Keona Health
Keona Health is the closest thing in this index to Clearstep's opposite number, and the two make a useful pair. Both route patients using the same family of licensed telephone triage protocols. Clearstep puts a patient in front of them directly. Keona puts a nurse or a call centre agent in front of them, and only recently began letting a model take the call instead.
The company qualifies for this index on the newer half of that sentence, and the older half is what it actually sells. CareDesk, previously Health Desk, is a healthcare customer relationship management and patient access platform built for contact centre work: intelligent call routing, adaptive queues, scheduling, prescription refills, referral management, health information calls and care management, unified across phone, text, email, chat and web. Underneath the triage module sits Schmitt Thompson Clinical Content, licensed rather than written, covering more than 600 adult and paediatric topics, reviewed annually by a panel including triage nurses, call centre medical directors, primary care and emergency physicians, and used in the great majority of North American medical triage call centres. Practices can add their own protocols alongside it.
The artificial intelligence arrived on top of that architecture. Kara is an assistant that handles repetitive calls autonomously around the clock and transfers to staff with full context when a situation needs a person. CareDesk Flo is the phone agent, described as using intent checks and fallback logic as guardrails, with uncertain cases handed to a human and edge cases flagged for nurse review. This is a 15 year old protocol engine with a voice layer on it, which is a different proposition from a model native product and should be understood as one.
The safety design is the strongest part of the record. Escalation levels are defined and triggered by risk thresholds, running to on call physician contact, home care, urgent follow up or emergency referral. Protocols adapt to age, comorbidities, medications and a practice's own standard operating procedures. Every triage decision generates structured documentation aligned to the clinical reasoning pathway, explicitly to make the decision defensible afterwards, and supervisors get visibility into protocol adherence. Telephone triage doctrine including the duty to warn is built into the workflow rather than left to the nurse.
A spin out of the University of North Carolina at Chapel Hill, still headquartered there, founded around 2010 and grown deliberately small at roughly 23 employees. It began on a $450,000 grant from the National Institutes of Health and has raised about $10.1M in total, with Riverside Acceleration Capital named as an investor. Founder accounts differ across sources: the university's own 2014 announcement credits Oakkar Oakkar, now chief executive, with professor Javed Mostafa, while company and database sources name Oakkar Oakkar with Stephen Dean, now chief operating officer. Integration is claimed in real time with Epic, Cerner, Allscripts, athenahealth and Greenway, writing encounter notes back to the chart, and the platform is hosted on Microsoft Azure.
One thing a reader should weigh. The safety architecture is unusually well described and the performance claims around it are not verifiable, including a claim of independent audits showing better than 95 percent alignment with human decisions that names no auditor.
Capability Axes
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read
A long lived rules based platform with a model layer added on top, and the company draws that line itself rather than blurring it.
The core is an expert system. Triage runs licensed Schmitt Thompson protocols through adaptive branching that adjusts for age, comorbidities, medications and practice specific standard operating procedures, presented to a nurse or an agent through guided scripting. That machinery predates the current wave of artificial intelligence by more than a decade and works entirely without models: a nurse follows the protocol, the software keeps them consistent and documents the reasoning. Strip the models out and a working, saleable product remains, which is not true of Clearstep on the neighbouring record.
The models are real and recent. Kara handles repetitive calls autonomously and transfers with context when a person is needed. CareDesk Flo answers the phone, interprets what the caller wants, applies intent checks and fallback logic, and hands off uncertain cases. Voice handling, intent recognition and natural language routing are genuine model work and they are what admits this record.
The company's own positioning confirms the reading, describing CareDesk as solving problems that generic artificial intelligence and traditional answering services cannot handle, and describing 13 years of healthcare specific intelligence as the differentiator against software retrofitted for healthcare. That is an argument for the protocol asset, with the models as the newer interface to it.
Graded C, above Mindray TE Air because the models here conduct autonomous patient conversations, and below Clearstep because there the models are the product rather than a layer on it.
The best described safety architecture in this part of the index, and the detail is specific enough to be checkable rather than reassuring.
Escalation is defined by named levels rather than by a promise to escalate. When risk thresholds are met the system flags the appropriate step: on call physician contact, home care, urgent follow up or emergency referral. Protocols adapt to age, comorbidities, medications and the practice's own standard operating procedures, so the disposition reflects the patient rather than the symptom alone. Telephone triage doctrine including the duty to warn is built into the workflow, which is a genuine piece of clinical practice most software leaves to the nurse's memory.
Documentation is treated as a safety control rather than a byproduct. Every triage decision generates structured documentation aligned to the clinical reasoning pathway, stated explicitly as strengthening defensibility, and supervisors are given visibility into protocol adherence and performance patterns. That combination, a recorded reasoning trail plus adherence monitoring, is what lets an organisation find drift before it becomes an incident.
On the autonomous side the guardrails are described concretely. The phone agent applies intent checks and fallback logic, hands uncertain cases to a human, transfers with full context so the patient does not repeat themselves, and flags edge cases for nurse review.
Two things hold this at B. The figures attached to those guardrails, better than 95 percent alignment with human decisions and 90 percent of edge cases flagged, cite no source and cannot be checked, so the architecture is documented and its performance is not. And nothing published describes how under triage is detected after go live, which is the failure that does not report itself.
Clinical content provenance is the most precise on any record in this session, and the models are undescribed.
On the content the company goes further than naming a standard. It names the licensor, the editions and the authors: adult telephone protocols in their fourth edition by David A Thompson and paediatric telephone protocols in their sixteenth edition by Barton D Schmitt, links to the licensor's own site, and describes the maintenance process, an annual review by a panel including triage nurses, specialty nurses, call centre medical directors, primary care physicians, emergency physicians and specialists, informed by user feedback, statistical evidence and literature review. Edition numbers and a described review cycle mean a buyer can verify what version of the clinical logic they are getting and how it changes. Almost nothing in this index is documented to that standard.
Infrastructure is also named, with hosting on Microsoft Azure.
On the models there is nothing. No architecture, no speech recognition or language model vendor, no description of how intent checks or fallback logic actually work, no evaluation method behind the alignment figure, no versioning and no update cadence. For products whose entire function is conducting a conversation, the identity and behaviour of the conversational model is a reasonable thing to disclose and none of it is.
The contrast within one product is the finding. A buyer can name the edition of the protocol that decides the disposition and cannot name the model that decides what the patient asked for.
The content supply chain is documented better than anywhere else in this session and the model supply chain is not documented at all.
The licensed component is named to a level that permits verification. Schmitt Thompson Clinical Content is identified as the source of the triage logic, with the licensor's own site linked, the specific editions cited, adult protocols in their fourth edition and paediatric in their sixteenth, and the authors named. The licensor independently lists this platform among its partners, which corroborates the relationship from the other side rather than leaving it as a vendor assertion. The maintenance chain is described too, with annual review by a named composition of clinical reviewers. A buyer can therefore establish exactly what clinical logic they are running, who wrote it, which version it is and how it changes over time.
Infrastructure is partly visible, with Microsoft Azure named as the hosting platform.
The models are entirely dark. No speech recognition provider, no language model, no framework, no hosted conversational service and no component inventory is named for Kara or for the phone agent. Whether the conversational layer runs on a commercial foundation model, on a specialist healthcare voice provider or on models built in house is unstated, and that question determines where patient call audio is processed and which additional party is in the data path. A product that names the edition of its clinical protocols while declining to name the vendor whose model answers the phone has an unusual disclosure profile, and the gap sits precisely where the newest risk is.
Graded C.
Deployment is real and lightly documented, and the performance claims will not survive contact with a diligence process.
On the deployment side there is substance. The protocol licensor lists this platform among its partner solutions and describes use across the United States and Canada by health systems and group practices. A named client, PRN Healthcare, is described in a case study reporting results over 60 days against a baseline, addressing variability in triage decisions and onboarding time. Customer reviews on a public platform describe multi year use and the ability to layer custom protocols onto the licensed content. For a company of roughly 23 people that is a credible operating footprint.
The published performance claims are a different matter and one of them should be treated as unverified rather than as evidence. The phone agent page states that independent audits show better than 95 percent alignment with human decisions. No auditor is named, no audit is published, no method or sample is given, and no denominator is offered. A claim of that specificity about a product that decides how a patient's call is dispositioned needs a source. The same page states that 90 percent of edge cases are flagged for nurse review, again with no denominator, alongside implementation and pricing answers written to an identical template, which is a pattern worth noting when weighing any figure on that page.
Separately, a returns page cites category level research, a 93 percent triage accuracy figure for artificial intelligence assisted triage generally and a 15 to 20 percent operational cost reduction from published health policy research. Those are honestly labelled as category findings rather than product results, and they are not evidence about this product.
No independent evaluation of the platform was located. Graded C: the footprint carries the grade, the claims do not.
Nothing published addresses the data the models consume or produce. No retention period, no statement on whether call recordings, transcripts or triage encounters are used to train or tune models, no de identification standard, and no customer control over any of it.
The content at stake is broader here than on most records in this category, because the product spans two sensitive surfaces at once. Autonomous phone agents generate audio recordings and transcripts of patients describing symptoms, which is protected health information in its most identifiable form, since a voice recording cannot be de identified the way a text field can. And the platform writes encounter notes into the patient's chart, so the vendor is producing clinical documentation rather than only reading it.
One product description sharpens the question rather than answering it. The company states its assistant learns a customer's workflows during onboarding and adapts as they evolve. That is a claim about learning from customer specific operational data, and nothing published describes what that learning consumes, whether it stays within a single customer's tenancy, or whether anything derived from one practice can surface in another.
The company also publishes commentary through its own leadership on privacy enhancing infrastructure and the proper protection of health data, which suggests the subject is understood internally. None of that thinking has been turned into a statement a customer can rely on.
Graded D on the absence. A tenancy isolation statement and a plain answer on whether call audio informs model development would be the two most valuable disclosures available here.
Two concrete facts are published and the contractual layer is absent.
The first fact is architectural. The platform integrates in real time with electronic health record and practice management systems, pulling patient demographics and history into a single working view and writing triage encounter notes back into the patient's chart. That is a bidirectional protected data flow described plainly, and it establishes without ambiguity that the vendor processes protected health information on the covered entity's behalf.
The second is that hosting is named. The platform is described as fully compliant with the United States health privacy statute, cloud based, and securely hosted on Microsoft Azure. Naming the hosting platform is a small disclosure that does real work, because it tells a security reviewer which underlying control environment is in play and which agreements the vendor will itself have needed to execute upstream.
What is missing is everything contractual. No business associate agreement is offered or described, no terms are published, no protected data handling summary exists, and no document sets out what the vendor may and may not do with chart data it reads and encounter notes it writes. Compliance is asserted as a property rather than evidenced by a document, and a compliance assertion is not a control description.
Graded C, above Clearstep because the data flow and the hosting environment are stated, and below the vendors in the adjacent inbox category that publish trust surfaces and certification claims.
No published security posture was located. No service organisation control report, no health information trust certification, no independent audit reference, no trust centre, no penetration testing statement, no vulnerability disclosure policy and no incident notification commitment. The only security adjacent statements found are an assertion of compliance with the United States health privacy statute, a description of the platform as securely hosted, and a reference to the platform being eligible for use with protected data. Those are claims rather than evidence, and the hosting platform's own certifications belong to the hosting platform.
One detail makes the gap more pointed than a simple absence. The company's own leadership has published commentary on the federal interoperability framework, noting approvingly that it requires participating entities to maintain health information trust certification or an equivalent and to comply fully with health privacy law. That is an organisation demonstrably paying attention to a certification standard, writing publicly about its importance, and not publicly claiming to hold it. Either it is held and unpublished, or it is not held, and a prospective buyer cannot tell which.
Size is a fair mitigation and not an answer. At roughly 23 employees a formal certification programme is a real cost, and plenty of small vendors sell successfully without one. The vendors this record sits alongside include one of comparable size that publishes a trust centre and another that states certification at the type two level, so the bar is being cleared in this market by companies of this scale.
Graded D on published evidence rather than on any judgement about the underlying engineering.
No clearance is claimed and, for the original product, none is required. Software that guides a licensed nurse through published telephone triage protocols is the clearest case of clinical decision support intended to inform rather than to direct: the protocols are established clinical guidelines, the nurse can see the reasoning, and a qualified professional makes the disposition. Decades of nurse call centre practice sit behind that position.
The autonomous products complicate it and nothing published acknowledges the complication. When a phone agent takes a patient call, applies protocol logic and issues a disposition without a nurse in the conversation, the person exercising independent judgement over the recommendation has been removed, and the reasoning transparency that justifies the decision support position is no longer being read by a clinician in real time. That does not automatically make it a regulated device, and it is a materially different regulatory question from the original product, one that turns on how far the agent goes before a human is involved and on what dispositions it is permitted to deliver directly.
The company has an unusually good answer available and does not make it. Edge case escalation to nurse review, defined risk thresholds and licensed guideline content are exactly the controls that keep an autonomous triage agent on the informing side of the line. None of that is presented as a regulatory position, an intended use statement or a boundary the company has analysed.
Graded C, the same as Clearstep and for the same reason: a defensible position today, undocumented, on a product that is moving toward the boundary rather than away from it.
Nothing was located. No model card, no training data description, no accuracy breakdown, no subgroup analysis and no bias statement.
The exposure attaches specifically to the voice products. An autonomous phone agent must recognise intent from speech, and speech recognition performance is known to vary with accent, dialect, speech rate, age and speech impairment. A patient the agent understands poorly gets more clarification loops, a higher chance of being misrouted and a higher chance of abandoning the call, and abandonment in a triage context means a symptomatic patient who gave up trying to reach care. That is a differential access harm produced by a system sold to widen access.
The protocol layer mitigates part of this and only part. Schmitt Thompson content is reviewed annually by a clinical panel and carries decades of use, so the disposition logic is not the weak point. The weak point is what the model believes the patient said before the protocol logic runs, and no evaluation of that step is published in any form.
The adaptive claim adds a second unexamined surface. The assistant is described as learning a customer's workflows during onboarding and adapting as they evolve, and an adapting system needs monitoring for drift and for the possibility that adaptation encodes a practice's existing routing inequities. Nothing published describes that monitoring.
Graded D. Recognition accuracy by accent and language, published as a range rather than a marketing number, would be the most useful disclosure this vendor could make.
The only record in this session where a vendor has clearly thought about defensibility, and it stops short of a published position on liability.
What exists is genuine and it is designed in rather than bolted on. Every triage decision generates structured documentation aligned to the clinical reasoning pathway, and the company states the purpose plainly, that this strengthens defensibility. Protocol adherence is visible to supervisors, so an organisation can show not only what was decided but that the decision followed the protocol it was supposed to follow. Anyone who has watched a telephone triage claim knows this is the material that decides it: what the nurse asked, what the patient said, which protocol was applied and what advice was given. Building the evidentiary record automatically is a real contribution to the customer's liability position.
What does not exist is anything about the vendor's own. No indemnity, no limitation or allocation clause published, no performance warranty on an autonomous disposition, and no recourse route if the phone agent misroutes a caller. The three way division between the vendor, the protocol licensor whose content determines the disposition and the practice whose nurses supervise it is unaddressed, and it is a genuinely hard question that a customer will otherwise meet for the first time during a claim.
The autonomous products widen the gap. When a nurse takes the call, the documentation defends the nurse's decision. When the agent takes the call and no nurse was involved, the same documentation records a decision nobody has published a position on owning.
Graded C, the highest on this axis in this session, on the strength of the defensibility design alone.
The strongest integration claim in this part of the index, and it rests on claims rather than on documentation.
Five electronic health record and practice management systems are named for real time integration: Epic, Cerner, Allscripts, athenahealth and Greenway. The direction of flow is stated in both directions, pulling patient demographics and clinical history into a single working view during the call, and writing triage encounter notes back into the patient's chart afterwards. Write back is the half most vendors in this category do not do, and it is what makes the difference between a triage conversation that lives in a contact centre log and one that becomes part of the clinical record. The platform also acts on the record rather than only reading it, handling appointment scheduling, prescription refills, referral management and follow ups.
The breadth of the named list matters commercially. A five system footprint means a health system running a mixed estate after acquisitions can standardise the contact centre without standardising the record, which is a common and expensive problem.
Two things hold this at B rather than higher. No mechanism is described anywhere located, so whether this runs on modern interoperability standards, on vendor specific interfaces or on per customer integration work is unknown, and that determines implementation cost and who bears it. And no marketplace listing was located in either of the major record vendor marketplaces, where two vendors in the adjacent inbox category appear in both, which would have provided independent confirmation that an integration exists as described.
One useful fact is published and the rest is not. The platform is described as a cloud based multi tenant service hosted on Microsoft Azure. Naming the hosting platform is a small disclosure that does more work than it appears to, because it tells a security reviewer which underlying control environment, certification set and regional footprint are in play before any conversation with the vendor begins. Most vendors in this category do not say even this much.
Everything past the platform name is undisclosed. No region is stated, no residency option is offered or ruled out, no subprocessor list exists, no retention or export position is described, and nothing addresses what happens to a customer's data at contract end.
Residency is not academic here. The protocol licensor describes this platform in use by organisations in both the United States and Canada, and Canadian provincial health information legislation places real constraints on where personal health information may be stored and processed. A Canadian customer either has a specific arrangement or is relying on something not described publicly, and a prospective Canadian buyer cannot tell which from anything published.
Availability deserves a mention on a product of this kind. The autonomous agent is sold substantially on after hours capture, converting calls that would otherwise reach voicemail, so the value depends on the service being up overnight and at weekends. No availability commitment, uptime record or disaster recovery position was located.
Graded C, one band above the equivalent record for Clearstep on the strength of the named hosting platform alone.
No numbers and more structure than most, which lands this above the floor and well below the leaders.
What is published is the shape of the deal. Pricing for the phone agent is stated as based on call volume rather than per seat licensing, which is the single most useful thing a buyer can know before a quote, because it tells them how cost scales with growth and whether adding staff is penalised. Implementation is described at four to six weeks for most organisations. The company recommends a no cost proof of concept followed by a 90 day pilot, which is a real commercial commitment and a low risk entry path for a mid sized practice.
What is missing is every figure. No rate per call, no minimum volume, no platform fee, no tier structure across CareDesk, the triage module, Kara, Flo and the analytics product, and no contract length. A buyer cannot model annual cost from anything published, and with volume based pricing the exposure is precisely the thing that varies most between practices.
One further gap is specific to how this product is built. The clinical content is licensed from a third party and practices can also author their own, and nothing published states whether the protocol licence is included, priced separately, or carried directly by the customer with the licensor. That is the same unanswered question as on the Clearstep record and it matters more here because the content is more central to what is being bought.
Graded C. Publishing a per call range would move this to a B without exposing anything a competitor could not already estimate.
Clinical breadth is inherited and genuine, and organisational reach is mid market rather than enterprise.
The licensed protocol library covers more than 600 adult and paediatric triage topics, which is the widest clinical coverage on any record in this part of the index, and the paediatric half is explicit rather than assumed. Named specialties in the vendor material include obstetrics and gynaecology, urology, family medicine and ear, nose and throat, and the software is described as supporting both low and high acuity triage conducted by clinical and non clinical staff, which is an unusual and useful distinction: the same platform guides an agent who cannot give clinical advice and a nurse who can.
Channel coverage is complete for this category, spanning phone, text, email, chat, web and self service, with after hours capture explicitly included, and the workflow set extends past triage into scheduling, refills, referrals, health information calls and care management.
Buyer types are described as large specialty and multi specialty groups, health systems, medical practices and call centres across the United States and Canada, and the protocol licensor confirms use in both countries. No enterprise scale deployment is named anywhere located, and the customers that do appear are a staffing and telehealth organisation and mid sized practices, which is consistent with a company of roughly 23 people.
Graded B: excellent clinical and channel breadth, modest and largely unnamed organisational reach.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
No pricing published; phone agent priced on call volume rather than per seat
|
Call volume based for the phone agent; platform and module pricing unstated, protocol licensing terms unstated | Not published | Not published; implementation stated at four to six weeks, with a no cost proof of concept and 90 day pilot offered | Vendor Published |
No figures are published and the structure is described, which puts this above the floor without giving a buyer anything to model.
The useful disclosure is the basis. Pricing for the autonomous phone agent is stated as based on call volume rather than per seat licensing, and the company presents that as deliberate, arguing it makes the product workable for small clinics and large systems alike. Basis matters more than price at the evaluation stage, because it tells a buyer how cost behaves as they grow: a volume model means adding staff is not penalised and seasonal surges are, which is the opposite exposure from the per provider per month ladders published in the adjacent inbox category.
Two other commercial terms are stated. Implementation is described at four to six weeks for most organisations, and the company recommends starting with a no cost proof of concept followed by a 90 day pilot. A free proof of concept is a real commitment for a company of roughly 23 people and it lowers the risk of a bad fit substantially.
Everything numeric is absent. No rate per call, no minimum volume, no platform or seat fee for the underlying CareDesk platform, no tier structure across the platform, the triage module, the assistant, the phone agent and the analytics product, and no contract length. With volume based pricing the absence of a rate means the exposure cannot be estimated at all, and volume is exactly the variable that differs most between practices.
One question specific to this architecture is unanswered, as it is on the Clearstep record. The clinical protocol content is licensed from a third party, and nothing published states whether that licence is included in the price, charged separately, or held directly by the customer with the licensor. Anyone evaluating this should settle it in writing, because it is a recurring cost attached to the part of the product that does the clinical work.