Diagnostics & Genomics
S

SOPHiA GENETICS

Cloud native genomics analysis company (NASDAQ: SOPH). The SOPHiA DDM platform applies machine learning with patented algorithms to call, annotate, and pre classify variants from next generation sequencing data, technology agnostic across sequencing instruments, with genomics, radiomics, and multimodal analytics modules. Deployed as software that hospitals and labs run themselves: at Mount Sinai, for example, SOPHiA provides the analytical software while the health system runs it as a laboratory developed test in its own CLIA certified, CAP accredited lab.

The platform reports a network of more than 750 hospitals, academic centers, and labs and a federated learning model across participating institutions. Certain applications are research use only and regional clearance varies.

AI Health Index verifiedJuly 28, 2026
Compare SOPHiA GENETICS with other vendors
Founded
2011
Headquarters
Boston, Massachusetts
Categories
diagnostics-and-genomics
Indexed Products
SOPHiA DDM Platform
Buyer Segments
Academic Medical Center, Large IDN, Pharma / Life Sciences
Assessment

Capability Axes

An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read

AI Capability
AA on AI CentralityThe artificial intelligence is the product. Remove the model and there is nothing left to sell.
Vendor Published

The product is the AI: SOPHiA DDM uses machine learning with patented algorithms to call, annotate, and pre classify genomic variants from raw sequencing data, distinguishing clinically relevant alterations from sequencing noise. Analysis is the deliverable.

CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism. Human in the loop appears as a phrase rather than a described control.
Vendor Published

A real external control exists because of how the product is deployed, and the internal design is undescribed.

The control is the customer's own laboratory. This platform is analytical software that institutions run themselves, and where it is used clinically the result is issued by that institution's accredited laboratory under its own quality system and signed out by its own director. In at least one health system the platform is the analytical component of a test that laboratory validated and owns. Responsibility therefore sits with a qualified professional employed by the customer, which is a stronger arrangement than a vendor issuing results directly.

What is not described is what that professional is working from. The platform calls, annotates and pre classifies variants, and pre classification is a filtering decision: it determines which of many thousands of variants reach a scientist's attention and in what order. A variant deprioritised before review is not reviewed, and its absence leaves no trace in the report. Nothing published states what the pre classification excludes, on what basis, whether excluded candidates can be recovered, or what confidence information accompanies a classification.

The federated element adds a second question. If classification behaviour improves from network learning, the system a laboratory validated may not behave identically six months later.

Ask what pre classification filters and how a reviewer can see past it, and how behavioural changes from network learning are surfaced to laboratories.

CC on Model and Technology TransparencyThe architecture is described in general terms with nothing identified. Proprietary is asserted rather than explained.
Vendor Published

The architecture is named at a high level and nothing beneath it is described.

What is public: machine learning applied to variant calling, annotation and pre classification from sequencing data, described as resting on patented algorithms, operating technology agnostically across instruments, and organised as a federated learning model across the institutional network. Naming federated learning is a genuine architectural disclosure rather than a marketing term, because it commits the company to a specific claim about where computation happens.

What is absent: any description of the models themselves, the features used, the training data and its provenance, validation design, performance figures, versioning practice, or how a model change is communicated to laboratories running the platform as part of their own validated test.

That last point carries particular weight for this deployment model. Institutions run this software inside their own accredited laboratories, in at least one case as the analytical component of a laboratory developed test they validated themselves. A laboratory that has validated a test is responsible for it, and an update to the analytical software beneath that test is a change to a validated system. The laboratory needs to know when the model changed, what changed, and whether revalidation is required, and it needs that in a form its own quality system can consume.

Ask how model versions are identified in results, what change notification laboratories receive, and what evidence accompanies an update.

BB on Model Supply Chain DisclosureSubstantial partial disclosure, or a chain that is structurally short: an in house build, a cleared model that cannot be quietly swapped, or a deployment where the transfer does not occur at all. Naming only the hosting provider sits at the top of this band rather than in A.
Vendor Published

Strong instruments, a clearly stated role, and one architectural question the instruments do not reach. Certification to the cloud personal information protection standard is the one specifically concerned with handling personal data as a cloud processor, and it sits alongside encryption and redundant storage in secured private data centres.

More useful than either is the stated allocation of roles: the hospital is the controller and this company is the processor, which is the correct allocation for a platform computing on data belonging to an institution and is something very few vendors in this index state at all. It matters because it settles who decides, who must be asked, and who a patient's rights run against, before any specific term is negotiated.

The product is also positioned around institutions retaining control of their own samples and data through in house analysis, a design choice consistent with that role rather than bolted onto it. The chief executive has stated the company can only compute the data and cannot sell it, which is the right commitment and was made in a press interview years ago rather than published as a standing term, so ask for it in the contract. The question the instruments do not reach is the network.

Federated learning means the model travels to the data rather than the reverse, which genuinely reduces movement and does not eliminate flow: the updates a model returns are derived from that institution's patients, and inference against model updates is an active research area rather than a solved problem. Ask what leaves under the federated arrangement, and what protects it.

BB on Clinical and Operational EvidenceNamed deployments with dated outcome figures and enough method to test them, or published research short of independent validation.
Vendor Published

Scale is well documented (reported 1.8 million plus genomic profiles analyzed, roughly 30,000 analyses per month, 750+ institutions). Analytical validation studies exist including a clinical trial assay validation with a research partner; independent performance figures per application were not compiled this pass.

BB on AI Safety and PHI StewardshipCategorical commitments are published, such as no training on customer data, without the retention schedule or the safety engineering behind them.
Vendor Published

Strong instruments, a clearly stated role, and one architectural question that the instruments do not reach.

What is documented. Certification to the cloud personal information protection standard, which is the one specifically concerned with handling personal data as a cloud processor. Encryption of uploaded data with redundant storage in secured private data centres. And a clearly stated position under European data protection law: the hospital is the controller and this company is the processor, which is the correct allocation for a platform that computes on data belonging to an institution. The product is also positioned around institutions retaining control of their own samples and data through in house analysis, which is a design choice consistent with that role rather than a claim bolted onto it.

The company's chief executive has stated plainly that it can only compute the data to help hospitals diagnose and treat, and cannot sell it. That is the right commitment. It was made in a press interview some years ago rather than published as a standing term, and a buyer should ask for it in the contract rather than relying on it.

The question the instruments do not reach is the network. The platform is described as operating a federated learning model across participating institutions. Federated learning means the model travels to the data rather than the data travelling to the model, which genuinely reduces movement. It does not eliminate flow: the updates a model returns are derived from that institution's patients, and inference against model updates is an active area of research rather than a solved problem.

Ask what leaves an institution under the federated arrangement, and what protects it.

Regulatory and Compliance
BB on HIPAA and BAA PostureBusiness associate status is stated and supported by a substantive privacy document, with the agreement or its scope not fully published. For a vendor outside the United States, an equivalent regime documented to this depth grades here.
Vendor Published

Both frameworks are named and one role is stated precisely, with the contracting detail unpublished.

The company states compliance with both the United States health privacy rule and European data protection law on its platform pages, and describes ensuring compliance with those and other local regulations across the profiles it processes each week. Under the European framework it states the allocation explicitly: the hospital is the controller, the company is the processor. That is the correct structure for a platform computing on an institution's data, and stating it plainly saves a buyer the analysis.

The United States side is necessarily different in kind rather than in degree. Where a hospital runs the platform to analyse its own patients' sequencing data, the company is receiving protected health information on that hospital's behalf and a business associate agreement is the operative instrument. A single platform therefore stands in two distinct legal relationships depending on which customer is using it, and the obligations, breach notification timelines and permitted uses differ between them.

What was not located: a business associate availability statement, the contracting entity, the subprocessor register, or the terms governing what the company may do with data it processes.

One question follows from the corporate structure. This is a Swiss headquartered company with United States operations serving institutions in more than seventy countries. Which entity contracts with a United States hospital, and whether staff outside the United States can access that hospital's data during support, are the practical questions.

Ask which entity signs, and where support access originates.

AA on Security Certifications and Trust CenterCertifications named with their type and version and presented as retrievable artefacts, usually through a trust portal a buyer can open without asking.
Vendor Published

A comprehensive, long standing and independently audited certification portfolio, and the duration is part of what earns the grade.

The company first certified its information security management system to the international standard in 2014 and has since recertified to the current 2022 revision, which means more than a decade of continuous certification with annual surveillance and periodic full reaudit rather than a recent push before a funding round. In January 2025 it added the cloud specific pair, covering cloud security controls and the protection of personal information in cloud services, which are the standards that speak directly to what a cloud native genomics platform actually does. It holds the medical device quality management standard alongside them, and maintains an entry in the cloud security alliance registry, which publishes a completed control questionnaire a counterparty can read rather than request. Certification is by an internationally recognised body.

The technical description is specific rather than general: data uploaded to the platform is encrypted, held redundantly in secured private data centres, and the company has described a patented approach to genomic data encryption.

What is not published, and is the only real gap: penetration testing results or a vulnerability disclosure programme.

One scope question worth asking despite the strength here. The company also holds European in vitro diagnostic certification for specific diagnostic solutions while most of the platform is research use only, so confirm which certificates cover the modules being deployed and in which territory.

BB on FDA and Regulatory StatusThe pathway is stated and in progress, or a clearance is named without the vintage and scope a buyer needs to match it to the product on offer.
Vendor Published

Positioning is stated with appropriate care: the platform is IVDR certified for certain applications in the EU, while some applications are labeled Research Use Only and clearance varies by country. Deployments such as Mount Sinai run DDM as a laboratory developed test in the customer's own CLIA certified, CAP accredited lab, with SOPHiA providing software and not performing diagnostic testing. Graded on clarity of regulatory positioning, not on possession of a specific US clearance.

CC on AI Governance and Bias DisclosureResponsible artificial intelligence is committed to in policy language with no evaluation behind it. Most of the index sits here.
Vendor Published

No governance framework, model documentation, evaluation methodology or subgroup performance analysis was located, on a record where security and quality certification is otherwise exemplary. That contrast is the same one this index has found at every mature platform vendor: strong disclosure in the established domains, nothing extended to the models.

Two domain questions apply.

The first is the one this lane puts to all clinical genomics. Variant calling, annotation and pre classification depend on reference population data drawn disproportionately from people of European ancestry, so classification confidence and uncertain variant rates differ across populations. A platform serving more than seventy countries encounters that unevenness more directly than a single country laboratory does, and the company publishes nothing on how performance varies or how it is monitored across its network.

The second concerns the network itself. The platform is described as operating federated learning across participating institutions, which means the model improves from what member institutions see. Whether that improvement is distributed evenly, or whether the model is shaped predominantly by the largest and best resourced members and then applied to smaller ones, is a governance question about who benefits from a collective asset. It is answerable and nothing addresses it.

Ask for classification performance by ancestry, how the company monitors drift across a heterogeneous global network, and how federated model improvements are validated before they reach an institution's clinical pipeline.

CC on AI Liability and RecourseMechanisms exist that let someone challenge an output, such as audit trails, source traceability or review before commit, with nothing standing behind the output and no route for the harmed party.
Vendor Published

Naming federated learning is a genuine architectural disclosure rather than a marketing term, because it commits the company to a specific and checkable claim about where computation happens, and the machine learning applied to variant calling, annotation and pre classification is described as operating across instruments rather than tied to one manufacturer.

Beneath that nothing is described: no account of the models, the features used, the training data and its provenance, validation design, performance figures, versioning practice, or how a model change is communicated to laboratories, and no warranty, indemnity or remediation commitment. That last omission carries particular weight for this deployment model and it is the finding on this record.

Institutions run this software inside their own accredited laboratories, in at least one case as the analytical component of a laboratory developed test they validated themselves, and a laboratory that has validated a test is responsible for it. An update to the analytical software beneath that test is a change to a validated system, so the laboratory needs to know when the model changed, what changed, and whether revalidation is required, in a form its own quality system can consume.

A silent update leaves an accredited laboratory formally responsible for a test it can no longer describe. Ask how model versions are identified in results, what change notification laboratories receive, and what evidence accompanies an update.

Integration and Deployment
BB on EHR and Interoperability DepthNamed systems with read access or one directional writing, or standards support with named deployments behind it.
Vendor Published

The domain relevant interoperability claim is real and is the right one for this product.

For a genomics analysis platform the interoperability question is not primarily about the medical record. It is whether the platform can ingest data from whatever sequencing instruments a laboratory already owns, because sequencers are capital equipment with long replacement cycles and a laboratory will not change instrument to suit an analysis vendor. The company states its platform is technology agnostic across sequencing instruments, which is a substantive claim and the reason a network of this size across this many countries is achievable at all: it removes the hardest adoption barrier in the category.

The deployment model reinforces it. Institutions run analysis in house on their own data, which means the platform has to fit into an existing laboratory pipeline rather than replace it.

Held at B rather than A because no named integration with a laboratory information management system or medical record platform was located from the company's own materials, and no interface documentation or supported standard was identified. A third party reference describes record and laboratory system interoperability, which this index does not credit without a vendor source.

Ask which instruments are supported and validated, what file formats are accepted, how results reach the laboratory information system and the chart, and whether variant classifications are delivered as structured data or as a report.

BB on Deployment Model and Data ResidencyOptions and residency are stated with isolation or the processing path left open.
Vendor Published

Cloud native and decentralized by design, deployed into hospital and lab workflows across a reported 750+ institution network with a federated learning approach that keeps analysis distributed. Held back from A because specific data residency commitments by region were not retrieved.

Commercial
CC on Commercial TransparencyNo price is published and the posture is discoverable: a buyer can establish how the product is sold and what drives the cost before contacting the vendor. Most of the index sits here.
Vendor Published

No public pricing. Contact the vendor. Enterprise and per analysis models are referenced in third party coverage but no rate card is published.

BB on Setting and Specialty CoverageCoverage is named with validation behind part of it.
Vendor Published

Broad and clearly stated, with an unusually precise regulatory boundary and one thing left undistinguished.

The scope is a global network of hospitals, laboratories and biopharmaceutical institutions, reported at more than eight hundred across over seventy countries, concentrated on oncology and rare disease, with modules spanning genomics, radiomics, digital pathology and multimodal analytics.

What lifts this above a broad claim is that the company states its regulatory position per product and per territory rather than in general. It marks its products as research use only and not for diagnostic use unless specified otherwise, and names the specific diagnostic solutions that carry European in vitro diagnostic certification and the exact territories in which they hold it. Very few vendors in this index volunteer the limits on where and how their product may be used clinically, and doing it product by product is more useful still.

What is not distinguished is maturity across modalities. Genomics, radiomics, digital pathology and multimodal analysis rest on different evidence bases and are at visibly different stages, and the platform presents them as one offering. A buyer evaluating the radiomics or multimodal modules should not assume the evidence and regulatory status supporting the genomics work transfers to them.

Ask which modules are in routine clinical use rather than research deployment, and for the evidence and regulatory position of each separately.

Comparisons

Compared With

Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.

Public Record

Announced Deployments

Publicly announced health system deployments and partnerships. This is a record of announcements, not an assessment of deployment success or scale.

Mount Sinai Health System
SOPHiA DDM for cancer genomics variant analysis, run as an LDT in Mount Sinai's own lab
Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis BAA Tier Implementation Source
Contact the vendor
Enterprise and per analysis agreements for the DDM platform Third Party Estimated

Enterprise and per analysis models are referenced in third party coverage; SOPHiA is a public company (NASDAQ: SOPH) so aggregate economics appear in filings, but platform pricing is not published.