Nanox.AI
Deep learning medical imaging analytics company, formerly Zebra Medical Vision, acquired in November 2021 for up to 200 million dollars and now operating as the AI subsidiary of Nasdaq listed medical imaging hardware company Nano-X Imaging. Its distinguishing strategy is opportunistic population health screening: mining CT scans already acquired for unrelated clinical reasons to surface undiagnosed conditions, with cleared products covering vertebral compression fractures and low bone density associated with osteoporosis via HealthOST, coronary artery calcium quantification for cardiovascular risk, plus pneumothorax and brain bleed detection. Reported ten FDA clearances across the portfolio. Sold to hospitals, HMOs, integrated delivery networks, pharmaceutical companies, and insurers.
Capability Axes
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read
The software subsidiary is purely algorithmic, mining existing CT scans with no scanner or services layer of its own. The complication is corporate rather than technical: since the 2021 acquisition this is the AI arm of a medical imaging HARDWARE company whose primary business is a multi-source digital X-ray system, and the parent's strategy pairs that hardware with a teleradiology network and pay-per-scan model. The algorithms are genuinely central to this business unit; they are one line of a hardware company. Graded B rather than A to reflect that structural position.
Cleared as clinical decision assist, presenting findings for radiologist evaluation rather than issuing conclusions. The opportunistic screening model creates a distinctive oversight question worth naming: the algorithm surfaces findings on scans ordered for entirely unrelated reasons, which means it generates work nobody requested and places on the health system a duty to act on incidental findings it was not looking for. That is a workflow and liability design decision as much as a clinical one, and the vendor materials do not address who owns follow up.
Product function and regulatory scope are described clearly, including which anatomical findings each cleared tool addresses, but performance is not published in the materials reviewed. No sensitivity, specificity, or reader study results were located for the individual products, and no third party head to head benchmarking.
As a Nasdaq listed parent the company files detailed SEC disclosures describing the product line, which gives more corporate transparency than most private competitors, but corporate disclosure is not model disclosure.
No handling or governance framework was located, and this is the vendor in the lane where that absence carries the most weight, because secondary use is not an edge case here. It is the business model. The product mines computed tomography studies acquired for unrelated clinical reasons, at archive scale, to surface conditions nobody was looking for, so every patient whose scan is analysed had that scan taken for a different purpose and in most cases will not know a second analysis occurred.
The questions that follow are unanswered: what authority the reanalysis runs under, whether the patient is told, what is retained after a finding is generated, and whether results are written back to the record. The customer list sharpens it further and turns the recipient into part of the stewardship question rather than a commercial detail. Alongside hospitals and delivery networks, the company sells to insurers and to pharmaceutical companies.
When the organisation commissioning an archive analysis is the one paying for the patient's care, or is a manufacturer of treatment for the condition being surfaced, who receives a finding and in what form matters as much as whether the finding is correct. Establish who receives it, whether it is identifiable, and whether the patient or their clinician learns of it at all. Ask also for retention, the de identification standard applied to studies analysed at scale, and whether analysed imaging contributes to model development.
The regulatory record is substantial, with a reported ten FDA clearances, and independent literature exists on the underlying concept, including a large French study of fully automated opportunistic screening for vertebral fractures and osteoporosis across more than 150,000 routine CT scans.
What was not located is peer reviewed outcome evidence specific to these products showing that opportunistic detection changes management or patient outcomes, which is the harder and more relevant question for a population health screening tool. Clearances demonstrate the algorithm detects; they do not demonstrate the program helps.
No handling or data governance framework was located, and this is the vendor in the lane where that absence carries the most weight, because secondary use is not an edge case here. It is the business model.
The product mines computed tomography studies that were acquired for unrelated clinical reasons, at archive scale, to surface conditions nobody was looking for. So every patient whose scan is analysed had that scan taken for a different purpose, and in most cases will not know a second analysis occurred. The questions that follow are not answered anywhere: what authority the reanalysis runs under, whether the patient is told, what is retained after a finding is generated, and whether results are written back to the record.
The customer list sharpens it further. Alongside hospitals and delivery networks, the company sells to insurers and to pharmaceutical companies. When the organisation commissioning an archive analysis is the one paying for the patient's care, or is a manufacturer of treatment for the condition being surfaced, the identity of the recipient becomes part of the stewardship question rather than a commercial detail. Establish who receives a finding, in what form, whether it is identifiable, and whether the patient or their clinician learns of it at all.
Ask for retention, for the de identification standard applied to studies analysed at scale, and for a plain statement of whether analysed imaging contributes to model development.
No commitment was located, and the customer mix means one agreement will not cover the business.
The company sells to hospitals, health maintenance organisations, integrated delivery networks, insurers and pharmaceutical companies. Those are not the same relationship. Providers and health plans are covered entities, so business associate terms apply and are required. Pharmaceutical manufacturers generally are not covered entities at all, which puts that part of the business outside the framework entirely and makes the patient's own authorisation the operative instrument rather than any agreement the vendor signs. A buyer should establish which of these its own engagement is, and should assume nothing carries across from one to another.
Jurisdiction adds a second layer. The operating company is in Israel under an Israeli parent, selling into United States health systems and plans, so Israeli privacy law governs the corporate entity while the United States framework attaches to the deployments. Israeli privacy law was substantially strengthened in 2025, which makes the parent side more demanding than it was when older material was written.
The parent's annual filing acknowledges that data protection and localisation rules may impose obligations on the company and on its ecosystem partners. That is an acknowledgment that the obligations exist. It is not a statement of what the company does about them, and nothing published closes that gap.
No attestation and no trust centre were located on any company surface. But there is a filed, legally attested document that a security reviewer should read, and it is not on the website.
The parent is a Nasdaq listed foreign private issuer and filed its most recent annual report on Form 20-F on 30 April 2026. Foreign private issuers disclose cybersecurity risk management, strategy and governance under Item 16K, the equivalent of the Item 1C requirement that applies to domestic filers, so a description of how this group assesses and manages cybersecurity risk exists in that filing whether or not anything appears in marketing material. Read that section before concluding the group has said nothing.
What is already visible from the filing's risk factors is worth carrying into the conversation, with one distinction attached. The company discloses that integration with third party systems and legacy infrastructure presents interoperability and cybersecurity risks it does not fully control, that its offering includes cloud based software working alongside customer networks, and that cybersecurity vulnerabilities could necessitate field corrective actions or recalls and could jeopardise regulatory authorisations.
The distinction: a securities risk factor is a warning written to protect an issuer from shareholder claims, not an assurance written for a customer. It establishes that the company takes the risk seriously enough to disclose it. It is not evidence that controls exist or have been examined. Graded C because no independent attestation was found and the governance section itself was not retrieved here.
Separately, assess supplier continuity from the same filing's liquidity discussion rather than from product pages.
A deep US clearance portfolio built over years, reported as ten FDA clearances spanning vertebral compression fractures cleared first in May 2020 and again via HealthOST in 2022, coronary artery calcium quantification, pneumothorax, and intracranial hemorrhage. Multiple clearances on the same clinical target, an initial detection clearance followed by a more precise quantitative one, shows iterative regulatory maturation rather than a single legacy clearance. Comfortably an A on breadth and currency of US authorization.
No governance framework, monitoring commitment or subgroup analysis was located. The gap is notable for a population health product, since opportunistic screening applied across an entire imaging archive will surface findings at different rates across demographic groups, and who gets flagged determines who receives follow up care.
Two things make the silence harder to excuse here than elsewhere in this lane.
The first is that the underlying measurements have documented demographic variation that is not a hypothetical concern but established clinical knowledge. Bone density reference ranges differ by sex and by ancestry, and the choice of reference population directly determines who crosses a diagnostic threshold. Coronary artery calcium distributions likewise differ by sex and ethnic group at the same level of underlying risk. A product quantifying both, at population scale, is making threshold decisions whose demographic behaviour is already known to vary, and it publishes nothing about which reference standards it applies or how it validated across groups.
The second is that the company reports around ten clearances across the portfolio, so per product performance data was generated and submitted for each of them. The information required to say something useful about subgroup behaviour exists. Publishing none of it is a choice rather than a limitation of an early stage company.
Ask which reference populations the thresholds derive from, and for detection and false positive rates by sex, age and ancestry across the screening portfolio.
Product function and regulatory scope are described clearly, including which anatomical findings each cleared tool addresses, and no performance was located in the materials reviewed: no sensitivity, specificity or reader study results for the individual products, no evaluation methodology, no third party benchmarking, and no warranty, indemnity or remediation commitment. The contrast inside the company is the fourth instance of a pattern this backfill keeps finding.
As a listed business it files detailed securities disclosures describing the product line, giving more corporate transparency than most private competitors, and corporate disclosure is not model disclosure. A firm capable of precise, audited, consequential public reporting is applying it where an external obligation exists and not otherwise, which disposes of the usual explanation that publication is too hard or too legally fraught.
The missing figures matter more given what the product does. An opportunistic screening tool surfaces findings in patients who were not being investigated for that condition, so both error types have unusual consequences: a false positive initiates a workup nobody would otherwise have started, in a person with no symptoms, and a false negative is invisible because the study was never being read for that purpose anyway. Neither rate is published. Ask for sensitivity and specificity per finding type, the positive predictive value in an unselected population, and what a patient is told about an incidental result.
Operates on existing CT archives and delivers findings into clinical workflows, with the parent describing cloud based computing infrastructure supporting its imaging systems. Customers span hospitals, HMOs, integrated delivery networks, insurers, and pharmaceutical companies, which implies varied delivery paths from PACS integration to bulk archive analysis. No named connector list, API documentation, or EHR integration detail was located.
The parent describes cloud based computing infrastructure as part of its cleared system, and the AI products work by mining existing scan archives, which implies scans are processed in vendor infrastructure rather than on premise. Specific tenancy, hosting, and residency terms are not published, which matters given the customer base includes insurers and pharmaceutical companies rather than only treating providers.
No product pricing is published, though the parent is Nasdaq listed and files SEC disclosures describing the business model and product line, which gives more visibility into company finances and strategy than any private imaging AI competitor offers.
The parent has publicly described a pay-per-scan model for its imaging hardware, but whether the AI products follow per scan, per site, or population licensing is not disclosed, and the answer materially changes the economics of a screening program run across an entire archive.
Focused by design on opportunistic population health rather than diagnostic breadth: musculoskeletal via vertebral fracture and bone density, cardiovascular via coronary calcium, with hepatic steatosis described as in development, plus acute findings including pneumothorax and brain bleed. The unifying thesis is chronic disease detection from scans already taken, which is a genuinely different market position from triage vendors competing on emergency turnaround. Coverage is CT centric and does not span general radiology.
Compared With
Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
Contact the vendor
|
Undisclosed. Sold to hospitals, HMOs, integrated delivery networks, insurers, and pharmaceutical companies; licensing structure not published. | Not disclosed. An Israel headquartered subsidiary selling to US health plans and insurers would need business associate terms established directly. | Not disclosed. Products operate on existing CT archives, and the parent describes cloud based computing infrastructure, which implies vendor side processing rather than on premise installation. | Vendor Published |
No product pricing is published, though the Nasdaq listed parent files SEC disclosures describing the business model and product line, giving more corporate visibility than any private imaging AI competitor. The parent has described a pay-per-scan model for its imaging hardware, but whether the AI products follow per scan, per site, or population licensing is not disclosed, and that answer materially changes the economics: an opportunistic screening program run across an entire existing CT archive has a very different cost profile under per scan pricing than under a population licence. Buyers should also budget for the downstream consequence rather than only the software, since surfacing incidental findings at scale creates follow up workload the health system must absorb.