remaining wholly inside the plan's environment. Establish where the line sits between the software engagement and the staffed one.

Commercial
BB on Commercial TransparencyA price or a pricing basis is published without full tiers, so a buyer can size the cost before making contact.
Vendor Published

Publishes the pricing mechanism plainly and has done so consistently for years, which puts it ahead of most of this index. The fee is contingency based, charged as a percentage of the funds recovered, with no upfront cost and no fixed fee. It also publishes a savings basis a plan can model against, citing roughly $150 per plan member per year in potential savings, worked through to about $15 million for a plan of 100,000 members.

Held at B because the percentage itself is never stated, and that is the number that determines what the arrangement actually costs. Contract length, minimum volumes and whether any floor applies are also unpublished.

One structural point a buyer should think through rather than take as a warning. Contingency pricing is marketed as alignment, and against the plan it genuinely is, since the vendor earns nothing unless it finds something. But it also means revenue rises with the volume and size of the reductions the system recommends, while the party who absorbs a reduction that turns out to be wrong is the provider or the member, neither of whom is a party to the contract. The alignment is real on one side of the transaction and absent on the other. Read alongside the absence of any published false positive rate on flagged claims.

AA on Setting and Specialty CoverageWhere the product is validated to operate is named and supported, settings and specialties both, whether the coverage is broad or deliberately narrow.
Vendor Published

Precisely bounded and unusually honest about it: health plan claims operations across payment integrity, utilization management, and appeals. The company states it is not a browser automation tool or a general agent builder, and is specialized for the payer rather than applicable across healthcare.

Comparisons

Compared With

Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Contact the vendor
Enterprise engagement tied to review volume and savings delivered Vendor Published

No rate card published. Sold to health plans as a cloud platform or fully managed service, with terms typically tied to review volume and savings delivered rather than a list price. The structure is worth scrutiny in procurement: if compensation is contingent on identified savings, the incentive runs toward finding more denials, which makes the clinician validation checkpoint the control that matters.