C8 Health
Clinical knowledge management platform anchored in anesthesiology and perioperative services, built on the premise that the problem is not missing evidence but the gap between documented protocol and actual practice. Hospitals hold their standards as scattered PDFs, unlisted videos and physical binders, and the company frames the resulting delay in adopting new evidence against the widely cited seventeen year evidence to practice lag. C8 unifies that material into one searchable corpus delivered by role, department and schedule, restructures uploaded documents into mobile navigable formats, and tracks adherence through dashboards for quality leadership.
The AI layer is C8 Panda AI, a generative assistant that answers natural language questions sourced exclusively from the institution's own vetted knowledge base, returning inline citations that name both the source document and its author, so a clinician can trace an answer back to the colleague who wrote it. A Knowledge Network lets participating institutions and clinical societies share protocols across organisational boundaries. The platform is explicitly architected to operate without requiring PHI, which is an unusual and materially different privacy posture from most clinical AI.
Founded 2019 at Geneva University Hospital by Dr Ido Zamberg, a physician and software engineer who spent fourteen years on enterprise knowledge management at HP and Autodesk, with Dr Olivier Windisch; incorporated in the United States in 2022 with CEO Galia Rosen Schwarz and co founder Tzach Klo. Anesthesia was the first vertical. Reported in use at more than one hundred US hospitals including Mount Sinai, UCSF Health, Brigham and Women's, MetroHealth, UTMB and Dartmouth Health, and named an official collaborator of the American Society of Anesthesiologists. Raised a 12 million dollar Series A in July 2025.
Capability Axes
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read
The grade describes the mechanism, not the quality, and the company's own history is the cleanest evidence for it. The platform existed and spread across Swiss hospitals from 2019, before generative AI was available, as a structured protocol access tool. Strip the assistant out today and a working product remains: a unified searchable knowledge base, role and department aware delivery, mobile access, adherence dashboards and a cross institution sharing network.
It sits at B rather than C for two reasons. The assistant is now the marketed centre of the product and the grounded retrieval architecture is a real engineering asset rather than a wrapper. And the formatting feature uses AI to restructure arbitrary uploaded documents into consistent navigable formats, which is a second genuine application rather than a restatement of the first.
What the AI does not do is reason about a patient. It retrieves and summarises guidance a human institution authored, which is why this sits below the vendors whose model output is the clinical judgement itself.
The oversight property is structural rather than promised. Because the assistant answers only from the institution's own approved corpus, it cannot surface guidance the institution has not sanctioned, and every answer is traceable to a named document and author. The clinician reads guidance and decides; nothing is actioned, ordered or suppressed. That is a materially safer posture than an open ended clinical question answering product.
Held at B on three absences. Nothing is published about behaviour when the corpus lacks an answer or contains conflicting protocols from different departments or sites, which is the realistic failure case in a multi site deployment. There is no dedicated clinical use and safety statement of the kind HealthLeap publishes in one findable place. And the microlearning framing, which encourages clinicians to keep refining questions until they have what they need, actively cultivates reliance on the assistant, which raises rather than lowers the bar for publishing what it does when it is wrong.
The architecture is described clearly and the constraint on it is the important part. The assistant sources information exclusively from the institution's own vetted knowledge base, which bounds the answer space to content the hospital approved.
One property is genuinely distinctive and worth treating as a benchmark. Answers carry inline linked citations naming both the source document and its author. In a local corpus the author is a named colleague at the same institution, so the clinician can escalate to a person rather than to a document. That is a stronger accountability path than a citation to a journal, which is the usual best case in this index.
The gaps are real and all of them concern the model rather than the plumbing: no model class, no foundation model named, no evaluation of any kind, no hallucination or accuracy rate, and nothing published about what the assistant does when the corpus does not contain the answer.
That last question is the one this index most wants answered of any generative clinical product. A system that retrieves confidently from a bounded corpus can still be confidently wrong when the corpus is silent, and nothing here describes the abstention behaviour.
This is a new and reusable answer that this index had not seen stated so plainly before. The company says the platform is compliant with the recognised standards without requiring protected health information for deployment, and markets that a hospital can implement it without creating additional compliance risk. Nearly every vendor in this index answers the stewardship question by describing how well it protects patient data.
This one answers that it does not need patient data at all, because the corpus is institutional knowledge rather than patient records. Minimisation as an architectural choice is a stronger answer than any protection claim, because a control can fail and an absence cannot, and it is worth asking of every product in this category and several others: does this need protected health information, and if not, does the vendor say so plainly?
Most that could say it do not, because saying nothing costs nothing. Held below the top grade on two points, both stated rather than implied. The quality improvement module tracks provider level compliance metrics that derive from patient care and identify individual clinicians, so the claim covers the knowledge platform more cleanly than the analytics layer and that boundary is not drawn anywhere public.
And a privacy policy and terms of use are published and linked but were not opened in this pass, which is a scope limit to close on refresh rather than a finding. Ask where the analytics layer sits relative to the minimisation claim.
One genuine peer reviewed publication, and it is credited precisely for what it is. Windisch O, Zamberg I, Zanella M, Gayet-Ageron A, Blondon K, Schiffer E, Agoritsas T. Using mHealth to Increase the Reach of Local Guidance to Health Professionals as Part of an Institutional Response Plan to the COVID-19 Outbreak. JMIR Mhealth Uhealth 2020;8(8):e20025. Geneva University Hospitals, more than 1,000 health professionals aligned on evolving guidance.
Author quality is a legitimate signal and it is high here, with a leading evidence based medicine methodologist and a biostatistician among the authors.
But it is a usage analysis study. It measures reach and adoption, not clinical outcomes, and it examines the pre commercial Geneva deployment.
Everything else is vendor reported: enhanced recovery protocol compliance at one system rising 35 percent in five months and quoted elsewhere as roughly 65 to over 88 percent, perioperative glucose management at another from about 72 to more than 81 percent in three months, 94 percent of clinicians consulting the platform for those protocols, over 90 percent adoption within six months, and a doubling of quality of care alongside a 3.4 times increase in staff satisfaction with no definition of either measure.
The compliance deltas are the right kind of metric, because adherence is this product's actual failure mode, but none carries a denominator, a comparison period or a control. A published compliance study with a denominator would move this axis immediately.
A new and reusable answer this index has not seen before. The company states the platform is SOC 2, GDPR and HIPAA compliant without requiring protected health information for deployment, and markets that a hospital can implement it without creating additional compliance risk.
Nearly every vendor in this index answers the stewardship question with how well it protects patient data. This one answers that it does not need patient data at all, because the corpus is institutional knowledge rather than patient records. Minimisation as an architectural choice is a stronger answer than any protection claim, and it is worth asking of every product in this category: does this need protected health information, and if not, does the vendor say so plainly?
Held at B rather than A on two points, both stated rather than implied. The quality improvement module tracks provider level compliance metrics that derive from patient care and identify individual clinicians, so the claim covers the knowledge platform more cleanly than the analytics layer, and that boundary is not drawn anywhere public. And a privacy policy and terms of use are published and linked but were not opened in this pass, which is a scope limit to close on refresh rather than a finding.
HIPAA compliance is stated inside a multi framework posture rather than as a lone assertion: SOC 2 Type II, HIPAA, GDPR and CCPA together, backed by a public trust centre. That is meaningfully more than the bare HIPAA claim graded C on the AgileMD record, and more than the silence common across this index. The architectural claim strengthens it further, since a platform that does not require PHI changes what a business associate agreement has to cover.
Still missing for A: no BAA terms, no tier, no execution path, no statement of which entity signs, and no subprocessor list, which matters for a cloud product serving hospitals on two continents.
Among the better security postures in this peer group, and it answers the question this index always asks. The company states compliance with SOC 2 Type II, with the type explicitly specified, alongside HIPAA, GDPR and CCPA. Specifying Type II rather than leaving SOC 2 ambiguous is the distinction that separates an audit of controls operating over a period from a point in time assessment, and several direct competitors omit it.
A public trust centre exists at trust.c8health.com, operated on Vanta, which is an artefact most vendors in this segment lack.
Two honest limits are recorded rather than glossed. The trust centre contents could not be enumerated in this pass because the page renders client side, so the specific certifications, reports and controls listed there are unverified here and should be opened on refresh. And no ISO 27001, no HITRUST and no penetration testing statement was located in the material that was readable.
GDPR and CCPA coverage is more than boilerplate given the Swiss origin and stated operations across the United States and Europe.
No FDA clearance, none claimed, and none apparently required. The grade records the absence; the note records that the position is defensible and unusually clean.
The clinical decision support exclusion argument here is the strongest available to any vendor in this index. The exclusion turns on whether a clinician can independently review the basis for a recommendation. Here the basis is the institution's own published protocol, surfaced with an inline citation to the source document and its named author. A clinician can not only review the basis, they can open it and contact the person who wrote it. That is the inverse of an embedded predictive score whose basis is disclosed to nobody.
Recorded as an observation rather than a legal conclusion. The company itself never makes the argument explicitly, so ask for its stated regulatory rationale directly, and ask whether the position changes for the analytics module, which derives from patient care rather than from published protocol.
Nothing published on retrieval performance, failure modes across content types, or whether the assistant surfaces some departments' protocols more reliably than others. No evaluation of any kind.
The more interesting exposure sits in the knowledge network, the cross institution sharing layer that lets hospitals and clinical societies copy each other's protocols. If the protocols of well resourced academic centres become the template smaller hospitals adopt, the network quietly standardises care on the practice patterns and resource assumptions of the best funded institutions, whose patient populations, staffing ratios and available equipment differ from the adopting site's. A protocol that assumes resources a hospital does not have is not a best practice there. Nothing published addresses who curates the shared library or how local applicability is assessed.
A related governance question follows from the anaesthesiology society collaboration. When society guidance and a local protocol conflict inside the same corpus, a buyer should establish which surfaces, who decides, and who owns the update cycle.
One property here is the strongest recourse route located in the reference category and it should be treated as a benchmark. Answers carry inline linked citations naming both the source document and its author, and because the corpus is the institution's own vetted knowledge base, that author is a named colleague at the same hospital. So a clinician who doubts an answer can escalate to a person rather than to a document, ask them what they meant, and get a correction made at source.
Every other citation mechanism in this index points at a journal article or a guideline, which is contestable in principle and unanswerable in practice. This one points at someone down the corridor. The corpus bound reinforces it, since the assistant sources exclusively from content the hospital approved, so the answer space is limited to material the institution has already accepted responsibility for.
Held below the top grade because nothing measures the system and one behaviour is undescribed. No model class, foundation model, evaluation, hallucination rate or accuracy figure was located, and nothing states what the assistant does when the corpus does not contain the answer.
That last is the question this index most wants answered of any generative clinical product: a system retrieving confidently from a bounded corpus can still be confidently wrong when the corpus is silent, and the abstention behaviour is where that failure is either caught or created. Ask for it.
The shallowest electronic health record integration of any record in this peer group, and the reason is design rather than neglect, which the note states so the grade is not misread as a defect. Because the platform deliberately operates without protected health information, it has no need for clinical data exchange, so there is no HL7 feed, no FHIR application and no SMART on FHIR launch described.
What exists is access plumbing and adjacent system integration. Epic is named, reached through address based magic links inside the record that give login free access, plus stated integrations with scheduling systems, policy systems, analytics and learning management platforms. Naming a record vendor at all puts it ahead of several vendors in this index that name none.
It is graded C because the axis measures interoperability depth, and this is a launch and single sign on mechanism rather than data exchange. The buyer consequence is worth stating plainly and it cuts both ways: nothing to build and nothing to break, but no patient context in the answer either, so the assistant cannot tailor guidance to the patient in front of the clinician.
Publishes the shape of an implementation, which most vendors omit entirely: department wide implementation typically within three months including content migration and user training, a named implementation specialist leading every deployment, an account manager who handles content upload and organisation, kickoff sessions for administrators, and a dedicated site manager providing ongoing analytics and expansion support, with no information technology resources required for ongoing maintenance. Reported adoption is over 90 percent of clinicians within six months.
Named customers are substantial and specific: Mount Sinai, UCSF Health, Brigham and Women's, MetroHealth, the University of Texas Medical Branch and Dartmouth Health, with the claim that seven of the top ten anaesthesiology residency programmes use the platform.
Two things hold it at B. The install base count is inconsistent within the vendor's own material, with the about page meta description saying more than 100 hospitals while the body of the same page says 150 or more institutions. And no data residency statement exists at all, despite stated operations across the United States and Europe and a Swiss origin, which is a real gap for a vendor claiming GDPR compliance.
No pricing published at any level. No rate card, no unit of pricing, no band, no implementation fee, and all routes lead to a demo request or a sales line.
This is the most carefully constructed version of the upside published, price gated pattern that recurs across this index. The company headlines more than 550,000 dollars in average annual savings per tracked quality metric.
It deserves partial credit for stating the basis, which most vendors do not. It names the mechanism as reduced surgical site infections and improved length of stay, the sample as two major academic medical centres with more than 20,000 combined cases, and the period as fiscal 2025 to 2026. It then marks the derivation as data on file, so the figure remains unverifiable from outside.
Stating your basis and withholding your data is a rung above asserting a number with nothing attached, and a rung below publishing it. Buyers should ask for the derivation and for the pricing unit, since a saving per quality metric says nothing about what the platform costs to run.
Scope is named rather than claimed universally, which this index credits. The product is anchored in anaesthesiology and perioperative services, which was the first vertical and remains the centre of gravity. The marketed solutions address anaesthesiology, perioperative services and enterprise deployment, the flagship use case is enhanced recovery protocol compliance, and the example assistant queries concern perioperative medication management, such as when to stop SGLT2 inhibitors or GLP-1 receptor agonists before surgery. The company is an official collaborator of the American Society of Anesthesiologists.
Secondary reach into resident onboarding and training is real enough to justify the workforce and training cross listing, with seven of the top ten anaesthesiology residency programmes claimed as users. Geography spans the United States and Europe, the latter following from the Geneva origin and continued Swiss deployment.
Held at B because enterprise and system wide deployment is presented as the direction of travel rather than as evidenced breadth, and because every named outcome sits in the perioperative domain, so performance in departments outside that anchor is unestablished.
Compared With
Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
Not published
|
Not published | Not published | Not published | Vendor Published |
No pricing published at any level. No rate card, no stated unit of pricing such as per clinician, per department, per site or per hospital, no indicative band, and no published implementation or content migration fee. All routes lead to a demo request form or a sales telephone line.
The asymmetry is the finding and this is the sixth instance recorded in this run of records: the company headlines more than 550,000 dollars in average annual savings per tracked quality metric, states the mechanism as reduced surgical site infections and improved length of stay, names the sample as two major academic medical centres with more than 20,000 combined cases in fiscal 2025 to 2026, and then marks the derivation data on file.
Stating the basis while withholding the data is better than an unsupported number and worse than publishing it. Four questions a buyer should raise directly. Whether pricing scales by clinician seat, by department or by site, since the product is sold both as a single department deployment and as an enterprise rollout.
Whether content migration is included, given that the vendor states an account manager handles content upload and organisation, which is professional services delivered inside the subscription unless stated otherwise. Whether the quality improvement analytics module and the Knowledge Network are separate lines from the core platform and Panda AI. And what happens to the institution's structured corpus at contract termination, since the migration effort that made deployment easy is also what makes leaving expensive.