Luma Health
Luma Health, founded in 2015 in San Francisco by Adnan Iqbal, Aditya Bansod and Tashfeen Ekram, sells what it now calls an operational artificial intelligence platform for health system patient access. The company states it works with more than 550 health systems, hospitals and clinic networks, has served more than 30 million patients, and integrates with more than 80 record and practice management systems. It raised 160 million dollars through a 130 million dollar Series C led by FTV Capital in November 2021, with Texas Medical Center and DocuSign Ventures among strategic investors. No later round was located.
The artificial intelligence core is Spark, announced in 2024 and described as multi model and zero retention, and the company names the providers behind it, including models from OpenAI, Anthropic and Deepgram, fine tuned for healthcare. The patient facing voice product is Navigator, an agentic concierge that answers inbound calls in multiple languages, verifies a caller's identity, lists and confirms appointments, cancels directly in the record system and handles prescription refill requests.
Its engineering lead describes the design plainly as several cooperating agents, each a model with a prompt and a set of tools, one verifying identity, another listing appointments, another cancelling. Alongside Navigator sit Fax Transform for inbound document processing, LumaPay for point of service payments, eligibility checking, self scheduling, waitlists and, from August 2026, Patient Pipeline, which converts advertising spend into booked appointments for organisations running Epic.
The company reported deployment of artificial intelligence workflows at more than 50 health systems and more than 2 million hours of staff time saved during 2025, and says a 2026 release will extend the conversational agent to proactive outbound follow up driven by record data, visit notes and prescriptions. Integration is built in house rather than bought, spanning Oracle Health, Epic, eClinicalWorks, MEDITECH, athenahealth, NextGen and Greenway Health, with inaugural membership of the MEDITECH alliance programme and validated integration status with Oracle. Chief product and technology officer Marcelo Oliveira. Research and development centres in the United States, Brazil and Europe.
Capability Axes
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read
A decade old patient access platform that has put artificial intelligence underneath itself rather than a company built around a model. The order of events is the grade. Scheduling, reminders, waitlists, intake, payments and record system connectivity came first and carried the business for nine years; Spark, the generative core, arrived in 2024, and Navigator and Fax Transform were its first two products.
The company is candid about the lineage, saying it has used machine learning and language models for years and that the platform now orchestrates rather than automates isolated tasks. Take the models away and a working patient engagement platform remains, which is not true of the pure voice agent vendors in this category.
What lifts it to B rather than lower is that the newer layer is doing real work and doing it in the record system: Navigator's agents complete a cancellation in the electronic record, and the stated 2026 direction is proactive outbound contact driven by visit notes and prescriptions. That is a genuine shift in what the product is, not a feature.
High autonomy with an unusually explicit statement of who sets the bounds. Navigator verifies a caller's identity, retrieves their appointments and cancels one directly in the record system without a person in the loop, and the described architecture is several cooperating agents each holding a model, a prompt and a set of tools. The oversight credit is real and specific.
Customers assemble agents from individual skills through a configuration interface and the agent determines each patient's next step from choices the organisation has predefined, so the decision space is bounded by the customer rather than by the vendor. The company also publishes material intended for a customer's artificial intelligence governance committee, which assumes such a committee exists and should be given something to review, and almost nothing else in this index does that.
Held at B on two points. Nothing published describes what happens when an inbound caller describes an emergency or acute distress, which is the question every product answering a health system line has to answer. And the announced outbound agent reviews visit notes and prescriptions to decide who needs contacting, which is a judgement about clinical follow up made before any human sees it, with no published criteria and no stated review step.
The most complete statement of model provenance located anywhere in this category. The generative core is described as multi model and the suppliers are named individually, spanning a large language model vendor, a second frontier model vendor and a speech recognition provider, stated to be fine tuned for healthcare.
Set that against the segment: across more than fifty voice and conversation vendors reviewed for this index, one named a single cloud model platform and one stated that the whole category buys the same models without saying which, and every other record carries the subprocessor question unanswered.
The architecture is also described in technical rather than promotional terms by a named engineer, as several cooperating agents each combining a model, a prompt and a set of tools, with a worked example of how a cancellation is executed. Held at B because provenance is not performance. No accuracy figures, no evaluation method, no model cards, no containment or task completion rates, and the named models date from the 2024 announcement, so which versions run today is unstated. Naming your suppliers tells a buyer where the data goes; it does not tell them how well the thing works.
This is the most complete statement of model provenance located in this category. The generative core is described as multi model and the suppliers are named individually, spanning a large language model vendor, a second frontier model vendor and a speech recognition provider, stated to be tuned for healthcare.
Set that against the segment: across more than fifty voice and conversation vendors reviewed for this index, one named a single cloud model platform, one stated that the whole category buys the same models without saying which, and every other record leaves the question unanswered. Alongside it sits a zero retention commitment stated as an architectural property of the generative layer rather than as a policy.
Two things keep it below the top grade and the first is about precision rather than substance. Zero retention needs the care any absolute claim needs, because a platform whose value comes from orchestration across a patient journey plainly retains something.
The likely reconciliation is that prompts and completions are discarded at the model boundary while workflow and record data persist inside the platform, which would be entirely reasonable, and it is not what the phrase says, and ambiguity in a data claim resolves in the vendor's favour by default. Second, nothing addresses the voice product specifically: whether calls are recorded, how long audio is kept, or whether a caller is told they are speaking to software. Flagged forward: an announced outbound agent reads visit notes and prescriptions, a materially deeper reach than scheduling data.
Named, dated and specific, which places it well above the segment norm without reaching the bar the axis sets. The company reports artificial intelligence workflows deployed at more than 50 health systems and more than 2 million hours of staff time saved during 2025, more than 550 health systems, hospitals and clinic networks on the platform overall, and more than 30 million patients served.
The reference customer is named with a named executive: an academic medical centre where the chief clinical access officer describes a three week implementation against the Epic record system and after hours cancellation handled without staff follow up. A specialty neurology institute is named for fax automation at a stated volume of hundreds of documents a day. What holds it at C is that every figure is vendor produced with no method behind it.
Two million hours saved has no baseline, no denominator, no measurement definition and no independent check, and staff time saved is the easiest number in this category to construct favourably. No peer reviewed publication and no independent evaluation was located, and no figure is published for the thing that would matter most on the voice product, which is how often the agent completes a request correctly rather than how often it completes one.
The zero retention commitment is the centre of this and it is stated as an architectural property of the generative layer rather than as a policy, alongside named model providers, which together answer the subprocessor question that goes unanswered on almost every other record in this segment.
Two things keep it from A. Zero retention needs the same precision that any absolute claim needs, because a platform whose value comes from orchestration across a patient journey plainly retains something. The likely reconciliation is that prompts and completions are discarded at the model boundary while workflow and record data persist inside the platform, which would be entirely reasonable, but that is not what the phrase says and ambiguity in a data claim resolves in the vendor's favour by default.
And nothing published addresses the voice product specifically: whether calls are recorded, how long audio is kept, or whether a caller is told they are speaking to software rather than a person. The last matters more for an inbound line than an outbound campaign, because a patient ringing their own clinic did not choose to interact with a machine.
Worth flagging forward: the announced outbound agent reads visit notes and prescriptions, which is a materially deeper reach into the clinical record than scheduling data and should be assessed on its own terms when it ships.
Stronger than the segment norm because the compliance claim is attached to specific architecture rather than left as an assertion. Generative processing is described as zero retention, the model providers are named, and for the advertising product the company states plainly that protected information is never provided to the search provider and stays inside its own environment and the record system.
That is a checkable statement about a named third party, made at the point where a reader would most reasonably be suspicious, and it is the kind of disclosure this index rarely finds. Held at B rather than A because the instruments themselves were not located. No business associate agreement terms, no notice of privacy practices and no published subprocessor list, so a counterparty can read what the company says it does but not the document that binds it. The role is not in doubt, since a supplier handling scheduling, identity verification and record writes across 550 provider organisations is plainly a business associate.
Four independent credentials, named precisely, covering different and complementary things. The health sector's own assurance framework at its risk based tier, an attestation report of the operating kind rather than the point in time kind, the international information security management standard with its year version stated, and a state government cloud security authorisation at level two. Precision is what earns the grade as much as the count.
Stating the version of a standard and the type of an attestation are the two disclosures most vendors omit, and omitting them is what separates the middle of this category from the top: within this segment the index holds vendors publishing a report type and a standard version, a badge with the type unstated, an attestation of the weaker design only kind, a claim of controls with no report at all, and a bare assertion of being secure.
This record sits at the top of that scale alongside the one other vendor with a comparable portfolio. The honest limit worth recording: no public trust centre was located, so the certificates are asserted in marketing and press material rather than presented as retrievable artefacts, and a procurement team should still request the reports themselves.
No device clearance, authorisation or submission was located and none would be expected. Scheduling, reminders, intake, document processing and payments are administrative functions and the product offers no clinical assessment or advice. The regulators that do apply sit elsewhere and this vendor touches more of them than most in the category.
Automated outbound calling and text messaging carry telephone consumer protection obligations enforced against healthcare callers, and the announced proactive outbound agent increases that exposure rather than leaving it flat. Payment collection brings consumer financial protection rules alongside.
The newest and least settled surface is the advertising product launched in August 2026, which links search advertising spend to booked appointments: health information in online advertising and tracking contexts has been an active enforcement area, and the company's statement that protected information never reaches the search provider is exactly the right thing to have published, though a buyer should still establish what identifiers do cross the boundary.
More governance structure than anything else in this category, and one precise catch inside it. The company states that its generative core is built to be in compliance with the artificial intelligence management system standard published in 2023, and it publishes material designed for a customer's own artificial intelligence governance committee to evaluate. Both are unusual and both are credited. The catch is the wording.
Built to be in compliance with a standard is not certified against it, and the distinction matters more here than it would elsewhere because this same company names its other credentials with complete precision, including a standard version and an attestation type. A vendor that demonstrably knows how to state a certification, and states this one differently, has chosen the softer phrasing deliberately. Ask whether an audit has since been completed.
The bias gap is the reason this is not higher. Navigator answers calls in multiple languages across 550 organisations and no performance is published broken down by language, accent or caller population, which is the thirteenth record in this segment carrying that exposure unexamined. A platform already reporting hours saved at this scale is well placed to report whether the agent serves some callers less well, and does not.
The architecture is described in technical rather than promotional terms by a named engineer, as several cooperating agents each combining a model, a prompt and a set of tools, with a worked example of how a cancellation is executed. The worked example is what earns the grade.
Describing a real task end to end tells a buyer where a decision is made, what the agent is permitted to do at each step and what would happen if a step failed, which no architecture diagram conveys, and it lets a reviewer reason about failure modes specific to their own workflows rather than in the abstract. Held at C on the distinction this index applies consistently: provenance is not performance.
No accuracy figures, evaluation method, model cards, containment or task completion rates were located, and no warranty, indemnity or remediation commitment. One dating problem compounds it and is worth checking rather than assuming.
The named models date from a 2024 announcement, so which versions run today is unstated, and a named model from two years ago may not be the model in production, which means the provenance credited on the other axis describes a configuration a buyer cannot confirm is current. Ask which model versions run now, for containment and task completion rates, and what the system does when it cannot complete a task.
The strongest interoperability position in this category and one of the strongest in the index. Integration is bidirectional and the counterparties are named individually rather than gestured at: Oracle Health, Epic, eClinicalWorks, MEDITECH, athenahealth, NextGen and Greenway Health, within a stated footprint of more than 80 record and practice management systems.
The relationships are formalised rather than asserted, including inaugural membership of one vendor's alliance programme, validated integration status with another, and delivery as a native component inside two more. The agents write as well as read, cancelling an appointment directly in the record system and returning an updated schedule to staff without manual follow up, and the fax product converts inbound paper into structured downstream workflow including outreach and self scheduling with the loop closed back to the referring provider.
Implementation evidence supports the claim rather than resting on it, with a named academic medical centre live against Epic in three weeks. The decisive point is architectural: the company states it deliberately built record system connectivity itself rather than depending on a third party integration platform, on the reasoning that the link was too important to outsource. That is the difference between a vendor that integrates and a vendor that owns its integration.
A single cloud delivered model with no self hosted or in place option, which is ordinary at this scale. Two things sit on the positive side. The zero retention position at the generative boundary is a residency claim of a kind, since data that is never stored has no residency question, and a state government cloud security authorisation at level two is a real jurisdictional credential that few vendors in this category hold. What is absent is the ordinary detail.
No cloud provider named, no regions stated, no retention schedule for the data that is kept as distinct from the generative traffic that is not, no tenancy model and no published subprocessor list beyond the model vendors. The specific question this record raises that most do not: the company operates research and development centres in the United States, Brazil and Europe.
Engineering locations are a data access question and not merely an organisational fact, because support and development staff outside the country where patient data sits need a defined basis for reaching it. Nothing published addresses whether they can, under what controls, or whether access is confined to one jurisdiction.
Nothing about the economics of buying this is published. No price list, no entry point, no unit of charge, no packaging. Licensing is quote based, module packaging and discount tiers are undisclosed, and implementation and integration fees are not standardised publicly, so a buyer cannot form even a rough estimate without entering a sales process.
The cost drivers that do exist are substantial and predictable: integration scope across record and practice management systems, workflow and template design, and change management for specialty scheduling rules. The funding record is the better half and is fully public up to a point. A 130 million dollar Series C in November 2021 led by FTV Capital brought the total to about 160 million dollars, with Texas Medical Center and DocuSign Ventures participating as strategic investors. Nothing later was located, which for a company of roughly 200 people with 550 customer organisations five years on is a gap a buyer should ask about directly rather than read either way.
Broad across organisation type and channel within one country. More than 550 health systems, hospitals and clinic networks spanning academic medical centres, federally qualified health centres, specialty groups and multi site clinic networks, reaching a stated 30 million patients.
The channel span is wider than most in this category because the platform covers voice, text message, web self scheduling, inbound fax and payments in one place, which means it reaches the older and rural patients that digital only platforms miss and the referring practices that still send documents on paper. Navigator operates in multiple languages and offers bidirectional translation to support staff, which is a genuine reach advantage rather than a localisation footnote.
Held at B because the deployed footprint located is entirely within the United States despite research and development centres in Brazil and Europe and a stated ambition to scale internationally, and because the buyer is a provider organisation in every case, with no payer or public health deployment.
What Changed
Material product, regulatory, evidence and commercial changes at Luma Health, each verified against a live source and tagged to the capability axis it bears on. Funding rounds and awards are not product changes and are not logged.
Luma Health shipped its Summer 2026 release, extending its Operational AI from pre visit preparation into what happens once the patient is physically in the clinic. Patients can now self check in by kiosk or QR code, an enhanced Queue Manager routes arrivals to the appropriate queue automatically, and new financial administration tooling supports facility managed card readers and transaction reporting. The through line is closing the gap between the digital front door and the front desk.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.