Healthcare Administrative Automation
P

Plenful

No code AI workflow automation for pharmacy and healthcare operations, with a center of gravity in 340B program compliance. The platform screens 340B eligible claims, uses language models to investigate unstructured EHR data for referral based savings, and automates rebate reporting, Maximum Fair Price reconciliation, intake, and prior authorization. Referral Agent, launched June 2026, is positioned by the company as the first AI agent purpose built for 340B referral capture.

The vendor reports customers including Tampa General Hospital, Renown Health, and Salinas Valley Health, more than 100 healthcare organizations on the platform, and customer reported reductions in manual work of up to 97 percent. Founded by Joy Liu, previously an operator at a health system specialty pharmacy company. Raised a $50 million Series B in 2025.

AI Health Index verifiedJuly 27, 2026
Compare Plenful with other vendors
Founded
Headquarters
San Francisco, California
Website
www.plenful.com
Categories
healthcare-admin-automation, rcm-and-prior-auth
Indexed Products
340B Suite, Referral Agent, MFP Intelligence
Buyer Segments
Large IDN, Academic Medical Center, Community Health System
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
BB on AI CentralityThe model is the engine of a core module. The platform carries other value, but this capability does not exist without it.
Vendor Published

Language models do the substantive work of investigating unstructured EHR data for referral based 340B savings, and the vendor reports this raises review capacity by a large multiple. Held back from A because the platform is explicitly a no code workflow automation layer in which AI is one component alongside configurable rules and audit logic, and some of the value is orchestration rather than inference.

BB on Autonomy and Oversight ModelThe oversight structure is described and one part is missing, commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

The vendor states the platform combines AI based automation with human oversight, and the 340B compliance context imposes an audit trail by regulation. Held back from A because the escalation and exception handling model is described in marketing terms rather than documented, and no published governance framework was retrieved.

CC on Model and Technology TransparencyThe architecture is described in general terms with nothing identified. Proprietary is asserted rather than explained.
Vendor Published

No foundation model is named, no evaluation methodology is published and no accuracy figure was located.

One architectural statement is worth crediting. The company describes combining deterministic rules with machine learning models rather than presenting everything as a model, which is the right structure for a domain where some eligibility criteria are bright line rules and others require reading a note. It also implies the team has thought about which is which, though nothing published says where the boundary sits.

The published figures describe throughput rather than performance: review capacity raised 98 times, and average recaptured savings per claim. Neither states how often the model is right. For a product whose output feeds a federally audited programme, precision on the eligibility judgement is the number that matters, and it is not disclosed.

DD on Model Supply Chain DisclosureNothing establishes who else sits between a patient record and an answer.
Vendor Published

No retention period, statement on whether customer data trains or improves models, or de identification posture was located, and no model, hosting arrangement or sub processor list was named. The data surface is wider than an administrative product usually carries and it is worth stating precisely what happens.

Language models investigate unstructured record content, specifically clinical notes, to find informal referrals that never appear as formal orders, which means the system reads narrative clinical documentation about named patients in order to establish a financial eligibility fact.

That is a category crossing this axis should flag wherever it appears: clinical narrative written by a clinician for a clinical purpose is being consumed for a revenue purpose, and the note's author had no reason to anticipate it. Two questions follow. What is retained from a note once the eligibility determination is made, given that the determination itself is what the customer needs rather than the underlying text, so retaining the note is a choice rather than a requirement.

And whether note content or model outputs from one covered entity inform models serving another, since referral patterns are exactly the kind of signal that would improve with pooled data and exactly the kind a competing health system would not want shared. Ask both directly, because neither is answerable from public material.

BB on Clinical and Operational EvidenceNamed deployments with dated outcome figures and enough method to test them, or published research short of independent validation.
Vendor Published

Named customers including Tampa General Hospital, Renown Health, and Salinas Valley Health, with more than 100 healthcare organizations reported on the platform and specific customer attributed figures such as up to 97 percent reductions in manual work and over 50 staff hours a day saved. Held back from A because the figures are customer testimonial rather than measured against a stated baseline methodology.

CC on AI Safety and PHI StewardshipGeneral assurances of privacy and security that do not answer the questions artificial intelligence raises: what is retained, what reaches a model, and what happens to it there.
Vendor Published

No retention period, no statement on whether customer data is used to train or improve models, and no de identification posture was located.

The data surface is wider than an administrative product usually carries. Language models investigate unstructured electronic health record content, specifically clinical notes, to find informal referrals that never appear as formal orders. That means the system is reading narrative clinical documentation about named patients in order to establish a financial eligibility fact.

Two questions follow. What is retained from a note once the eligibility determination is made, given that the determination itself is what the customer needs rather than the underlying text. And whether note content or model outputs from one covered entity inform models serving another, since referral patterns are exactly the kind of signal that would improve with pooled data.

Ask both directly. Neither is answerable from public material.

Regulatory and Compliance
CC on HIPAA and BAA PostureCompliance is claimed without the underlying document, or the published privacy notice covers the website rather than the service that handles patients.
Vendor Published

No HIPAA compliance statement and no business associate agreement terms were located. Business associate status is structurally certain, since the platform processes claims and reads clinical documentation on behalf of covered entities.

The contracting question is more layered than usual because of where 340B data lives. The platform is described as connecting electronic health records, third party administrators, pharmacy systems, fax systems and contract pharmacies, and as working across entity owned pharmacies, contract pharmacies, mixed use settings and child sites. Several of those are separate legal entities from the covered entity buying the software.

Establish which parties in that chain the vendor holds agreements with, and under whose authority data moves between a contract pharmacy and the covered entity through the platform. A contract pharmacy relationship is already a complex data sharing arrangement before an automation layer is added on top of it.

CC on Security Certifications and Trust CenterControls are described with an outside check behind them, such as independent penetration testing on a stated cadence, but no attestation against a recognised framework.
Vendor Published

No SOC 2, HITRUST or ISO 27001 attestation was located across two differently phrased searches, and no trust centre or security page was found.

A retrieval caveat belongs in the record because it weakens the inference slightly. The company name is one character from an unrelated enterprise software company, and security targeted queries surface that company's announcements instead. The absence is recorded on that basis and a buyer should ask directly rather than treat it as settled.

The request is straightforward and worth making early. The platform ingests claims data, clinical notes and pharmacy records from more than 100 healthcare organisations, including named academic medical centres, so an attestation and its scope should exist even if it is not published.

BB on FDA and Regulatory StatusThe pathway is stated and in progress, or a clearance is named without the vintage and scope a buyer needs to match it to the product on offer.
Vendor Published

No FDA pathway applies and none is claimed. Graded B rather than C because the regime that governs this product is named, understood and built into it rather than left for a buyer to infer.

The governing framework is the 340B drug pricing programme, administered by the Health Resources and Services Administration, with covered entities subject to audit against the duplicate discount and diversion prohibitions and to patient definition requirements. The company operates explicitly inside that framework across owned pharmacies, contract pharmacies, mixed use settings and child sites, and separately automates Maximum Fair Price reconciliation under the Medicare drug price negotiation programme.

The liability allocation is the part a buyer must understand, and to the company's credit it says so plainly: the platform surfaces insights that align with the customer's own interpretation of programme requirements. THAT places interpretation, and therefore audit exposure, with the covered entity. The vendor supplies capability and configuration; the entity answers to HRSA. Establish who reviews the interpretation encoded in the configuration, and how a changed rule or a new opinion propagates through claims already captured.

CC on AI Governance and Bias DisclosureResponsible artificial intelligence is committed to in policy language with no evaluation behind it. Most of the index sits here.
Vendor Published

No AI governance framework, model monitoring disclosure or accuracy evaluation was located.

The gap has a specific shape here and it is about direction rather than demographics. Every published figure measures capture: review capacity raised from 130 claims a month to 12,700, a 98 times increase, and more than 1,850 dollars in average recaptured savings per claim. Nothing published measures the opposite error. There is no false positive rate, no statement of how often a claim surfaced as eligible would fail an audit, and no reported rate at which captured claims are later reversed.

That asymmetry matters because the model is tuned to the customer's own interpretation of eligibility. A more expansive interpretation raises both capture and audit exposure at once, and the two move together by construction. The company acknowledges that growing a programme introduces more complex risk, which is candid, but candour about the risk is not measurement of it.

The standing ask for this vendor and any 340B optimisation product: what share of captured claims survive audit, and is that reported back to the customer.

CC on AI Liability and RecourseMechanisms exist that let someone challenge an output, such as audit trails, source traceability or review before commit, with nothing standing behind the output and no route for the harmed party.
Vendor Published

One architectural statement is worth crediting. The company describes combining deterministic rules with machine learning models rather than presenting everything as a model, which is the right structure for a domain where some eligibility criteria are bright line rules and others require reading a note, and it implies the team has reasoned about which is which.

That distinction is useful to a buyer because the two halves fail differently and need different assurance: a rule is auditable and wrong only if it was written wrong, while a model reading narrative can be wrong case by case in ways nobody notices. What is not published is where the boundary sits, so a buyer cannot tell which determinations rest on which.

No foundation model is named, no evaluation methodology is published, no accuracy figure was located, and no warranty, indemnity or remediation commitment attaches. The published figures describe throughput rather than performance, covering a multiple on review capacity and average recaptured savings per claim, and neither states how often the model is right.

For a product whose output feeds a federally audited programme, precision on the eligibility judgement is the number that matters, because an incorrect eligibility determination is not a missed saving, it is a claim to a benefit the entity was not entitled to, and the audit finds it later with the customer carrying the consequence. Ask where the rules end and the model begins, and for precision on the eligibility judgement.

Integration and Deployment
BB on EHR and Interoperability DepthNamed systems with read access or one directional writing, or standards support with named deployments behind it.
Vendor Published

Integration breadth is central to the product rather than incidental, because 340B data is fragmented by design. The platform is stated to connect electronic health records, third party administrators, pharmacy systems and fax systems, centralising data across entity owned pharmacies, contract pharmacies, mixed use settings and child sites, with automated ingestion and export across multiple third party administrators and referral partners.

That spread is the harder half of the problem in this category, and reaching contract pharmacy claims data to attribute referrals originating outside the health system's own record is a genuine capability rather than a claim.

Held at B rather than A because no specific electronic health record or third party administrator platforms are named and no integration method is described. For a product whose value depends on reconciling systems that were never designed to reconcile, the absence of named connections is the main thing a buyer cannot verify in advance.

CC on Deployment Model and Data ResidencyA single hosted option with location implied rather than committed.
Vendor Published

No hosting provider, region, tenancy model or data residency commitment was located, and no subprocessor list is published.

The question that matters most is where the language model inference runs. The product's distinguishing capability is applying language models to unstructured clinical notes at scale, and if that inference executes at an external model provider then narrative clinical documentation leaves the covered entity's boundary on every review. If it runs inside a controlled environment, it does not. Nothing published distinguishes them.

Given the review volumes described, tens of thousands of claims a month at a single site, this is not a marginal question. Ask where inference executes, which providers are involved, and what they retain of prompt and completion content.

Commercial
CC on Commercial TransparencyNo price is published and the posture is discoverable: a buyer can establish how the product is sold and what drives the cost before contacting the vendor. Most of the index sits here.
Vendor Published

No public pricing. Contact the vendor. Enterprise agreements with health systems and pharmacy organizations; no published rate card.

AA on Setting and Specialty CoverageWhere the product is validated to operate is named and supported, settings and specialties both, whether the coverage is broad or deliberately narrow.
Vendor Published

Precisely scoped and honestly bounded: pharmacy and healthcare administrative operations, centered on 340B covered entities, specialty and long term care pharmacy, and health system pharmacy departments. The vendor does not claim clinical scope.

Comparisons

Compared With

Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.

Public Record

Announced Deployments

Publicly announced health system deployments and partnerships. This is a record of announcements, not an assessment of deployment success or scale.

Tampa General Hospital
Plenful workflow automation across pharmacy operations
Renown Health
Plenful workflow automation across pharmacy operations
Salinas Valley Health
Plenful 340B auditing and compliance
Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Contact the vendor
Enterprise agreements scoped by use case Vendor Published

Enterprise agreements with health systems and pharmacy organizations, typically scoped by use case. The vendor markets savings recapture in 340B referral claims, which means part of the economics is framed as recovered revenue rather than cost. No rate card published.