Censinet
Healthcare cyber risk management operating on a fundamentally different model from the device security vendors that dominate this category: Censinet RiskOps is a cloud-based risk exchange where healthcare organisations and vendors share assessment data collaboratively, so the asset compounds with network participation rather than being rebuilt by each customer. Boston based, founded by CEO Ed Gaudet, and an American Hospital Association Preferred Cybersecurity Provider.
The scope is third-party and enterprise risk rather than connected devices: assessing the vendors, products and services a health system depends on, spanning medical devices, cloud software, robotics and consulting, with assessments flowing into structured remediation workflows and continuous oversight rather than point-in-time reviews. Reported reach exceeds 1,000 healthcare organisations across a network of over 50,000 vendors and products. Delivery is flexible between fully self-operated, co-managed risk management services, and the on-demand Censinet One model. The 2026 direction is the interesting part for this index.
At ViVE 2026 the company set out a Censinet GRC AI vision extending from third-party risk into an AI-native governance, risk and compliance platform, and launched capabilities operationalising the HSCC Sector Mapping and Risk Toolkit framework, mapping vendors to the 17 critical functions underpinning healthcare delivery, with a healthcare-specific FICO-style inherent risk score from 300 to 850, concentration risk and chokepoint visibility to expose systemic dependencies, and network-powered intelligence drawn from the exchange.
It also announced AI Telemetry, providing continuous evidence-based visibility into a health system's AI exposure across its third-party ecosystem rather than a point-in-time snapshot. That last capability is notable in context: this is a vendor whose product is partly governance of the AI its customers buy, which makes it structurally adjacent to what this index does. The Change Healthcare attack is the reference case the company cites for systemic concentration risk.
Capability Axes
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read
A deliberate C, and the honest grade for this record.
The moat is unambiguously the risk exchange network: more than 1,000 healthcare organisations and over 50,000 vendors and products sharing assessment data, which compounds with participation and cannot be replicated by a model. The company's own framing is that it transforms risk management by leveraging network scale and efficiencies.
AI is a 2026 layer on top, with the GRC AI vision described as a roadmap rather than a shipped capability, and the FICO style 300 to 850 inherent risk score is a scoring methodology whose algorithmic basis is not established.
The same principle applies to Reveleer, the credentialing lane and Neurotrack: where the asset is the network or dataset rather than the model, AI Centrality is graded down regardless of how the company positions itself. Indexed because the AI capabilities are identifiable and gradeable, which is the ModMed test.
Assessment and workflow automation feeding human risk decisions, with the platform explicitly adapting to the customer's operating model across three modes: the internal team operating it independently, a co-managed arrangement where Censinet provides Risk Management Services alongside the customer, and the on-demand Censinet One managed-service-enabled model.
Being explicit that a customer can choose how much of the work the vendor performs is a clearer statement of the human boundary than most vendors offer. Graded B rather than A because no statement was located on what, if anything, the platform determines without human review, particularly for the automated inherent risk scoring.
The frameworks are named precisely, which is creditable: HSCC Sector Mapping and Risk Toolkit, the 17 critical functions underpinning healthcare delivery, and NIST Cybersecurity Framework support. But the AI itself is described at vision and capability level without technical substance.
The FICO-style 300 to 850 risk score is the central quantitative output and no derivation, weighting or validation is published, which matters because a numeric score carries an implied precision that an unexplained methodology does not support. Borrowing the FICO framing invites an inference of comparability and rigour that is not evidenced.
The distinctive feature of this platform is that the other participants are the chain, and the vendor is candid that this is the design rather than hiding it. Participating organisations share cybersecurity and risk assessment data across a collaborative network, and that pooling is the source of the platform's value, since an assessment completed once can serve many buyers and spare a supplier from answering the same questionnaire fifty times.
Disclosing that openly is the right posture and it puts this above the vendors whose pooling is inferable but unstated. What is not published is the shape of the sharing. No detail on segregation, anonymisation, or what is visible to other participants was located, so a health system contributing its own risk posture data cannot establish who can see it, at what granularity, or whether a competitor participating in the same exchange learns anything about its security weaknesses.
That is an unusual exposure: most stewardship questions in this index concern what a vendor does with data, and here the material question is what peers can see. The structural position on patient data is favourable, since the platform holds vendor risk assessment content rather than clinical records. Ask what other participants can see, at what granularity, and what happens to contributed assessments on exit.
Strong commercial and adoption evidence, no efficacy evidence. Reported scale is substantial and specific at over 1,000 healthcare organisations and more than 50,000 vendors, with named health system investors including MemorialCare, Rex Health Ventures, Ballad Ventures and Cedars-Sinai, and a reported period of 100 percent year-over-year ARR growth with no customer losses.
American Hospital Association Preferred Cybersecurity Provider status is meaningful third party endorsement from the sector's own trade body. The company also publishes an annual Healthcare Cybersecurity Benchmarking Study, which is genuine industry research rather than marketing. Graded B rather than A because none of this demonstrates that using the platform reduces breaches, incidents or third-party risk exposure, and no outcome study was located.
The platform is described as a HIPAA-secure risk exchange, and the data it holds is vendor risk assessment content rather than patient records, so the PHI surface is structurally small. The more interesting stewardship question is the exchange model itself: participating organisations share cybersecurity and risk data across a collaborative network, which is the source of the platform's value and also means a health system's own risk posture data sits in a shared environment. No published detail on segregation, anonymisation or what is visible to other participants was located.
Described consistently as a HIPAA-secure platform, and the company operates as a risk and compliance vendor to more than 1,000 healthcare organisations, so HIPAA alignment is core to the offering. Graded B rather than A because no BAA terms were located in published form.
Upgraded from Not Rated, and the prior note is superseded rather than refined. It recorded that no attestation was retrieved and treated the gap as sharper than usual because this company's product is assessing exactly this in other vendors. One of those things has changed.
The company completed a SOC 2 Type 2 examination in February 2026, scoped to the risk exchange platform itself rather than to the corporate entity generally, conducted by a named external audit firm. The stated examination covered access management, system monitoring, change management, incident response and vendor security practices. Three details make this a solid B rather than a bare mention. It is a Type 2, which tests whether controls operated effectively across a period rather than existed on a date. The scope names the product a customer actually buys. And the auditor is identified, which is what allows a counterparty to place the report.
Held at B rather than A for two reasons. There is no trust centre, so obtaining the report requires a sales conversation rather than a request form. And the company does not hold HITRUST.
That second point deserves care rather than a cheap shot, because this company publishes extensive guidance on exactly this question. Its own material argues that HITRUST is often the better option for high risk vendors handling sensitive patient data, and separately makes the correct technical point that SOC 2 is an attestation rather than a certification. It holds the attestation and not the certification. That is not a contradiction: this platform holds cyber risk assessment data about health systems and their suppliers rather than patient records, so its own published guidance is aimed at a different class of vendor. It does mean a buyer has an unusually precise way to ask the question, using the company's own framework.
One figure to pin down when requesting the report. The examination announcement describes the company as entrusted with risk data for more than 200 healthcare organisations and 55,000 vendors and products, while other company materials describe a network of over 1,000 healthcare organisations. Those are probably different denominators, customers against network participants, but confirm which population sits inside the audited scope.
Not an FDA regulated product. Risk management and governance tooling sits entirely outside Software as a Medical Device, and no clearance is expected.
Graded B rather than C because the framework surface that does govern is substantial and the company states its position within it rather than staying silent. The relevant instruments are the HIPAA Security Rule, the NIST Cybersecurity Framework, and the Health Sector Coordinating Council Sector Mapping and Risk Toolkit, which the company states it is the first platform to operationalise.
Held off A because that is a self declared first rather than an externally verified one, and because no independent attestation of the platform itself was located. A vendor whose product assesses third party risk for health systems is measured against a higher bar on this axis than one whose product does not.
Graded on an unusual basis, because this vendor sells AI governance rather than only practising it. The AI Telemetry capability provides healthcare organisations with continuous evidence-based visibility into AI exposure across their third-party ecosystem, explicitly to close the gap between AI adoption and AI governance, which is a substantive contribution to the governance problem this index cares about.
The irony worth noting is that the company publishes no governance framework for its OWN scoring models, so a platform that monitors customers' AI exposure does not disclose how its own risk scores are produced or validated. Graded B for the product contribution, held back from A by that gap.
Two passes located no derivation, weighting or validation for the platform's central quantitative output, and no warranty, indemnity or remediation commitment. The frameworks the platform maps to are named precisely, which is creditable and is a different thing from the score itself. The finding worth naming is the form of the claim rather than only its absence, and it is a shape this index has not recorded before.
The risk score is presented on the same numeric range as the familiar consumer credit score. Borrowing a recognised scale imports an inference of comparability and rigour that the underlying methodology has not earned: a reader encountering that range brings expectations built by decades of a regulated, extensively studied and legally contestable scoring system, and applies them to a number whose derivation is unpublished.
A numeric score also carries an implied precision that an unexplained methodology cannot support, and three digits of resolution implies a discrimination nobody has demonstrated. The consequence is commercial rather than clinical and still real, since these scores govern which vendors a health system will contract with and on what terms, and a supplier scored down has no described route to see the derivation or contest it. Ask for the derivation and weighting, any validation against observed breach outcomes, and what a scored vendor is entitled to see.
Converted from Not Rated after a second search. The prior note identified the correct scoping and simply had not retrieved the integrations, which do exist and are named.
The scoping stands: this is a governance, risk and third party assessment platform, so the meaningful integration surface is procurement, vendor management and ticketing rather than clinical systems. Grading it against electronic health record depth would misdescribe the product.
Against that surface the position is documented. The company publishes a workflow connector for a major enterprise service management platform, listed in that platform's own application store, which is third party verification of the integration's existence rather than a vendor claim about itself. The connector is bidirectional in a substantive way: an assessment can be launched from the ticketing system, status updates flow back automatically as the assessment progresses, and the vendor and product inventory synchronises between the two systems so the service management platform holds current findings. Named compatible releases are listed. The company also states an open interface for connecting IT, governance and procurement systems.
Held at B rather than A because only one named platform connector was located, no public interface documentation or supported object specification was found, and no integration with any named procurement or sourcing suite was identified even though procurement is the stated surface and the company positions the product as accelerating acquisition workflows.
One caution for anyone re running this. A third party software directory describes this platform as connecting to electronic health record systems, security event management tools and vulnerability scanners. None of that is claimed in the company's own materials. Directory descriptions are written to fill a template and routinely attribute capabilities a vendor does not assert, so confirm any integration against the vendor's own documentation or a first party marketplace listing before crediting it.
Cloud platform with genuinely flexible operating models, which is the notable feature: customers can run it themselves, operate it co-managed with Censinet Risk Management Services, or consume it on demand through Censinet One, described as a managed-service-enabled platform. That range accommodates health systems with very different internal security staffing, which is a real constraint in this market. No data residency disclosure located.
No pricing published and no pricing basis disclosed. The multi-modal delivery structure, spanning self-operated, co-managed and on-demand, implies materially different cost profiles depending on how much service is bundled, and none of that is public. Buyers cannot determine whether they are comparing software cost or software plus managed service cost against alternatives.
Broad across both risk domains and participant types, and distinctly wider than the device-security vendors in this category. Covers third-party risk and enterprise risk, spanning vendors and products from medical devices and cloud software to robotics and consulting services, and serves health systems, health plans and vendors themselves, meaning both sides of the assessment relationship participate in the same exchange.
The 2026 additions extend to systemic and concentration risk across 17 sector-defined critical functions, which moves the analysis from individual vendor risk to ecosystem-level dependency, a genuinely different scope from anything else in this lane.
What Changed
Material product, regulatory, evidence and commercial changes at Censinet, each verified against a live source and tagged to the capability axis it bears on. Funding rounds and awards are not product changes and are not logged.
Censinet introduced comprehensive support for the new HHS Cybersecurity Performance Goals (CPGs) within its risk management platform. The update provides built-in capabilities to help healthcare organizations track and accelerate their compliance with the federal cybersecurity guidelines.
Compared With
Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
Not published
|
Undisclosed. Three delivery models (self-operated, co-managed, on-demand) with materially different cost structures. | — | — | Third Party Estimated |
No pricing published and no pricing basis disclosed. The complication specific to this vendor is that it sells across three materially different delivery models, so a quoted figure means little without knowing which is being priced: the customer's internal team operating the platform independently, a co-managed arrangement where Censinet provides Risk Management Services alongside the customer's team, and Censinet One, described as an on-demand managed-service-enabled platform.
Those carry very different cost structures, and a buyer comparing Censinet against a pure software GRC tool may be comparing software cost against software plus staffed service. Buyers should establish which model is quoted, whether pricing scales by number of vendors assessed, assessments performed, or organisation size, and what the incremental cost is for the 2026 capabilities including SMART framework mapping, concentration risk analysis and AI Telemetry, since those were announced as new platform capabilities and may not be included in a base subscription.
One structural point in the buyer's favour: because the platform operates as a risk exchange where assessment data is shared across more than 1,000 healthcare organisations and 50,000 vendors, a vendor already assessed by another participant may not require a fresh assessment, so the effective cost per vendor assessed should fall as network coverage of a given organisation's vendor portfolio rises. Worth asking directly what proportion of a prospective customer's existing vendor list is already covered in the exchange, since that determines realised value more than the licence rate.