Behavioral Health AI
M

mdhub

AI native operating system for behavioral health clinics, combining a set of named AI workers with an integrated EHR, CRM, and revenue cycle management in one platform. Sarah, the admissions coordinator, answers inbound calls, texts, and faxes around the clock and verifies insurance in real time, with more than 100,000 patients booked reported. Emma, the clinical assistant, generates ICD-10 and CPT coded session notes within about 30 seconds and is reported to have supported more than 3 million patient sessions. Eric handles coding, claim scrubbing, submission, and denial management. Laura manages between visit engagement.

The fully integrated platform launched April 2026, partners with athenahealth through the athenaOne Marketplace, and reports clinics booking 30 percent more patients with clinicians saving more than two hours daily, across hundreds of mid to large behavioral health clinics. Behavioral health operations are a distinct problem from general practice, and the specialization is the point. Backed by Y Combinator, Precursor Ventures, Pioneer Fund, Rebel Fund, and Expansion Venture Capital.

AI Health Index verifiedJuly 26, 2026
Compare mdhub with other vendors
Founded
Headquarters
San Francisco, California
Website
www.mdhub.ai
Categories
behavioral-health, patient-facing-voice-agents, rcm-and-prior-auth
Indexed Products
Sarah (admissions), Emma (clinical), Eric (billing), Laura (care coordination)
Buyer Segments
Medical Group, Community Health System, Independent Practice
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
AA on AI CentralityThe artificial intelligence is the product. Remove the model and there is nothing left to sell.
Vendor Published

The AI workers are the product. Admissions calls, session note generation, claim scrubbing and denial management, and between visit engagement are each performed by a named agent, and the surrounding EHR, CRM, and RCM exist to give those agents a system to act in.

BB on Autonomy and Oversight ModelThe oversight structure is described and one part is missing, commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

Upgraded from C on better evidence. The earlier grade recorded that no human review step, escalation criterion or handoff logic could be found for any of the four agents. Material published since, and located on a second pass, establishes the clinical checkpoint clearly, so the grade moves. The gap that remains is narrower and sits elsewhere.

What is now evidenced: every clinical note requires clinician review and sign off before it enters the patient record, artificial intelligence output is described as a structured first draft or a flag rather than a final authority, and the company states that workflows are built with mandatory human checkpoints. Its guidance is explicit that for high acuity situations including suicidality, self harm and crisis, a qualified provider must evaluate any flag independently and never act on model output alone. The billing sequence follows from the signature rather than bypassing it: the billing agent pulls the signed note, then codes and submits. That ordering puts a licensed human upstream of the claim, which is the right architecture and is what this axis rewards.

Two reservations hold it at B.

The first is that the review is sold on its speed. The stated target is a clinician signing in under a minute, or a two to three minute review, and closing the laptop. Sign off is the control that makes the whole design safe, and compressing it is presented as the benefit. A signature applied in under a minute to a note generated from a therapy session is a weak check, and the marketing optimises the thing the safety case depends on.

The second is the admissions agent, where the original concern stands undisturbed. It answers inbound calls, texts and faxes around the clock, and some of those callers will be in distress. No escalation criteria, crisis detection behaviour or human handoff path for that agent was retrieved. The company's own crisis guidance is addressed to what a clinic's protocols should require, not to what the agent does at three in the morning.

Establish the escalation path for inbound contact before deployment, and treat the review target as a floor rather than a goal.

CC on Model and Technology TransparencyThe architecture is described in general terms with nothing identified. Proprietary is asserted rather than explained.
Vendor Published

Nothing published about the models, by a vendor that tells buyers this is the thing to demand.

No foundation model is named, no architecture described, no evaluation methodology published, no versioning or update policy, and no accuracy figure for any of the four agents. That includes the two places a number would matter most: the fidelity of a generated session note to what was actually said, and the correctness of the diagnostic and procedure codes assigned from it.

Coding accuracy is the sharper gap because of what happens next. The billing agent takes the signed note, assigns codes and submits the claim. This index already has a benchmark for exactly this: one coding vendor publishes its confidence threshold, routing high confidence output to billing and returning the rest to human coders, and is graded accordingly, while a peer that publishes no threshold is graded lower. Here there is neither a threshold nor an accuracy figure nor any statement of what happens to a low confidence code.

The asymmetry is worth stating because the vendor supplied the test itself. Its published buyer guidance argues that a vendor unable to articulate clearly how its model generates documentation output is asking the buyer to stake clinical and legal liability on a process they cannot verify. That is correct, useful and well put. Applied to the publicly available material about this platform, the answer is that no such articulation exists.

Write that as an asymmetry a buyer can act on rather than as hypocrisy. The guidance is accurate and the gap is real, and the vendor is better placed than most to close it.

Ask for note fidelity and coding accuracy figures, the evaluation set, and the threshold behaviour for low confidence output.

DD on Model Supply Chain DisclosureNothing establishes who else sits between a patient record and an answer.
Vendor Published

Nothing identifies any party in the chain: no model or model family, no foundation model provider, no hosting arrangement and no sub processor list was located in two passes. One commitment is real and specific and it covers a single artefact: session audio is stated to be discarded once the note has been generated and not retained afterwards, which for an ambient system in a therapy room is the most consequential retention decision available. What it leaves open is the corpus.

Nothing states whether session transcripts, generated notes or call recordings are used to improve models, and the company reports supporting more than three million patient sessions, so the accumulated content is large and it is psychotherapy. No rule squarely settles whether de identified therapy transcripts may train commercial products, and reidentification risk in behaviourally rich text is well documented, so silence here leaves the buyer to assume.

A second content category sits outside the usual framing entirely and should be asked about separately. The admissions agent gathers intake detail, screens and qualifies people who have not yet entered a treatment relationship. Highly sensitive mental health information is therefore created at a point where the protections attaching to a clinical record may not yet apply, about people who may never become patients. Ask what governs that intake data, whether transcripts and notes train models, and for a sub processor list.

BB on Clinical and Operational EvidenceNamed deployments with dated outcome figures and enough method to test them, or published research short of independent validation.
Vendor Published

Operational scale is substantial and specific for a company at this stage: more than 100,000 patients booked by the admissions agent, over 3 million patient sessions supported by the clinical assistant, hundreds of mid to large clinics on the platform, and reported outcomes of 30 percent more patients booked with clinicians saving over two hours daily. Partnership through the athenaOne Marketplace is modest independent validation of integration quality. Held back from A because the outcome figures are vendor reported without methodology or named references.

BB on AI Safety and PHI StewardshipCategorical commitments are published, such as no training on customer data, without the retention schedule or the safety engineering behind them.
Vendor Published

One genuinely good commitment, and two questions the product's own design raises and does not answer.

The commitment first, because it is specific and checkable in a way that most privacy language is not: session audio is stated to be discarded once the note has been generated and not retained afterwards. For an ambient system in a therapy room that is the single most consequential retention decision available, and making it plainly is better practice than a general assurance. Encryption at rest and in transit, role based access and audit logging are also stated, alongside a commitment not to store data beyond what treatment requires.

The first open question is model training. Nothing states whether session transcripts, generated notes or call recordings are used to improve the models. The company reports supporting more than three million patient sessions, so the corpus is large and it is psychotherapy content. The compliance literature is explicit that no federal rule squarely addresses whether de identified therapy transcripts may train commercial products, and that reidentification risk in behaviourally rich data is well documented. Silence here leaves the buyer to assume.

The second is data collected before anyone is a patient. The admissions agent gathers intake detail, screens and qualifies people who have not yet entered a treatment relationship, and dispatches screening instruments in advance. Highly sensitive mental health information is therefore created at a point where the protections attaching to a clinical record may not yet apply, and where the person may not understand they are talking to a system that records.

Ask whether transcripts and notes train models, whether that is severable, and what governs intake data for people who never become patients.

Regulatory and Compliance
BB on HIPAA and BAA PostureBusiness associate status is stated and supported by a substantive privacy document, with the agreement or its scope not fully published. For a vendor outside the United States, an equivalent regime documented to this depth grades here.
Vendor Published

Clear on the instrument, accurate in its buyer education, and deferring on the regime that matters most in this specialty.

The strong parts are unambiguous. A business associate agreement is stated to be available to every customer rather than to enterprise accounts only, which removes the usual smaller buyer gap. The company states it works directly with a customer's security team through vendor review and shares audit documentation. Its published guidance on the health privacy rule is accurate, including the covered entity and business associate distinction and the point that layering several tools each under its own agreement creates uncovered gaps at the handoffs, which is a fair argument for a single platform and a real risk that most vendors never mention.

What is not published is the instrument itself. No business associate agreement text, no provider facing addendum, no subcontractor flow down, no breach notification timetable and no review cadence were retrieved. Publishing the instrument is the route to an A in this index and it is not taken.

The deferral is the more significant reservation and it sits alongside rather than inside this axis. Asked directly whether the platform handles substance use disorder records under 42 CFR Part 2, the published answer recommends that practices discuss the requirements with their own compliance team, with support available for configuration. That is not a statement that the platform enforces Part 2 segmentation. In a product sold to behavioural health clinics, a share of which treat substance use disorder, it is the question a buyer must resolve before signing.

Ask for the agreement text and for a written description of how Part 2 records are segmented from automated processing.

BB on Security Certifications and Trust CenterA recognised certification is named in the vendor own material without the artefact, or with a scope or renewal question the buyer has to raise. A certification has a scope and a clock, and both are part of this grade.
Vendor Published

A real posture with real third party involvement, carrying a discrepancy the vendor should reconcile.

What is claimed and supported: an attestation named with its type as SOC 2 Type II, encryption in transit and at rest, role based access, audit logging, single sign on through Microsoft and Google, a business associate agreement to every customer, and a stated willingness to share audit documentation with a buyer's security team. Listing on the athenahealth marketplace carries independent weight too, since the partner states that listing requires passing its technical and security vetting rather than resting on vendor assertion.

The discrepancy concerns the attestation. The company's audit partner published a case study describing completion of health privacy and SOC 2 Type I work, and describing the company as preparing for the Type II audit. The vendor's own enterprise material states Type II. The case study carries an April 2026 date, so a Type II report may well have completed in the months since and the two statements may both have been true when written. A buyer cannot tell from public material which is current.

This index treats an audit partner's own case study as creditable for certification facts, with attribution, and that rule cuts both ways. Here it is the source that raises the question rather than the one that settles it.

One terminology point, consistent across this index. SOC 2 produces an attestation report from an accounting firm. There is no certifying body, no certificate and no registry, so certified is the wrong word wherever it appears.

Ask for the report, the type, the period covered and the date of issue.

CC on FDA and Regulatory StatusNo device claim is made and the product is scoped accordingly. Most administrative and operational products sit here and are not penalised for it, because this axis grades the appropriateness of the positioning rather than possession of a clearance.
Vendor Published

No clearance, almost certainly none needed, and a regulatory surface unusually wide for a single product.

Documentation, scheduling and billing software sits outside the device definition. That part is straightforward. What is not straightforward is that this platform runs four agents across four functions, and each one lands in a different regime. A buyer inherits all of them at once.

Substance use disorder records are governed by 42 CFR Part 2, whose modernised framework reached its enforcement date on 16 February 2026. Part 2 is stricter than the Health Insurance Portability and Accountability Act: it requires specific patient consent for disclosures that the health privacy rule would permit for payment and operations without one, and it restricts redisclosure downstream. The technical requirement it creates is concrete, namely that automated systems must segment Part 2 records out of processing unless consent is on file.

That requirement points directly at the admissions agent. An artificial intelligence answering an inbound call and reading appointment history to give context can disclose that a caller has a substance use appointment, to a person not authorised to receive it. This is the textbook Part 2 exposure for conversational systems.

Three further regimes apply. Outbound patient engagement engages the Telephone Consumer Protection Act, under which artificial voice calls need prior express consent and automated texts are separately covered; inbound contact raises none of this, so direction is the distinction. Claim submission carries no vendor level regulator at all, with liability sitting on the clinic under the False Claims Act. And many states impose mental health confidentiality rules stricter than the federal floor.

Nothing published states the company's position on any of them. Graded C on that silence.

CC on AI Governance and Bias DisclosureResponsible artificial intelligence is committed to in policy language with no evaluation behind it. Most of the index sits here.
Vendor Published

A published ethics position and no published evidence about its own models.

The company writes about ethical artificial intelligence in behavioural health, including bias auditing and clinician oversight, and the writing is sound. What is absent is any performance data broken out by group, any bias testing statement about its own systems, any governance or model update policy, and any third party audit of the models.

Two concerns are specific to this product rather than generic.

The first is speech. Both the clinical assistant and the admissions agent depend on understanding spoken language, one transcribing therapy sessions and the other conducting calls. Speech recognition accuracy varies measurably across accent and dialect, and this index has already recorded that the populations affected overlap with those already underserved. Community mental health serves a disproportionately multilingual and dialect diverse population. A note generated from a degraded transcript is a clinical record that misstates what a patient said, and it is signed and billed.

The second is gating. The admissions agent qualifies prospective patients and matches them to a clinician. That is an access decision made before anyone becomes a patient. If qualification, scheduling priority or clinician matching varies systematically by how someone speaks or by their coverage, the effect falls on who receives care at all. Nothing published describes what qualification means operationally or what is measured.

Ask for transcription and comprehension accuracy by accent and language, and for the qualification criteria the admissions agent applies.

DD on AI Liability and RecourseNothing published on what happens when the system is wrong.
Vendor Published

Two passes located no accuracy figure, no error rate, no published limitations, no evaluation methodology and no warranty, indemnity or remediation commitment for any of the platform's agents, and two of the gaps sit where a number would matter most: the fidelity of a generated session note to what was actually said, and the correctness of the diagnostic and procedure codes assigned from it. Coding is the sharper one because of what happens next.

The billing agent takes the signed note, assigns codes and submits the claim, so an error leaves the building as a representation to a payer with false claims consequences for the practice. This index has a benchmark for exactly that situation, since one coding vendor publishes its confidence threshold and routes low confidence output to human coders. Here there is no threshold, no accuracy figure, and no statement of what happens to a low confidence code.

The asymmetry deserves recording as something a buyer can act on rather than as a criticism. The vendor's own published buyer guidance argues that a vendor unable to articulate clearly how its model generates documentation is asking the buyer to stake clinical and legal liability on a process they cannot verify. That guidance is correct and well put, and applied to this platform's public material the answer is that no such articulation exists. A vendor that authored the test is better placed than most to pass it. Ask for note fidelity and coding accuracy, the evaluation set, and the threshold behaviour.

Integration and Deployment
BB on EHR and Interoperability DepthNamed systems with read access or one directional writing, or standards support with named deployments behind it.
Vendor Published

The axis reads differently here, because this vendor is also an electronic health record.

The platform includes a behavioural health native record system designed around its own agents, so for a clinic adopting the full stack the usual integration question dissolves. What remains is what it connects to for everyone else, and there the position is genuinely flexible: clinics may keep an existing record system and run agents alongside it, adopting individual functions before committing to the whole platform.

The strongest external evidence is the athenahealth relationship. Listing on the athenaOne marketplace is corroborated outside the vendor's own site and the partner states that listing requires passing its technical and security vetting. That is a meaningful third party check on integration quality rather than a logo.

An open interface is offered for integration and data access, described as used to connect analytics and workflow systems, and single sign on is supported through Microsoft and Google. For a buyer, an open interface on the record of account matters more than any single connector, because it is what makes reporting and eventual migration possible.

The qualifications are real. Only one major record system is named specifically; integration with other major platforms is asserted without naming them. No standards based interoperability is described, no support for the usual clinical data exchange standards is stated, and no interface documentation, uptime commitment or export specification was retrieved.

Ask which record systems are supported today rather than in principle, whether standard clinical data exchange is available, and for the interface documentation before signing.

CC on Deployment Model and Data ResidencyA single hosted option with location implied rather than committed.
Vendor Published

Nothing published on where any of it runs, under a purchase that is harder to reverse than most.

No hosting provider, no region, no tenancy model, no subprocessor list, no backup or recovery posture and no data residency commitment was retrieved. The service is evidently cloud delivered and vendor operated, with implementation managed end to end and clinics typically live within about four weeks including configuration, integration, data migration and training.

The deployment fact a buyer should weigh hardest is not technical. This is offered as a full platform including the record of account, so adopting it at full scope is a system of record replacement rather than a tool addition. Clinical records migrate in at implementation. That raises the exit question sharply: what leaves, in what format, on what timetable, and who bears the cost. An open interface for integration and data access is stated, which helps, but no export specification or retention and return terms were retrieved.

The adoption path is better designed than the exit path, and that is worth crediting. Clinics can run individual agents alongside an existing record system and move across later, so the initial commitment can be partial and reversible. The commitment becomes hard only at the point the record itself moves.

Ask where the platform is hosted and in which region, whether tenancy is shared or isolated, and what the contractual data return and deletion terms are at termination. Settle the exit terms while adoption is still partial.

Commercial
CC on Commercial TransparencyNo price is published and the posture is discoverable: a buyer can establish how the product is sold and what drives the cost before contacting the vendor. Most of the index sits here.
Vendor Published

No pricing published, detailed returns published, and a switching position that changes what the price means.

Nothing is disclosed: no rate card, no basis, no statement of whether pricing is per clinician, per agent, per session or per site, no term, no minimum and no volume banding. Sales are demo led with implementation managed by the vendor and clinics typically live within about four weeks.

The returns are specific by contrast: around 30 percent more patients booked, more than two hours saved per clinician per day, and administrative cost burden reduced by up to half. A buyer is given a precise numerator and no denominator, which is the same asymmetry this batch has found in three other categories. The figures may be sound and they cannot be compared to anything until a price sits beside them.

What is particular here is the position the buyer occupies afterwards. This is offered as a full platform including the record of account, so at full adoption the vendor is not a tool the clinic uses but the system the clinic runs on. Pricing power at renewal is different when leaving means migrating the clinical record. That is not a criticism of the model, which has real advantages the vendor argues well, but it is a commercial fact that belongs in the first conversation rather than the third.

The modular path is the mitigation and it is genuine. A clinic can adopt individual agents alongside its existing record system and move fully later, which keeps early commitment reversible. The moment that changes is the record migration.

Ask for the pricing basis, for renewal and escalator terms in writing, and for the cost of exit, before adoption passes the point where the record has moved.

AA on Setting and Specialty CoverageWhere the product is validated to operate is named and supported, settings and specialties both, whether the coverage is broad or deliberately narrow.
Vendor Published

Tightly and deliberately bounded to behavioral health clinics, community mental health organizations, and psychiatry and therapy practices. Behavioral health operations differ materially from general practice in intake, documentation, and payer rules, and building only for that segment is the differentiator rather than a limitation.

Tracked Since Listing

What Changed

Material product, regulatory, evidence and commercial changes at mdhub, each verified against a live source and tagged to the capability axis it bears on. Funding rounds and awards are not product changes and are not logged.

Aug 20, 2026Product / capability

mdhub introduced three new platform capabilities: AI Analytics for custom reporting on clinical and financial metrics, an AI Care Coordinator named Laura for patient engagement via the portal, and an automated Chart Audit tool to review documentation against payer requirements.

Bears on: AI CentralitySource
Aug 11, 2026EHR / interoperability

mdhub launched a native integration with athenaOne, officially becoming a vetted partner on the athenahealth Marketplace. The integration connects mdhub's AI-powered admissions, clinical documentation, and smart scheduling tools directly to athenaOne workflows.

Bears on: EHR and Interoperability DepthSource
Our read on these changes →Tracked since Aug 2026
Comparisons

Compared With

Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Contact the vendor
Enterprise platform agreements with behavioral health clinics Vendor Published

No public pricing. Demo led with implementation and onboarding managed by the vendor, typically live within about four weeks. Note the scope of the buy: this is offered as a full AI native stack including EHR, CRM, and revenue cycle, so for a clinic running an existing EHR the comparison is a system replacement rather than adding a point solution, and switching cost should be modeled accordingly.