Infinx
Patient access and revenue cycle automation built around an agent platform the company calls a Healthcare Revenue Operating System. Founded 2012 and headquartered in Cupertino, California, originally as a radiology prior authorisation business, now spanning financial clearance, prior authorisation, document capture, coding, denials and accounts receivable. Backed by KKR and Norwest with roughly 194 million dollars raised, serving a reported 900 or more provider organisations, and having acquired the healthcare revenue cycle business of i3 Verticals.
The architecture is a three tier agent model stated plainly. Automation agents handle high volume repetitive work such as eligibility verification, claim status tracking and payment posting. Artificial intelligence agents handle work requiring cognitive reasoning and action, such as classifying and extracting patient detail from referrals or predicting denial risk before submission. Human agent specialists supplied by the company step in for complex denials, payer escalations, credential verification and prior authorisation exceptions. Agent suites sit on top: Patient Access Plus, Document Capture Plus and a revenue cycle suite, available standalone or integrated.
Membership was decided on the services filter and survived it. The company's own framing is technology led outcomes delivered through agentic solutions, outsourced operations and consulting, which puts technology rather than expertise in the load bearing position and inverts the Cotiviti formulation. Standalone solutions are offered without a services engagement. And in April 2026 its in scope revenue cycle and patient access platforms and supporting environments attained HITRUST Implemented one year certification under framework version 11.5.1: a certification is scoped to a product and an environment, which is evidence the platform is a discrete licensable thing rather than a wrapper on a service. The company does supply human labour as a named component, which is why the artificial intelligence centrality grade sits below the pure engines in this index.
Infrastructure is named more openly than most. Amazon Web Services is the cloud foundation, with a managed foundation model service used for summarisation and workflow understanding, alongside named data stores, private network segmentation, encryption at rest and in transit and permission gated file access.
One relationship connects this record to the coding lane. In August 2025 Infinx made a strategic investment in Maverick Medical AI to bring real time autonomous coding into its offering, which means part of the coding capability may originate outside the company. That relationship is documented from the other side in the Maverick record.
The gap across this record is measurement. No accuracy figure, automation rate, service commitment or price is published anywhere, and the only quantified customer outcome located is a single named practice reporting case handling time falling from roughly three and a half minutes to under one.
Capability Axes
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read
The models do substantial work and the company also sells the people. Its agent taxonomy names three tiers, and the third is human specialists supplied by Infinx who handle complex denials, payer escalations, credential verification and prior authorisation exceptions. Fully managed services are described as built in, so the customer's technical staff do not run the automation.
That is the honest reason this sits below the pure engines. Fathom and Arintra sell a model; this sells an orchestrated workforce in which models are the largest tier. The company is also explicit that the operating system framing is the value, positioning itself as connective tissue across patient access, mid cycle and back end rather than a point solution, which means the workflow and orchestration layer would retain worth even with weaker models.
Graded B rather than lower because the automation and reasoning tiers plainly carry the volume, and rather than higher because vendor supplied labour is a named part of the product. This is the same distinction that placed Optum Integrity One at B.
The routing model is described clearly and never quantified. Work is allocated across three tiers by character: repetitive high volume tasks to automation agents, tasks requiring cognitive reasoning to artificial intelligence agents, and exceptions requiring expertise to human specialists. That is a more legible allocation principle than several competitors publish, and human in the loop is stated as the operating model rather than a fallback.
What is absent is every number that would let a buyer size it. No automation rate, straight through processing share, accuracy figure or confidence threshold appears anywhere, so the proportion of work reaching completion without a human is unknown. No service level agreement, validation trial or benchmark offer was located.
The August 2026 platform description adds human in the loop oversight, monitoring and auditability as named layers of the operating system, which suggests the mechanism exists as engineering rather than as marketing. Its outputs are not published. Ask what share of each workflow completes autonomously and what triggers escalation to a human specialist.
The technique stack is enumerated and, unusually, part of the model supply chain is named rather than behind the word proprietary. Generative artificial intelligence, machine learning, natural language processing and robotic process automation are each identified, and the company states it uses a managed foundation model service from its cloud provider for summarisation and workflow understanding. Naming the model service at all puts this ahead of most of this index.
The operating system is described as eight layers spanning workflow execution, oversight, agent orchestration, monitoring, auditability and security controls, with agent suites configured on top. Data infrastructure is named down to the database and object storage services.
What is missing is performance and scope. No accuracy, precision or throughput figure appears for any agent suite. Output scope for the coding capability specifically is not enumerated, which matters more here than usual because a 2025 investment in another vendor's coding engine means part of that capability may originate outside the company and nothing states which parts are built and which are partnered.
Better party enumeration than almost anything else in this index, and still incomplete in the way that matters.
Named parties include the cloud provider, its managed foundation model service used for summarisation and workflow understanding, and the database and object storage services holding customer data. Network architecture is described specifically enough to see where data sits. Most competitors name none of this and hide the entire chain behind the word proprietary.
One further link is disclosed by circumstance rather than by the platform material. The company took a strategic investment position in Maverick Medical AI in August 2025 specifically to bring real time autonomous coding into its revenue cycle offering, which means a third party engine may sit inside the coding capability. That is public and it is not stated on the product pages, so a buyer evaluating the coding suite should establish what is native and what is partnered.
No sub processor list was located, no position on whether customer documentation contributes to model development, and no retention or de identification statement. The offshore operations component raises a chain question of its own that is unaddressed. Ask for the sub processor register, the training position, and the provenance of the coding engine.
Scale is claimed and outcomes are barely evidenced. The company reports serving more than 900 provider organisations across the United States, which if accurate is a substantial installed base and the largest customer count claimed by any record built in this sweep. Buyer types span hospitals, health systems, physician groups, imaging centres and laboratories, consistent with an origin in radiology prior authorisation.
Against that footprint the published evidence is thin. One named customer outcome was located, a practice reporting case handling falling from roughly three and a half minutes to under one minute on document intake. No accuracy measurement, denial reduction figure, cash acceleration figure or cost to collect figure is published for any agent suite. No third party research organisation assessment, buyer survey score, peer reviewed publication or independently audited measurement was found.
The HITRUST certification is real and is security assurance rather than performance evidence, and should not be read across. Graded C for a large claimed footprint with almost nothing measured attached to it. Ask for reference customers by agent suite and the outcome metrics behind the 900 organisation claim.
Protection is described concretely and stewardship is not addressed. Published controls include encryption at rest and in transit across the named database services, private network segmentation with internal services isolated from public access, internet facing services reached through a load balancer, and permission gated access to files and images generated by automation, with encryption applied to stored objects and during transfer. That is more infrastructure specificity than most vendors publish and it is externally corroborated by a health specific certification covering the in scope environments.
None of it answers what this axis asks. There is no retention schedule, no data ownership or deletion position, no statement on whether customer data contributes to model development, and no de identification position. Competitors in this index answer all four.
The question is sharpened by the delivery model. The company supplies human specialists who handle exceptions, which means people employed by the vendor access protected data as a routine part of the product, and it operates outsourced operations at scale. Nothing published describes where those personnel are located, what access controls govern them, or whether that access sits inside the certified scope. Ask.
Backed by a health specific external certification rather than an assertion, and stated with unusual precision about its own limits. In April 2026 the company's in scope revenue cycle and patient access platforms and supporting environments attained HITRUST Implemented one year certification following a validated assessment against framework version 11.5.1.
Three things make that disclosure better than the norm here. The tier is named, the framework version is named, and the scope is explicitly qualified as defined rather than presented as blanket coverage. Competitors routinely display a certification badge with no tier, no version and no scope boundary, and this index has recorded several such cases in this lane. Stating that the certification covers in scope platforms and supporting environments is a limitation the company did not have to publish.
The tier sits between Arintra's entry level certification and the full risk based assessment, matching what Fathom holds.
No business associate agreement posture, template, negotiation stance or execution requirement was located, and no privacy control enumeration comparable to CombineHealth's was found. Ask which platforms and environments fall inside the certified scope, and which do not.
One health specific credential, disclosed with more precision than is customary, and no trust center behind it.
The certification is stated with its tier, its framework version, the assessment type as a validated assessment, the date of April 2026, and an explicit scope qualifier describing coverage as the in scope platforms and supporting environments. Publishing the scope limitation rather than implying blanket coverage is a disclosure choice that works against the company's marketing interest, and this index credits it. The tier sits above the entry level certification Arintra holds and matches Fathom.
Supporting control detail is published on product pages rather than on a security page: encryption at rest and in transit, private network segmentation, restricted public access and permission gated object storage.
What is missing keeps it at B. No trust center exists as a standing page, no controls report of any type is mentioned, no report availability or request process, no audit period or assessor named, no penetration testing disclosure, no vulnerability disclosure policy and no subprocessor page. Ask which environments fall inside the certified scope, and whether a controls report exists alongside the certification.
No device pathway applies and none is claimed. Eligibility verification, prior authorisation submission, document capture, coding and denial management are administrative determinations rather than clinical ones, so the absence of a clearance is correct.
The usual coding exposure applies: codes on a claim are representations to a payer and error is governed by federal false claims enforcement landing on the billing provider.
One workflow warrants a distinction the company does not draw explicitly and a buyer should. The platform automates prior authorisation, and prior authorisation has two sides with very different regulatory weight. Automating the provider side, assembling and submitting requests and tracking approvals, is administrative. Automated determination of medical necessity on the payer side is a materially different activity now attracting legislative and regulatory attention in several states. Published material places this firmly on the provider side, obtaining approvals rather than granting them, and nothing suggests otherwise. Graded C because the position is correct and the boundary is nowhere stated for a product marketed to both providers and, historically, payer adjacent workflows.
Governance appears as named architecture and never as published output. The August 2026 description of the operating system lists human in the loop oversight, agent orchestration, monitoring, auditability and security controls as distinct layers, and the chief product officer frames the domain as high volume, exception heavy and audit sensitive. That is an accurate reading of the problem and it indicates the instruments were built deliberately.
Nothing from those instruments is disclosed. No distribution of agent decisions against a benchmark, no exception or escalation rate, no accuracy or precision measurement, no bias or fairness testing, no model validation methodology, and no external audit of agent output was located.
Two workflows here carry governance weight that coding alone does not. Denial risk prediction before submission decides which claims receive scrutiny, and a model that systematically misjudges risk for particular payers, service lines or patient populations would shift attention in ways invisible without distribution reporting. And automated eligibility and benefit determination touches patient financial exposure directly. Neither is examined in published material. Ask what the monitoring layer reports and whether any of it is shared with customers.
No performance figure of any kind is published, so there is no stated level against which a shortfall could be measured and nothing to hold the vendor to. No accuracy, precision, automation rate, straight through processing share or confidence threshold appears for any agent suite.
No service level agreement, warranty, indemnity or remediation commitment was located. No denial or reversal rate for automated work is published. No validation trial, pilot term or benchmark offer of the kind RapidClaims, XpertDox and AccuCode publish was found, so a buyer has no published route to establishing performance on their own data before committing.
The apportionment question is unusually layered here because the work is layered. Where an automated agent, a partnered coding engine and a vendor supplied human specialist all touch the same claim, responsibility for an error is genuinely harder to trace than in a single engine product, and nothing published addresses how it is allocated.
One pre emptive note for future passes: further scale, footprint or time saving figures cannot move this grade. Customer counts and case handling durations measure adoption and efficiency rather than accuracy or recourse. Only a published accuracy or exception rate measurement, or a contractual commitment on either, will change it.
Integration breadth is claimed in every direction and specified in none. Published material states the platform integrates with record systems, billing systems and payer platforms with real time data synchronisation, that extracted data flows from intake into the record system in real time and triggers next step actions, and that the company maintains secure connections to most payers.
That payer connectivity is the distinctive claim and it is genuinely differentiating, since prior authorisation and eligibility work depend on payer side integration that pure coding vendors never build. It is also the least verifiable statement on the record, because most payers is not a list.
No record system is named anywhere. No interface standard is described, no connection mechanism is specified, no vendor marketplace or programme listing was located, and target systems appear only as generic categories covering record, radiology and laboratory information systems. Competitors a fraction of this company's size name ten or twelve platforms and cite published standards.
Graded C for credible breadth with no published specification, consistent with how the same absence was treated elsewhere in this lane. Ask which record systems and which payers, and through what standards.
More architecture is published than by most, and the residency question itself is untouched.
What is stated is real: the cloud provider is named as the platform foundation, database and object storage services are named, internal services sit in private network segments, public access is restricted with internet facing services behind a load balancer, and stored objects carry access controls and encryption. A buyer can picture the topology, which is more than the silent competitors in this lane allow.
What is absent is where any of it runs. No processing or storage region, no residency commitment, no tenancy model and no customer controlled option was located.
The omission carries more weight here than for a pure software vendor because the company delivers outsourced operations alongside the platform and staffs human specialists who resolve exceptions. Whether protected data is processed, stored or accessed outside the United States is therefore both a hosting question and a personnel question, and neither is answered. The health specific certification covers in scope environments without those environments being publicly described. Graded C, at the top of the band for the architecture detail. Ask for regions, tenancy, and where exception handling personnel are located.
Nothing about cost is published. A dedicated pass across the company's platform, agent and solution pages located no pricing page, no unit of charge, no range, no implementation or onboarding fee position, no minimum commitment, no pilot or trial terms, no return calculator, and no percentage saving against existing cost to collect.
Every commercial route terminates in the same instruction to book time with a solution expert to discuss patient access, coding, revenue cycle solutions, full service outsourcing and custom automation build services. That the same call covers licensed software and outsourced operations is itself the finding: a buyer cannot tell from published material what the platform costs on its own.
One partial disclosure is worth noting. The company states the platform requires no new hardware or software investment and no months long setup, configuration or maintenance, which is an implementation burden claim rather than a price. Ask for the pricing mechanism per agent suite, whether the platform is licensed without a services engagement and at what difference in price, and how custom automation build work is charged.
Broad across the revenue cycle and across buyer types, with a documented origin that explains the shape. The company began in radiology prior authorisation and retains depth there, and now names hospitals, health systems, physician groups, imaging centres and laboratories as buyers.
Functional coverage is the widest of any record built in this sweep, spanning financial clearance, eligibility and benefit verification, patient payment estimation, prior authorisation, document capture from referrals and faxes, coding, claim submission, denial prevention and resolution, appeals and accounts receivable. Each is packaged as a named agent suite rather than described generically.
Two limits hold it at B. Specialty enumeration for the coding capability is absent, so a buyer cannot tell which specialties are supported or how performance varies, and that gap is wider given the coding engine may be partnered rather than native. And nothing addresses coding or payer regimes outside the United States. Ask which specialties the coding suite covers and whether prior authorisation depth still concentrates in imaging.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
Not published
|
Not disclosed. No unit of charge is described for any agent suite. Whether pricing is per transaction, per agent suite, per provider, per volume band or bundled into a broader outsourced engagement is unstated, and the same sales conversation covers licensed platform and full service outsourcing. | Not disclosed. No business associate agreement posture, template or execution requirement was located. The health specific certification attained in April 2026 covers in scope platforms and supporting environments at the implemented one year tier under framework version 11.5.1, which is a security assurance rather than a contractual privacy posture, and the boundary of that scope is not publicly described. | Not disclosed. The company states no new hardware or software investment is required and that setup, configuration and maintenance do not take months, with no fee position stated. Fully managed operation of the agents is described as built in, with no indication whether that is bundled or separately charged. | Vendor Published |
Nothing about cost is published. A dedicated pass across the platform, agent suite and solution pages located no pricing page, no unit of charge, no range, no implementation or onboarding fee position, no minimum commitment, no pilot or trial terms, no return calculator, and no percentage saving against existing cost to collect.
Every commercial route terminates in the same instruction to book time with a solution expert, and notably that single conversation is described as covering patient access, coding, revenue cycle solutions, full service outsourced revenue cycle management and custom automation platform build services together.
That bundling is the central commercial finding: a buyer cannot determine from published material what the platform costs licensed on its own, which matters because the platform being separately licensable is what carried this vendor past the services filter in the first place. Two partial disclosures exist.
The company states the platform requires no new hardware or software investment and no months long setup, configuration or maintenance, which is an implementation burden claim rather than a price. And fully managed services are described as built in, meaning operational running of the automation is included rather than charged to the customer's technical staff, with no indication of how that is priced.
Ask for the pricing mechanism per agent suite, whether the platform can be licensed without any services engagement and at what difference, how vendor supplied human specialist time is charged when exceptions escalate, and how custom automation build work is priced.