Ambient Scribes
C

CareCortex

CareCortex is the clinical documentation platform from NeuroReef Labs, a Mountain View company that also builds MedAura, a separate evidence retrieval product using the GRADE framework. CareCortex covers more of the visit than the note: automated pre charting pulls the referral letter, prior notes, vitals, medications and current diagnoses into the active note as patient insights before the encounter, multilingual transcription handles the visit itself, CPT and ICD-10 codes are generated from it, and visit summaries and follow up instructions are sent to the patient by secure email afterwards.

Two features are unusual for a product of this size and are the reason to look at it: real time compliance validation checking documentation as it is produced, and audit logs recording what happened. It states HIPAA and SOC 2 compliance, though the wording attributes that posture to a partnership with a secure infrastructure provider rather than to the vendor's own audited controls, which is a distinction worth pressing.

AI Health Index verifiedJuly 23, 2026
Compare CareCortex with other vendors
Founded
Headquarters
Mountain View, California, United States
Website
carecortex.ai/
Categories
ambient-scribes
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
AA on AI CentralityThe artificial intelligence is the product. Remove the model and there is nothing left to sell.
Vendor Published

Described by its parent as an AI native platform, and NeuroReef Labs presents itself as building neuro inspired intelligent systems with CareCortex and MedAura as its two products. Every capability in the documentation product, from pre charting synthesis through transcription to coding and patient summaries, is model output with no services layer underneath.

BB on Autonomy and Oversight ModelThe oversight structure is described and one part is missing, commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

Two mechanisms lift this above the tail norm, though neither is a review gate. Real time compliance validation checks documentation as it is produced rather than after submission, which is the same in flight correction principle that works well in Lime Health's real time OASIS prompting. Audit logs record what the system did, which is the accountability layer most vendors in this category omit entirely and which matters when coding is being generated.

Held at B because no clinician review step, confidence threshold, acceptance rate or abstention behaviour was described, so what a clinician is required to confirm before a note or code is used remains unstated.

CC on Model and Technology TransparencyThe architecture is described in general terms with nothing identified. Proprietary is asserted rather than explained.
Vendor Published

Dynamic evidence mapping is named as a capability, which suggests traceability between output and source, but it is not described in enough detail to assess. No accuracy figure, model card, named models or evaluation methodology for CareCortex was located.

Worth recording without crediting it here: the sibling product MedAura is described as benchmarked against expert level clinical questions and validated by 21 medical professionals, and as applying the GRADE framework to evidence quality. That is real methodology, but it belongs to a different product and this index does not transfer claims between them.

DD on Model Supply Chain DisclosureNothing establishes who else sits between a patient record and an answer.
Vendor Published

Nothing identifies any party in the chain: no model or model family, no foundation model provider, no hosting arrangement and no sub processor list was located in two passes. One published statement is worth examining because it looks like a disclosure and functions as the opposite. The vendor states that its technology, in partnership with a secure infrastructure provider, follows strict security and privacy protocols that are constantly monitored.

That attributes the security posture to a hosting partner rather than to the vendor's own audited practice, and it does so without naming the partner, so a buyer receives neither an assurance they can verify nor a party they could ask. Borrowed posture from an unnamed third party is weaker than saying nothing, because it invites a reader to credit an arrangement whose terms and counterparty are both undisclosed.

The surface is wider than a capture only scribe as well, since the platform ingests substantial prior clinical data for pre charting, so whatever unnamed parties sit in this chain are handling record extracts rather than a single conversation. Ask who the infrastructure partner is, what obligations bind it, whether any third party model provider is invoked, and for a sub processor list.

CC on Clinical and Operational EvidenceNamed customers, or vendor reported percentages with no method, denominator or reference standard. Scale of use is recorded here and is not treated as evidence of benefit.
Vendor Published

No study, controlled evaluation, accuracy benchmark, named customer or deployment count was located for CareCortex. Presence on independent software directories and an urgent care buyers guide establishes that the product is real and marketed to a defined segment, which is more than nothing, but none of it measures benefit.

CC on AI Safety and PHI StewardshipGeneral assurances of privacy and security that do not answer the questions artificial intelligence raises: what is retained, what reaches a model, and what happens to it there.
Vendor Published

Audit logging is a genuine control, and the platform ingests substantial prior clinical data for pre charting, so the surface is wider than a capture only scribe.

What holds this at C is the framing of the compliance claim. The vendor states that its technology, in partnership with a secure infrastructure provider, follows strict security and privacy protocols that are constantly monitored. That attributes the posture to a hosting partner rather than to the vendor's own audited practice, the same pattern flagged for RXNT's certified data centres. No retention schedule, de identification practice or training use statement was located.

Regulatory and Compliance
BB on HIPAA and BAA PostureBusiness associate status is stated and supported by a substantive privacy document, with the agreement or its scope not fully published. For a vendor outside the United States, an equivalent regime documented to this depth grades here.
Vendor Published

HIPAA compliance is stated directly and consistently. Business associate agreement terms are not published for inspection. Note that the platform sends visit summaries and follow up instructions to patients by secure email, so the compliance question extends beyond the record system to outbound patient communication.

CC on Security Certifications and Trust CenterControls are described with an outside check behind them, such as independent penetration testing on a stated cadence, but no attestation against a recognised framework.
Vendor Published

SOC 2 is named and a trust centre exists at a dedicated subdomain, which puts this well above vendors claiming nothing. The trust centre presents the parent company as compliant with HIPAA and SOC 2, lists named controls including segregation of environments, change management and business continuity testing, and states that the environment is continuously monitored through a compliance automation platform. A published security policy is also available and is more detailed than most at this size, describing a defence in depth architecture that places systems holding sensitive data in an internal network zone, firewall and web application firewall controls, network ports restricted on a least functionality basis, intrusion monitoring, and maintained network and data flow diagrams.

Read carefully what that establishes and what it does not. Continuous control monitoring through a compliance platform is a real operating practice and evidences that controls are implemented and watched. It is not the same artefact as a completed independent examination, and the trust centre states neither the report type nor an audit date.

The remaining question is narrower than it first appeared but still material. Ask which legal entity the report covers, whether it is Type I or Type II, and what period it covers. The compliance framing has also rested partly on a partnership with a secure infrastructure provider, and certification inherited from infrastructure is not the vendor's own.

Held at this grade on report type and date rather than on absence of evidence, which is a materially better position than most of this segment occupies.

CC on FDA and Regulatory StatusNo device claim is made and the product is scoped accordingly. Most administrative and operational products sit here and are not penalised for it, because this axis grades the appropriateness of the positioning rather than possession of a clearance.
Vendor Published

No clearance claimed and none required for the documentation component. No United States device pathway attaches to a note the clinician reviews and signs.

The earlier assessment flagged the sibling product as the scope question and treated it as belonging to a different record. That framing needs revising, because the evidence function is not confined to the sibling. This product is positioned as an end to end evidence based platform, and its described feature set includes dynamic evidence mapping and real time compliance validation alongside documentation. Evidence mapping inside the documentation product is decision support rather than documentation.

The sibling remains relevant as context rather than as a separate conversation, since both are products of the same company. It is described as emulating human cognitive processes to deliver medical information using the GRADE framework. That is worth recording in the vendor's favour: GRADE is an established published methodology for appraising the quality of evidence, and a system that grades its evidence against a named external framework is more inspectable than one simply asserting reliability. The question that follows is whether a clinician is actually shown that appraisal, because the reasoning keeping clinical decision support outside device regulation depends on a professional being able to review the basis rather than rely on the conclusion.

Two further boundaries sit alongside. The product performs CPT and ICD-10 coding for billing, which is the reimbursement boundary. And it sends visit summaries and follow up instructions to patients by email, which is patient facing output derived from a clinical encounter.

Markets appear to include Australia alongside the United States. No United Kingdom or European Union presence was located, where a different regulatory conversation would apply.

CC on AI Governance and Bias DisclosureResponsible artificial intelligence is committed to in policy language with no evaluation behind it. Most of the index sits here.
Vendor Published

Partial rather than absent. Real time compliance validation and audit logs are genuine governance mechanisms and more than most vendors of this size offer, giving a compliance function something to inspect. What is missing is disclosure about behaviour: no fairness statement, no subgroup analysis and no accent or dialect performance data, despite multilingual transcription being a headline capability, and no accuracy figure for the CPT and ICD-10 generation that feeds billing.

DD on AI Liability and RecourseNothing published on what happens when the system is wrong.
Vendor Published

Two passes located no accuracy or error figure, no published limitations and no warranty, indemnity or remediation commitment for this product. Dynamic evidence mapping is named as a capability, which would suggest traceability between output and source and would be a genuine control if it were described, but nothing published explains what it maps, what a user sees, or whether it covers every generated element, so it cannot be assessed and is not credited here.

One thing needs recording precisely so that a reader does not credit it either. A sibling product from the same company is described as benchmarked against expert level clinical questions, validated by a named number of medical professionals, and applying an established framework for grading evidence quality. That is real methodology and it belongs to a different product.

This index does not transfer claims between products of the same vendor, and the reason applies with full force here: a reader scanning one website will accumulate rigour that was demonstrated for something they are not buying. The question to ask is whether any equivalent evaluation exists for this product, and if so where it is published. Ask that, and ask what the vendor commits to when a pre charted summary or a generated note is wrong.

Integration and Deployment
CC on EHR and Interoperability DepthIntegration is claimed through standards or a middleware layer with no system named and nothing to verify.
Vendor Published

Notes are described as EMR ready and pre charting demonstrably ingests prior clinical data including referral letters, previous notes, vitals, medications and diagnoses, which implies a real data connection rather than a standalone tool. But no named EHR integration, integration architecture, certification or write back mechanism was located, so the depth of that connection cannot be assessed and EMR ready may describe formatting rather than delivery.

CC on Deployment Model and Data ResidencyA single hosted option with location implied rather than committed.
Vendor Published

A second search reached the vendor's own legal and trust surfaces, which the first pass did not, and the position is better substantiated than previously recorded. The core question on this axis nonetheless remains open.

What is now established: the operating entity is a United States company with California and Texas addresses, a published security policy describes a defence in depth architecture placing systems that hold sensitive data in an internal network zone, and a trust centre names segregation of environments as a control alongside business continuity and disaster recovery testing. Segregation of environments is the relevant control for a multi tenant service and it is worth having named explicitly.

What remains unanswered is what this axis asks first. No hosting region is stated, no data residency option is offered, and no subprocessor list was located. Most importantly for an ambient scribe, nothing published establishes whether encounter audio or transcript is processed by a third party model service, which provider that would be, or what it retains. The compliance framing has rested partly on a partnership with a secure infrastructure provider that is not named.

Residency is not a theoretical concern on this record. Third party guidance places this product in the Australian market alongside local competitors, and multilingual capability is part of its positioning. A vendor serving clinicians outside the United States with no stated residency position leaves those buyers unable to establish where consultation audio comes to rest, or which jurisdiction's authorities could reach it.

Ask for the hosting region, whether residency can be pinned, the named subprocessors, and specifically which model provider processes the encounter.

Commercial
CC on Commercial TransparencyNo price is published and the posture is discoverable: a buyer can establish how the product is sold and what drives the cost before contacting the vendor. Most of the index sits here.
Vendor Published

No published rate card, tier structure or pricing model located on the vendor's materials or on the independent directories carrying its profile.

CC on Setting and Specialty CoverageCoverage is claimed broadly without specifics, or stated clearly with nothing validating it yet.
Vendor Published

Marketed into urgent care, where it appears in a segment buyers guide, with multilingual transcription extending reach to non English speaking patients. Coverage across the visit is broader than most, running from pre charting through the encounter to automated patient follow up communication. Held at C because no specialty count, specialty tuning claim, note format list or supported language list was located.

Comparisons

Compared With

Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Not published.
Not disclosed. Marketed to clinicians and urgent care practices as an end to end documentation and workflow platform. HIPAA compliance stated. SOC 2 claimed but framed around an infrastructure partner. BAA terms not published. Not published. Vendor Published

No published price on the vendor's own materials or on the independent directories carrying its profile. Three questions matter more than the rate for a product of this size. Which entity actually holds the SOC 2 report, since the claim is framed around a partnership with a secure infrastructure provider rather than the vendor's own audit. What a clinician is required to review before generated CPT and ICD-10 codes are used, since no review gate is described and the codes feed billing.

And what the audit logs actually capture, because they are one of the better features here and their value depends entirely on whether they record model suggestions and human overrides or only system events.