Medwise.ai
Clinical search platform built for the National Health Service, from Medwise AI Ltd, registered in England and Wales and now based in Leeds having started in Cambridge. Co founded in 2019 by Dr Keith Tsui, a doctor, and Luis Ulloa, who came from applied machine learning.
The distinguishing feature is what it indexes. Alongside national guidance from the National Institute for Health and Care Excellence and other national sources, it ingests an individual trust's own local policies, formularies and antimicrobial guidelines, and answers a natural language question across both in one place. No other vendor in this category holds national and local institutional guidance in the same answer surface: the reference incumbents index published evidence only, and the institutional knowledge tools index only what the hospital wrote.
The platform states conformance to the clinical risk management standards that govern health information systems in England, covering both the manufacturer's safety case and the deploying organisation's, and its published terms carry an explicit statement that the platform involves artificial intelligence and automated decision making when returning results and generating responses, framed by the company as something good governance requires it to say plainly.
Evidence includes a peer reviewed prospective pilot conducted with a Welsh health board on emergency and acute medicine queries, and an evaluation funded through a national innovation agency which estimated substantial time savings per search. Set against that, a headline claim of a 25 percent consultation time saving was published without a supporting reference, and an independent reviewer testing the platform in general practice reported finding a filtered link list rather than synthesis and no saving of that scale. Both are on the record.
Commercial model is unclear from public material: earlier accounts describe free sign up open to any healthcare professional, later third party accounts describe enterprise licensing not available to individual clinicians.
Capability Axes
The asset is corpus assembly and governance conformance more than it is a model, and the record should say so plainly rather than either inflating or dismissing the technology.
What is genuinely hard here is getting an individual trust's own policies, formularies and antimicrobial guidance indexed, kept current and made searchable alongside national guidance. That is content plumbing and institutional relationship work, and it is the reason customers buy. Strip the model out and a federated guideline search across national and local sources remains, which is a real product.
The evidence on the model layer is mixed and dated, and both halves belong on the record. An independent reviewer testing the platform in general practice reported that it returned a list of links to trusted sources with keywords highlighted rather than a synthesised answer, and concluded it did not appear to be using much artificial intelligence. That assessment is now some years old. The company's current published terms describe the platform as generating responses and involving automated decision making, so it has moved since. Nothing published describes how.
Graded C on that combination: a distinctive and defensible asset that is not primarily a model, plus a generation layer whose mechanism is undescribed. Flagged for refresh, since this axis could move if the current generation capability is documented.
One published statement here is unlike anything else in this category. The platform terms state expressly that using it involves interacting with an artificial intelligence interface and a recommender system, that returning search results and generating responses involves automated decision making, and that the platform does not make decisions about people with legal or similarly significant effects. The company frames the disclosure itself as what good governance requires, rather than burying it.
That is a jurisdictional artefact and it is worth naming as such. Vendors operating under the United Kingdom data protection regime face an obligation around automated decision making that the United States cohort does not, and it produces an affirmative statement of what the system is and what it does not decide. Every vendor in this category should be able to say that; only this one does.
Grounding is to curated national and local sources rather than the open web, which bounds the answer space.
Held at B on a question unique to this product's architecture, and it is the sharpest thing to ask the vendor. This is the only platform in the category that indexes national guidance and a hospital's own local protocol in the same answer surface. Nothing published states what happens when the two disagree: whether the local protocol wins, whether the conflict is surfaced to the clinician, or whether one is silently preferred. A clinician acting on the wrong one of two authoritative sources is the failure mode this product creates and no competitor faces. No abstention behaviour is described either.
The vocabulary is published and the mechanism is not. The company describes natural language processing and artificial intelligence technology, and its terms name an artificial intelligence interface, a recommender system and automated decision making. No model class, no provider, no retrieval architecture, no ranking method and no evaluation harness were located in two retrieval passes.
The local guidance ingestion is the part a buyer most needs described and it is the least described. How local documents are parsed, how often they are refreshed, how a superseded trust policy is detected and retired, and how the system decides which corpus to draw on for a given question are all unstated. For a product whose whole proposition is that it knows your hospital's own protocol, the freshness and retirement mechanism is the transparency question that matters.
One claim circulating about this vendor is that its enterprise tier carries a zero risk of hallucination by virtue of strict grounding. That characterisation appears in material published by a competing United Kingdom clinical artificial intelligence vendor, not on this company's own site, and it was not verified here. It is recorded as unverified and is not graded on. If it does appear on the vendor's own material at refresh it should be treated the same way this index has treated identical claims elsewhere in the category.
More independent scrutiny than most vendors in this category attract, and it points in two directions, which is why this sits at the top of a C rather than higher.
On the positive side there is a peer reviewed prospective pilot study conducted with a Welsh health board, examining user experience and time efficiency against traditional guideline searching for hospital emergencies. A peer reviewed prospective study of the actual product is rare in this category. There is also an evaluation funded through a national innovation agency reporting roughly two and a half minutes saved per search during a ten minute consultation, and a modelled national saving on one clinical topic.
Two caveats limit what that establishes. The pilot was conducted with a health board that co developed the platform, so it is not arm's length. And it measured time and satisfaction, not correctness. Nothing located measures whether the answers returned are right, which is the question this category exists to answer.
Against it sits an independent critical assessment in a professional journal, and this index takes those seriously because it receives so few. The reviewer noted that a published claim of a 25 percent consultation time saving carried no supporting reference, tested the platform in practice, and reported neither synthesis nor anything approaching that saving. A vendor publishing a headline efficiency figure with no citation, in a market where an independent reviewer will check it, is the specific thing to ask about.
The architecture is favourable in the same way as most of this category: the system answers from guidance documents rather than from a patient record, so patient data is not required for the product to work.
The published terms address the artificial intelligence interaction directly and state that the platform does not make decisions about people with legal or similarly significant effects, which is a meaningful statement about the limits of automated processing even though it is not a data handling statement.
Beyond that, nothing was located. No retention period, no data residency statement, no encryption practice, no statement on whether free text clinical queries are stored or used to improve the system, and no data protection impact assessment or processing agreement published. For a supplier selling into health organisations that must complete their own data protection assessments before deployment, publishing the supplier side documentation would remove a procurement step, and it is the obvious thing to ask for.
Graded on what a buyer can find rather than as a finding that controls are absent. Flagged for refresh.
This axis is graded against the framework that actually governs the vendor rather than against an irrelevant one, per this index's stated method. The company is registered in England and Wales and sells into the National Health Service, so the governing regime is United Kingdom data protection law and the health service's own data security requirements, not the United States health privacy statute. A business associate agreement is not the instrument a buyer here would ask for, and its absence is not a finding.
What is verifiable is thin. The published terms carry an affirmative statement about artificial intelligence and automated decision making, which reflects a specific obligation under the United Kingdom regime and is credited. The company states conformance to the clinical risk management standards for health information systems, which carry data and safety obligations of their own.
What is not published and would be the equivalent artefacts: a data processing agreement, evidence of completion of the health service data security self assessment that gates procurement, a data protection impact assessment, and a statement of where data is processed and stored. None was located in two passes. A buyer should request the full compliance pack rather than rely on the site.
Graded C for the same reason a United States vendor asserting compliance without publishing an instrument grades C: the posture is stated and nothing can be inspected.
No certification was located in two retrieval passes. No ISO 27001, no Cyber Essentials or Cyber Essentials Plus, no SOC 2 of either type, no trust centre, no penetration test statement and no vulnerability disclosure programme.
That is a conspicuous gap in this particular market rather than a general one. Suppliers to health organisations in England are routinely asked for a defined compliance pack during procurement, and the certifications a buyer expects are well known and specific. A vendor selling at claimed scale across health service organisations has necessarily produced this material repeatedly for individual customers; none of it is published.
Recorded as a retrieval outcome and not as a finding that controls are absent. The fastest route to closing it is to ask for the same pack the vendor has already supplied to its existing deployments, and to ask specifically whether processing and storage remain within the United Kingdom.
Graded against the regime that governs this vendor. There is no United States clearance and none would be sought, so the relevant question is the United Kingdom position, and here this record is ahead of every other vendor in the category.
The platform states conformance to the two clinical risk management standards that apply to health information systems in England: the one placing obligations on the manufacturer, and the one placing obligations on the deploying health organisation. Conformance to the manufacturer standard requires a documented clinical safety case, a hazard log and a named clinical safety officer. No United States vendor in this category has published an equivalent commitment under its own regime, and several publish nothing at all about regulatory position.
One precision point belongs on the record and it generalises. These standards are conformance obligations evidenced by a safety case the manufacturer produces, not certificates awarded by a regulator, and third party write ups sometimes describe them as certifications. That distinction is the same one this index already applies to the difference between being registered with a device regulator and being cleared by one. Conformance is real and meaningful; it is not third party approval.
Held at B rather than A because the safety case itself is not published, conformance is self declared, and no position is stated on whether the product is treated as a medical device by the United Kingdom regulator. Ask for the safety case and the hazard log, and for the clinical safety officer by name.
One distinctive artefact and very little around it.
The artefact is the affirmative statement in the platform terms that the service involves an artificial intelligence interface, a recommender system and automated decision making, and that it does not make decisions about people with legal or similarly significant effects, published with an explicit rationale that good governance means saying so expressly. That is the single clearest governance sentence any vendor in this category publishes, and it exists because the regime the vendor operates under asks for it. Conformance to clinical risk management standards adds a mandated hazard and safety process behind it.
Everything else is missing. No artificial intelligence principles document, no responsible use framework, no external advisory body, no bias evaluation, no subgroup analysis, no error taxonomy and no published measurement of any kind.
Held at C rather than B on that comparison. Two other vendors in this category publish full principle sets with named commitments on bias and explainability and still grade B because they publish no results. A single clause plus mandated conformance is less than a principle set, however well aimed the clause is.
The bias question specific to this product has not been asked anywhere: local guidance is written by individual institutions with varying resource and rigour, so a platform that ranks local protocol alongside national guidance is making an editorial judgement about relative authority on every query.
No integration was verified on the vendor's own material in two retrieval passes. No named clinical system, no marketplace listing, no conformance statement for a health data exchange standard, no clinical terminology support and no application programming interface were located.
Access is described as web based, reachable through health service email credentials among other routes, which is a practical authentication path in this market but is not integration.
A claim that the enterprise tier offers integration with electronic patient record systems appears in material published by a competing vendor rather than by this company, and is recorded here as unverified and not graded on. Given that the two dominant primary care systems in this market are well known and that integration with them is the decisive procurement question for a point of care tool, the absence of any named integration on the vendor's own site is the gap to close first.
Hosted web platform, deployed at health service organisations and configured per organisation with that organisation's own local guidance loaded alongside national sources. That configuration step is the substance of deployment here and it is genuinely different from the other vendors in this category, where deployment means granting access to a fixed corpus.
Geographic scope is effectively a single market. The product is built around one country's national guidance and one health service's institutional structure, which is a deliberate and defensible focus rather than a limitation, but it means the deployment picture does not generalise.
No hosting provider, no cloud region and no explicit data residency statement were located. Operating exclusively in one market implies domestic processing but does not establish it, and residency is a standard procurement question in this market rather than an unusual one, so the absence of a published statement is more surprising here than it would be elsewhere. No alternative deployment model exists for an organisation requiring processing inside its own environment.
The public record is contradictory across time and the record states both accounts with their dating rather than picking one.
An independent review some years ago described the platform as available free of charge, open to sign up by any healthcare professional, reachable through health service email credentials. More recent third party material describes enterprise licensing sold to organisations and explicitly not available to individual clinicians. The likeliest reading is a deliberate move from open individual access to institutional sales, which is a normal path, but nothing on the vendor's own material states the current position.
No price, tier structure, per seat basis, per organisation basis or implementation fee was located at any point. For a product sold into public health organisations, where procurement is documented and comparative, publishing a pricing basis would be unusually low cost and unusually useful.
A buyer's first question should therefore be the simplest one: is there still a free tier, and if so what is in it and what is not.
Coverage is defined by an institution rather than by a specialty, which is unusual in this category and worth stating precisely. What a given clinician can find depends on what their own organisation has loaded, so coverage varies by deployment rather than being a fixed property of the product.
On the general side, national guidance provides a common floor across all deployments. On the local side the named content types are policies, formularies and antimicrobial guidance, and antimicrobial guidance is the clearest example of why the product exists, since local resistance patterns cannot come from a national source.
Settings evidenced are general practice, where the time saving claims originate, and emergency and acute medicine, where the peer reviewed pilot was conducted. Both are within one national health system, and no coverage outside that market is claimed.
Held at C because breadth is narrow by design and because demonstrated usefulness rests on two settings in one country, with no specialty level evidence published. The narrowness is a coherent strategy, not a failing, and a buyer inside that market should weigh it very differently from a buyer outside it.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
Not published; earlier accounts describe free access for healthcare professionals, later accounts describe enterprise licensing only
|
Not published; organisation level licensing, quoted case by case | Not applicable to this jurisdiction. The governing instruments would be a data processing agreement and evidence of the health service data security self assessment; neither was located | Not published; local guidance ingestion and configuration are part of deployment and their commercial treatment is unstated | Vendor Published |
The public record contradicts itself across time and both accounts are recorded here with their dating rather than one being chosen.
An independent review published some years ago described the platform as available free of charge and open to sign up by any healthcare professional, reachable through health service email credentials. More recent third party material describes enterprise licensing sold to organisations and explicitly not available to individual clinicians. The likeliest reading is a deliberate shift from open individual access to institutional sales, which is an ordinary path for a vendor moving upmarket, but nothing on the company's own material states the current position.
No figure was located at any point on any tier: no per seat rate, no per organisation rate, no implementation or configuration fee, and no statement of what the local guidance ingestion and ongoing maintenance costs, which is the work that actually differentiates the product.
That last point is the one to press. Loading, refreshing and retiring an individual organisation's own policies is recurring effort, and a buyer should establish whether it is included, charged once at onboarding, or billed as the local corpus grows.
For a product sold into public health organisations, where procurement is documented and comparable, publishing a pricing basis would cost the vendor very little.