Healthcare Administrative Automation
C

CodaMetrix

Autonomous medical coding platform spun out of Mass General Brigham in 2019, built on coding AI the founding team originally developed inside that health system in 2016. Uses machine learning, deep learning, and natural language processing to translate clinical documentation in the EHR directly into ICD-10, CPT, and related billing codes across radiology, pathology, surgery, gastroenterology, and inpatient professional coding, with a continuous feedback loop from real-time audit. Reported in use at more than 25 provider organizations representing over 200 hospitals and 50,000 providers, and ranked number one by KLAS Research in the Reduce Cost of Care category. Notable in this index as one of the few vendors selling genuine autonomy in a high volume administrative workflow rather than assistive support.

AI Health Index verifiedJuly 26, 2026
Compare CodaMetrix with other vendors
Founded
2019
Headquarters
Boston, Massachusetts, United States
Categories
healthcare-admin-automation, vbc-intelligence
Indexed Products
CMX CARE, CMX Automate, CMX Audit
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
AA on AI CentralityThe artificial intelligence is the product. Remove the model and there is nothing left to sell.
Vendor Published

The model is the product, and the company's origin makes that unusually clear. The platform began as coding AI built inside Mass General Brigham in 2016 to solve that system's own problem, and was spun out in 2019 specifically because the technology proved useful beyond it. What is sold is autonomous code assignment from clinical documentation using machine learning, deep learning, and natural language processing. There is no coding services bureau or offshore workforce underneath it, which is the distinction that separates this from most revenue cycle vendors claiming AI.

BB on Autonomy and Oversight ModelThe oversight structure is described and one part is missing, commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

Genuinely autonomous by design and marketed as such, which is rare in this index and appropriate for the task since coding is an administrative determination reviewable after the fact rather than a clinical judgment made at the bedside. The company states the aim is coding that is largely autonomous and reports roughly 70 percent reduction in manual labour, meaning a substantial share of charts are coded without a human touching them.

The check is real-time audit capability and a continuous feedback loop rather than case by case human sign off. What is not published is the confidence threshold at which a chart routes to a human coder, which is the single most important operational disclosure for an autonomous coding system and worth pressing on.

CC on Model and Technology TransparencyThe architecture is described in general terms with nothing identified. Proprietary is asserted rather than explained.
Vendor Published

Technique is named at a general level, machine learning plus deep learning plus natural language processing operating on longitudinal EHR records with a patient centric view, and the CMX Care platform is described as contextual coding automation. What is absent is the substance a technical buyer needs: no published coding accuracy rate, no per specialty performance breakdown, no error taxonomy, and no independent audit of code assignment quality. For a system assigning billing codes autonomously, accuracy against a human gold standard is the central number, and it is not published.

BB on Model Supply Chain DisclosureSubstantial partial disclosure, or a chain that is structurally short: an in house build, a cleared model that cannot be quietly swapped, or a deployment where the transfer does not occur at all. Naming only the hosting provider sits at the top of this band rather than in A.
Vendor Published

This vendor states plainly that it analyses denials information shared by customers in order to improve its models and coding capabilities. That is a model training disclosure, made without prompting, and scoped to a named data category rather than left as a blanket right, which across this index is genuinely unusual: the normal answer to whether customer clinical data trains the models is silence, so saying it earns real credit.

It should be read for what it implies as well as for the candour. A model learning from denials is learning what payers accepted, which is not the same as learning what was clinically accurate, and the two diverge wherever a payer's policy is stricter or looser than the documentation supports. That is a legitimate optimisation target for a revenue cycle product and it should be understood as what it is rather than mistaken for accuracy improvement.

Supporting controls are specific: encryption in motion and at rest, a full audit trail, role based access and a least privilege model. For a platform reading the longitudinal record rather than a single note, an auditable trail of what was accessed to produce a given code is the control that matters most, and it exists. The surface is correspondingly broad, since contextual coding requires reading the whole patient record over time. Absent: retention periods, any de identification step before model improvement, whether the training use is severable, and what happens at termination. Ask whether the training use can be declined.

BB on Clinical and Operational EvidenceNamed deployments with dated outcome figures and enough method to test them, or published research short of independent validation.
Vendor Published

Adoption at academic medical centers is the strongest signal here. Named deployments include Mass General Brigham, Yale Medicine, University of Colorado Medicine, and Henry Ford Health, with reported scale of more than 25 provider organizations covering over 200 hospitals and 50,000 providers. KLAS Research ranked it number one in the Reduce Cost of Care category, which reflects direct customer feedback rather than vendor assertion.

Reported outcomes of roughly 70 percent manual labour reduction and 59 percent fewer coding related denials are vendor stated and unaudited. Note several named academic customers are also investors through their physician organizations, which is a genuine alignment signal and also a caveat on independence.

BB on AI Safety and PHI StewardshipCategorical commitments are published, such as no training on customer data, without the retention schedule or the safety engineering behind them.
Vendor Published

Corrected from Not Rated, and the reason is a disclosure most peers do not make at all.

The company states that it analyses denials information shared by customers in order to improve its models and coding capabilities. That is a model training disclosure, made plainly, and scoped to a named data category rather than left as a blanket right. Across this index the usual answer to whether customer clinical data trains the models is silence, so stating it earns real credit here.

Read it with the governance point though, because the two connect. A model learning from denials is learning what payers accepted, which is not the same as learning what was clinically accurate. That is a legitimate optimisation target for a revenue cycle product and it should be understood as what it is.

Supporting controls are specific: encryption in motion and at rest, a full audit trail, role based access and a least privilege model. For a platform reading the longitudinal record rather than a single note, an auditable trail of what was accessed to produce a given code is the control that matters most, and it exists.

The surface is broad and worth stating plainly. Contextual coding requires reading the whole patient record over time, which is a wider protected health information exposure than a note level tool has.

What is not published: retention periods for clinical documentation and derived artefacts, any de identification step before model improvement, whether the denials training use is severable in contract, and what happens to accumulated data at termination.

Ask whether the training use can be declined, and what is retained after a code is produced.

Regulatory and Compliance
BB on HIPAA and BAA PostureBusiness associate status is stated and supported by a substantive privacy document, with the agreement or its scope not fully published. For a vendor outside the United States, an equivalent regime documented to this depth grades here.
Vendor Published

Corrected from Not Rated. The previous note observed correctly that these obligations apply as a matter of law and would be settled in enterprise contracting. The company does state a position, and it is more specific than a compliance assertion.

What is published: technical and procedural safeguards described as implemented for HIPAA, and named individually elsewhere in its security material as encryption in motion and at rest, a full audit trail, role based access and a least privilege model. Naming the safeguards rather than asserting compliance is the distinction this axis rewards, because a buyer can test each one.

The role is unambiguous. The health system is the covered entity. This platform reads clinical documentation and produces codes on its behalf, which makes it a business associate with direct liability under the rule.

The audit trail deserves specific weight here rather than being treated as generic security hygiene. Where an automated system assigns a billing code from the record, the ability to reconstruct which documentation produced which code is simultaneously a privacy control, a compliance artefact and the customer's defence if a claim is later challenged. It is the right control to have built and it is stated.

Held at B rather than A because the instrument itself is not published. No business associate agreement text, no provider facing addendum, no subcontractor flow down, no breach notification timetable and no review cadence were retrieved. The route to an A in this index is publishing the agreement so a buyer can read what governs the relationship before entering it.

Ask for the agreement, and ask specifically how the denials data used for model improvement is treated under it.

AA on Security Certifications and Trust CenterCertifications named with their type and version and presented as retrievable artefacts, usually through a trust portal a buyer can open without asking.
Vendor Published

Corrected from Not Rated. The previous note recorded that no attestation and no trust centre were located. Both certifications are held and the supporting control detail is among the more specific in this index.

Held: ISO 27001 certification and SOC 2 Type 2, with the type stated rather than left ambiguous. Controls named individually rather than gestured at: encryption in motion and at rest, a full audit trail, a documented information security management system, third party penetration testing, static and dynamic code vulnerability scanning, role based access and a least privilege model.

Static and dynamic application security testing is worth calling out because almost no vendor in this index names it. Most security disclosure describes how data is protected once it exists. Naming code scanning describes how the software that handles the data is built, which is a different and usually invisible layer.

One independent check sits alongside it. Epic Toolbox designation is granted to products meeting Epic's recommended integration practices, and reaching it for the fully autonomous coding category means passing a review by the record vendor rather than self certifying. That is not a security attestation and should not be counted as one, but it is a third party examination that most peers do not have.

One qualification. No public trust centre was found, and the fullest statement of this posture surfaced through a healthcare marketplace profile rather than the company's own security page. The substance is the vendor's own and is attributed as such, but a buyer cannot self serve it from the vendor site, which is where it belongs.

Ask for both reports directly, and confirm the SOC 2 period covered.

BB on FDA and Regulatory StatusThe pathway is stated and in progress, or a clearance is named without the vintage and scope a buyer needs to match it to the product on offer.
Vendor Published

Converted from Not Rated. The prior note already carried the correct regulatory analysis and simply had no grade attached, which is the reflexive Not Rated this index rules against. Where no device regulator applies, grade against the regime that actually governs.

The scoping holds and it is the provider side revenue cycle position. No Food and Drug Administration pathway applies to medical coding automation and none is claimed. The governing constraints are payer billing rules and coding compliance. Critically, no vendor level regulator exists at all in this category: the liability for an incorrect code submitted to a federal payer sits with the billing organisation under the False Claims Act, not with the software supplier. A buyer is accepting that exposure, and understanding the allocation before deploying autonomous coding is the whole point.

Where no regulator exists, this index grades against what the vendor publishes in its place: accuracy, audit trail, and whether a credentialed human verifies before submission. Three of the relevant items exist here. A full audit trail is published as a control, which is the artefact that lets a customer defend a claim later. An automation rate above 96 percent is published. And Epic Toolbox designation for the fully autonomous coding category means the integration passed review by the record vendor rather than being self asserted.

Held at B rather than A on the single most useful number, which is absent. The benchmark in this index is set by a peer that publishes its confidence threshold, stating what level of certainty routes a code to billing and what returns it to a human coder. An automation rate describes how much was automated. A confidence threshold describes where the line sits between machine and human, and it is the number the whole safety argument rests on.

Ask for the threshold, the accuracy figure as distinct from the automation rate, and what happens to codes below the line.

CC on AI Governance and Bias DisclosureResponsible artificial intelligence is committed to in policy language with no evaluation behind it. Most of the index sits here.
Vendor Published

Converted from Not Rated. The prior analysis was right about the risk and it is now sharper, because the training data is disclosed.

No governance framework, monitoring commitment, bias analysis or third party model audit was retrieved.

The relevant risk here is not demographic bias in the usual clinical sense. It is systematic coding drift. A model that learns from a health system's historical coding will reproduce that system's coding intensity, including any tendency to code up, and will do so at machine scale and machine consistency. Nothing published describes guardrails against that.

The company's own disclosure sharpens the question rather than answering it. It states that it analyses denials information shared by customers to improve the models. Denials data teaches a model which codes payers accepted and which they rejected. That is a reasonable optimisation target for a revenue cycle product, and it is not the same target as clinical accuracy. A code that survives adjudication and a code that best describes the encounter are usually the same thing and are not always the same thing, and a system tuned on the first will drift toward it.

The consequence runs both ways, which is why this is a governance question rather than an accusation. Drift toward what payers accept can suppress legitimate coding as easily as it can inflate it, and neither direction is visible to the customer without monitoring designed to detect it.

Ask what monitoring exists for coding intensity drift over time, whether output is benchmarked against anything other than the customer's own history, and who reviews it.

DD on AI Liability and RecourseNothing published on what happens when the system is wrong.
Vendor Published

Two passes located no published coding accuracy rate, no per specialty performance breakdown, no error taxonomy, no independent audit of code assignment quality and no warranty, indemnity or remediation commitment. For a system assigning billing codes autonomously, accuracy against a human gold standard is the central number and it is absent, as is any threshold governing which encounters are finalised without a person.

Per specialty matters as much as the aggregate, because coding difficulty varies enormously by service line and a figure averaged across a health system's mix describes none of them. One point from the other axis bears directly here and a buyer should carry it across. The company states it improves its models by analysing denials, so the optimisation target is what payers accepted rather than what the documentation supports.

Those coincide most of the time and diverge exactly where an auditor would look: a code that reliably gets paid is not necessarily a code that survives review, and a system tuned on acceptance has no signal telling it the difference. That makes the missing independent audit more consequential than the missing accuracy figure.

Ask for accuracy by specialty against a blinded human standard, the autonomous finalisation threshold, the rate at which autonomously assigned codes are later reversed or recovered, and what the vendor commits to when one is wrong.

Integration and Deployment
BB on EHR and Interoperability DepthNamed systems with read access or one directional writing, or standards support with named deployments behind it.
Third Party Estimated

EHR integration is structural rather than optional, since the platform reads clinical documentation from the record and writes codes back into the revenue cycle. Epic integration is specifically cited in third party analysis as a differentiator, and the company describes seamless EHR integration with real-time audit and a continuous feedback loop. No published connector list or API documentation covering EHRs beyond Epic was located, so depth outside the dominant systems is undocumented.

CC on Deployment Model and Data ResidencyA single hosted option with location implied rather than committed.
Vendor Published

Converted from Not Rated. Delivered as a software as a service platform, and nothing published states where it runs.

No hosting provider, no region, no tenancy model, no subprocessor list, no backup or recovery posture and no data residency commitment was retrieved.

The reason this matters more than for a typical software purchase is what the platform consumes. Contextual coding requires reading the longitudinal patient record rather than a single document, so the question is not whether a note is transmitted but whether a substantial slice of the clinical record leaves the institution and where it comes to rest. Nothing published answers it.

The integration architecture is well evidenced even though the hosting is not. Deep Epic integration with Toolbox designation, support for other major record systems, and stated use of the standard clinical interoperability protocols mean the data path into the platform is understood. What is missing is the other half: where inference runs once the data arrives, whether customer environments are logically or physically separated, and what is retained.

One related question belongs here rather than only on the privacy axis. The company states that customer denials data improves its models, and models improved across a customer base imply data leaving a single tenant boundary in some form. Whether that is aggregated, de identified, or pooled is a deployment architecture question as much as a privacy one.

Ask where the platform is hosted and in which region, whether tenancy is isolated, and whether any model improvement pipeline crosses customer boundaries.

Commercial
CC on Commercial TransparencyNo price is published and the posture is discoverable: a buyer can establish how the product is sold and what drives the cost before contacting the vendor. Most of the index sits here.
Vendor Published

No pricing is published. The value framing is unusually concrete for modeling purposes, since coding is the most expensive component of the revenue cycle and the company cites published estimates that 20 to 25 percent of US healthcare spending goes to administrative and revenue cycle tasks, giving a buyer a baseline to compare against current coding cost per chart. The commercially important unknown is whether pricing is per chart, per provider, or subscription, which determines whether savings scale with automation rate or are captured by the vendor.

AA on Setting and Specialty CoverageWhere the product is validated to operate is named and supported, settings and specialties both, whether the coverage is broad or deliberately narrow.
Vendor Published

Multi specialty coverage is the explicit differentiator and it is substantiated: code classification spans radiology, pathology, surgery, gastroenterology, and inpatient professional coding, and the company positions itself as the first platform to work across departments rather than automating a single high volume specialty. That matters because most autonomous coding competitors start in radiology, where studies are templated and codes are narrow. Serving health systems from academic medical centers to smaller organizations across more than 200 hospitals demonstrates the breadth in deployment rather than only in marketing.

Comparisons

Compared With

Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Contact the vendor
Undisclosed. Software as a service platform sold to health systems and provider organizations; no per chart, per provider, or subscription rates published. Not disclosed. As a US vendor processing clinical documentation for health systems, HIPAA obligations apply by law and would be handled in enterprise contracting, but terms are not published. Not disclosed. Deployment requires EHR integration to read clinical documentation and write codes back into the revenue cycle; Epic integration is cited in third party analysis as a differentiator. Vendor Published

No pricing is published, though the value case is easier to model here than for most vendors because the comparison is a known internal cost line. Coding is the most expensive component of the revenue cycle, and the company cites published estimates that 20 to 25 percent of US healthcare spending goes to administrative and revenue cycle tasks, so a buyer can benchmark against current cost per chart.

The decisive unknown is the pricing unit: per chart, per provider, or subscription determines whether the savings from a higher automation rate accrue to the health system or to the vendor. Two further questions worth raising in diligence: the confidence threshold at which a chart routes to a human coder, and where liability sits, since incorrect codes submitted to Medicare create False Claims Act exposure for the billing organization rather than the software vendor.