Health System AI Platforms
B

Bunkerhill Health

Agentic AI platform for health systems. Carebricks lets clinical and operational teams build, deploy, and govern their own AI agents across clinical, operational, and administrative workflows rather than buying a point solution per use case. Agents in production include coronary calcium detection on routine chest CT, nephrology triage, lung nodule follow up, referral prioritization, prior authorization packet assembly, and registry automation.

The company develops its own FDA cleared imaging algorithms that run inside the platform, including algorithms for coronary artery calcium and aortic valve calcium on contrast enhanced non gated chest CT, mitral annular calcification, and bone mineral density. CMS established a national billing code and OPPS payment for algorithmic CAC and AVC analysis on chest CT effective April 1, 2026. In production at Cleveland Clinic, the University of Texas Medical Branch, Intermountain Health, and Mayo Clinic. Founded by Nishith Khandwala, previously a researcher at Stanford's Center for Artificial Intelligence in Medicine and Imaging.

AI Health Index verifiedJuly 27, 2026
Compare Bunkerhill Health with other vendors
Founded
Headquarters
San Francisco, California
Categories
health-system-ai-platforms, clinical-decision-support, rcm-and-prior-auth
Indexed Products
Carebricks, Bunkerhill Contrast CAC, Bunkerhill Contrast AVC, Bunkerhill MAC, Bunkerhill BMD
Buyer Segments
Large IDN, Academic Medical Center, Community Health System
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
AA on AI CentralityThe artificial intelligence is the product. Remove the model and there is nothing left to sell.
Vendor Published

The product is AI infrastructure: a platform whose entire function is building, deploying, and governing AI agents, plus the company's own FDA cleared imaging algorithms that run inside it. Remove the AI and nothing remains.

BB on Autonomy and Oversight ModelThe oversight structure is described and one part is missing, commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

Agents take real actions rather than only surfacing recommendations, and the vendor describes drafting orders for clinician sign off, which is an explicit human in the loop pattern on the clinical side. The company states the platform provides governance, monitoring, and safety capabilities.

Held back from A because no published governance framework, escalation policy, or audit documentation was retrieved, and an agent authoring platform pushes oversight design onto the customer, which raises rather than lowers the disclosure bar.

BB on Model and Technology TransparencyThe approach or the suppliers are named without the version and update discipline behind them.
Regulatory Filing

Unusual in this index for holding two very different levels of evidence inside one product, and the note grades the whole while naming the split.

The company's own imaging algorithms carry FDA clearances, which means public regulatory summaries exist describing intended use, study design and performance for coronary artery calcium, aortic valve calcium, mitral annular calcification and bone mineral density on chest CT. That is genuine external documentation of model performance and it is why this sits at B rather than C.

The agent layer has nothing equivalent. The platform is described as using vision models and large language models, and Carebricks Chat answers open questions grounded in the full longitudinal record, with no published foundation model, evaluation method, accuracy figure or hallucination rate for any of it.

A buyer sees one platform and two evidence regimes. Establish which components in a proposed deployment are cleared devices with performance data behind them and which are agents assembled on the platform, because the assurance available differs completely between them.

DD on Model Supply Chain DisclosureNothing establishes who else sits between a patient record and an answer.
Vendor Published

Nothing identifies the model layer: no foundation model provider is named for the agent or chat components, no hosting arrangement is published, and no sub processor list was located, though a trust centre exists and is the obvious place a buyer should look before relying on this grade. The surface is among the widest in this index.

The platform reads imaging archives and clinical report archives alongside the live record, and the chat product is grounded in the full longitudinal record including notes, laboratory results and images, so a system that reasons across everything holds everything, at least in transit. Two questions matter more than the general enumeration gap.

What is retained after an agent completes its task, given that agents are described as running continuously across a population rather than per encounter, so there is no natural point at which a working set would be discarded. And whether prompts, retrieved record content or agent outputs reach any external model provider, since the platform is stated to use large language models and nothing published says whether those run inside the customer's boundary or outside it. That second question determines whether this is a contained deployment or a chain, and it is unanswered. Ask both, and ask for the sub processor list the trust centre should already carry.

BB on Clinical and Operational EvidenceNamed deployments with dated outcome figures and enough method to test them, or published research short of independent validation.
Third Party Estimated

Named institutional deployments at scale, with more than 20 agents reported running simultaneously at UTMB, and specific operational figures including a reported reduction in average specialist wait times of more than 50 percent for a nephrology triage agent.

Held back from A because the clinical outcome evidence is presented as individual case narratives, including a coronary calcium detection that preceded a triple bypass, rather than as cohort level published results, and the figures are vendor and customer reported without stated methodology.

CC on AI Safety and PHI StewardshipGeneral assurances of privacy and security that do not answer the questions artificial intelligence raises: what is retained, what reaches a model, and what happens to it there.
Vendor Published

No retention period, no statement on whether customer data is used to train or improve models, and no de identification posture was located. A trust centre is published and is the obvious place for a buyer to look for these, but its contents were not verified in this assessment.

The surface is among the widest in the index. The platform reads imaging archives and clinical report archives alongside the live record, and the chat product is grounded in the full longitudinal record including notes, labs and images. A system that reasons across everything holds everything, at least in transit.

Two questions matter most. What is retained after an agent completes its task, given that agents run continuously across a population rather than per encounter. And whether prompts, retrieved record content or agent outputs reach any external model provider, since the platform is stated to use large language models and nothing published says whether those run inside the customer's boundary or outside it.

Regulatory and Compliance
BB on HIPAA and BAA PostureBusiness associate status is stated and supported by a substantive privacy document, with the agreement or its scope not fully published. For a vendor outside the United States, an equivalent regime documented to this depth grades here.
Vendor Published

The company states full compliance with the privacy and security rules and publishes a trust centre, but no business associate agreement terms were located. That is the standard middle rung: a compliance claim supported by an independent audit of the security programme, without the contractual instrument being visible.

Business associate status is structurally certain given system wide deployment at named academic and regional health systems with read and write access to the record.

One question follows from the platform model rather than the company. Where a health system builds its own agents on the platform, some of those agents will move protected health information into workflows the vendor did not design, including outbound patient communication. Establish how the agreement allocates responsibility for data handling in a customer authored agent, since the vendor supplies the capability and the customer defines the use.

BB on Security Certifications and Trust CenterA recognised certification is named in the vendor own material without the artefact, or with a scope or renewal question the buyer has to raise. A certification has a scope and a clock, and both are part of this grade.
Vendor Published

The company states it is independently audited to SOC 2 Type II, names the type rather than leaving it ambiguous, and publishes a trust centre for buyers to work through. Both of those are things a majority of vendors in this index do not do.

Held at B rather than A because this is a single framework. No HITRUST certification and no ISO 27001 is claimed, and the vendors graded A on this axis carry a second independent framework alongside SOC 2. The trust centre was not opened during this assessment, so its contents and the report's scope and period are unverified here.

One wording point, minor but worth noting because this index tracks it consistently: SOC 2 produces an attestation report issued by a CPA firm rather than a certification, so certified to SOC 2 Type II standards is imprecise. The substance is right and the type is stated, which is what matters.

AA on FDA and Regulatory StatusThe regulatory position is unambiguous and verifiable: a clearance or authorisation identifiable in the public databases, with the version and indication it actually covers.
Regulatory Filing

The strongest regulatory position among provider side vendors in the index. Multiple FDA clearances on the company's own algorithms, including Bunkerhill Contrast CAC and Contrast AVC, which the company states are the first AI algorithms cleared to detect and quantify coronary artery calcium and aortic valve calcium on contrast enhanced non gated chest CT, alongside earlier non contrast clearances, mitral annular calcification, and bone mineral density.

CMS established a national billing code and OPPS payment for algorithmic CAC and AVC analysis effective April 1, 2026. A reimbursement pathway is materially rarer than a clearance and is disclosed precisely.

CC on AI Governance and Bias DisclosureResponsible artificial intelligence is committed to in policy language with no evaluation behind it. Most of the index sits here.
Vendor Published

The company states the platform provides governance, monitoring and safety capabilities and refers to governance standards built into every deployment, but no framework, bias evaluation or subgroup performance disclosure was located.

The governance question here has the customer authorship shape. Carebricks is sold on letting clinical and operational teams design and deploy their own agents, with one health system reported running more than fifteen custom agents and moving from idea to live deployment in days. Speed of deployment is the selling point, and it is also the thing that determines how much review an agent receives before it acts.

The questions that follow are what validation a customer authored agent must pass before going live, who signs it off, whether performance is monitored after deployment, and what happens when an agent built by one team behaves badly in another's workflow. Nothing published answers them.

Separately, the incidental findings agents raise an equity question the company itself gestures at when it talks about closing gaps: a follow up agent acting on findings in existing imaging will reach patients who already had the scan, and whether that widens or narrows access depends on who was imaged in the first place.

CC on AI Liability and RecourseMechanisms exist that let someone challenge an output, such as audit trails, source traceability or review before commit, with nothing standing behind the output and no route for the harmed party.
Regulatory Filing

One platform contains two entirely different evidence regimes and a buyer sees one product, which is the finding on this record and a shape worth watching for wherever a cleared device sits inside a broader software offering. The company's own imaging algorithms carry clearances, so public regulatory summaries exist describing intended use, study design and performance for the specific measurements they produce, and those components also carry the reporting, complaint handling and correction obligations that follow from being a device.

That is real external documentation and a real recourse floor. The agent layer has nothing equivalent. The platform is described as using vision models and language models, with a chat capability answering open questions grounded in the full longitudinal record, and no published foundation model, evaluation method, accuracy figure or hallucination rate exists for any of it.

So within a single procurement one component is externally validated and regulated while another answers open clinical questions with no published characterisation at all, and nothing in the product framing distinguishes them for the person using it.

Establish which components in your proposed deployment are cleared devices with performance data behind them and which are agents assembled on the platform, because the assurance available differs completely, and ask what a clinician sees at the point of use to tell the two apart.

Integration and Deployment
BB on EHR and Interoperability DepthNamed systems with read access or one directional writing, or standards support with named deployments behind it.
Vendor Published

Integration is central to the product rather than a feature of it. The platform reads clinical report archives and imaging archives, integrates with the electronic health record to filter cases against prior history and guidelines, and writes back by generating documentation, notifying care teams and initiating patient outreach. Carebricks Chat reasons across the full longitudinal record including electronic health record data, imaging, labs and encounter notes.

That depth is corroborated by system wide deployment at named institutions including Cleveland Clinic, Intermountain Health, the University of Texas Medical Branch and Mayo Clinic, and the company states the chat product is available to any United States health system through a standard integration.

Held at B rather than A because no specific electronic health record platforms are named in the company's own materials and no integration method is described. Reading imaging archives alongside the chart is a wider surface than most vendors here touch, which makes the missing detail on how it connects more consequential rather than less.

CC on Deployment Model and Data ResidencyA single hosted option with location implied rather than committed.
Vendor Published

No hosting provider, region, tenancy model or data residency commitment was located, and no subprocessor list is published.

The question that matters most here is not where the platform runs but where the language model inference happens. The product is stated to use vision models and large language models and to reason across the full patient record. If that inference runs at an external model provider, record content leaves the health system's boundary on every query, and the subprocessor and retention terms of that provider become part of the buyer's exposure. If it runs inside a customer controlled environment, it does not. Those are entirely different postures and public material does not distinguish them.

Ask directly, and ask for the answer in writing: where does inference execute, which model providers are involved, and what are their retention terms for prompt and completion data.

Commercial
CC on Commercial TransparencyNo price is published and the posture is discoverable: a buyer can establish how the product is sold and what drives the cost before contacting the vendor. Most of the index sits here.
Vendor Published

No public pricing. Contact the vendor. Sold through enterprise agreements with health systems; no rate card published. Note that the CMS billing code for CAC and AVC analysis creates a reimbursement path for certain algorithm use, which is a distinct economic question from platform licensing cost.

BB on Setting and Specialty CoverageCoverage is named with validation behind part of it.
Vendor Published

Coverage is broad by design, spanning cardiology, nephrology, pulmonary nodule follow up, oncology prior authorization, and registry operations across clinical, operational, and administrative functions. Clearly described, though breadth is a property of the platform model rather than a validated scope, and the axis rewards validated clarity over range.

Tracked Since Listing

What Changed

Material product, regulatory, evidence and commercial changes at Bunkerhill Health, each verified against a live source and tagged to the capability axis it bears on. Funding rounds and awards are not product changes and are not logged.

Apr 15, 2026Regulatory / FDA

CMS established a national billing code and associated payment under the Hospital Outpatient Prospective Payment System for algorithmic analysis of coronary artery calcium and aortic valve calcium on chest CT, effective April 1, 2026. The company separately received FDA clearance for Bunkerhill Contrast CAC and Bunkerhill Contrast AVC, which it states are the first AI algorithms cleared to detect and quantify coronary artery calcium and aortic valve calcium on contrast enhanced, routine non gated chest CT, extending prior clearances that covered non contrast chest CT.

Bears on: FDA and Regulatory StatusSource
Our read on this change →Tracked since Apr 2026
Comparisons

Compared With

Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.

Head to head

Vendors the index assesses as direct competitors to Bunkerhill Health for the same buyer.

Adjacent comparisons

Products a buyer researches alongside Bunkerhill Health that do a different job: a different category, a different layer of the stack, or a specialist scope. These pages exist to settle whether the comparison is real before it settles which one to pick.

Public Record

Announced Deployments

Publicly announced health system deployments and partnerships. This is a record of announcements, not an assessment of deployment success or scale.

Intermountain Health
Carebricks platform in production
Mayo Clinic
Carebricks platform in use
University of Texas Medical Branch (UTMB)
More than 20 AI agents built on Carebricks running across clinical, operational, and administrative functions
Cleveland Clinic
Carebricks platform in production
Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Contact the vendor
Enterprise platform agreements with health systems Vendor Published

Enterprise platform agreements with health systems; no rate card published. Separately, CMS established a national billing code and OPPS payment for algorithmic coronary artery calcium and aortic valve calcium analysis on chest CT effective April 1, 2026, which creates a reimbursement pathway for certain algorithm use. That is distinct from the cost of licensing the platform and buyers should model the two separately.