NeuroFlow
Behavioral health integration infrastructure sold to risk bearing organisations, health systems and health plans rather than to patients. Founded 2016 in Philadelphia by Chris Molaro, chief executive, and Adam Pardes, chief operating officer; one source gives 2017. Funding totals roughly 58 million dollars, including a 20 million dollar Series B led by Magellan Health and a 25 million dollar growth round led by SEMCAP Health, with a later private equity round.
The premise is that behavioral health need surfaces in physical care settings that are not equipped to handle it. Three named products address that in sequence. BHIQ applies machine learning across claims, record system, admission discharge transfer and assessment data to surface undiagnosed and undertreated behavioral health conditions across a population. IntegrateBH, expanded in February 2026 with capabilities from recent acquisitions, operationalises those findings through risk identification, intelligent referral matching and care coordination, delivering patient data inside the provider's existing workflow. TxProgress measures treatment impact over time.
One component distinguishes this record from every other behavioral health vendor in the index and should be read against them directly. NeuroFlow operates Response Services, a human staffed safety net for crisis moments, which the company describes as unique in its ability and willingness to address suicidality. The two patient facing conversational products built immediately before this one, Wysa and Limbic, publish no crisis escalation pathway at all. This company sells one.
Named customers include Magellan Health, Trinity Health, Bozeman Health and the Department of Defense, with platform reach reported at roughly 15 million patients. Note that Magellan Health is both a customer and the investor that led the Series B, so that reference is not disinterested. The company was a finalist in a federal grand challenge to reduce veteran suicide, receiving 250,000 dollars and advancing to a second phase, which is competitive government evaluation rather than a marketing award.
Security credentials are stated correctly and with their tiers: health specific certification at the implemented one year level, a controls report at the second type, and privacy compliance. A published example reports a large integrated health system stratifying more than 3,000 patients within four months.
The gaps are measurement and commerce. No accuracy figure is published for the risk identification models, no peer reviewed evidence was located, and nothing about pricing is disclosed.
Capability Axes
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read
The models carry the identification and a substantial platform carries everything after it. Machine learning applied across claims, record system, admission discharge transfer and assessment data is what surfaces behavioral health risk that a health system could not otherwise see, and that is genuine analytical work rather than reporting.
What sits around it would retain value without the models. Referral matching, care coordination, patient engagement between visits, outcome measurement and the human staffed crisis response are workflow, infrastructure and labour. The company's own description is a combination of workflow automation, patient engagement solutions and services, and applied artificial intelligence, which lists the models third and includes services explicitly.
Graded B on the same reasoning applied to Optum Integrity One, Infinx and Andor Health: real intelligence doing consequential work, inside a platform that is more than the intelligence. The human response service is a deliberate design choice rather than a dilution, and it is discussed on the autonomy axis where it belongs.
The best crisis architecture in the behavioral health lane, and the reason this record reads as a corrective to the two built before it.
The model identifies and stratifies; a human decides. Risk findings are delivered into the provider's existing workflow rather than acted on autonomously, so a clinician owns every downstream decision. Automated follow up runs between visits, and beneath it sits Response Services, a human staffed safety net for crisis moments that the company describes as willing to address suicidality directly.
That matters because the alternative was just examined. Wysa reaches over six million people with no clinician in the default path and publishes no escalation pathway. Limbic assesses patients for a national therapy service and publishes no crisis protocol. This vendor sells the escalation layer as part of the product and names it.
What is missing is measurement of the thing being escalated. No sensitivity or specificity for risk identification, no false negative rate on suicide risk, no threshold governing what reaches a human, and no volume or response time figure for the crisis service. A safety net with an unpublished catch rate is still an unquantified safety net. Ask for detection sensitivity and response service performance.
The inputs are enumerated and the company makes an explicit claim about the character of the models, which is unusual.
Four data sources are named individually: claims, record system data, admission discharge transfer feeds and assessment instruments. Naming admission discharge transfer specifically is meaningful, because real time movement data is what lets a risk model act on a current episode rather than a historical pattern. The company describes the approach as transparent machine learning, which is a deliberate positioning against opaque scoring and is the right claim for a product whose output is a clinician facing risk flag.
Three products are separately named with distinct functions, so a buyer can tell which component does what.
What is absent is the substance behind the transparency claim. No model class or architecture is described, no explanation is given of what transparent means operationally, whether a clinician sees the features driving a risk score or only the score, and no accuracy, sensitivity or calibration figure is published for any model. A transparency claim that cannot itself be inspected is a positioning statement. Ask what a clinician actually sees behind a flag.
No party in the chain is named. No cloud platform, no model or analytics framework, no sub processor list, and no statement on whether customer data contributes to model development.
The input data is well described and that is a different question. Knowing the models consume claims, record, movement and assessment data tells a buyer what goes in; it says nothing about who processes it, where, or under what terms.
The training question carries specific weight here because of the data type. Behavioral health information receives heightened protection under United States law beyond general health privacy rules, and substance use disorder records carry their own federal confidentiality regime with consent requirements that do not apply to ordinary clinical data. Whether population data from one health plan improves models sold to another is therefore both a competitive and a regulatory question, and it is unaddressed in either direction.
The February 2026 product expansion incorporated capabilities from recent acquisitions, which folded additional technology stacks into the platform without those components being separately described. Ask for the sub processor register, the training position, and what the acquisitions brought.
Substantial institutional adoption, one genuine competitive evaluation, and no measured clinical outcome.
Named customers span a large behavioral health managed care organisation, two health systems and the Department of Defense, with platform reach reported at roughly 15 million patients. A federal department carrying out its own procurement diligence is a meaningful signal, and the company was separately a finalist in a federal grand challenge on veteran suicide reduction, receiving 250,000 dollars and advancing to a second phase. Competitive government evaluation of that kind is scrutiny of the approach rather than of the marketing.
One conflict belongs on the record. Magellan Health is named as a customer and led the Series B financing, so the flagship commercial reference is also an investor. This is the third instance this session of a headline validation carrying a commercial relationship, after a related party accuracy audit and an investor customer in the operating room lane.
What is absent is outcome measurement. No peer reviewed publication was located, no third party research assessment, and no published figure for detection accuracy, treatment engagement or clinical improvement. The one operational example, more than 3,000 patients stratified in four months, measures throughput rather than benefit. Ask for outcomes from a named site.
Externally assessed controls, and the stewardship specifics unaddressed.
What is established is real: health specific certification at the implemented tier and a controls report at the second type, both externally audited, covering the platform rather than a subset. That is stronger assurance than an unaudited claim and matches what Fathom holds.
What is missing is everything about handling. No retention schedule, no encryption statement, no access control description, no data ownership or deletion position, no data minimisation commitment, and no statement on whether population data contributes to model development.
The sensitivity here is higher than the certifications alone convey. The platform ingests claims and clinical data to infer that a person may have an undiagnosed behavioral health condition, and then acts on that inference by routing them toward care. An inferred mental health condition attached to an identifiable person, derived rather than diagnosed, is among the most consequential data objects any vendor in this index creates. Nothing published describes how such an inference is stored, who can see it, whether it enters the medical record, or whether the person is told. Ask all four.
Two externally assessed credentials stated correctly, with tiers given, which is the disclosure this index consistently rewards.
The company holds health specific certification at the implemented one year tier and a controls report at the second type, alongside stated privacy compliance. Naming the tier of the first and the type of the second is the precise usage, and this session has recorded several vendors blurring exactly those distinctions. The health specific framework maps a certifiable control set onto health privacy requirements and is assessed by an external party, so the compliance claim rests on something checkable.
No business associate agreement posture, template or execution requirement was located, which is the usual gap.
One dimension specific to this vendor is unaddressed anywhere. Behavioral health information carries protection beyond general health privacy rules in the United States, and substance use disorder records fall under a separate federal confidentiality regime with its own consent and redisclosure requirements. A platform surfacing undiagnosed behavioral health conditions from claims data across a population sits directly in that territory, and nothing published describes how those rules are handled. Ask specifically about substance use records.
Two credentials, both named with the specificity that makes them assessable.
The company states health specific certification at the implemented one year tier and a controls report at the second type, alongside privacy compliance. Both are externally assessed, and both are described with the qualifier that matters: the tier for the first, the report type for the second. The tier sits above the entry level certification Arintra holds and matches Fathom and Infinx.
That precision deserves note because it has been the exception this session rather than the rule. Three separate vendors have been recorded blurring the same distinctions, presenting framework alignment as a badge, a non certifiable framework as a certification, and self described compliance in the same breath as an audited certification.
What is missing keeps it at B. No trust centre exists as a standing page, no report availability or request process was located, no audit period or assessor is named, and no penetration testing disclosure or vulnerability disclosure policy was found.
Ask for the certification date and scope, the report period, and whether either can be shared under agreement.
No device pathway is claimed and the classification is probably correct. Risk stratification delivered to a clinician who decides, referral routing and outcome measurement are decision support and care coordination rather than diagnosis.
The boundary is closer than for the administrative products elsewhere in this index. Software that identifies individuals at risk of suicide, and that the company markets on its willingness to address suicidality, is operating where a misclassification has the gravest possible consequence. The exemptions most regimes provide for clinical decision support turn on whether the clinician can independently review the basis of the recommendation, which is exactly what the unexplained transparent machine learning claim leaves unresolved.
The more immediate regulatory exposure is not device law but behavioral health confidentiality. Substance use disorder records carry a separate federal regime governing consent and redisclosure, and inferring behavioral health conditions from claims data across a population raises questions under it that no other record in this index has to answer.
Graded C because the device position is correct and undocumented, and the confidentiality dimension is unaddressed. Ask for the stated device determination and the substance use records position.
A transparency claim with nothing published behind it, against a bias risk that is close to textbook.
The company describes its approach as transparent machine learning, which is a governance oriented framing and better than the opaque scoring it implicitly contrasts with. No content supports it. No bias or fairness testing, no validation methodology, no performance breakdown by population, no calibration data, no drift monitoring output and no external audit was located.
The specific risk is structural and severe. Models trained on claims and clinical data to surface undiagnosed behavioral health conditions are learning from a historical record of who received care, and access to behavioral health care in the United States is patterned strongly by race, income, insurance type and geography. A population that historically had less contact with the system generates less signal, so a model can systematically under identify exactly the people the product exists to find. The company's stated purpose, surfacing conditions that would otherwise remain hidden, is the same mechanism by which the bias would operate invisibly.
Nothing addresses it. Ask for identification rates broken down by race, insurance type and geography, and for calibration across those groups.
One genuine operational commitment, and no performance figure or contractual term behind it.
The commitment is Response Services, a human staffed crisis capability the company operates rather than delegates. A vendor that answers the phone when a risk flag fires has taken on operational responsibility that no other behavioral health record in this index accepts, and it is a materially different posture from shipping a score and leaving the consequences with the customer.
Nothing quantifies or contracts it. No detection sensitivity for the risk models, no response time, no coverage hours, no escalation success measure, and no service level agreement, warranty, indemnity or remediation commitment was located.
The allocation question is unusually grave. If a model fails to identify a person at risk, the harm is not a denied claim or a misfiled note. Where responsibility sits between an unpublished model sensitivity, a health system's configuration and a vendor operated crisis line is undefined in public material, and it is the first question a health system's counsel should ask.
One pre emptive note: further customer counts or patient reach figures cannot move this grade. Only published detection performance, or a contractual commitment on the response service, will change it.
The data sources are named with more precision than most and the connection layer is not described at all.
Four input types are enumerated: claims, record system data, admission discharge transfer feeds and assessment instruments. Consuming movement data alongside claims and clinical records means integrating with at least three distinct feed types, which is a harder engineering problem than record system access alone, and the company states that findings are delivered back into the provider's existing workflow, implying an outbound path as well as inbound.
No record system is named. No interface standard is described. No connection mechanism is specified. No vendor marketplace or certification listing was located, and nothing states whether risk findings write into the medical record or sit in a separate application.
That last question matters more here than usual, because an inferred behavioral health risk flag entering the permanent medical record is a materially different act from displaying it in a care management tool.
Graded C for capability evidenced by the data types named, with no published specification, consistent with the treatment of this absence across the index. Ask which systems, through what standards, and where findings land.
The delivery model is stated at the highest level and nothing beneath it. Tools are described as cloud based, which distinguishes them from installed software and is the whole of what is published.
No cloud provider, region, tenancy model, residency commitment or customer controlled option was located.
Two factors make the tenancy question more pointed than usual. The platform ingests population level claims and clinical data from multiple health plans and health systems that compete with one another, so whether those datasets sit in shared or isolated environments is a commercial question as well as a security one. And a federal department is among the named customers, which typically carries its own hosting and authorisation requirements that nothing published addresses.
Graded C consistent with how a bare cloud statement has been treated across this index. Ask for the hosting arrangement, the tenancy model, whether customer datasets are segregated, and what environment serves the federal deployment.
Nothing about cost is published. A dedicated pass located no pricing page, no unit of charge, no range, no implementation or onboarding fee position, no minimum commitment, no pilot terms and no return calculator.
Nor is there a proxy. No cost per member, no avoided admission figure, no medical cost offset estimate, despite the company's entire argument to a risk bearing organisation being that unaddressed behavioral health comorbidity increases medical costs and harms quality metrics. That argument invites a financial model and none of the inputs is supplied.
The product structure sharpens the question. Three separately named products spanning analytics, integration and outcome measurement, plus a human staffed crisis response service, cannot plausibly share one pricing basis. Analytics over a population and a staffed response line have completely different cost structures, and nothing indicates whether they are bought together or separately.
Ask for the pricing basis per product, whether the response service is bundled or charged by volume, and what the medical cost offset has been at a reference customer.
Coverage is defined by where the product looks rather than by clinical specialty, and that framing is the point.
The target is behavioral health need appearing in settings not built to handle it: primary care, physical health services and general population management within health systems and health plans. Buyer types are named and distinct, spanning risk bearing organisations, providers and a federal department, which are three different procurement contexts.
Severity coverage is stated across a spectrum from self guided support through to crisis response, which is broader than any other behavioral health record here. The veteran population is addressed specifically through the federal challenge work, and the company has described expansion into Spanish and other languages.
Held at B rather than A because depth by setting is not evidenced. The named customers do not distinguish which products are deployed where, no figure separates health plan from health system deployment, and nothing addresses paediatric or adolescent behavioral health, which is a distinct population with distinct instruments. Nothing addresses markets outside the United States. Ask which products run at which named customers.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
Not published
|
Not disclosed. No unit of charge is described. Whether pricing is per member, per patient, per provider, per product or enterprise wide is unstated, as is how the human staffed crisis response service is charged relative to the software. | Not disclosed as a template or posture. Two externally assessed credentials are stated with the qualifiers that make them assessable: health specific certification at the implemented one year tier, and a controls report at the second type, alongside stated privacy compliance. No business associate agreement template, negotiation stance or execution requirement was located. One dimension unaddressed anywhere in published material deserves direct enquiry: behavioral health information carries protection beyond general health privacy rules in the United States, and substance use disorder records fall under a separate federal confidentiality regime with distinct consent and redisclosure requirements. A platform inferring undiagnosed behavioral health conditions from population claims data sits squarely in that territory. | Not disclosed. No implementation, integration or onboarding fee position was located and no implementation timeline is published, despite the platform requiring ingestion of claims, record system, admission discharge transfer and assessment data, which is a multi feed integration effort. One published example describes a health system stratifying more than 3,000 patients within four months, which indicates time to value rather than cost. | Vendor Published |
Nothing about cost is published. A dedicated pass located no pricing page, no unit of charge, no range, no implementation or onboarding fee position, no minimum commitment, no pilot terms and no return calculator. Nor is there a proxy of the kind that lifts several records above D. No cost per member, no avoided admission figure and no medical cost offset estimate appears anywhere, despite the company's entire commercial argument to a risk bearing organisation being that unaddressed behavioral health comorbidity raises medical costs and damages quality metrics.
That argument explicitly invites a financial model and none of the inputs is supplied. The product structure makes a single pricing basis implausible and the absence therefore more consequential. Three separately named products span population analytics, integration and referral, and outcome measurement, and alongside them sits a human staffed crisis response service.
Analytics across a covered population and a staffed response line have entirely different cost structures, and nothing indicates whether they are licensed together, separately, or in tiers. The response service in particular is labour the vendor operates, which implies either volume based charging or a capacity assumption, and neither is described.
Buyer type compounds it further, since a health plan buying population analytics, a health system buying integration into primary care, and a federal department buying suicide prevention capability are three different commercial conversations. Ask for the pricing basis per product, whether the crisis response service is bundled or charged by volume, what capacity assumption underlies it, and what medical cost offset a named customer has measured.