RCM & Prior Auth AI
C

Candid Health

Revenue cycle automation platform for medical groups and digital health companies, built around a single headline metric the company puts at the centre of its own product page: touchless claim rate, the percentage of claims submitted, processed and adjudicated correctly the first time with no manual intervention. The strategic framing is explicit and worth noting, because it distinguishes the company from most of the RCM category. Traditional RCM vendors aim to make manual cleanup work more efficient; Candid aims to prevent the cleanup by getting claims right on submission.

The mechanism is a rules engine carrying reverse-engineered payer requirements that are continuously refined, combined with claim autocorrection that validates data pre-submission, with machine learning used to automate the feedback loop between claim insights and systemic rule changes. Customers can author and manage their own custom rules directly, with vendor training offered. The platform is API-first with flexible modern APIs for direct integration alongside out-of-the-box connections, and compiles provider rosters, credentialing data and custom key/value pairs to widen the share of the claims process that can be automated. Founded out of Y Combinator.

Reported touchless claim rates and payor net collection rates above 95 percent, revenue growth of nearly 250 percent year over year in 2024, and a $52.5 million Series C led by Oak HC/FT in February 2025 bringing total funding to $99.5 million. Named customers include Talkiatry and Nourish. Holds a SOC 2 report covering security, availability and confidentiality.

AI Health Index verifiedJuly 26, 2026
Compare Candid Health with other vendors
Founded
Headquarters
San Francisco, California, United States
Categories
rcm-and-prior-auth, healthcare-admin-automation
Assessment

Capability Axes

The short answer

Candid Health is a revenue cycle automation platform for medical groups and digital health companies, built around one headline metric it puts at the centre of its own product page: touchless claim rate, the share of claims submitted, processed and adjudicated correctly the first time with no manual intervention. Its strategic position separates it from most of the category. Traditional revenue cycle vendors make manual cleanup more efficient; Candid aims to prevent the cleanup by getting the claim right on submission, using a rules engine carrying reverse engineered payer requirements with claim autocorrection that validates data before it goes out. The AI Health Index grades it A on Autonomy and Oversight Model and A on EHR and Interoperability Depth, its two strongest axes, while C on Clinical and Operational Evidence and C on Commercial Transparency sit lower. Verified as of Jul 26, 2026.

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
BB on AI CentralityThe model is the engine of a core module. The platform carries other value, but this capability does not exist without it.
Vendor Published

Deliberate B, and the reasoning matters for consistency with the rest of the RCM lane. The core engine is a rules engine carrying reverse-engineered payer requirements, which is sophisticated data engineering rather than machine learning, and the company describes AI as automating the feedback loop between claim insights and rule changes rather than as making the claim decisions.

Graded B not C because that ML feedback loop is a substantive and specific role, and because there is genuinely no offshore billing bureau underneath, unlike most of the category. Not A because the moat is the payer rules corpus and the data model, not the model. Compare CodaMetrix, graded A because the coding decision itself is the model output.

AA on Autonomy and Oversight ModelWhat the system may do and what it may not do are both published, with escalation thresholds, override paths and the conditions that route a case to a person.
Vendor Published

The autonomy claim is quantified with a defined, checkable metric, which is rare in this category. Touchless claim rate is explicitly defined on the product page as the percentage of claims submitted and finalised without human intervention, and the company reports rates above 95 percent. Publishing the definition alongside the number is what earns the A: a buyer can audit against it.

Customers also retain direct control over the automation, authoring and managing their own custom rules and enforcing their own workflows, so the autonomy is configurable rather than opaque. Contrast CodaMetrix, graded B precisely because its human routing threshold is not published.

BB on Model and Technology TransparencyThe approach or the suppliers are named without the version and update discipline behind them.
Vendor Published

The architecture is described concretely: a rules engine holding reverse-engineered payer requirements kept current, pre-submission claim validation and autocorrection, and ML applied to the insight-to-rule feedback loop. The company is also refreshingly non-inflationary about it, describing the approach as modern data engineering and automation rather than dressing the rules engine as artificial intelligence. Graded B rather than A because no model detail, training data description or accuracy methodology is published, and the 95 percent figures carry no stated denominator, sample or audit basis.

CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

The audited attestation explicitly covers confidentiality alongside security and availability, which is a meaningful attested control over how patient information is handled rather than a claim, and the scoping distinction matters more than the certificate: most vendors in this index cite an attestation without saying which criteria it covered, and a report scoped to security alone establishes that the systems are defended while saying nothing about who inside the organisation may see what, or what the company may do with it.

Naming confidentiality as in scope answers a different and more relevant question. End to end encryption is also reported. Held at C because the question this business model turns on is unanswered. No published statement was located on data retention or on whether customer claims data is used to improve the shared rules corpus, and that is the pertinent question for a platform whose value compounds across customers: the corpus of reverse engineered payer requirements gets better precisely because many customers submit through it, so a customer is plausibly contributing to an asset their competitors use.

That may be entirely acceptable and it should be a stated term rather than an inference. No model, hosting arrangement or sub processor list was located either. Ask whether submission data informs the shared rules corpus, whether that can be declined, and for a retention schedule.

CC on Clinical and Operational EvidenceNamed customers, or vendor reported percentages with no method, denominator or reference standard. Scale of use is recorded here and is not treated as evidence of benefit.
Vendor Published

All performance evidence is vendor generated. Touchless claim rate and payor net collection rates above 95 percent, increased net collections and faster reimbursement are reported by the company without an independent audit, a named customer result, a stated measurement period or a baseline comparison. Revenue growth of nearly 250 percent year over year is a business metric, not evidence of customer outcome.

Named customers exist, including Talkiatry and Nourish, and a MedTech Award for Best RCM Software in 2025 is third party recognition, but neither is a measured result. Same standard applied to QuantHealth and Infervision: specific numbers with no disclosed methodology are still vendor claims. Not a clinical product, so this axis is read as operational evidence.

BB on AI Safety and PHI StewardshipCategorical commitments are published, such as no training on customer data, without the retention schedule or the safety engineering behind them.
Third Party Estimated

The SOC 2 report explicitly covers confidentiality alongside security and availability, which is a meaningful attested control over PHI handling rather than a claim. End-to-end encryption is reported. Graded B rather than A because no published statement was located on data retention or whether customer claims data is used to improve the shared rules corpus, which is the pertinent question for a platform whose value compounds across customers.

Regulatory and Compliance
BB on HIPAA and BAA PostureBusiness associate status is stated and supported by a substantive privacy document, with the agreement or its scope not fully published. For a vendor outside the United States, an equivalent regime documented to this depth grades here.
Third Party Estimated

HIPAA-compliant security reported by third party review, and the platform processes claims containing PHI as core function. Graded B rather than A because no BAA terms or execution process were published in located materials.

BB on Security Certifications and Trust CenterA recognised certification is named in the vendor own material without the artefact, or with a scope or renewal question the buyer has to raise. A certification has a scope and a clock, and both are part of this grade.
Third Party Estimated

Holds a SOC 2 report against the AICPA trust services criteria for security, availability and confidentiality, covering the Revenue Cycle Automation Platform specifically. A real named attestation, scoped to the product rather than to the company generally, puts this ahead of most vendors assessed in the same category, several of which hold none at all.

Graded B rather than A because the located announcement does not specify Type I versus Type II, and that distinction carries most of the weight in a SOC 2 report: a Type I covers the design of controls at a single moment, a Type II their operating effectiveness over a period. A buyer should require the report itself and check its scope section against the systems being purchased. The top band on this axis is reserved for vendors publishing a complete certification set with scope and audit dates available for inspection.

BB on FDA and Regulatory StatusThe pathway is stated and in progress, or a clearance is named without the vintage and scope a buyer needs to match it to the product on offer.
Vendor Published

Converted from Not Rated. The prior scoping was correct and this vendor answers the substitute regime better than most in its category.

No device pathway applies. Claims processing and billing automation sit entirely outside software as a medical device. What governs is payer compliance and claims accuracy, and the structural point this index has established for the provider side holds: no vendor level regulator exists, and liability for an incorrect claim sits with the submitting organisation under the False Claims Act.

Where no regulator exists, this index grades on what the vendor publishes in its place. Three things stand out.

The headline metric is defined rather than asserted. Touchless claim rate is published alongside its definition, which is the difference between a number a buyer can compare and a number a buyer must trust. This index treats publishing the definition of a metric as a distinct credit, because most vendors publish the figure and leave the denominator unstated.

The rules are inspectable and editable by the customer. Buyers can author and manage their own payer rules directly, with training offered. That places the compliance logic where the liability already sits, with the organisation submitting the claim, rather than inside a vendor black box.

And the architecture is preventive rather than corrective, validating before submission rather than reworking denials afterwards.

Held at B because touchless by definition means no human verifies the individual claim. Oversight sits at the rule layer, which is a coherent design and a different one. Ask what proportion is reviewed and what governs rule changes.

CC on AI Governance and Bias DisclosureResponsible artificial intelligence is committed to in policy language with no evaluation behind it. Most of the index sits here.
Vendor Published

No governance framework or bias disclosure located. The risk here is not demographic bias in the clinical sense but the same coding drift exposure flagged on CodaMetrix, in a different form: a rules engine optimised for touchless submission and net collections is optimising for claims that get paid, which is not identical to claims that are correct.

The liability asymmetry also applies, since incorrect claims to Medicare create False Claims Act exposure for the billing organisation rather than the software vendor. No published statement addresses how the rules engine is audited against coding accuracy as opposed to payment success.

BB on AI Liability and RecourseA published falsifiable commitment, or a real correction route for the affected person. A published error rate with its method and denominator grades here, and so does a jurisdiction whose law gives the patient an enforceable right to correct an inaccurate record.
Vendor Published

One quality on this record is rare enough in this market to carry the grade, and it is a form of accuracy about the company's own product. The approach is described as modern data engineering and automation rather than dressed up as artificial intelligence, when a rules engine holding reverse engineered payer requirements is exactly the kind of system most vendors in this index would market as intelligent.

A company that declines to overstate what it has built is telling a buyer something reliable about how it will describe everything else, and it also sets the right expectation about failure modes, since a rules engine fails by having a stale or missing rule rather than by fabricating, and those need different diligence.

The architecture is described concretely around that engine, covering requirements kept current, pre submission claim validation and autocorrection, and machine learning applied to the loop that turns observed insight into a new rule, which identifies precisely where the learned component sits. Held below the top grade because nothing is measured.

No model detail, training data description or accuracy methodology is published, the headline percentage figures carry no stated denominator, sample or audit basis, and no warranty, indemnity or remediation commitment attaches. The rule currency claim is the one to test, since a rules engine's whole value is being up to date and a stale rule produces a confidently wrong submission. Ask how quickly a payer change reaches the corpus, and how the figures were measured.

Integration and Deployment
AA on EHR and Interoperability DepthNamed bidirectional integrations with major record systems, verifiable in marketplace listings or integration documentation, with evidence the connection runs in production.
Vendor Published

API-first by design and explicit about it. The platform offers flexible modern APIs for direct integration alongside out-of-the-box connections, and is built to integrate with existing custom and commercial infrastructure, which is why it fits digital health companies with home-grown stacks as well as conventional medical groups. It also compiles provider rosters, credentialing data and custom key/value pairs into the claims process.

Same architectural posture that earned CertifyOS an A in credentialing: sold as infrastructure to build on rather than an application to log into. Note the practical caveat from third party review that data mapping setup requires dedicated time.

CC on Deployment Model and Data ResidencyA single hosted option with location implied rather than committed.
Vendor Published

Converted from Not Rated. No hosting, region, tenancy or residency terms were located.

The platform is cloud delivered by implication rather than by statement. No cloud provider, no region, no indication of whether processing remains in country, no tenancy model, no subprocessor list, no backup or recovery posture and no retention schedule was retrieved.

What is documented is the connection layer rather than the hosting one, and it is documented well. The platform is interface first, offering flexible programmatic integration alongside prebuilt connections, and it compiles provider rosters, credentialing data and custom key value pairs to widen the share of the claims process it can automate. That tells a buyer how data moves in. It says nothing about where it comes to rest.

The holding is not clinical documentation but it is not trivial either: claims data carries diagnosis and procedure codes, patient identity and payment detail, and the roster and credentialing material adds provider level information. For customers that include digital health companies rather than only medical groups, that data may be the operational core of the business.

The company holds a SOC 2 report covering security, availability and confidentiality, which is graded on the security axis and does not substitute for a residency answer.

Ask where the platform is hosted, whether tenancy is isolated, and what the data return terms are at termination.

Commercial
CC on Commercial TransparencyNo price is published and the posture is discoverable: a buyer can establish how the product is sold and what drives the cost before contacting the vendor. Most of the index sits here.
Third Party Estimated

No pricing published and no pricing basis disclosed. This is a notable gap for an RCM platform specifically, because the category's dominant commercial model is a percentage of collections, which aligns vendor and customer incentives but also means cost scales with revenue. Whether Candid prices on collections percentage, per claim, or as a platform fee materially changes the buy, and none of it is public. Third party listings do not fill the gap.

BB on Setting and Specialty CoverageCoverage is named with validation behind part of it.
Third Party Estimated

Targets multi-site provider groups, medical groups and digital health companies nationally, with named customers spanning telepsychiatry and nutrition care, indicating genuine multi-specialty reach in the outpatient and virtual care setting. Graded B rather than A because coverage is ambulatory and digital health oriented, with no located evidence of hospital inpatient or facility billing, which is a materially different and harder claims environment.

Citable summary

Self contained paragraphs, free to quote with attribution. Grades shown resolve from this record and change when it is regraded.

What Candid Health does, and why publishing a metric definition earns a grade

The AI Health Index grades Candid Health A on Autonomy and Oversight Model, and the reason is narrow and worth stating because it is the kind of thing that separates vendors on this axis. Candid publishes the definition of its touchless claim rate rather than only the number. A rate is uninterpretable without its denominator, and in claims automation a vendor can raise the same headline figure by excluding difficult claim types from the measurement. Publishing what the metric counts is what makes it checkable, and the index grades what a counterparty can verify rather than what a vendor asserts. The company is also unusually direct that its engine is reverse engineered payer rules continuously refined rather than a model doing the reasoning, which is why it grades B on AI Centrality: honest scoping rather than a deficiency. Verified as of Jul 26, 2026.

Source: AI Health Index, Jul 26, 2026

Where Candid Health fits, and what a multi site group should ask

The AI Health Index records Candid Health as built for ambulatory medical groups and digital health companies rather than for inpatient or facility billing, and grades it B on Setting and Specialty Coverage on that basis. Its integration approach is API first with out of the box connections alongside direct integration, and it compiles provider rosters, credentialing data and custom key value pairs so more of the claims process can be automated, which is what earns A on EHR and Interoperability Depth. The axis to read carefully is evidence, graded C: the touchless rate and net collection figures reported publicly are vendor generated, which is not the same as independently established, and the AI Health Index grades on what an outside party can verify. Verified as of Jul 26, 2026.

Source: AI Health Index, Jul 26, 2026

Common questions

How does Candid Health automate revenue cycle management for multi site providers?

By preventing claim errors at submission rather than working denials afterwards, which is the design choice that distinguishes it in this category. A rules engine carries reverse engineered payer requirements that are continuously refined, claim autocorrection validates data before submission, and machine learning automates the feedback loop between claim insights and systemic rule changes, with customers able to author and manage their own custom rules. For a group operating across multiple sites, the relevant mechanics are that the platform is API first with connections to existing record systems, and that it compiles provider rosters and credentialing data centrally so payer specific requirements resolve per site and per provider rather than being maintained by hand in each location. The AI Health Index grades Candid Health A on EHR and Interoperability Depth and A on Autonomy and Oversight Model as of Jul 26, 2026. Its evidence grade is C, so the reported touchless and collection rates should be read as vendor generated.

What is Candid Health?

Candid Health is a revenue cycle automation platform for medical groups and digital health companies, founded out of Y Combinator, that automates claim submission through payment around a single metric it calls touchless claim rate. Rather than making denial cleanup more efficient, it aims to prevent denials by validating and autocorrecting claims before submission against continuously refined payer rules. It is API first, holds a SOC 2 report covering security, availability and confidentiality, and names customers including Talkiatry and Nourish. The AI Health Index indexes it in revenue cycle and prior authorisation with secondary placement in healthcare administrative automation, and grades it across fifteen capability axes with the date of last verification published on the record.

Is Candid Health an AI product or a rules engine?

Both, and the company is more candid about the split than most of the category, which is why the AI Health Index grades it B on AI Centrality rather than higher. The core of the product is a rules engine carrying reverse engineered payer requirements; machine learning automates the feedback loop that turns claim outcomes into systemic rule changes. That is a smaller claim than an AI first pitch and a more accurate one, and the index treats accurate scoping as better disclosure rather than a weaker product. For a buyer the practical consequence is that performance depends on how current the payer rules are and how quickly the feedback loop updates them, which is a maintenance question to ask about rather than a model question.

Does Candid Health publish pricing?

Not in a form a buyer can act on before a sales conversation. The AI Health Index grades Candid Health C on Commercial Transparency as of Jul 26, 2026. In this category the structure matters more than the headline rate, so the questions to settle are whether the fee is a percentage of collections or a platform charge, how it changes with claim volume across sites, and what is included when the same vendor handles submission, autocorrection and reporting.

Does Candid Health pay to be listed on the AI Health Index?

No. The AI Health Index is researched from public sources, no vendor pays for inclusion, for a grade or for placement, and every record carries the date it was last verified. A vendor that publishes more is regraded and the change is logged.

Comparisons

Compared With

Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Not published
Undisclosed. RCM category norm is percentage of collections, but Candid does not confirm its basis publicly. Third Party Estimated

No pricing published and no pricing basis disclosed, which is a more consequential gap in RCM than in most categories. The prevailing commercial model across revenue cycle management is a percentage of collections, typically in the low single digits, which aligns vendor incentives with customer revenue but means cost scales as the practice grows.

Whether Candid prices on a collections percentage, per claim submitted, or as a flat platform fee changes the total cost of ownership substantially and cannot be determined from public materials. Third party software directories list the product without rates.

Buyers should establish the pricing basis first, then the treatment of the implementation phase, since third party review notes that data mapping setup requires dedicated time and the API-first integration model implies engineering effort on the customer side that may sit outside the licence. Also worth asking whether the custom rules a customer authors remain theirs and are portable if the relationship ends, given that customer-built business logic accumulates in the platform over time.