Health System AI Platforms
H

Health Catalyst

Health Catalyst sells health systems the data layer beneath their improvement work, plus the people to run it. The company describes two operating segments in its filings. Technology is the larger and covers a cloud data platform, analytics applications and support, sold as cloud subscriptions and term licences. Professional Services covers analytics, implementation, strategic advisory, outsourcing and improvement services, positioned as the expertise a customer needs to configure and actually use the technology. That structure is the defining fact about this company: the improvement outcomes it markets are attributed to the combination of software and expert labour rather than to software alone.

Ignite is the current platform. It ingests electronic health record, claims, financial and operational data through prebuilt source starter sets, profiles it for quality, resolves patient and provider identity, and exposes a unified data model that customers query with their own business intelligence and modelling tools if they prefer. Ignite Intelligence, introduced in 2025, layers shared models, software agents, benchmarks and comparison services on top. Clinical Cost Intelligence is the flagship example and its published method is unusually specific for this lane, combining supply normalisation, ontology mapping, machine learning driven variation analysis and large language model assisted opportunity screening to move service line costing from months of analysis to immediate results. Healthcare.AI is sold as a mix of self service model building products and expert services covering analytics integration, model selection and model optimisation.

Much of the estate arrived by acquisition and is co branded rather than absorbed. Twistle, Upfront and Lumeon are all sold as products by Health Catalyst, a patient engagement tool, a patient experience platform and a care orchestration engine respectively. An interoperability and health information exchange suite carries the company name after having been acquired as Medicity. Registry, quality measure and revenue cycle applications sit alongside them.

Security disclosure is the strongest part of the public record. A dedicated information security page enumerates which certifications cover which named products, with framework versions and explicit coverage periods, spanning HITRUST certification across three business unit product families and audited reports at the type two assurance level. Recertification has continued through 2025 across the acquired brands.

More than 1,100 organisations are stated to use the offerings, across hundreds of millions of patient records. Headquartered in Salt Lake City and listed on the Nasdaq exchange.

Three things a reader should weigh. Trailing twelve month revenue stood at roughly 302 million dollars as of March 2026 against a market capitalisation of roughly 154 million dollars at the end of July 2026, a company valued below one year of revenue, and a buyer signing a multi year data platform contract should form its own view of what that indicates. Revenue growth is described as modest with full year guidance reduced and restructuring under way. And the headline claim of billions of dollars in measurable results appears across company material with no method, no time period and no breakdown.

AI Health Index verifiedAugust 26, 2026
Compare Health Catalyst with other vendors
Founded
Headquarters
Salt Lake City, Utah, United States
Categories
health-system-ai-platforms, vbc-intelligence
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
CC on AI CentralityArtificial intelligence is a feature layer on a product whose value stands without it.
Vendor Published

Real inference doing real work, inside a company whose own description of itself places expert labour beside the software as a peer rather than a supplement.

The artificial intelligence is not decorative. Ignite Intelligence combines shared models, software agents, benchmarks and comparison services. The flagship costing application publishes its method at a level of specificity most vendors in this lane avoid: supply normalisation, ontology mapping, machine learning driven variation analysis, and large language model assisted screening of improvement opportunities. Naming four distinct techniques and what each contributes is more disclosure than the category norm, and the underlying task, finding cost variation across procedures and service lines that a human analyst would take months to surface, is a genuine inference problem.

Where the grade settles is the surrounding business. The Professional Services segment exists to configure and operate the technology, and the improvement results the company markets are attributed to that combination. The platform is also explicitly open to customers bringing their own modelling and business intelligence tools, and Healthcare.AI is sold as products alongside expert services for choosing and optimising models. Strip the models out and a substantial business remains: a healthcare specific data model, standardised measures and registries, identity resolution, an interoperability suite and a large consulting practice.

Graded C on the same reasoning applied to Arcadia and Huma in this index, where the differentiating asset is the platform and a meaningful share of the intelligence belongs to the customer or is delivered by people.

Ask which shipped applications produce output no analyst could produce, and what share of a typical contract value is technology rather than services.

CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.
Vendor Published

Autonomy varies sharply across the product estate and no single oversight model covers it.

The analytics core is advisory in the ordinary way. Dashboards, registries, benchmarks and costing analysis surface to analysts and improvement teams who decide what to do, and the newer intelligence layer is described as a co pilot, which is the right framing for output that informs a decision made over weeks or months.

The acquired applications behave differently. A care orchestration engine automates steps in a care pathway, and patient engagement and experience products reach patients directly with messages and prompts. Those act rather than advise, and the person affected is a patient rather than an analyst. Software agents in the intelligence layer point the same direction. That is not a criticism of the design, since automated pathway steps and outreach are the point of those products, but it means the company now spans passive analysis and active patient contact under one roof.

What is absent is any unified account of oversight across that range. Nothing located describes which actions execute without a person approving them, what a clinician can override, whether overrides are recorded, or how an orchestration rule is reviewed once live. Oversight of an analytics dashboard and oversight of an engine that messages patients are different problems and the published material treats the estate as one.

Graded C for a clear posture on the analytics core, unstated for the products that act.

Ask which actions execute without human approval, what the override path is, and how live orchestration logic is reviewed.

CC on Model and Technology TransparencyThe architecture is described in general terms with nothing identified. Proprietary is asserted rather than explained.
Vendor Published

Method disclosure that is genuinely above the category norm, sitting on top of models that are not described at all.

The published methods are specific. The flagship costing application names supply normalisation, ontology mapping, machine learning driven variation analysis and large language model assisted opportunity screening as distinct techniques with distinct roles. Naming what each contributes tells a technical evaluator how the result is produced, which is materially more than a claim to be powered by artificial intelligence. Architecture is also described concretely, with prebuilt source collections, data profiling, identity management, a unified data model and named cloud and data platform partnerships.

One design choice deserves particular credit. Customers may bring their own modelling and business intelligence tools and work against the same data model, which means a customer who wants to inspect or replace the vendor's analysis can do so. Transparency implemented as an architectural option is worth more than transparency asserted in marketing copy.

Everything about model performance remains closed. A dedicated pass located no model card, no accuracy or calibration figure, no validation methodology, no retraining cadence, no drift monitoring account, and no identification of the large language model used in the screening layer. For a company that markets transparency as a property of its artificial intelligence offering, the absence of a single published performance number is the notable gap.

Graded C: method and architecture disclosed unusually well, model performance not at all.

Ask for accuracy figures on the variation analysis, the base model behind the screening layer, and the retraining cadence.

DD on Model Supply Chain DisclosureNothing establishes who else sits between a patient record and an answer.
Vendor Published

Infrastructure dependencies are named and the model dependencies are not.

The visible part is genuine. A major cloud data platform partner is named as the infrastructure underneath the analytics layer, and a major public cloud is documented as hosting at least one acquired application. A buyer can therefore identify who holds the data and reason about the concentration risk that follows.

The inference layer is closed. A large language model performs opportunity screening in the flagship costing application and is not identified, so a buyer cannot tell whether an external provider processes clinical and financial content, what that provider retains, or what happens to the product if a version is deprecated or output behaviour changes. A dependency that cannot be named cannot be assessed, and this one sits inside the application the company promotes most.

No sub processor register was located, and no subcontractor list covers either the software or the services side. The services dimension is the one this index rarely encounters. Outsourcing is a named component of the services segment, and outsourced analytics labour has a supply chain of its own, including who the people are, where they sit and what they can see. Nothing located addresses it.

The acquired estate compounds the problem. Applications built by different companies carry whatever third party components their original builders chose, and nothing describes whether those inventories have been consolidated or even collected.

Graded D.

Ask for the sub processor register, the model behind the screening layer, and where outsourced services personnel are located and what data they access.

BB on Clinical and Operational EvidenceNamed deployments with dated outcome figures and enough method to test them, or published research short of independent validation.
Third Party Estimated

Scale that can be checked against audited filings, a long published improvement record, and an aggregate claim that cannot be examined.

The verifiable part is unusual for this index. As a listed company, customer count, revenue, segment mix and growth are filed rather than asserted, so the claim of more than 1,100 organisations sits alongside audited financial statements a reader can inspect. Very few vendors graded here can be checked that way at all, and it removes the most common doubt about scale claims in this category.

The improvement record is long and specific. The company publishes named customer case studies across clinical quality, cost, operations and population health, and improvement measurement is the organising idea of the business rather than a marketing layer over it. Independent recognition includes leader placement in an analyst radar report for population health management.

Two things hold this below the top grade. No peer reviewed publication was located, which is notable for a company positioned around measurable clinical improvement and operating at this scale for this long. And the headline figure, billions of dollars in measurable results delivered, appears across company material without a method, a time period, a customer breakdown or any account of how a result is attributed to the platform rather than to the improvement programme the customer ran around it. That attribution question is the hard one in this category and the number is presented as though it were settled.

Ask how measurable results are attributed and verified, over what period, and across how many customers.

CC on AI Safety and PHI StewardshipGeneral assurances of privacy and security that do not answer the questions artificial intelligence raises: what is retained, what reaches a model, and what happens to it there.
Vendor Published

Solid custodial engineering, and one published phrase that raises the central question without answering it.

The stewardship apparatus is described and credible. Data profiling examines and summarises incoming data for quality issues, identity management resolves patient and provider records centrally, and the whole estate sits under audited security frameworks with named product scope. For a platform whose function is joining records that arrived separately, deliberate identity resolution and continuous quality inspection are the correct controls.

The phrase that needs an answer is shared models. Ignite Intelligence is described as combining shared models, software agents, benchmarks and comparison services, and benchmarking across a customer base is presented as a benefit. Comparison against peers requires other customers data in some form, and nothing located states whether that form is aggregated statistics computed under contract, or model parameters learned from one customer and applied to another. Those are very different arrangements with very different consent and business associate implications, and the published material does not distinguish them.

The large language model layer adds a second unanswered question. An application that screens improvement opportunities from clinical and financial data passes that content to a model, and no statement was located covering retention, output logging, or whether an external model provider processes it.

Graded C: the data handling engineering is credible and the model data governance is undisclosed at exactly the point where the product claims most value.

Ask what shared means in shared models, whether learning crosses customer boundaries, and what any external model provider retains.

Regulatory and Compliance
BB on HIPAA and BAA PostureBusiness associate status is stated and supported by a substantive privacy document, with the agreement or its scope not fully published. For a vendor outside the United States, an equivalent regime documented to this depth grades here.
Vendor Published

The control posture is documented to an unusual standard and the contractual terms remain private.

What lifts this above the category norm is scoping. A public information security page names which certifications and audited reports cover which products, states framework versions, and gives explicit coverage periods rather than asserting compliance at the company level. That distinction matters a great deal in practice, because a compliance claim covering an unspecified subset of a large product estate is close to meaningless, and a customer buying one application can determine here whether that specific application is in scope. Coverage extends across the data platform, interoperability, population health, patient engagement, clinical quality, patient safety, cost and revenue cycle families.

Business associate status is the correct and obvious posture for a processor handling identified clinical, claims and financial data on behalf of providers, and the framework used maps regulatory requirements onto an audited control set rather than leaving the mapping to assertion.

What is missing is the agreement. No template business associate agreement, breach notification window, liability cap position, audit rights statement or data return provision was located. The services segment adds a dimension most vendors here do not have, since consultants and outsourced staff work inside customer environments and the material located does not describe how personnel handling protected health information are governed, screened or bound.

Graded B for genuinely scoped, current and verifiable compliance documentation, held below the top by the absence of any contractual detail.

Ask for the template agreement, the breach notification window, and how services personnel are governed when working inside a customer environment.

AA on Security Certifications and Trust CenterCertifications named with their type and version and presented as retrievable artefacts, usually through a trust portal a buyer can open without asking.
Third Party Estimated

The best security disclosure encountered in this lane, and the reason is scoping rather than volume.

A public information security page states which certification covers which named product, which framework version applied, and the exact coverage period of each audited report. That is the disclosure a buyer actually needs. A company level claim to be certified says nothing about whether the specific application being purchased was in scope, and product estates assembled through acquisition are precisely where that gap normally hides. Here it is closed by publication rather than by request.

The substance behind the scoping is current and independently examined. Certification under the demanding healthcare assurance framework covers three business unit product families, including the data platform, interoperability, population health, patient engagement, clinical quality, patient safety, cost and revenue cycle applications. Audited reports at the type two assurance level, which test whether controls operated effectively across a period rather than whether they were designed correctly at a moment, are listed with their coverage windows. Publicly available general use reports are offered alongside the restricted ones, which lets an evaluator see the control environment before a confidentiality agreement is in place.

Currency is demonstrated rather than claimed. Acquired applications have been brought into certification progressively through 2024 and 2025 with individual dates given for each, which shows an ongoing programme rather than a one time achievement, and it answers the question a buyer would otherwise have to ask about every acquisition. A named chief information security officer speaks for the programme publicly.

Graded A. Scoped to the product, current, independently audited at the operating effectiveness level, and published rather than gated.

CC on FDA and Regulatory StatusNo device claim is made and the product is scoped accordingly. Most administrative and operational products sit here and are not penalised for it, because this axis grades the appropriateness of the positioning rather than possession of a clearance.
Vendor Published

Outside device regulation by function, with the boundary approached from an unusual direction.

Data aggregation, benchmarking, cost variation analysis, quality measurement and registry reporting are administrative and financial activities rather than diagnosis or treatment, so no clearance is required and none is claimed. Making no regulatory claim where none applies is the honest position.

The company does carry regulatory weight in the reporting domain. Quality measures and registries produced on this platform feed submissions that determine payment and public reporting, and the accuracy of that output is externally consequential even though it is not device regulated. A regulatory and cybersecurity solution line indicates the company treats compliance reporting as a product category in its own right.

The boundary case here is care orchestration rather than a clinician facing assistant. Software that automates steps in a care pathway, deciding when a patient is contacted, when a task is raised and when a protocol advances, sits nearer to clinical workflow than a dashboard does, and how such logic is classified depends on whether it merely executes clinician authored rules or applies inference to a clinical decision. Nothing located addresses which description applies as models are introduced into that layer.

Graded C: correctly outside device regulation, genuinely consequential in payment and public reporting, and unexamined at the one boundary that is moving.

Ask how care orchestration logic is classified as inference enters it.

DD on AI Governance and Bias DisclosureNothing published on how model behaviour is governed or tested. Multilingual operation with no subgroup performance sits here when the vendor markets recognition quality as a strength, because a caller the system failed to understand leaves no complaint and no record.
Vendor Published

The governance structure exists on the organisation chart and the disclosure does not exist on the public record.

The structural signal is real and worth crediting. A named chief artificial intelligence officer sits in the leadership team and speaks publicly about product design, which is more accountability than most vendors in this index have assigned to anyone. Healthcare.AI is also marketed on transparency as an explicit property rather than an afterthought.

Nothing follows it into the public record. A dedicated pass located no published bias testing, no subgroup performance figures, no fairness review process, no model documentation and no statement of what any predictive model takes as its target variable.

The exposure is the documented one for this category. Population health risk stratification built on claims and utilisation history has a widely cited failure mode, where using historical cost as a proxy for health need understates illness in Black patients because less had historically been spent on them, and correcting the target variable substantially changed who was enrolled in additional care. Cost variation analysis carries a related risk from the opposite direction: a model identifying providers or service lines as high cost outliers may be detecting patient complexity and social need rather than inefficiency, and acting on that finding shifts resources away from the populations who generated the cost.

Both harms are silent. A patient never enrolled is never told, and a service line trimmed on a variation finding produces no adverse event report.

Graded D. A chief artificial intelligence officer is structure, and this axis measures disclosure.

Ask what target variables the models predict, whether subgroup performance has been measured, and what review a model passes before release.

DD on AI Liability and RecourseNothing published on what happens when the system is wrong.
Vendor Published

Recourse is undefined at every point where a buyer would need it, and the services structure makes the question harder rather than easier.

A dedicated pass located no indemnification position, no warranty covering model or analytic output, no accuracy guarantee, no service credit regime tied to data quality or availability, and no described route for a customer to dispute an output it believes to be wrong.

The failure modes are financial and specific. A quality measure computed on incompletely ingested data moves a reported score and the payment attached to it. A cost variation finding that misreads patient complexity as inefficiency drives a real operational decision with real consequences for a service line. An orchestration rule that misfires reaches patients directly. Each is a quantifiable loss that traces back to work this vendor performed, and none has a stated remedy.

The services segment complicates attribution in a way that is unusual in this index and works against the customer. When implementation consultants configure the platform, advisory staff design the improvement programme and the vendor's own experts interpret the output, the line between a defective product and a customer that used it badly becomes very difficult to draw. That ambiguity is normally resolved in whichever direction the contract specifies, and nothing about how these agreements allocate it is published.

Graded D.

Ask for the indemnification position on quality and regulatory submissions, whether any accuracy warranty attaches to analytic output, and how fault is allocated when the vendor's own consultants configured the system.

Integration and Deployment
AA on EHR and Interoperability DepthNamed bidirectional integrations with major record systems, verifiable in marketplace listings or integration documentation, with evidence the connection runs in production.
Vendor Published

Interoperability is a product line here rather than a capability, which is the strongest form this axis can take.

The company owns and sells a health information exchange and interoperability suite as a distinct offering, acquired as an established exchange business and now carrying the company name, with its own security certification scope. A vendor that sells exchange infrastructure to regional data sharing organisations is operating at a different level from one that connects to source systems for its own purposes, because the exchange must serve participants who are not its analytics customers.

The ingestion side is correspondingly deep. Prebuilt source collections cover electronic health record and claims systems alongside financial and operational data, which makes a new source an onboarding step rather than an engineering project. Data profiling analyses and summarises incoming data for trends and quality problems, identity management resolves patient and provider records so that data from many systems is centrally accessible, and a unified data model gives a single access point across everything mapped.

The openness of the far end matters as much as the breadth of the near end. Customers may point their own business intelligence and modelling tools at the mapped data, and the platform is integrated with a major cloud data platform partner. Data that arrives easily and can then be taken elsewhere is a materially different proposition from data that arrives easily and can only be viewed in the vendor's own screens.

Scale supports the claim, at more than 1,100 organisations and hundreds of millions of patient records.

Graded A. Owning exchange infrastructure, prebuilt ingestion breadth, identity resolution and an open consumption layer, held together.

CC on Deployment Model and Data ResidencyA single hosted option with location implied rather than committed.
Vendor Published

Cloud based on named infrastructure, with tenancy, residency and continuity unstated.

The established facts are useful as far as they go. The platform is a cloud technology ecosystem, one acquired application is documented as hosted on a named public cloud, and a partnership with a major cloud data platform provider is described as the modern architecture underneath the analytics. A technical buyer can therefore identify the infrastructure layer, which is more than most records in this lane offer.

The unresolved questions are the ones a security review asks. Whether customer data occupies a dedicated tenancy or a shared environment with logical separation is not stated, and it matters here because benchmarking and comparison services depend on some form of cross customer computation, so the tenancy boundary and the analytical boundary are not obviously the same line. Geographic residency is not addressed, no region selection is described, and no position on data leaving a jurisdiction is published despite customers being described as worldwide.

Continuity is absent. No recovery objective, availability commitment or failover description was located, for a platform health systems run quality reporting and cost management on continuously.

The estate assembled by acquisition raises a further question the material does not answer, since separately acquired applications with separately scoped certifications may well sit on separately architected infrastructure, and nothing describes whether a customer buying several is buying one deployment or many.

Ask whether tenancy is dedicated or shared, where data resides, the recovery objective, and whether the acquired applications share infrastructure.

Commercial
DD on Commercial TransparencyNothing a buyer can establish before a sales conversation. A published pricing claim contradicted by evidence also grades here.
Vendor Published

Cost is absent from every published surface. A dedicated pass located no pricing page, no unit of charge, no range, no tiering, no implementation fee position and no minimum commitment.

The listing status is worth addressing directly, because it looks like transparency and is not the transparency this axis measures. Filings disclose what the company earns, how revenue splits between technology and services, and how that is trending. None of that tells a prospective buyer what they will be charged. Revenue divided by customer count produces a number that means very little, because the installed base ranges from single application users to full platform customers with large services engagements, and the filings do not decompose it in a way that lets anyone place themselves in the range.

The services segment is the specific reason the gap matters more here than for a pure software vendor. When implementation, advisory and improvement services are a reported segment rather than a line item, the professional services attach is structural, and a customer signing for the technology is very likely also signing for labour. The ratio between the two is the single most useful number a buyer could have and it is not published in any form a buyer could apply to themselves.

Module count compounds it. Data platform, interoperability, patient engagement, care orchestration, clinical quality, registries and revenue cycle are sold as distinct capabilities, and nothing indicates how cost accumulates as scope grows.

Ask for the unit of charge, the typical ratio of services to technology in first year cost, how modules price incrementally, and the contract term.

BB on Setting and Specialty CoverageCoverage is named with validation behind part of it.
Vendor Published

Among the broadest coverage in this index, spanning function, setting and buyer type.

Functional coverage runs across clinical quality and patient safety, cost and revenue cycle, population health and value based care, patient engagement, care orchestration, regulatory reporting and health information exchange. Setting coverage extends from acute care into ambulatory, with a product line specifically addressing acquired and independent ambulatory practices where access, panel management, provider productivity and referral management are the operative problems. Health information exchange participation extends reach past a single organisation to regional data sharing.

The supporting assets are the reason this is coverage rather than a list. Standardised measures and registries mean specialty specific measurement is prebuilt rather than assembled per customer, and prebuilt source collections for electronic health record and claims data mean a new setting is an onboarding task rather than an engineering project.

Scale corroborates it, with more than 1,100 organisations stated across hundreds of millions of patient records, a figure sitting alongside audited filings rather than standing alone.

What holds it at B is depth per area. Breadth of this kind is assembled partly through acquisition, and the material located does not establish how deeply any single specialty is served relative to a focused competitor, nor how well the acquired products integrate with one another rather than merely being sold together.

Ask how deeply integrated the acquired application suites are with the core platform, and what a single specialty gets beyond standard measures.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Not published
Undisclosed Not published Not published Vendor Published

A dedicated pass located no pricing page, no unit of charge, no range, no tiering, no implementation fee position and no minimum commitment. Public company status does not close this gap: filings disclose what the company earns and how revenue splits between technology and services, which tells a shareholder something and tells a prospective buyer nothing about what they will be charged.

Revenue divided by stated customer count is not usable, because the installed base spans single application users and full platform customers with large services engagements and the filings do not decompose it. The services attach is the material unknown, since implementation, advisory, outsourcing and improvement services form a reported segment rather than a line item, so a customer buying the technology is very likely also buying labour, and the ratio between the two is the single most useful figure a buyer could have.

Contracts are described as cloud subscriptions and term based licences plus maintenance and support, which establishes the shape and not the magnitude. Module count compounds it across data platform, interoperability, patient engagement, care orchestration, clinical quality, registries and revenue cycle.