Value Based Care Intelligence
A

Arcadia

Arcadia sells the data foundation underneath value based care, and increasingly the models that run on top of it. The platform ingests clinical records from electronic health record systems, payer claims, admission and discharge feeds, pharmacy data and social determinants information, resolves them to a single member through a proprietary master patient index, applies natural language processing to unstructured text, and presents the curated result to population health, risk, quality and network teams. Named components include a data gateway that handles ingestion and monitors for quality anomalies, a lakehouse platform layer, Arcadia Vista for value based care insights, Network Modeler, Contract IQ, Provider Intelligence, and an AI Factory positioned as an analyst facing environment for building predictive models on a customer's own data. A point of care assistant is the company's first generative artificial intelligence product.

Two ownership events shape what the company is now. CareJourney, acquired in June 2024, supplied national benchmark data derived from Medicare claims, which gave Arcadia an external comparison set rather than only the data its customers bring to it. In July 2025 Nordic Capital took ownership. The brand is still sold under its own name and the product line has expanded since, so the change of owner does not alter how this record reads.

Credentials in the quality domain are held rather than asserted. The company earned the Certified Data Partner designation in the National Committee for Quality Assurance Data Aggregator Validation programme, and separately a Validated Data Stream designation covering the use of its clinical data for HEDIS performance measurement. That second one matters more than it sounds, because it means an external body examined whether data flowing through this platform is fit to be scored on rather than taking the vendor's word for it. Security credentials are long standing: ISO 27001 in 2017, a SOC 2 Type One report in 2019, HITRUST CSF certification in 2020, and top ratings across every category in an independent cybersecurity preparedness evaluation conducted by KLAS Research and Censinet, an exercise roughly ten percent of eligible vendors agreed to enter.

Buyers are health systems, provider groups, accountable care organisations and health plans operating under shared savings, ACO REACH, Medicaid and commercial risk contracts. Named customers include Southwestern Health Resources, Tandigm, Castell, Rush Health and Beth Israel Lahey Health.

Three things a reader should weigh. The published outcome figures, including 81 percent in visit diagnosis capture, 59 percent more closed risk per patient and a 24 percent reduction in inpatient admissions, carry no denominator, no time period and no stated method. The most recent security report located is a SOC 2 Type One rather than a Type Two, which tests whether controls are designed correctly rather than whether they operated correctly over a period. And a dedicated pass located no pricing of any kind.

AI Health Index verifiedAugust 26, 2026
Compare Arcadia with other vendors
Founded
Headquarters
Boston, Massachusetts, United States
Website
arcadia.io
Categories
vbc-intelligence, health-system-ai-platforms
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
CC on AI CentralityArtificial intelligence is a feature layer on a product whose value stands without it.
Vendor Published

The scarce asset here is assembled data, and the models mostly sit on top of it rather than constitute it.

What the company does that is genuinely hard is ingest clinical records from more than fifty electronic health record systems, claims, admission and discharge feeds, pharmacy data and social determinants information, resolve them to one member through a proprietary master patient index, and keep that current at population scale. Machine learning is used inside that pipeline, notably for mapping and normalising source data, and a natural language processing engine reads unstructured clinical text so that content trapped in notes becomes scoreable. Both are real technical work.

Where the grade settles is the layer above. The AI Factory is described as an analyst facing environment for activating customer data and building predictive models, which is a place for the buyer to construct intelligence rather than intelligence the vendor ships. The first generative product is a point of care assistant and it arrived recently. Strip the models out of this business and a very large amount of value remains, because a unified, deduplicated, benchmarked longitudinal record is worth buying on its own.

Graded C on the same reasoning applied to Huma in this index, where a platform holds the differentiating asset and a meaningful share of the intelligence running on it belongs to the customer or partner. That is a different shape from vendors graded higher, where a model produces something that could not otherwise exist.

Ask which shipped features depend on inference rather than aggregation, and what the models in the AI Factory are pretrained on before a customer touches them.

BB on Autonomy and Oversight ModelThe oversight structure is described and one part is missing, commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

The system informs decisions and does not take them, and that boundary is consistent across the product line.

Every output described lands in front of a person who then acts or declines to act. Risk and quality insights surface to care teams, gap lists drive outreach that humans conduct, network and contract analysis informs decisions made by executives over months, and the generative assistant is positioned as support for care team efficiency at the point of care. There is no described mechanism by which this platform submits a claim, alters a record, denies anything or contacts a patient without a person initiating it.

That conservatism is appropriate to what is being decided. A risk stratification output that routes a patient into or out of a care management programme is consequential precisely because it is silent: nobody is told they were not selected, and the person affected never sees the score. Keeping a human in that loop is the correct design even though it is also the less impressive one.

What is not described is the quality of the oversight rather than its existence. Whether a care manager reviewing a ranked list can see why a patient ranked where they did, whether an override is captured, and whether disagreement feeds back into anything are not addressed in material located. Oversight that cannot inspect the reasoning is attendance rather than supervision.

Graded B for a clear and consistently advisory posture, held below the top by the absence of any account of what the reviewing human can actually see.

DD on Model and Technology TransparencyNothing is published about what produces the output.
Vendor Published

The platform is described at the level of components and the models inside it are not described at all.

Architecture disclosure is comparatively good. A lakehouse foundation, a data gateway with proprietary source adapters, a matching and normalisation layer built on a proprietary master patient index, a natural language processing engine for unstructured text, and a metrics layer computing expense grouping and risk are all named, which lets a technical buyer form a picture of how data moves.

Everything about the inference is opaque. A dedicated pass located no model card, no accuracy or calibration figure for any predictive model, no statement of what algorithms are used, no validation methodology, no description of how often models are retrained, and no account of how model drift is detected in a platform where the underlying data composition changes every time a customer adds a source.

The natural language processing engine is the sharpest omission, because its output feeds quality measurement that determines payment. An extraction engine reading clinical notes has a precision and recall figure, and whether it errs toward missing findings or inventing them is the difference between a quality submission that survives audit and one that does not. Neither number nor even a direction is published.

The generative assistant compounds it. The underlying model is not named, no evaluation of its outputs is published, and there is no statement of what it is permitted to assert in front of a clinician.

Graded D. Architecture is visible, inference is a closed box, and the closed part is what the grades in this index are meant to describe.

Ask for extraction precision and recall, predictive model calibration, the retraining cadence, and the base model behind the generative assistant.

DD on Model Supply Chain DisclosureNothing establishes who else sits between a patient record and an answer.
Vendor Published

One dependency is named and the rest of the chain is closed.

The visible part is the benchmark data. National benchmarks entered the platform through the acquisition of CareJourney in June 2024 and are derived from Medicare claims, so a buyer can identify that source and reason about what it does and does not represent. Benchmarks built on a Medicare population describe a population older and differently insured than a commercial book, and knowing the provenance is what allows that adjustment to be made. Naming it is better than most records in this lane manage.

Everything else is undisclosed. No sub processor register was located, no cloud region or subcontractor list is published, no third party data licensor beyond the acquired benchmark asset is identified, and the terms under which any licensed data may be used are not stated. For a platform whose principal asset is assembled data, the data supply chain is the supply chain, and most of it is not visible.

The generative assistant is the newest and least disclosed link. The base model behind it is not named, so a buyer cannot tell whether an external model provider processes clinical content, what that provider's retention behaviour is, or what happens to the product if the provider changes terms, deprecates a version or alters output behaviour. A dependency you cannot name is a dependency you cannot assess.

The ownership change adds a governance question rather than a technical one. Under private equity ownership since July 2025, decisions about which components are built, licensed or consolidated sit with a new owner, and nothing published describes how supply chain changes would be communicated to customers.

Graded D.

Ask for the sub processor register, the base model behind the generative assistant, and whether any licensed data carries use restrictions that pass through to the customer.

BB on Clinical and Operational EvidenceNamed deployments with dated outcome figures and enough method to test them, or published research short of independent validation.
Third Party Estimated

External validation by the body that governs quality measurement, named customers, and outcome numbers that cannot be checked.

The validations are the substance and they are of an unusual kind. The Certified Data Partner designation in the National Committee for Quality Assurance Data Aggregator Validation programme, and a separate Validated Data Stream designation for use of the company's clinical data in HEDIS measurement, both involve an external body examining whether data flowing through this platform is fit to be scored on. For a vendor whose product is data, that is closer to the point than an analyst ranking, because it tests the actual deliverable rather than customer sentiment about it.

Customer evidence is present and specific, which distinguishes this record from several others in the lane. Southwestern Health Resources, Tandigm, Castell, Rush Health and Beth Israel Lahey Health are named, and the company states it serves a substantial share of one national best hospitals list along with top performers in Medicare shared savings and accountable care organisation risk models.

The outcome figures are where the record weakens. Published results include 81 percent in visit diagnosis capture, 59 percent more closed risk per patient and a 24 percent reduction in inpatient admissions. Each is the right kind of measure for this product, and each appears without a denominator, a time period, a comparison group or a stated method. A 24 percent admissions reduction is a large clinical claim and the arithmetic behind it is not shown anywhere located.

No peer reviewed publication was located, which holds this below the top grade despite the strength of the certifications.

Ask for the denominator and time period behind each outcome figure, the comparison group used, and how many customers the figures are drawn from.

CC on AI Safety and PHI StewardshipGeneral assurances of privacy and security that do not answer the questions artificial intelligence raises: what is retained, what reaches a model, and what happens to it there.
Vendor Published

Strong custodial credentials, and an unanswered question about what the models are allowed to learn.

The stewardship apparatus is real. Identity resolution runs through a proprietary master patient index, ingestion is monitored for volume and quality anomalies with alerting to a support team, and the whole estate sits inside an audited security framework. For a business whose function is joining records that were separate, deliberate patient matching and continuous data quality monitoring are the right controls, and having them named is better than most records in this lane.

The gap is model data governance. A natural language processing engine reads unstructured clinical notes, machine learning assists source mapping, and a generative assistant now sits at the point of care. Nothing located states whether customer protected health information is used to train, tune or evaluate models, whether learning is confined within a single customer tenancy, or whether any model benefits from data contributed by other customers. That question is the central one for a multi customer aggregation platform, because the commercial temptation to improve shared models with pooled data is exactly what a business associate agreement is meant to constrain.

The generative assistant sharpens it. A point of care assistant sees clinical context by design, and no statement was located covering prompt retention, output logging, or whether any third party model provider processes that content.

Graded C: the custodial engineering is credible and the model governance is undisclosed.

Ask whether customer data trains or tunes any model, whether learning crosses tenancy, and what is retained from generative assistant sessions.

Regulatory and Compliance
CC on HIPAA and BAA PostureCompliance is claimed without the underlying document, or the published privacy notice covers the website rather than the service that handles patients.
Vendor Published

The compliance posture is stated plainly and the terms behind it are not published.

The platform is described consistently as cloud based and compliant with the Health Insurance Portability and Accountability Act, and HITRUST CSF certification maps that framework onto an audited control set, so a covered entity has a reasonable basis to believe the regulatory obligations were engineered for rather than assumed. Business associate status is the obvious and correct posture for a vendor processing identified clinical and claims data on behalf of providers and plans.

What is missing is the agreement itself. No template business associate agreement, no breach notification window, no liability cap position, no audit rights statement and no data return or destruction provision was located. Third party buyer guidance for this category flags exactly those clauses as the ones to negotiate, which indicates they are neither standard nor published.

One structural point deserves attention. This platform holds identified longitudinal records for very large populations aggregated from many upstream sources, which makes it a concentration point. The consequence of a failure here is not one organisation's data but the joined records of many, and the published material does not address how obligations flow back to the contributing organisations when something goes wrong.

Graded C for a credible and certified posture with the contractual specifics undisclosed.

Ask for the template agreement, the breach notification window, the liability cap, and whether audit rights extend to subcontractors.

BB on Security Certifications and Trust CenterA recognised certification is named in the vendor own material without the artefact, or with a scope or renewal question the buyer has to raise. A certification has a scope and a clock, and both are part of this grade.
Third Party Estimated

A long and independently examined security record, with one report type and one currency question holding it below the top.

The credential stack is genuine and was built early. ISO 27001 certification dates to 2017, a SOC 2 report followed in 2019, and HITRUST CSF certification came in 2020, at which point the company was among the first in value based care and population health to hold it. HITRUST is the demanding one in healthcare because it rationalises multiple regulatory and standards regimes into a single audited framework rather than testing controls against a self selected scope.

The most useful evidence is the one the company did not design. An independent cybersecurity preparedness evaluation conducted by KLAS Research with Censinet rated the platform highest across every category, and roughly ten percent of eligible vendors in the industry agreed to submit solutions for it. Voluntarily entering a comparative evaluation that can produce a bad public result is a meaningfully different signal from commissioning a report you control, and it is the reason this grade sits where it does rather than a step lower.

Two things hold it at B. The SOC 2 report located is a Type One, which examines whether controls are suitably designed at a point in time rather than whether they operated effectively across a period, and Type Two is the report a healthcare buyer normally requires. And the certification dates are all several years old with no published statement of current currency, no renewal date, and no trust centre or portal located where a buyer could retrieve current attestations without asking.

Graded B. Strong, externally tested, and stale on the public record.

Ask for a current SOC 2 Type Two report, the present HITRUST certification date, and penetration testing cadence.

CC on FDA and Regulatory StatusNo device claim is made and the product is scoped accordingly. Most administrative and operational products sit here and are not penalised for it, because this axis grades the appropriateness of the positioning rather than possession of a clearance.
Vendor Published

Outside device regulation, correctly, with one product edging toward the boundary.

Population analytics, quality measurement, risk stratification for programme targeting and network design are administrative and financial functions rather than diagnosis or treatment, so no clearance is required and none is claimed. Making no regulatory claim where none applies is the honest position and it is what this record shows.

The regulatory weight the company does carry sits elsewhere and is substantive. Designations under the National Committee for Quality Assurance Data Aggregator Validation programme govern whether data from this platform may be used in quality measurement that determines payment, and quality measurement under Medicare shared savings and accountable care organisation risk contracts is federally consequential even though it is not device regulation. Holding a certification that gates participation in a payment programme is a real external constraint on how this product may behave.

The boundary case is the point of care assistant. Software that presents information to a clinician during an encounter sits near the clinical decision support exemption criteria, where what matters is whether the clinician can independently review the basis for the recommendation rather than relying on it. Nothing located addresses which side of that line the assistant is designed to fall on, and as generative features expand at the point of care the question becomes live rather than theoretical.

Graded C: correctly outside device regulation, meaningfully regulated in the payment domain, and unclear on the one product where the boundary matters.

Ask how the point of care assistant is positioned against clinical decision support exemption criteria.

DD on AI Governance and Bias DisclosureNothing published on how model behaviour is governed or tested. Multilingual operation with no subgroup performance sits here when the vendor markets recognition quality as a strength, because a caller the system failed to understand leaves no complaint and no record.
Vendor Published

The exposure here is well documented in the literature and unaddressed in anything published by this vendor.

Risk stratification built on claims and utilisation history has a specific and famous failure mode. A widely cited study of a commercial population health algorithm found that using historical cost as a proxy for health need systematically underestimated illness in Black patients, because less money had historically been spent on them for the same conditions, and correcting the target variable changed who was enrolled in extra care by a very large margin. That finding concerns precisely this product category: an algorithm ranking a population for care management using claims derived features.

The consequence is silent, which is what makes disclosure matter more here than in a diagnostic product. A patient who is scored too low is simply never contacted. There is no alert to review, no clinician who disagrees, and no adverse event to report, so the harm never surfaces as an incident and can persist for years inside a programme that reports good aggregate outcomes.

A dedicated pass located no published bias testing, no subgroup performance figures, no statement of what target variable the risk models predict, and no description of any fairness review applied before a model reaches a customer. The AI Factory raises the same question in a second form, since models a customer builds inside a vendor environment inherit whatever guardrails that environment does or does not impose, and none are described.

Social determinants data is ingested and presented as a strength. Using deprivation and demographic signals to improve targeting is defensible and can reduce disparity, but it also places protected characteristic proxies directly into the feature set, and no governance statement covers how those features are used.

Graded D. The category has a documented bias mechanism, this product sits squarely inside it, and nothing published addresses it.

Ask what target variable the risk models predict, whether subgroup performance has been measured, and what fairness review a model passes before it reaches a customer.

DD on AI Liability and RecourseNothing published on what happens when the system is wrong.
Vendor Published

Recourse is undefined at every point where a buyer would need it.

A dedicated pass located no indemnification position, no warranty covering model output, no accuracy guarantee, no service credit regime tied to data quality or availability, and no described process for a customer to dispute or escalate an output believed to be wrong.

The failure modes here are financial and specific, which is what makes the silence costly. If the natural language processing engine misses documented conditions, risk adjustment revenue is understated. If it captures conditions the record does not support, a submission fails audit and the exposure becomes a payer recovery or worse. If quality measures are computed on incompletely ingested data, a shared savings or star rating result moves. Each of those is a quantifiable loss landing on the customer, and each traces back to work this vendor performed.

The programme dimension makes it sharper. Data validated under an external aggregator programme is used in measurement that determines payment, so an error propagates into a regulated submission bearing the provider's name. The provider remains accountable to the programme regardless of which vendor produced the number, and nothing published describes how that accountability is shared, or whether it is shared at all.

The generative assistant introduces a clinical version of the same gap. Where an assistant surfaces something incorrect during an encounter, no allocation of responsibility between the clinician who acted and the vendor whose product spoke is described anywhere located.

Graded D.

Ask for the indemnification position on risk adjustment and quality submissions, whether any accuracy warranty exists, and the escalation path for a disputed output.

Integration and Deployment
AA on EHR and Interoperability DepthNamed bidirectional integrations with major record systems, verifiable in marketplace listings or integration documentation, with evidence the connection runs in production.
Vendor Published

This is the axis the whole company is built on, and it is the strongest interoperability record in this lane.

The breadth is stated concretely rather than gestured at. Off the shelf integration technology covers more than fifty electronic health record vendors spanning physical and behavioural health, and the connection method is proprietary adapters written for source systems rather than a dependency on each customer building an interface. Ingested sources extend past clinical records to claims, admission discharge and transfer feeds, pharmacy data and social determinants information, which is the full set a population health calculation actually needs.

The work after ingestion is what earns the top grade. Records are matched to a member through a proprietary master patient index, deduplicated and normalised to a common dataset, then made available to applications. Aggregating feeds is straightforward and resolving identity across them is not, and identity resolution is where most integration projects in this category fail.

There is external corroboration, which is rare on this axis anywhere in the index. The Certified Data Partner designation in the National Committee for Quality Assurance Data Aggregator Validation programme is an assessment of exactly this capability by a body with no commercial interest in the answer, and the Validated Data Stream designation extends it to the use of the resulting clinical data in HEDIS measurement.

One operational detail supports the claim rather than sitting beside it. The ingestion layer monitors for volume and quality anomalies and alerts a support team, which indicates the integration is treated as a running system to be maintained rather than a project to be completed.

Graded A. Breadth, identity resolution, source variety and independent validation of the data itself, held together.

Ask which of the fifty integrations are bidirectional and how insights return into the record.

CC on Deployment Model and Data ResidencyA single hosted option with location implied rather than committed.
Vendor Published

Cloud only, on a named public cloud, with the tenancy and residency questions unanswered.

What is established is the shape. The platform is cloud based on a lakehouse architecture and is transacted through a major public cloud marketplace, which confirms the hosting provider and tells a buyer that procurement can run through an existing cloud agreement. For an organisation with committed cloud spend that is a practical benefit worth knowing about.

The unresolved questions are the ones a security review asks. Whether customer data sits in a dedicated tenancy or a shared one with logical separation is not stated, and it matters more here than for most vendors because the entire product is aggregation and the boundary between customers is the boundary the architecture is under pressure to blur. Geographic residency is not stated, no region choice is described, and no position on data leaving a jurisdiction is published.

Continuity is also absent. No recovery objective, no availability commitment and no failover description was located, for a platform that health systems run care management and quality reporting on daily.

Nothing indicates an on premises or customer hosted option, which is a legitimate architectural choice and a constraint for organisations whose policy requires one.

Graded C for a clear and credible hosting story with tenancy, residency and continuity undisclosed.

Ask whether tenancy is dedicated or shared, where data physically resides, and what recovery objective the contract carries.

Commercial
DD on Commercial TransparencyNothing a buyer can establish before a sales conversation. A published pricing claim contradicted by evidence also grades here.
Vendor Published

Cost is absent from every published surface. A dedicated pass located no pricing page, no unit of charge, no range, no tiering, no implementation fee position and no minimum commitment.

One structural signal exists without being a price. The platform is listed on a public cloud marketplace where charging is described as depending on the duration and terms of the contract plus additional usage, which tells a buyer that the shape is a negotiated term deal with a consumption component and nothing about the size of either half.

The unit question is wide open and consequential. A platform sold to health systems, provider groups, accountable care organisations and health plans could plausibly charge per attributed life, per covered member per month, per data source connected, per named application licensed, per seat, or as an enterprise licence. Those produce very different totals for the same organisation, and the modular product line, with Vista, Network Modeler, Contract IQ, Provider Intelligence and the AI Factory sold as distinct capabilities, implies cost grows as scope grows without indicating how steeply.

Implementation is the specific omission that matters most here. Third party buyer guidance for this category flags data integration complexity, patient matching accuracy across multiple source systems, and workflow redesign as the principal risks, all of which are cost. A platform that connects dozens of source systems carries a real onboarding bill and no figure or even a ratio to licence cost is published.

The value side is published without the cost side, which is the asymmetry. Outcome percentages appear prominently and nothing anywhere lets a prospective buyer estimate what pursuing them would cost.

Ask for the unit of charge, how modules price incrementally, the implementation cost as a multiple of first year licence, and the contract term.

BB on Setting and Specialty CoverageCoverage is named with validation behind part of it.
Vendor Published

Broad across the two sides of a risk contract, deliberately narrow within them.

Buyer coverage spans health systems, independent provider groups, accountable care organisations and health plans, and the contract types named cover Medicare shared savings, accountable care organisation risk models, Medicaid, commercial risk and fee for service. Serving payer and provider from one platform is a genuine breadth claim in this lane, because the two ask opposite questions of the same data: a provider group asks where its attributed population is leaking and which gaps are closeable, while a plan asks which providers cost more than they should and how a network should be shaped.

Data breadth supports the coverage claim rather than decorating it. Integration is stated across more than fifty electronic health record systems spanning physical and behavioural health, plus claims, admission and discharge feeds, pharmacy and social determinants sources. Behavioural health inclusion is worth noting specifically, since it is the source category most often omitted from population health aggregation and the one where omission most distorts a risk picture.

The boundary is functional rather than clinical. This is a platform for population level financial and quality performance, not for a specialty workflow, so a cardiology service line or an oncology pathway is addressed only insofar as it appears in claims and quality measures. Coverage of care settings outside ambulatory and inpatient, notably post acute and home, is not described in any detail located.

Graded B for genuine two sided coverage with the depth of specialty and setting handling unstated.

Comparisons

Compared With

Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Not published
Undisclosed Not published Not published Vendor Published

A dedicated pass located no pricing page, no unit of charge, no range, no tiering, no implementation fee position and no minimum commitment. The one structural signal is a public cloud marketplace listing describing charges as dependent on contract duration and terms plus additional usage, which establishes a negotiated term deal with a consumption component and no magnitude for either half.

The modular product line, spanning Vista, Network Modeler, Contract IQ, Provider Intelligence and the AI Factory, implies cost scales with scope adopted without indicating how. Implementation is the material omission: third party buyer guidance for this category flags data integration across multiple source systems, patient matching accuracy and workflow redesign as the principal risks, all of which carry cost, and no figure or ratio to licence cost is published. Outcome percentages are published prominently while nothing lets a buyer estimate the spend required to pursue them.