Fathom
Fathom is a San Francisco company selling autonomous medical coding: clinical documentation arrives from the record system after a visit, deep learning and large language models assign the codes, and complete results return for claim submission without a human coder touching most encounters. Chief executive Andrew Lockhart co founded it. Sources disagree on the founding year, giving 2015 and 2017.
Coverage spans the full set of elements a coder assigns rather than a subset: diagnosis codes, procedure codes, evaluation and management levels, modifiers, provider assignment, units, shared services and documentation deficiencies, across specialties. Turnaround is stated at under two hours for a day's encounters, averaging 57 minutes.
The published figures are unusually specific. Around 90 percent or more of encounters are coded autonomously or correctly flagged for documentation deficiency, accuracy is stated above 96 percent with ongoing audit programmes, and cost to code falls by 30 to 50 percent with a stated average of 42.3 percent. A customer, Your Health, reported a 95.5 percent automation rate at 98.3 percent accuracy across all service lines in March 2026.
Two commitments distinguish it from the category. The company offers contractual service level agreements guaranteeing automation rate, accuracy and turnaround time, which converts published performance into an enforceable obligation. And it offers a risk free trial in which a provider validates coding quality on their own encounters before production models are switched on.
Independent recognition includes a KLAS Spotlight report in September 2024 reporting 100 percent high customer satisfaction and validation of automation rates above 90 percent, and the top position for reducing the cost of care in the 2025 KLAS Emerging Solutions report. The company holds HITRUST i1 certification, obtained December 2024. It has raised roughly 61 million dollars from investors including Lightspeed Venture Partners, Alkeon Capital Management, Inflect Health, Tarsadia Investments and the Cedars-Sinai Accelerator, with a later strategic investment from CVS Health Ventures.
Capability Axes
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read
The models do the work that people previously did, end to end. Documentation arrives, codes come back, and for roughly nine encounters in ten no coder is involved. There is no workflow layer, network or platform underneath that would function without the model, because the model is the labour.
One qualification belongs on the record. Third party descriptions refer to a coding platform and related coding services, and any autonomous coder must handle the residual encounters it declines, so a human coding capability exists behind the automation. That is the correct design rather than a dilution, and the contractual commitments are made on the automated share.
The highest defensible autonomy grade in this index so far, and the reason is not the automation rate but what sits underneath it.
Three things are published rather than implied. The share of encounters handled without a human is stated at 90 percent or more, with the remainder either coded or correctly flagged as documentation deficient, so the boundary of the automation is a number rather than a claim. Accuracy is stated above 96 percent with ongoing audit programmes behind it. And the company offers contractual service level agreements guaranteeing automation rate, accuracy and turnaround, which converts all of that from marketing into an enforceable obligation with a counterparty.
A vendor accepting contractual liability for the quality of its autonomous output is a materially different oversight proposition from one publishing a threshold and hoping. Add the risk free validation trial before go live, in which the provider checks the coding on their own encounters, and the buyer has two independent ways to test the claim before relying on it.
The mechanism is named at the level that matters commercially: deep learning and large language models, applied to documentation from the record system, producing every coding element rather than a subset. The elements themselves are enumerated precisely, which tells a buyer what is in scope and what still needs a coder.
Performance is stated with numbers rather than adjectives, including turnaround measured as an average rather than a maximum. What is absent is architecture, training data provenance or scale, and any breakdown of accuracy by coding element, which matters because evaluation and management level assignment is a harder and more consequential judgement than procedure code selection.
The mechanism and the scope are named and the chain is not. Deep learning and large language models are identified as the substrate applied to documentation from the record system, and the coding elements produced are enumerated precisely, which tells a buyer what is in scope and what still requires a coder. Scope enumeration is a genuine disclosure and rarer than it sounds, because a product that produces some elements and not others is easy to describe vaguely.
On enumeration of parties there is nothing: no foundation model provider, model class or version is named, no architecture or training data provenance is published, no hosting arrangement is described and no sub processor list was located, and no position on whether customer documentation contributes to model development was found. Two things widen what that unnamed chain handles.
The data is the complete clinical note for every encounter coded rather than an extract, so the volume and sensitivity are high. And a residual human coding workforce handles what the engine does not, which means people are in the chain as well as systems, and nothing states where they sit, whether they are employees or contracted, or how they access records. Ask for the base model, a sub processor list, the training position, and the location and access model of the human coding workforce.
The strongest evidence in the coding category, and it stops just short of an A for a specific reason.
A third party research organisation published a spotlight report validating automation rates above 90 percent alongside 100 percent high customer satisfaction, and separately ranked the company first for reducing the cost of care in its emerging solutions report. That is independent confirmation of the headline operational claim rather than a satisfaction survey alone, which is what most vendors in this index can show. A named customer reports 95.5 percent automation at 98.3 percent accuracy across all service lines.
What holds it at B is that accuracy remains vendor and customer reported. The automation rate has been verified by an outside party; the accuracy figure that makes the automation safe has not been independently audited against a gold standard, and the audit programmes referenced do not publish their results.
HITRUST i1 certification, obtained December 2024, is an independently assessed control set covering data protection and privacy rather than a self declaration, and the company framed the certification in exactly those terms.
The data handled is the complete clinical documentation for every encounter coded, which is the whole note rather than an extract, so the volume and sensitivity are high. What is not published is retention, whether customer documentation contributes to model development, or how the residual human coding workforce accesses records. That last question is specific to this model of business and worth asking.
Stronger than an assertion because HITRUST maps a certifiable control set onto health privacy requirements and is assessed by an external party, so the compliance claim rests on something checkable rather than on the company's own statement.
No business associate agreement posture or contractual documentation was located publicly. Given that the company contracts service level agreements with health systems, the underlying agreements are clearly negotiated in detail; none of it is public.
A named certification with its tier stated, which is the disclosure this index consistently rewards. HITRUST i1 was obtained in December 2024.
The tier is worth understanding rather than treating as a single badge. The i1 assessment sits above the entry level e1 and below the full risk based r2, covering a curated control set rather than the complete framework, so it is a real independent certification and not the most demanding one available. Held at B rather than A because no trust centre, report availability statement or penetration testing disclosure was located, and because a dedicated trust search was not run in this pass.
No device pathway applies and none is claimed. Assigning billing codes from documentation is an administrative act, not a clinical determination, so the absence of a clearance is correct.
The regulatory exposure sits elsewhere and is substantial. Codes submitted on a claim are representations to a payer, and where those are inaccurate the framework is federal false claims enforcement rather than device law. That makes the contractual accuracy commitment more interesting than it first appears: a vendor guaranteeing coding accuracy is taking a position adjacent to a compliance risk the provider ultimately carries, and a buyer should establish exactly how liability is apportioned when an automated code is later found wrong.
The audit programmes referenced amount to a monitoring mechanism, which is more than most records here have, and their results are not published.
Nothing addresses systematic drift, which is the governance question specific to coding. A model that assigns evaluation and management levels slightly high across a population increases revenue and compliance exposure together; one that assigns slightly low does the reverse quietly. Neither error announces itself in a single encounter, both are visible only in aggregate, and no distribution of assigned levels against expected benchmarks is published. Nor is any breakdown by specialty, payer or documentation style, all of which vary systematically between the physicians whose notes the model reads.
Numbers are published and one of them is stated in a form that deserves credit. Performance is given with figures rather than adjectives, and turnaround is reported as an average rather than a maximum, which is the harder and more honest of the two framings because a maximum can be met by a system that is usually slow and a stated average can be checked against experience.
An independently assessed certification covering data protection controls, obtained through a third party rather than self declared, sits alongside it. What is missing is the breakdown that matters for this product. No accuracy figure is published by coding element, and the elements are not equivalent: assigning an evaluation and management level is a harder and more consequential judgement than selecting a procedure code, because it rests on documented complexity rather than on a stated procedure, and it is the element most often challenged on audit.
A single aggregate figure across all elements therefore describes the easy cases and the hard ones together, and a buyer cannot tell which side of that mix their own specialty falls on. No confidence threshold for autonomous handling, no denial or reversal rate, and no warranty, indemnity or remediation commitment was located. Ask for accuracy by coding element, the autonomy threshold, and the rate at which coded claims are later denied or reversed.
The integration is the delivery mechanism rather than a feature: documentation is received from the record system after a visit and complete coding results are returned for claim submission, so the product sits inside an existing billing pipeline rather than beside it.
A third party review describes the integration with the dominant record system as among the smoothest available in this category, which is a comparative judgement from outside the company. Held at B because no interface standard, certification or mechanism is described publicly, and because integration with the claim submission side is as important here as the documentation side and is not detailed.
Not described. No hosting model, region, retention schedule or customer controlled option was located.
The throughput implied by a stated 57 minute average turnaround across a day's encounters means substantial volumes of complete clinical documentation move to the vendor and back daily, so the question of where that processing happens is a real one rather than a formality. Nothing published answers it.
No absolute price is published, and yet a buyer can evaluate the economics, which is why this earns a B rather than the usual D.
The company publishes cost relative to the alternative: a 30 to 50 percent reduction in cost to code, with a stated average of 42.3 percent. That is unusually useful because the alternative is a cost the buyer already knows precisely, namely what they currently spend on coding, whether in salaried staff or outsourced services. A percentage against a known internal figure produces a real number in a way a percentage against an unknown does not.
The service level agreements strengthen it further, since a contractual commitment on automation rate and accuracy implies remedies, and remedies imply the commercial terms are specific. What remains unpublished is the pricing mechanism itself, whether per encounter, per coder replaced or per volume band, and a buyer should ask which, because the risk profile differs sharply between them.
Broad within one function. Coding spans specialties rather than concentrating on one, with a named customer reporting automation across all service lines, and coverage extends to the full set of coding elements rather than the easy ones.
The buyer is a health system, provider group or coding operation, and the strength is described as high volume outpatient work, where encounter counts are large and documentation is comparatively structured. Nothing addresses non United States coding regimes, which is a real boundary given that coding systems are national.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
—
|
Not published in absolute terms. Cost reduction against existing coding spend is published, and contractual service level agreements cover automation rate, accuracy and turnaround. | Not published. HITRUST i1 certification provides externally assessed evidence of controls; the contractual position is negotiated and not public. | Not published. A risk free validation trial is offered before production go live, in which the provider checks coding quality on their own encounters. | Vendor Published |
No absolute price is published, but the economics can still be evaluated, which is unusual enough to lift this above the category norm. The company publishes cost relative to the alternative rather than in isolation: a 30 to 50 percent reduction in cost to code, with a stated average of 42.3 percent.
That is genuinely useful because the alternative is a figure the buyer already knows precisely, being what they currently spend on coding in salaried staff or outsourced services, so a percentage against a known internal number produces a real answer. Two things to establish before that number means anything. The pricing mechanism, since per encounter, per volume band and per coder replaced carry very different risk if volumes move.
And the treatment of the residual encounters the system declines, because a 90 percent automation rate leaves 10 percent needing a coder and whether the vendor prices that work, the provider absorbs it, or it falls under the service level agreement changes the total materially. The contractual service level agreements on automation rate, accuracy and turnaround imply remedies exist; ask what they are, since a guarantee without a remedy is a claim.