Healthcare Administrative Automation
M

Medallion

Provider network operations platform automating credentialing, payer enrollment, state licensing, privileging, and ongoing compliance monitoring, positioned as an AI operations partner running a real time credentials verification organization. Integrates directly with primary sources including federation and federal databases to verify and monitor credentials, and pairs AI agents with credentialing specialists who review critical stages and handle exceptions. Serves health systems, digital health companies, payers, and provider groups.

AI Health Index verifiedJuly 21, 2026
Compare Medallion with other vendors
Founded
2020
Headquarters
San Francisco, California, United States
Website
medallion.co
Categories
healthcare-admin-automation, workforce-and-training, rcm-and-prior-auth
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
BB on AI CentralityThe model is the engine of a core module. The platform carries other value, but this capability does not exist without it.
Vendor Published

AI agents do the credentialing work, but the company is unusually candid that they do not do all of it. It describes purpose built AI agents for credentialing overseen by industry experts, paired with a proprietary payer clearinghouse to deliver real time results. It then states plainly that AI is not perfect yet, which is why credentialing expertise is embedded directly into every workflow and specialists step in when automation encounters an exception. That is a hybrid model honestly labeled rather than an autonomy claim, and a buyer should size it as automation plus a services layer.

AA on Autonomy and Oversight ModelWhat the system may do and what it may not do are both published, with escalation thresholds, override paths and the conditions that route a case to a person.
Vendor Published

The oversight design is explicit, structural, and stated without spin. Experts review critical stages across credentialing and enrollment before work moves forward to ensure accuracy, completeness, and readiness for regulatory review, and from primary source verifications through committee ready packets that review is built into the process.

The company also states its experts continuously train and configure the AI agents, which makes human review a feedback mechanism rather than only a gate. For work where an error means an improperly credentialed clinician treating patients, embedding review rather than sampling is the right architecture.

CC on Model and Technology TransparencyThe architecture is described in general terms with nothing identified. Proprietary is asserted rather than explained.
Vendor Published

The company describes an AI agent workforce combined with a proprietary payer clearinghouse and direct integration with primary source databases, which explains where the data comes from and how results are produced at a functional level. No model provider, architecture, accuracy measurement, or exception rate is published, and exception rate is the figure that would tell a buyer how much of the work the AI actually completes unaided.

CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

One architectural feature makes the re use question sharper here than the usual enumeration gap, and it follows from the value proposition rather than from an omission. The company markets a solution that reduces redundant recredentialing effort for payers, and reducing redundancy across payers necessarily means verified provider data is shared or re used beyond the customer that originally collected it.

The efficiency is the sharing, so a buyer cannot separate the two: establish what crosses that boundary, which entities can see a given provider's re used record, on what legal basis, and whether the provider is told or able to correct it.

The data is highly sensitive and sits largely outside health privacy law, covering national identifiers, controlled substance registrations, state licences, board certifications, malpractice history, sanctions and exclusion records, and commonly social security numbers, governed instead by state breach notification law, consumer protection law and payer contract terms.

The vendor's own framing is accurate: what flows through a credentialing platform is provider and customer data rather than patient data, so a mid grade here does not carry the meaning it would for a clinical vendor. Published: encryption, strict access management, infrastructure audits and formal incident response, plus an external certification subjecting file handling and quality oversight to inspection. Absent: retention or deletion schedule for verification source documents, any statement on whether provider data trains the agents, and sub processor disclosure.

BB on Clinical and Operational EvidenceNamed deployments with dated outcome figures and enough method to test them, or published research short of independent validation.
Vendor Published

Operational rather than clinical, appropriately, and backed by an unusual commercial commitment. The company states it stands behind credentialing operations with performance backed guarantees, which transfers some delivery risk to the vendor and is rare in this index. Third party analysis cites credentialing time cut by up to 80 percent with committee ready files in days rather than weeks.

The company reports saving more than 250,000 administrative hours across named customers including several large digital health and primary care organizations. Figures are vendor or third party reported without independent audit.

CC on AI Safety and PHI StewardshipGeneral assurances of privacy and security that do not answer the questions artificial intelligence raises: what is retained, what reaches a model, and what happens to it there.
Vendor Published

The company's own framing describes protecting provider and customer data as foundational, not patient data, which is the correct description of what flows through a credentialing platform and means a low grade here does not carry the meaning it would for a clinical vendor. The data is still highly sensitive: national provider identifiers, DEA registrations, state licences, board certifications, malpractice history, sanctions and exclusion records, and commonly Social Security numbers.

It sits largely outside HIPAA, governed instead by state breach notification law, the FTC Act and payer contract terms. What is published: encryption, strict access management, infrastructure audits and formal incident response procedures, plus NCQA certification, which subjects file handling and quality oversight to external inspection.

What is absent and would support a higher grade: no retention or deletion schedule for verification source documents, no statement on whether provider data trains or improves the AI agents, no data classification policy and no subprocessor disclosure. One architectural feature makes the retention and visibility question sharper here.

Medallion markets a solution that reduces redundant recredentialing effort for payers, and reducing redundancy across payers necessarily means verified provider data is shared or re used beyond the customer that originally collected it. Worth establishing what crosses that boundary, which entities can see a given provider's re used record, on what legal basis, and whether the provider is told or able to correct it.

Regulatory and Compliance
CC on HIPAA and BAA PostureCompliance is claimed without the underlying document, or the published privacy notice covers the website rather than the service that handles patients.
Vendor Published

No business associate agreement statement, terms, tier or execution path was located, and no explicit HIPAA assertion was found. That absence is more pointed here than elsewhere in this segment, because this vendor has a dedicated compliance page that addresses NCQA and SOC 2 and does not mention HIPAA at all.

When a company builds a page specifically to answer compliance questions and omits the United States health privacy statute, that reads as a scoping decision rather than an oversight, and it is consistent with the shape of this segment: the core dataset is provider identity data, so HIPAA is genuinely not the primary governing regime for most of it. That is context rather than absolution.

Medallion sells payer enrolment, delegated credentialing and network operations to health plans and large provider groups, and integrates directly with CAQH, so configurations touching data that is unambiguously protected health information are plausible and an agreement is very likely executed in practice even though none is published.

The non HIPAA data carries its own regime, since Social Security numbers, DEA registrations and licensure records concentrate identity theft exposure under state breach law and the FTC Act, which a buyer's compliance team will still need answered. Two questions worth putting directly: whether an agreement is executed as standard and at which tier, and which regulatory regime the vendor treats as governing for provider information falling outside HIPAA. The compliance page was read in full; the privacy policy and terms of service were not opened.

CC on Security Certifications and Trust CenterControls are described with an outside check behind them, such as independent penetration testing on a stated cadence, but no attestation against a recognised framework.
Vendor Published

A dedicated compliance page exists, which is more than several competitors offer, and it states that Medallion is SOC 2 compliant without specifying the type. The type is the substantive question: Type 1 tests control design at a point in time, while Type 2 tests whether controls operated effectively across a period. Third party sources describe Medallion as SOC 2 Type 2 compliant, and that is not treated as vendor disclosure here.

Specifying the type on the company's own compliance page would change this assessment immediately. What is genuinely credited: the controls are described substantively rather than gestured at, covering encryption, strict access management, infrastructure audits and formal incident response procedures, and the SOC 2 scope is characterised as security, availability and data protection.

The stronger external examination sits on the regulatory axis and is worth reading across: NCQA certification for credentialing means an accreditor has inspected documentation, verification and quality oversight practice, which is a real third party review of exactly the file handling this axis cares about.

Held at this level on the unspecified type plus three absences: no public trust centre, so certificates and audit dates cannot be checked; no penetration testing statement; and no ISO 27001 or HITRUST located.

BB on FDA and Regulatory StatusThe pathway is stated and in progress, or a clearance is named without the vintage and scope a buyer needs to match it to the product on offer.
Vendor Published

No FDA pathway applies, but this vendor operates under a real and specific accreditation regime that functions as its equivalent. The company describes an NCQA certified credentials verification organization and states it generates NCQA compliant credentialing files in real time, with workflows aligned to both NCQA and Joint Commission standards for privileging. Those accreditations are what allow a health plan or health system to rely on delegated credentialing, so they are the credential that matters commercially, and the company holds them.

CC on AI Governance and Bias DisclosureResponsible artificial intelligence is committed to in policy language with no evaluation behind it. Most of the index sits here.
Vendor Published

No formal governance framework was located, but the stated design of expert review at critical stages before work advances, plus specialists handling automation exceptions, is a functioning control on AI error even though it is not framed as governance.

No bias analysis was located, and the relevant question is whether verification performance varies by provider type, state licensing board, or credential pathway, since uneven automation could slow credentialing for clinicians from less common backgrounds.

DD on AI Liability and RecourseNothing published on what happens when the system is wrong.
Vendor Published

Two passes located no model provider, architecture, accuracy measurement, validation methodology or warranty, indemnity or remediation commitment. The specific missing figure is worth naming because it is the right one for a product of this shape and it is not a general accuracy number.

The company sells an agent workforce, and the measure that tells a buyer whether that claim holds is the exception rate: how much of the work the agents complete unaided, and how much falls through to a person. A product marketed as replacing manual effort with automation is making a quantitative claim by implication, and the exception rate is that claim made explicit.

Without it a buyer cannot distinguish a system that handles most cases end to end from one that handles the easy ones and routes the rest, and the two have completely different economics and completely different staffing consequences. The consequence side is also personal rather than institutional.

Credentialing decides whether a clinician can practise and bill, so an error delays or blocks someone's ability to work, and a wrongly failed verification is not absorbed by a workflow the way a wrong suggestion is. Ask for the exception rate, what the agents decide unaided versus route to a human, the error rate on completed verifications, and what recourse a provider has when a verification fails wrongly.

Integration and Deployment
BB on EHR and Interoperability DepthNamed systems with read access or one directional writing, or standards support with named deployments behind it.
Vendor Published

Integration is with credentialing infrastructure rather than the clinical record, which is the correct surface. The company integrates directly with primary sources including the federation of state medical boards, the national practitioner data bank, federal exclusion and entity databases, and the national provider registry to verify and monitor credentials automatically, and operates its own payer clearinghouse for enrollment submission. Continuous monitoring against those sources with real time alerts on credential and sanction changes is a materially harder integration than periodic manual checks. No EHR integration applies.

CC on Deployment Model and Data ResidencyA single hosted option with location implied rather than committed.
Vendor Published

The model is a hybrid of software and staffed service rather than pure software: the platform is wrapped around an NCQA certified credentials verification operation, described as AI agents purpose built for credentialing and overseen by industry experts, with credentialing specialists reviewing critical stages. Direct integration with CAQH is named, which is the sector's central provider data utility and a meaningful interoperability anchor in this segment.

The distinctive and genuinely creditable feature is commercial rather than technical, and almost nothing in this index offers it: Medallion publishes performance backed guarantees, including one day credentialing file delivery and a stated near 100 percent accuracy guarantee. A contractual service level commitment is a different and stronger thing than a marketing metric, because it transfers risk to the vendor and is enforceable.

It is also the only accuracy figure found anywhere in this segment, though the phrase near 100 percent is imprecise and the denominator, the definition of an error and the remedy on breach are all unpublished. Held at this level on the absences this axis exists to catch, which are common across this segment: no data residency statement of any kind, no region and no residency commitment, no hosting provider or cloud named, and no implementation timeline or support model.

The services component raises a further question worth asking, since a staffed verification operation means human reviewers handling provider Social Security numbers and licensure files at scale, making personnel screening, access control and staffing location live issues a pure software vendor does not face.

Commercial
CC on Commercial TransparencyNo price is published and the posture is discoverable: a buyer can establish how the product is sold and what drives the cost before contacting the vendor. Most of the index sits here.
Third Party Estimated

No published rates, but two disclosures give a buyer more than most vendors here provide. The company states it offers performance backed guarantees on credentialing operations, which is a commercial term rather than a marketing claim and shifts delivery risk. Third party review notes the absence of a strong self service option for organizations wanting to manage their own enrollments, which implies the model is oriented toward managed service rather than software licensing. Neither structure nor price is published.

AA on Setting and Specialty CoverageWhere the product is validated to operate is named and supported, settings and specialties both, whether the coverage is broad or deliberately narrow.
Vendor Published

Broad on every dimension that matters for this function. Provider type coverage spans all major categories including physicians, nurses, nurse practitioners, physician assistants, and licensed clinical social workers. Geographic coverage spans all United States states and territories for licensing.

Functional coverage runs the full lifecycle: licensing, primary source verification, credentialing, payer enrollment for both commercial and public programs, delegated credentialing, privileging, and continuous monitoring. Buyer types span health systems, digital health companies, payers, and provider groups.

Tracked Since Listing

What Changed

Material product, regulatory, evidence and commercial changes at Medallion, each verified against a live source and tagged to the capability axis it bears on. Funding rounds and awards are not product changes and are not logged.

Aug 24, 2026Product / capability

Medallion shipped three platform capabilities at once. An AI provider outreach agent now contacts stalled providers by phone, text and email to chase profile completion, taking over the follow up that credentialing coordinators normally do by hand. Provider profile auto fill populates records from NPPES, CAQH and uploaded documents instead of requiring the provider to retype what already exists in public registries. Self serve webhooks let organizations push enrollment and credentialing status changes into their own systems over API rather than polling for them.

Bears on: AI CentralitySource
Our read on this change →Tracked since Aug 2026
Comparisons

Compared With

Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Contact the vendor
Undisclosed. Managed service oriented rather than self service software, serving health systems, digital health companies, payers, and provider groups. Not disclosed, and less central here than for most vendors since the platform operates on provider credentials rather than patient records. Not disclosed. Third Party Estimated

Two disclosures give a buyer unusual purchase here despite the absent rate. The company states it offers performance backed guarantees on credentialing operations, which is a contractual commitment shifting delivery risk to the vendor and is rare in this index. Separately, third party review notes the lack of a strong self service option for organizations wanting to manage their own enrollments, which signals the model is oriented toward managed service rather than software licensing. A buyer should establish what the guarantees actually cover and what remedies attach.