Flexbone
Flexbone builds artificial intelligence agents for the back office of outpatient healthcare, deliberately aimed at the organisations large vendors skip. Its strategic argument is stated plainly: the great majority of outpatient facilities do not run Epic or Cerner, the best funded competitors have built for Epic, and the rest of the market is left to systems nobody integrates with. Flexbone's answer is multi modal agents rather than interfaces. Voice agents answer and place calls for scheduling, triage, post operative follow up and payer follow up, navigating payer phone menus and holding on the line.
Browser agents log into practice systems and payer portals the way a member of staff does, verifying eligibility across more than 25 portals and submitting prior authorisations where no interface exists. Document agents ingest denial letters, classify the cause against the encounter and republish corrected claims to clearinghouses. Voice Room, the product named on this list, plugs into an existing telephone system and analyses every call rather than the small sample manual quality review reaches, producing sentiment, compliance monitoring and automated scoring. Named system targets include Tebra and an ambulatory surgery centre platform. The company publishes entry pricing, begins engagements with a no cost operational audit, and embeds forward deployed engineers during implementation.
Capability Axes
Models do the work across every part of the product. Voice agents conduct both inbound and outbound calls including navigating payer telephone menus, document agents read denial letters and classify cause against an encounter, and call analytics runs over every conversation.
The browser automation layer is the least model dependent component, since driving a portal is closer to scripted automation than to inference, but it is the smallest part of the value and it is put to work by the same agents that handle the conversation. Remove the models and what remains is a set of empty integrations.
The healthcare specificity is genuine rather than a vertical wrapper: eligibility carve outs, telehealth parity rules and denial cause taxonomies are not concepts that exist in any other industry's back office.
A stated human review step, which several peers in this segment lack. Voice agents escalate clinical or sensitive calls to staff with the transcript attached, and the company states that a human reviews the exceptions the agent flags. One action deserves particular attention and is not addressed: document agents republish corrected claims to clearinghouses, which means software is submitting a claim on a provider's behalf.
Claim submission carries its own liability, since accuracy of a submitted claim is the submitting provider's responsibility regardless of what generated it. The published design reviews exceptions, and the unanswered question is what happens to everything the agent does not flag as exceptional. A practice should establish what proportion of corrected claims a human sees before they go out.
Two passes located no architecture description, no model detail, no validation methodology and no accuracy figure for any component. Three outcome numbers circulate, a 30 percent reduction in eligibility denials, more than 200 staff hours saved and a 43 percent improvement in first contact resolution, none with a baseline, denominator, time period or source.
A second problem compounds the first and is a source quality issue rather than a technical one: almost everything discoverable about this company is written by the company, and much of it takes the form of competitor comparison pages framing rivals. That is a legitimate marketing strategy and it means an assessor has essentially no independent material to weigh, so every claim here rests on a single interested source.
Two retrieval passes located no named customer, no case study with an identified organisation, no publication, no independent evaluation and no third party coverage of any kind. The outcome figures quoted across the company's material are unattributed to any deployment. This is a fuller absence than most records in this index carry, because usually at least one customer is named or one journalist has written something.
The company is candid in one respect that partly offsets this, stating in its own comparison material that it is newer than vendors with hundreds of enterprise deployments and advising organisations that need a long track record to check deployment references carefully. Volunteering that is unusual and is credited.
The strongest claim available is made and then left ambiguous. The company states a zero retention architecture in which patient data is processed for analysis but never stored, which it correctly notes would eliminate an entire category of breach risk. If that holds for raw recordings and transcripts it is a better position than any retention policy.
The tension is that the same platform is sold as operations intelligence that surfaces patterns such as billing confusion and scheduling friction before they affect revenue, and detecting a pattern across time requires retaining something.
The likely reconciliation is that raw protected information is discarded while derived structured data persists, which would be entirely reasonable, but that is not what the sentence says, and an ambiguous security claim resolves in the vendor's favour by default. Ask precisely what is discarded, what is kept, and for how long.
Better than most in this segment and specific enough to be useful. The company states HIPAA compliance with a Business Associate Agreement as standard rather than as something to be negotiated, and names actual technical controls rather than gesturing at security: encryption at rest, encryption in transit and role based access, each with the standard identified. Naming the agreement as standard matters practically, because a buyer who knows the agreement is routine can plan a timeline.
Held at B rather than A because no agreement terms, privacy page or subprocessor list was located, and the subprocessor question is live for a product built on voice and document models, which frequently route through external providers.
The precise wording matters here and it is doing a lot of work. The company states that it operates with SOC 2 Type II controls. That is not the same as holding a SOC 2 Type II report. Implementing controls of that kind is a statement about design that the company makes about itself; a Type II report is an independent auditor's finding that controls operated effectively across a defined period.
The phrasing invites the stronger reading while committing only to the weaker one, and two passes located no report, no auditor and no examination period. Placed against the others this index has graded in the same segment, the scale now runs: an audited portfolio naming standard versions and report type earns an A, a published badge with the type unstated earns a B, a dated Type 1 examination with the auditing firm named earns a C, a claim of Type II controls with no report earns this C, and an unevidenced assertion of being secure earns a D. Naming specific encryption and access controls, which this company does, is what keeps it out of the bottom band.
No clearance, authorisation or submission located and none needed. Answering telephones, checking eligibility and appealing denials is administrative work. The regulatory exposure that does attach is again not device law: automated claim correction and resubmission sits inside payer contracting and, at its outer edge, federal false claims liability, where the submitting provider carries responsibility for accuracy however the claim was produced.
Prior authorisation automation likewise operates inside payer rules that vary by contract. A buyer assessing this product against a device framework would be examining the wrong statute, and the questions worth asking concern claim accuracy controls and audit trails.
Nothing published, and two exposures are specific. The first is now familiar and this is its seventh appearance in this index: speech recognition accuracy varies with accent, dialect, first language, age and emotional state, and voice agents answering an outpatient practice line encounter all of it, with no subgroup or per language performance published. The second is more particular to this product.
Voice agents are described as running post operative calls at ambulatory surgery centres, capturing pain scores and recovery checks and escalating anything abnormal. Pain scoring by an autonomous agent is a clinical assessment however lightly framed, and what counts as abnormal is a threshold somebody set. No validation of that threshold, no false negative rate and no clinical sign off is published. That is the component to ask about first, ahead of anything on the billing side.
The most interesting strategic position on this record. Rather than competing for integrations into the systems everyone builds for, the company targets the long tail explicitly, arguing that the overwhelming majority of outpatient facilities run neither of the two dominant record systems and are therefore served by nobody.
Its method is the notable part: browser agents that log into a practice system or payer portal exactly as a member of staff would, which works against software that exposes no interface at all, and voice agents that navigate payer telephone menus, which works where there is not even a portal. Substituting a login or a phone call for an integration is a pragmatic answer to a real structural problem.
Named targets include Tebra and an ambulatory surgery centre platform, plus more than 25 payer portals and clearinghouse submission. Held at B rather than A because none of it is evidenced at scale: no customer count, no volume figure and no named deployment were located.
No hosting architecture, named region or residency commitment located in two passes, though the zero retention claim discussed on the stewardship row would, if it holds in the strong form, make residency a smaller question than usual since there would be less persisting anywhere.
The implementation model is unusual and worth recording: forward deployed engineers embedded with the customer during rollout and afterward, which is a services heavy approach to deployment that suits the long tail of small practices with no technical staff, and which also means the economics depend on people as well as software. That is a durability consideration rather than a criticism.
The clearest commercial disclosure encountered in this index outside a listed company, and it is voluntary rather than compelled. Entry pricing is published openly, starting at 99 dollars per month, which the company itself notes is uncommon in healthcare artificial intelligence, and it is right about that: this index has recorded a D on this axis for vendor after vendor precisely because no price exists anywhere a buyer can read.
Alongside it sits an audit first sales model in which every engagement begins with a no cost operational assessment, so an organisation sees its own data and its own gaps before committing to anything. That inverts the normal sequence, where a buyer must commit to discovery before learning whether a problem is worth solving. The honest limit is that a starting price is a floor rather than a schedule, and what a multi site group actually pays is not published. Artrya remains the benchmark for publishing mechanism, rate and concentration risk together, but this is the closest a private company in this index has come.
Wide across outpatient functions and deliberately narrow on organisation type. The functional span runs from the front desk through the revenue cycle: inbound and outbound calling, scheduling, triage, after hours cover, post operative follow up, eligibility verification, prior authorisation, denial appeal and clearinghouse resubmission, which is more of the operational chain than most single vendors attempt.
Customers are independent practices, specialty groups, ambulatory surgery centres, multi location groups and outsourcers serving providers, rather than large health systems, and specialty specific detail such as behavioural health carve outs and telehealth parity appears in the eligibility material, which suggests real depth rather than a generic engine. Geography is the United States. Held at B because the breadth is functional rather than evidenced, and because covering this much of the chain at a small organisation places considerable dependence on one supplier.
Compared With
Editorial comparisons are published only where the index assesses two vendors as direct competitors for the same buyer. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.