RCM & Prior Auth AI
H

Humata Health

Humata Health automates prior authorisation end to end, and its distinguishing claim is that the process can be made touchless: a clinician enters an order in the record system, and the platform determines whether authorisation is required, assembles the clinical documentation that supports it, and submits it, without further human involvement. In February 2026 Allegheny Health Network was named the first United States health system to run medical prior authorisation that way from order to approval.

The company is based in Winter Park, Florida and was founded in 2023 by Jeremy Friese, a radiologist trained at Mayo Clinic and Harvard who is chairman and chief executive. He had earlier co founded Verata Health, which the health automation company Olive acquired in 2020, and served as a president of Olive; when Olive wound down, its remaining assets went to Waystar and to Humata. It raised 25 million dollars from a syndicate that is notable for who is in it: alongside Blue Venture Fund, LRVHealth and .406 Ventures sit Optum Ventures and Highmark Ventures, both arms of large payer organisations.

The positioning is provider side and the company describes itself as built for yes, but it operates across the divide. It integrated the intelliPath technology of EviCore by Evernorth, a utilisation management business, so that provider clients reach a broad payer network. In June 2026 it launched what it describes as the first artificial intelligence enabled prior authorisation portal designed for providers rather than payers, extending beyond large health systems to independent practices, regional centres and specialty clinics. Its technology has also been made available within Microsoft Dragon Copilot.

It sits inside the federal reform of this process as well. It joined the Centers for Medicare and Medicaid Services electronic prior authorisation acceleration initiative, and was selected as a technology partner for the WISeR model, standing for Wasteful and Inappropriate Service Reduction, which went live in January 2026 and applies artificial intelligence driven clinical review within Medicare. The company also supports an industry commitment to return more than 80 percent of prior authorisation decisions in real time by 2027.

AI Health Index verifiedAugust 8, 2026
Compare Humata Health with other vendors
Founded
2023
Headquarters
Winter Park, Florida
Categories
rcm-and-prior-auth, healthcare-admin-automation
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
BB on AI CentralityThe model is the engine of a core module. The platform carries other value, but this capability does not exist without it.
Vendor Published

Two assets carry this product and only one of them is a model. Deciding whether a given order requires authorisation, then finding and assembling the specific clinical evidence a specific payer needs to approve it, is genuinely a reasoning task over an unstructured chart.

The other asset is the network. The company's own framing is that the hardest part is making systems at every payer talk to systems at every hospital, and it describes building that connectivity and holding the largest ecosystem of integrations in the category. That is the moat is the network case this index applies elsewhere, and it is why the grade is B: a competitor with an equal model and no connections could not deliver the same outcome.

BB on Autonomy and Oversight ModelThe oversight structure is described and one part is missing, commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

The demonstrated position is high. At a named health system the company reports authorisation running from order to approval with no human intervention at any point, which is full automation of a process that normally consumes a dedicated department.

What holds it at B is that the claim is anchored to a first rather than to a rate. Nothing published states what share of requests complete touchless across the customer base, at what confidence the system stops and hands to a person, or what happens when the assembled documentation is insufficient. A category whose failure mode is a patient waiting needs those numbers, and the comparison record in this index for high autonomy publishes an automation rate and contracts to it.

Worth noting on the correct side of the ledger: the automation here assembles a case for approval rather than issuing a denial. The consequential decision still sits with the payer.

CC on Model and Technology TransparencyThe architecture is described in general terms with nothing identified. Proprietary is asserted rather than explained.
Vendor Published

The workflow is described clearly and the technology is not. No model, architecture or method is named, no accuracy or completeness figure is published for the documentation the system assembles, and the claim of the largest integration ecosystem in the category carries no count of integrations or payers.

That matters more than usual because the product's core act is a judgement: deciding which parts of a chart constitute evidence that a specific payer's criteria are met. A buyer cannot tell from public material how often that judgement is right, only that at one health system it was right often enough to run untouched.

DD on Model Supply Chain DisclosureNothing establishes who else sits between a patient record and an answer.
Vendor Published

No retention schedule, encryption detail, model training position, hosting arrangement or sub processor list was located. The data movement is worth naming because it is the point of the product rather than a side effect: the system reads the chart to find supporting evidence and then transmits that clinical documentation to a payer, so its function is to move patient information across an organisational boundary, from an entity the patient chose to one they did not.

How much it sends, whether it sends more than the criteria require, and what the payer retains are all questions a provider should ask, and the incentive runs the wrong way. Over disclosure in pursuit of approval is a real failure mode rather than a hypothetical one, because more supporting evidence makes approval more likely and nothing in the workflow rewards restraint, so a system optimised for approval rate will tend to send more of the chart than the criteria strictly need.

The minimum necessary principle is precisely what that pressure erodes. Nothing published describes whether the assembled packet is scoped to the criteria, whether a human reviews what is being sent before it goes, or what the payer is permitted to do with clinical narrative it received for an authorisation decision. Ask all three, plus retention on the assembled packet at both ends.

CC on Clinical and Operational EvidenceNamed customers, or vendor reported percentages with no method, denominator or reference standard. Scale of use is recorded here and is not treated as evidence of benefit.
Vendor Published

Corroboration is unusually strong and measurement is absent, and this index does not let the first substitute for the second.

What exists: a named health system reported as the first in the country to run fully touchless prior authorisation, selection by the federal Medicare agency as a technology partner for a live national model, participation in a federal acceleration initiative, and an integration with a major utilisation management business. Selection by a public agency after its own process is a meaningful external signal, and stronger than most vendor references here.

What is absent: any published rate. No touchless percentage, no turnaround time distribution, no approval rate comparison against the manual process, and no study. The company's own goal, that the industry return more than 80 percent of decisions in real time by 2027, is a target rather than a result.

CC on AI Safety and PHI StewardshipGeneral assurances of privacy and security that do not answer the questions artificial intelligence raises: what is retained, what reaches a model, and what happens to it there.
Third Party Estimated

Graded on an honest basis. No retention schedule, encryption detail or model training position was located in this pass.

The data movement is worth naming because it is the point of the product. The system reads the chart to find supporting evidence and then transmits that clinical documentation to a payer, so its function is to move patient information across an organisational boundary. How much it sends, whether it sends more than the criteria require, and what the payer retains are all questions a provider should ask, since over disclosure in pursuit of approval is a real failure mode rather than a hypothetical one.

Regulatory and Compliance
CC on HIPAA and BAA PostureCompliance is claimed without the underlying document, or the published privacy notice covers the website rather than the service that handles patients.
Third Party Estimated

Graded on an honest basis. No compliance statement or agreement posture was located in this pass.

The contracting picture is more layered than usual because the company serves providers, integrates with a utilisation management business, and acts as a technology partner to a federal agency. Those are three different relationships with three different sets of obligations, and which governs a given data flow is not described publicly.

CC on Security Certifications and Trust CenterControls are described with an outside check behind them, such as independent penetration testing on a stated cadence, but no attestation against a recognised framework.
Third Party Estimated

Recorded honestly and provisionally: the dedicated trust and security search this index requires was not run in this pass, and no attestation was encountered incidentally.

Selection as a technology partner in a federal Medicare model implies security review by the agency, which is a demanding gate, and nothing about it was retrieved.

CC on FDA and Regulatory StatusNo device claim is made and the product is scoped accordingly. Most administrative and operational products sit here and are not penalised for it, because this axis grades the appropriateness of the positioning rather than possession of a clearance.
Vendor Published

No device pathway applies and none is claimed. Assembling and submitting an authorisation request is administrative.

The regulatory environment is nonetheless the most consequential of any record in this category, and it changed in January 2026. Federal interoperability and prior authorisation requirements now mandate electronic submission and faster turnaround, which is what makes this segment move. Separately, the Medicare agency's own model applying artificial intelligence to clinical review went live in the same month with this company as a technology partner.

So the buyer is purchasing into a process that is being restructured by regulation while they buy, and the vendor is helping build the infrastructure the regulation assumes. That is a strong commercial position and a reason to read the vendor's public statements about the direction of reform as those of an interested party.

DD on AI Governance and Bias DisclosureNothing published on how model behaviour is governed or tested. Multilingual operation with no subgroup performance sits here when the vendor markets recognition quality as a strength, because a caller the system failed to understand leaves no complaint and no record.
Vendor Published

Nothing published on evaluation, monitoring, error rates or subgroup performance, and the position this company occupies makes that gap the most important thing on the record.

The company's provider facing identity is built for yes, and the automation it sells assembles a case for approval. It is simultaneously a technology partner in a federal Medicare model named for the reduction of wasteful and inappropriate services, which applies artificial intelligence to clinical review. Those are not contradictory, and they are not the same job either: one accelerates approval, the other exists to decline what should not be paid for. The same capability serves both.

Nothing published describes how the company separates them, what governs the model on the federal side, or how a patient or clinician would learn that an automated review contributed to a decision about their care. Given that this index has already recorded several states restricting artificial intelligence driven coverage denials, a vendor operating on both sides of that line should be expected to say more.

DD on AI Liability and RecourseNothing published on what happens when the system is wrong.
Vendor Published

The workflow is described clearly and the technology is not: no model, architecture or method named, no accuracy or completeness figure for the documentation the system assembles, no evaluation methodology, and no warranty, indemnity or remediation commitment, while a claim to the largest integration ecosystem in the category carries no count of integrations or payers. That matters more than usual because the product's core act is a judgement rather than a transfer.

It decides which parts of a chart constitute evidence that a specific payer's criteria are met, which is an interpretive task with two distinct failure modes: assembling a packet that omits the element the payer needed, producing a denial that looks like a clinical disagreement rather than an assembly error, or asserting that criteria are met on evidence that does not support it.

A buyer cannot tell from public material how often that judgement is right, only that at one health system it was right often enough to run untouched, and a single site's tolerance is not a performance figure. The affected party is a patient whose authorisation was delayed or denied, and who will never learn that the packet rather than their clinical picture was the problem.

Ask for the approval rate on submissions the system assembled unaided compared with human assembled ones, the rate of denials attributable to missing documentation, and what the system does when it cannot find supporting evidence.

Integration and Deployment
BB on EHR and Interoperability DepthNamed systems with read access or one directional writing, or standards support with named deployments behind it.
Vendor Published

Interoperability is the product rather than a supporting feature. The workflow starts when a clinician enters an order in the record system and ends with a payer decision returning, which requires live connection at both ends, and the company describes the payer to hospital connectivity problem as the central obstacle it is solving.

Distribution reinforces it: the technology is available within a widely deployed ambient clinical assistant, so authorisation can be initiated from inside the documentation workflow, and an integration with a utilisation management platform extends payer reach. Held at B because no named record vendor certification, interface standard or count of payer connections was located.

CC on Deployment Model and Data ResidencyA single hosted option with location implied rather than committed.
Third Party Estimated

Not described. No hosting model, region or retention position was located.

A product that transmits clinical documentation to payers and to a federal programme is moving regulated data between several organisations, and where it rests in between is not published.

Commercial
DD on Commercial TransparencyNothing a buyer can establish before a sales conversation. A published pricing claim contradicted by evidence also grades here.
Vendor Published

Nothing published: no price, no mechanism, no unit of sale.

The unit question is sharper here than usual because the company now sells to two very different buyers. A large health system replacing an authorisation department has a different economics from an independent practice where one person handles prior authorisation between other duties, and the new provider portal is aimed squarely at the latter. Per request, per provider and per site would each land very differently across that range. Ask which applies, and ask what happens to the fee when a request is denied, since the vendor is paid for work whose value to the provider depends on the answer.

BB on Setting and Specialty CoverageCoverage is named with validation behind part of it.
Vendor Published

Broad within one process and deliberately widening. The company states coverage of all services and procedures rather than a subset, which distinguishes it from vendors handling only specialty drugs or only imaging, and prior authorisation is specialty agnostic by nature.

The buyer range expanded materially in June 2026, from large health systems and provider groups to independent practices, regional health centres and specialty clinics, which are the settings where this work is still done by fax and telephone. Reach extends to payers through the utilisation management integration and to Medicare through the federal model. Held at B because everything sits inside one administrative process and coverage is United States only, which is inherent since prior authorisation is a feature of this payment system.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Not published. Sold to health systems and provider groups, and since June 2026 to independent practices through a self contained portal. Not located. Three distinct relationships exist, with providers, with a utilisation management business, and with a federal agency, and which governs a given data flow is not described publicly. Not published. Deployment requires live connection to the record system at one end and to payers at the other. Vendor Published

Nothing is published: no price, no mechanism, no unit of sale. The unit matters more than usual because the company now sells to two very different buyers. A large health system replacing a staffed authorisation department has entirely different economics from an independent practice where one person handles prior authorisation between other duties, and the provider portal launched in June 2026 targets exactly that second group.

Per request, per provider, per site and a flat enterprise licence would land very differently across that range. Two questions to put in writing. What happens to the fee when a request is denied, since the vendor is paid for work whose value to the provider depends entirely on the answer, and a per request model with no outcome condition pays the same for a rejection as for an approval.

And whether pricing differs by payer, since the touchless outcome depends on the connection to that specific payer and the company's own account is that connectivity is the hard part. Worth asking for the touchless rate achieved at comparable customers before agreeing any per request price, because that rate determines whether the fee replaces staff cost or sits on top of it.