Kyruus Health
Kyruus Health is the incumbent in patient access and the only vendor in this part of the index that sells the same platform to both sides of the market. Where Loyal Health serves provider organisations and RadiantGraph serves payers, Kyruus does both, which is the direct result of an acquisition strategy rather than a product decision.
The foundation is provider data rather than conversation. The platform maintains a single authoritative source of provider information across a network, ingesting, curating and cleansing records from multiple systems, then distributing that data outward to health system websites, scheduling systems, search engines, listings, record systems and payer directories. Everything else depends on it: a matching engine cannot route a patient to the right clinician if the underlying data on specialty, insurance, language, location and availability is wrong, and provider directory inaccuracy is both a chronic operational problem and a regulated one for health plans. The commercial products sit on top as named modules covering listings management, provider search, patient self scheduling with direct record system integration, and digital intake, payment and check in, alongside published application programming interfaces for search, availability and scheduling.
The artificial intelligence claims are concentrated in three places and are more specific than most in this category. Data quality monitoring identifies inaccurate or outdated provider records across a directory. Patient to provider matching connects a person to an appropriate clinician on specialty, location, insurance, language and availability rather than on a keyword. And conversational search, launched for health plans, replaces filter and jargon driven directory navigation with natural language, with the company's own chief product officer framing complex filters and clinical jargon as the barrier being removed. Predictive access analytics identifying where access barriers exist across a network are also described.
Scale is the strongest fact on the record and predates the current artificial intelligence positioning by years. Public statements have described 600 hospitals and more than a quarter of a million providers, 70 health systems and 100 health plan brands after the payer acquisition, and more than 80 million health plan members reached through the acquired payer business. Named health system customers include Intermountain Health. Record system integrations are named for Epic, Oracle Health, MEDITECH and athenahealth.
Founded in 2010 in Boston by Graham Gardner and Julie Yoo, with roughly $196M raised across ten rounds from Highland Capital Partners, Venrock, Francisco Partners, Providence Ventures, Cambia Health Solutions, UPMC Enterprises and Salesforce Ventures. The company acquired HealthSparq from Cambia in 2021, opening the health plan business, and Epion Health in 2022, adding digital patient engagement and intake. Kyruus Health was itself acquired by RevSpring in September 2025, and the brand continues to trade under its own name, which is why it is enrolled.
Two things a reader should weigh. The platform is now three companies joined together and nothing published describes how far the underlying technology has actually been unified, so a buyer should establish which module carries which heritage. And the artificial intelligence is real but sits on the data layer rather than in front of the patient, so this is a matching and directory business with models inside it rather than a conversational product.
Capability Axes
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read
A data management business with models inside it, which is a different proposition from a model business and should be read as one.
The foundation is a provider data platform: ingesting, curating and cleansing records from multiple sources into a single authoritative directory, then distributing that data to websites, scheduling systems, search engines, listings, record systems and payer directories. That work is data engineering, integration and governance, and it would remain valuable if every model were removed. Health plans buy it partly because directory accuracy is a regulatory obligation, and a regulatory obligation is satisfied by correct data rather than by intelligent data.
The models sit on top and three are described specifically enough to credit. Data quality monitoring identifies inaccurate or outdated provider records at directory scale, which is a classification problem no rules engine handles well. Patient to provider matching routes a person on specialty, location, insurance, language and availability rather than keyword lookup. Conversational search interprets a natural language description of a need and returns providers, explicitly replacing filter and jargon driven navigation.
The company's own framing supports the reading rather than contradicting it. Its published commentary positions accurate data as the precondition for artificial intelligence in patient access, and a report it issued in late 2025 argued that unreliable provider data is stalling artificial intelligence integration for health plans. That is a company arguing its data layer matters more than its model layer, which is unusual and is probably correct about its own business.
Graded C: real models doing real work, on a product whose centre of gravity is the data underneath them.
Low inherent risk by design, with one consequential decision made autonomously and no published governance around it.
Nothing here diagnoses, triages or advises. The models rank providers, flag suspect directory records and interpret a search query, and a human always chooses from the results. A patient who dislikes the matches scrolls, refines or calls, so the ordinary failure mode is friction rather than harm. That is a materially safer profile than the triage products on the neighbouring records and it is why this does not grade lower.
The consequential decision is ranking. Deciding which clinicians appear, and in what order, in response to a described need determines who patients actually reach, and most people choose from the first few results. That is an allocation decision made without a human in the loop for each instance. Nothing published describes what governs the ordering, whether availability, network economics, panel capacity or referral value influence it alongside clinical fit, or whether a health system can weight it commercially. For a platform whose customers include organisations with growth objectives, whether a match can be tuned toward employed providers over independent ones is a fair question and is unaddressed.
The data quality models raise a second and smaller version. Flagging a provider record as outdated is a recommendation to a human operations team rather than an automatic change, and the company's own material makes that explicit, noting that technology alone cannot maintain directory accuracy without process change. That is an unusually honest statement of a product's limits.
Graded C: correctly bounded, with the ranking logic undisclosed.
Functional description is unusually specific and the mechanisms are entirely undisclosed.
What is described is better than the category norm. Three distinct capabilities are named with what each does: data quality monitoring identifying inaccurate or outdated provider records across a directory, matching connecting patients to clinicians on specialty, location, insurance, language and availability, and conversational search interpreting natural language in place of filters. Predictive access analytics identifying where access barriers exist across a network is a fourth. Naming the specific attributes the matching engine considers is genuinely useful, because it tells a buyer what the model can and cannot account for, and most vendors describe matching as intelligent without saying on what.
The platform architecture is also clearly laid out, with named modules and published application programming interfaces for search, availability and scheduling, so a technical buyer can understand the integration surface without a sales conversation.
Below that, nothing. No architecture, no training data, no accuracy or precision figures for any model, no evaluation method, no versioning and no update cadence. For conversational search, no language model provider is named and nothing states whether interpretation runs on a commercial foundation model or on in house work.
The ranking weighting is the specific omission worth naming, since knowing that matching considers five attributes says nothing about how they are weighted against each other, and the weighting is the product.
Graded C: a clear account of what the models do, and none of how.
No upstream dependency is named for any model, and the corporate history makes the question harder rather than easier.
Nothing states whether the matching engine, the data quality monitoring or the conversational search are built in house, licensed, or assembled on commercial foundation models. For the conversational capability, launched most recently and doing natural language interpretation, no provider is named and no statement establishes whether interpretation runs on an external service. That is the layer where an outside party would most likely sit and where customer search queries would flow to it.
The assembled history compounds it. This platform is three companies joined: the original provider data and matching business, a payer transparency business acquired in 2021, and a patient engagement business acquired in 2022, with the whole acquired again in 2025. Each brought its own technology stack and its own third party dependencies, and nothing published describes how far those have been unified or what components came along. A buyer asking what runs underneath a given module has no starting point, and the answer plausibly differs by module.
One upstream category is partly visible and it is data rather than models. Provider information is described as ingested and curated from various sources, which implies external data suppliers, licensed reference data and public registries feeding the directory. None of those sources is enumerated, and for a product whose entire value is data accuracy, the provenance of the input data is a reasonable thing to disclose.
Graded D as an absence of disclosure rather than evidence of a problem.
Deployment evidence is the strongest of any vendor built in this session, and evidence for the models specifically is thin.
The footprint is large, long established and stated consistently across years rather than assembled for a marketing page. Public statements have described 600 hospitals and more than a quarter of a million providers, 70 health systems and 100 health plan brands following the payer acquisition, and more than 80 million health plan members reached through that acquired business. Named customers include Intermountain Health, a 33 hospital not for profit system with more than 3,900 employed clinicians, expanding its use of the matching platform to power a rebranded digital patient experience, and a named 60 location medical group. A 2021 emerging technology spotlight from an independent healthcare research firm is cited.
One quantified outcome is published for the payer side, an increase in member interactions of up to 114 percent from enhanced provider profiles. It is a vendor figure with no method, no baseline and an up to qualifier, so it indicates direction rather than magnitude.
What is missing is any evaluation of the intelligence. No measurement of matching accuracy, no study of whether patients routed by the model reach a more appropriate clinician than those who navigate filters, no data quality detection precision or recall, and no independent evaluation of the conversational search. For a platform whose central claim is a better match, the absence of a published match quality measure is the notable gap, and the company's own trademark line makes that claim explicitly.
Graded B: scale and named enterprise deployment carry the grade, with the product's core claim unmeasured in public.
Nothing published addresses what the platform retains or learns from, and the most sensitive data here is the kind people do not think of as clinical.
Provider search queries are the overlooked category. When someone types a description of a symptom or a condition into a health system or health plan directory, that query reveals what they believe is wrong with them, and it is generated before any encounter exists, before any consent form is signed, and often on a public website. A conversational search product deliberately encourages richer, more narrative queries than a filter interface does, so the newest capability on this platform is the one that collects the most revealing input. Nothing published states whether those queries are retained, for how long, whether they are linked to an identity, or whether they inform the matching models.
The matching models raise the cross customer question directly. Routing improves with volume, and a vendor operating across 600 hospitals and 100 health plan brands has an obvious technical incentive to learn patterns across the whole book. Whether matching models are trained per customer or across the network, and under what de identification standard, is unstated in either direction.
A third surface is the check in and intake module, which handles protected information and payment data at the point of arrival, and nothing describes its retention position.
One architectural point works in the vendor's favour and is worth recording. Much of the platform operates on provider data rather than patient data, so the protected information exposure is narrower than the customer count suggests. That reduces the scope of the question without answering any part of it.
Graded D on the absence.
Certification is documented for one acquired component and not established for the platform as a whole, which is the recurring theme on this record.
What is documented is specific. The digital patient engagement business acquired in 2022 was described at acquisition as a secure, health privacy statute compliant and HITRUST certified platform. HITRUST is the credential that matters most in this market and the claim was made in a public transaction announcement rather than in marketing copy.
What is not established is the scope. That certification attached to one company at one point in time, four years and one further ownership change ago. Nothing located states whether HITRUST now covers the combined platform, the provider data management foundation, the payer business acquired in 2021, or the modules a given buyer would actually license. For a company assembled from three businesses, certification scope is not a formality: it is the question of which parts of the product a certificate actually covers.
The data flows are extensive and mostly not protected health information, which is worth stating because it works in the vendor's favour. Provider directory data is business data. Scheduling and check in are where protected information enters, and the intake, payment and check in module handles it directly, as does any booking written into a record system.
No business associate agreement is offered or described, no protected data handling summary exists, no retention position is stated, and nothing addresses whether patient search behaviour, which reveals what a person believes is wrong with them, is treated as protected information or as analytics.
Graded C.
One documented certification, attached to one acquired component at one point in time, and no current platform level position.
The documented fact is that the digital patient engagement business acquired in 2022 was described at acquisition as health privacy statute compliant and HITRUST certified. HITRUST is the strongest credential in this market and the claim appeared in a public transaction announcement, so it is more substantial than a marketing assertion.
Everything about its current applicability is unestablished. That certification belonged to a separate company in 2022. Since then it has been absorbed into a larger platform, and the parent was itself acquired in September 2025. Nothing located states whether HITRUST covers the combined platform today, whether it extends to the provider data management foundation or the payer business, or what the certification scope is. For a company assembled from three businesses under two ownership changes, scope is the whole question, and a buyer cannot answer it from anything public.
No trust centre, no service organisation control claim at the platform level, no penetration testing statement, no vulnerability disclosure policy, no subprocessor list and no incident notification commitment were located.
The scale makes the gap conspicuous. An incumbent serving 600 hospitals and 100 health plan brands has unquestionably satisfied hundreds of security reviews, so the artefacts exist. They are being shown under agreement to individual prospects rather than published, which is a choice available to a market leader and less available to a challenger.
Graded C on the strength of one real but dated and narrowly scoped certification.
No clearance is claimed, none is required, and unusually for this index the company operates inside a different regulatory regime that it addresses directly.
On devices the position is straightforward. Provider directory management, search, matching and scheduling are administrative functions with no clinical claim, and nothing in the product approaches a device question.
The regime that does apply is provider directory accuracy regulation, and it is substantial. Health plans carry federal and state obligations to maintain accurate directories, with surprise billing protections attaching consequences to directory errors, and network adequacy rules requiring plans to demonstrate their networks are what they claim. A vendor selling the authoritative directory to 100 plan brands is selling into a compliance obligation, and the company engages with that explicitly, describing compliance and attestation capabilities in its provider data solutions and publishing research on the state of plan directory data.
That is the distinguishing feature of this record on this axis. Most vendors in this index are silent about the regulation that governs their buyers. This one has built product features against it, named them, and published market research framing the problem. Whatever else is undisclosed here, the company demonstrably understands the rules its customers operate under.
What is not published is any position on accuracy guarantees, or on how the artificial intelligence driven data quality monitoring interacts with a plan's attestation obligations, which is the point where a vendor's automated judgement meets a customer's regulatory filing.
Graded B, the highest on this axis for any non device vendor in this session.
Nothing was located. No model card, no training data description, no accuracy figures for matching or data quality detection, no subgroup analysis and no bias statement.
The exposure is specific and it is about clinicians as much as patients, which makes it unlike the other records in this session.
On the patient side, matching routes on language among other attributes, so the model's handling of language is itself an equity mechanism: a patient searching in Spanish either surfaces Spanish speaking clinicians reliably or does not, and nothing published describes performance across languages. Conversational search compounds it, because interpreting a narrative description of a need depends on how the need is phrased, and phrasing varies with literacy and cultural framing.
On the provider side there is a mechanism this index rarely encounters. A ranking model decides which clinicians receive patient volume, and patient volume is income, referral pattern and career trajectory. If ranking is influenced by profile completeness, review counts, historical booking rates or anything correlated with how long a clinician has been in the network, the model will systematically advantage established providers over new ones, and could disadvantage clinicians whose patient populations book differently. Nothing published addresses ranking fairness from the provider side, and no vendor in this category appears to.
The data quality models carry a third: whether detection performs evenly across practice types, or flags small independent practices more often than large employed groups.
Graded D on the absence, with the mechanisms named because they are not obvious.
Nothing published addresses responsibility for an automated outcome, and on this platform the exposure is regulatory as much as clinical.
The distinctive risk is directory accuracy. Health plans carry statutory obligations for accurate provider directories, and surprise billing protections attach consequences when a patient relies on a directory that wrongly shows a provider as in network. This vendor supplies the directory and its models flag which records are suspect. If the data quality monitoring misses an outdated record and a patient is balance billed as a result, the liability lands on the plan, and nothing published describes accuracy commitments, service levels on detection, or how the vendor's automated judgement interacts with a plan's own attestation obligations. That interaction is the single most consequential unaddressed question on this record.
A second exposure follows from matching. If a patient is routed to a clinician who does not treat their condition, or misses a Spanish speaking provider because the model handled the language attribute poorly, the consequence is delay and a wasted visit. No performance warranty, indemnity or recourse route was located.
A third follows from scale. When the platform is the booking path for 600 hospitals, an availability failure is an operational event across a large part of the country, and no service commitment is published.
The company does make one honest statement adjacent to this, noting that technology alone cannot maintain directory accuracy without customer process change. That is a fair allocation of responsibility and it is a statement about effort rather than about liability.
Graded D.
The deepest interoperability on any record built in this session, and it is the product rather than a supporting feature.
Four record systems are named for integration, Epic, Oracle Health, MEDITECH and athenahealth, which covers effectively the entire United States market rather than the one or two typical elsewhere in this index. Scheduling is described as patient self scheduling with direct record system integration, meaning a booking lands in the system of record rather than in a queue for staff to rekey, and that is the hard half of the problem.
Published application programming interfaces for provider search, availability and scheduling are the distinguishing feature. A vendor that publishes interfaces rather than only consuming them is letting customers build their own experiences on its data, which is a different commercial posture from a closed platform and materially lowers the risk of being locked out of your own directory.
Distribution runs outward as well as inward. Provider data is pushed to health system websites, scheduling systems, search engines, listings and payer directories, so the platform is a hub rather than an endpoint, and the payer side connects plan directories to provider scheduling, which is a bridge almost nobody else spans.
The honest limit is that none of this touches clinical data. Everything moving here is provider information, availability and appointments, and nothing writes clinical content into a chart. For this product that is correct scope rather than a gap, and it means the interoperability depth is administrative rather than clinical.
Graded A on breadth, direction and published interfaces.
Nothing published. No deployment model, no hosting platform, no region, no residency option, no subprocessor list, no retention position and no availability commitment was located.
The architecture is inferable as a vendor hosted multi tenant service, given a customer base of 600 hospitals and 100 health plan brands consuming published application programming interfaces, and inference is not disclosure.
Two characteristics make the omission more material here than the generic case. First, this platform distributes data outward as a matter of function, pushing provider information to health system websites, search engines, listings and payer directories, so the data path extends beyond the vendor to a set of downstream destinations that are never enumerated. A customer cannot map where their provider data ends up from anything published. Second, the search and scheduling experiences run embedded in customer websites and portals, so vendor code executes in the customer's own domain, which is a client side data path question as well as a hosting one and is the configuration that has drawn regulatory attention over tracking technologies on healthcare websites.
Availability deserves specific mention. When the platform is the scheduling path for 600 hospitals, an outage is a health system that cannot book patients, and there is no published uptime commitment, status history or disaster recovery position. For an incumbent at this scale that is the disclosure a procurement team would most expect to find.
Graded D on the absence rather than on any evidence of a problem.
Nothing is published. No price, no unit of charge, no tier structure, no implementation fee, no contract term and no minimum was located in vendor or third party material.
The packaging makes that absence unusually consequential. The platform is presented as a set of named modules, covering provider data management, application programming interfaces, analytics, listings, search, scheduling and check in, sold to two distinct buyer types with different needs. A health system buying search and scheduling and a health plan buying directory management and conversational search are buying different products from the same catalogue, and nothing indicates whether the data management foundation is licensed separately from the modules that sit on it or bundled with them. That single question determines whether a buyer can start small.
Unit of charge is equally open and the plausible bases diverge sharply. Per provider under management, per hospital or location, per member, per booking, or an enterprise platform fee would each produce a different curve, and at a quarter of a million providers under management a per provider model would be a very different conversation from a flat fee.
One structural point a buyer should note. Because provider data accuracy is a regulatory requirement for health plans rather than a discretionary improvement, the buyer has less leverage than usual, and an incumbent holding the authoritative directory has considerable renewal power. Published pricing would be against the vendor's commercial interest here more than in most categories, which explains the silence without excusing it.
Graded D.
The broadest coverage of any vendor built in this session, and it spans both sides of the market rather than one.
Organisation types are named specifically: health systems and hospitals, medical groups, management services organisations and independent practice associations, primary care practices, surgical specialties and women's health practices, alongside a health plan business serving 100 plan brands. Serving providers and payers from one platform is genuinely unusual and it is the direct result of the payer acquisition rather than an aspiration.
Scale supports the claim at both ends. Six hundred hospitals and more than a quarter of a million providers on the provider side, more than 80 million plan members reached on the payer side, and named record system integrations across Epic, Oracle Health, MEDITECH and athenahealth, which covers effectively the entire United States record system market rather than the usual one or two.
Journey coverage is complete for patient access. Listings and search reach a consumer before they have chosen anywhere, matching routes them, scheduling books them, and digital intake, payment and check in handles arrival. Few platforms in this index cover a journey end to end without a gap.
Clinical coverage is inherited from the specialty taxonomy underneath the matching engine rather than built as protocol content, so the depth is in how finely a clinician's expertise can be described rather than in clinical logic. That is the right depth for this product.
Graded A.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
No pricing published; enterprise quote by module
|
Enterprise quote across a multi module platform sold to both provider and payer buyers; unit of charge unstated | Not published | Not published | Third Party Estimated |
Nothing is published and there is no numeric price to record. No rate card, no unit of charge, no tier structure, no implementation fee, no contract term and no minimum was located in vendor or third party material.
The module structure makes the absence unusually consequential. The platform is sold as named components covering provider data management, application programming interfaces, analytics, listings, search, scheduling and digital check in, to two different buyer types with different needs. Nothing indicates whether the data management foundation is licensed separately from the modules that depend on it, which is the question that decides whether a buyer can start with one capability or must take the platform. Given that matching and search are worthless without accurate underlying data, a bundled foundation is the commercially rational design and would mean a considerably larger entry commitment than a module price would suggest.
Unit of charge is entirely open and the candidates diverge sharply. Per provider under management, per hospital or location, per member, per booking, or a flat enterprise platform fee would each produce a different curve, and with more than a quarter of a million providers under management across the customer base, a per provider basis would be a very different conversation from a flat fee.
One structural point belongs on the record because it affects negotiating position rather than price. Provider directory accuracy is a regulatory obligation for health plans rather than a discretionary improvement, and an incumbent holding the authoritative directory for a network has substantial renewal leverage. Buyers should establish exit terms, data export rights and format at the point of first signature rather than at renewal, because the switching cost on a system of record for provider data is the real commercial exposure here and it is not visible in any first year figure.
A further item to settle in writing, carried over from the security assessment: which modules the HITRUST certification actually covers, given it was documented for one acquired component in 2022 and the platform has changed ownership since.