Subtle Medical
Deep learning software that enhances and accelerates medical image acquisition on existing scanners rather than detecting pathology. SubtlePET (FDA cleared 2018) and SubtleMR (2019) denoise and sharpen PET and MRI images, allowing faster and lower dose acquisition; SubtleHD (MR) cleared November 2025 and SubtleHD (PET) cleared May 2026 extend that with newer model architectures, with SubtleHD (PET) supporting all FDA approved radiotracers and, per the vendor, up to 75 percent faster PET imaging. A CT product has clearance pending.
The company reports 11 FDA clearances, more than 25 peer reviewed publications, and deployment on more than 1,300 scanners, with customers including Mount Sinai, RadNet, and Radiology Partners. Raised $33 million in growth capital anchored by a Series C led by Morgan Stanley Expansion Capital in 2026.
Capability Axes
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read
Deep learning reconstruction and denoising is the entire product. The software's function is to produce diagnostic quality images from faster or lower dose acquisitions, which is a model output, not a workflow wrapper.
This product class inverts the usual oversight question and a buyer should understand why before comparing it to a detection tool.
A detection aid shows the radiologist the original image and adds a flag. The reader can disagree with the flag because the reader can still see what the model saw. This software does something different: it modifies the primary diagnostic image itself. The radiologist reads the model's output as the study. There is no unmodified comparator on screen in routine practice, and no equivalent of accepting or rejecting a finding.
The failure mode compounds it. The published radiology literature on deep learning reconstruction warns that denoising can change the imaging features of lesions or obscure small ones, and that this can happen on images that look high quality. The usual warning sign, an image that looks degraded, points the wrong way. A denoised study that has lost a small lesion looks better, not worse.
So oversight here is real but displaced. It sits in protocol design rather than at the point of read: which acceleration or dose reduction factor is authorised, validated against what, and enforced how. That is a defensible model and the vendor does not claim autonomy. The radiologist still reads and reports and remains responsible.
What makes it a B rather than a C is that the boundary has been published by others. An independent validation across 110 patients and three scanner models found performance maintained at a 50 percent count reduction and degradation at 66 percent, stating plainly that the more aggressive setting could lead to loss of information on lesion detectability. A buyer therefore has a defensible place to set the protocol.
Ask which reduction factor the contract and the clinical protocol assume, who authorised it, whether it is enforced technically or by convention, and whether any unenhanced series is retained for audit.
Unusually well characterised from the outside, and opaque from the inside.
The external record is the strength and it is substantial. More than 25 peer reviewed publications, a large share from independent academic groups rather than the company, covering phantom work, clinical cohorts, multiple scanner manufacturers and multiple radiotracers including fluorodeoxyglucose, gallium 68 PSMA-11 and fluorine 18 FDOPA. Several were designed explicitly to find the limits rather than to confirm the claim. That is a better transparency position than most vendors achieve through their own documentation.
The company also publishes a DICOM conformance statement, which is a real technical artefact rather than a marketing page and describes how the software behaves in an imaging network.
What is not disclosed is the model itself. No training data description, no statement of which scanner models, field strengths, tracers, body regions or patient populations the networks learned from, no architecture detail beyond the general category of deep learning denoising and a reference to newer architectures in the current generation, and no model card.
The version question is the sharper one. Eleven clearances across two modalities implies many model versions in the field, and no public policy describes how models are updated, how a site knows which version processed a given study, or whether prior validation carries forward to a new version. For software that alters primary diagnostic data, version provenance is a clinical audit question, not an IT one.
Ask which model version is deployed, whether it is recorded in the DICOM header of the output, and what happens to validation when it changes.
The architecture is sound and documented rather than asserted, and one default deserves flagging rather than condemning. An on premise gateway strips identifiers from studies before anything is transmitted to the vendor cloud, and the company states it nonetheless treats that environment as though it held protected data, with encryption, a business associate agreement with its cloud provider, a security programme and both internal and external audit each year.
Applying the stricter control to data you have already de identified is conservative and creditable. The default is the finding: a programme returns de identified studies from customers to the vendor after processing, and the company's own technical documentation states it forms part of the contract unless the customer opts out, so data flows to the vendor by default and the customer must act to stop it. Three things make that a flag rather than a fault.
The disclosure is real and specific, the data is de identified at the edge before leaving the building, and the opt out is named rather than hidden. Against that, it appears in a conformance statement, a document read by imaging engineers rather than by the people who sign contracts or answer to patients, and the document itself advises checking with the business owner and the vendor's account manager, which implies the vendor expects customer staff not to know. This is the better posture, disclosed in the wrong place. Check whether the programme is enabled on your contract.
More than 25 peer reviewed publications reported alongside FDA clearance validation, including SubtleHD (PET) validation across a range of accelerated low count acquisitions. Deployment scale is corroborated at more than 1,300 scanners with named customers including Mount Sinai, RadNet, and Radiology Partners. Graded on the existence and depth of peer reviewed evidence; this index does not re verify the underlying studies.
Better architected than most and carrying one default a buyer must find before signing.
The architecture is sound and it is documented rather than asserted. An on premise gateway component strips protected health information and other identifiers from studies before anything is transmitted to the vendor cloud. The company states it nonetheless treats that environment as though it held electronic protected health information, with encryption at rest and in transit, a business associate agreement in place with its cloud provider, an information security program, and internal and external audit activity each year. Applying the stricter control to data you have already de identified is conservative and creditable.
The default is the finding. A program named SubtleShare returns de identified studies from customers to the vendor after processing, on a per study basis, and the company's own technical documentation states that it forms part of the contract unless the customer opts out. Data flows to the vendor by default and the customer has to act to stop it.
Three things make that worth flagging rather than condemning. The disclosure is real, and specific, which is more than several peers manage. The data is de identified at the edge before it leaves the building. And an opt out is named rather than hidden.
Against that, it is disclosed in a DICOM conformance statement, a document read by imaging engineers rather than by the people who sign contracts or answer to patients, and the document itself advises the reader to check with the application's business owner and the vendor's customer success manager, which implies the vendor expects customer staff not to know. Read alongside the sibling record in this batch that is simply silent on whether customer images train its models, this is the better posture, disclosed in the wrong place.
Note also that de identification of medical images is imperfect, particularly for burned in annotation and for head imaging where surface anatomy can be reconstructed.
Check whether SubtleShare is enabled on your contract.
The posture is described in technical documentation rather than in a compliance page, which is unusual and mostly to the vendor's credit.
What is published: an information security program, encryption of data at rest and in transit, a business associate agreement held with the cloud infrastructure provider, an annual combined attestation and HIPAA audit, and a stated decision to treat the de identified cloud environment as though it contained electronic protected health information. The architectural choice to remove identifiers on premise before transmission is itself a HIPAA relevant design decision and it is documented.
The role is straightforward. The imaging provider is the covered entity. This vendor processes studies on its behalf and is a business associate, so a written agreement between them is the governing instrument.
What was not retrieved is that instrument or its terms. The published material evidences the downstream agreement with the cloud provider, not the upstream one with the customer. No published business associate agreement, no provider facing addendum, no subcontractor flow down language, no breach notification timetable and no review cadence were found. The route to an A in this index is publishing the instrument so a buyer can read what governs the relationship before entering it, and that route is not taken.
One consequence of the de identification architecture is worth raising rather than assuming. Where a vendor asserts data has been de identified, the parties should agree in writing which HIPAA standard was applied, safe harbour or expert determination, because that determines whether the material remains protected health information at all and therefore which obligations survive.
Real controls, real audit activity, and the attestation is under specified in the way this index keeps finding.
What is disclosed is more concrete than most: encryption at rest and in transit, a business associate agreement with the cloud infrastructure provider, an information security program, and a statement that the environment undergoes a variety of internal and external audit activities each year including an annual combined attestation and HIPAA audit.
The gap is one word. The attestation is described without its type. SOC 2 Type I assesses whether controls are suitably designed at a single point in time. Type II tests whether they actually operated effectively across a period, usually six to twelve months. Those are materially different assurances and a buyer cannot tell which one is held here.
That matters more given the sibling imaging record graded in the same batch, which names its attestation as Type II explicitly. Two vendors in one category, comparable in most other respects, and only one lets a buyer know what it holds. The precision is available; it simply is not used here.
No ISO 27001, no HITRUST certification and no public trust centre were retrieved. Given that this software sits inline in the imaging network and modifies primary diagnostic data before it reaches the reader, its integrity properties matter as much as its confidentiality ones, and nothing published addresses tamper evidence or output validation.
Ask for the report, confirm the type, confirm the period covered, and ask which trust services criteria beyond security are in scope.
A reported 11 FDA clearances across PET and MR, with product level specificity and dates: SubtlePET in 2018, SubtleMR in 2019, SubtleHD (MR) in November 2025, SubtleHD (PET) in May 2026. A CT product is disclosed as clearance pending rather than described as cleared. Precise, per product, and does not overstate.
No subgroup performance is published by the vendor, and the independent literature points at the gap that matters most.
Nothing was retrieved describing performance across age, sex, race or body habitus, and no AI governance framework, model update policy, bias testing statement or third party AI audit was found beyond clearance documentation.
Body habitus is the specific concern and it is not speculative. Positron emission tomography count statistics degrade as body size increases, because more signal is attenuated before it reaches the detector. A larger patient therefore produces a noisier study at the same dose and acquisition time. Denoising is asked to do more work in exactly that population.
The published evidence runs the other way. A 2026 study of 282 patients notes that its subgroup analysis for body mass index above 35 involved a smaller cohort and that this may explain why it found no significant difference. A separate implementation study reports that dose reductions were particularly substantial in patients with low body mass index. Read together: the benefit is documented most clearly in smaller patients and the evidence is thinnest in larger ones.
That is a real question about who the acceleration is safe for, and the vendor does not answer it. A site that applies one reduction factor across all patients is applying a setting validated mainly in the population where the task is easiest.
The same question applies to the breadth of the current radiotracer claim, since published evidence covers a handful of tracers rather than the full approved set.
Ask for performance stratified by body mass index, and whether the protocol should vary with patient size.
The external record is the strength here and it is substantial: more than twenty five peer reviewed publications, a large share from independent academic groups rather than the company, covering phantom work, clinical cohorts, multiple scanner manufacturers and multiple radiotracers.
Several were designed explicitly to find the limits rather than to confirm the claim, which is the strongest external evidence form available, because a study built to break a product is run by people with no interest in it surviving. That is a better position than most vendors achieve through their own documentation. A published conformance statement adds a real technical artefact describing how the software behaves in an imaging network.
Held below the top grade on a gap that matters more for this product than for a detection aid, because this software alters primary diagnostic data rather than annotating it. Eleven clearances across two modalities implies many model versions in the field, and no public policy describes how models are updated, how a site knows which version processed a given study, or whether prior validation carries forward to a new version.
A radiologist reading an enhanced image is reading an output, and if the version that produced it cannot be identified afterwards, an audit of a disputed study has nothing to reconstruct. Version provenance is a clinical audit question here, not an information technology one. Ask which version is deployed, whether it is recorded in the output header, and what happens to validation when it changes.
Standards based rather than partnership based, and the specification is published.
The company publishes a DICOM conformance statement. In imaging that document is the interface contract: it sets out which service classes are supported, how the software behaves as a network node, and what an integrator can rely on. Publishing one means a hospital imaging team can evaluate the integration before buying rather than after, and can hold the vendor to a written specification. Very few vendors in this index publish anything equivalent.
The deployment model follows from it. The software sits inline in the existing imaging workflow through an on premise gateway, receives studies, processes them and returns them, and is described as agnostic to scanner manufacturer and to picture archiving and communication system. No new capital equipment, no replacement of the imaging chain.
The contrast with the other imaging record in this batch is instructive and both approaches are legitimate. That one integrates with more than 40 named practice management and imaging systems through proprietary bilateral connectors, which delivers breadth but ties portability to the vendor. This one works through an open standard with a published conformance statement, which delivers fewer named partnerships and better portability, because anything that speaks DICOM is a candidate and the buyer can verify compatibility from the document. In a hospital imaging estate the standards based route is the stronger position.
What is not evidenced: how results are represented in the radiology information system or report, whether the output records which model version processed the study, and whether uptime or throughput commitments exist.
Upgraded from B on better evidence. The earlier grade was set from marketing material, which described scanner and vendor agnostic deployment but carried no residency or tenancy detail. The company's published DICOM conformance statement answers most of it, and a technical document written for integrators outranks a product page.
The architecture is a hybrid with the boundary in the right place. An on premise gateway component receives studies inside the facility and strips protected health information and other identifiers before anything is transmitted onward. Fully on premise deployment is also supported; the company's documentation distinguishes online from offline on premise installations when describing which features require connectivity.
That is a stronger structural answer than naming a cloud region. Naming a region tells a buyer where the transfer lands. Removing identifiers at the edge, or not transferring at all, reduces what is transferred in the first place. Where the cloud path is used, the vendor states data is encrypted at rest and in transit and that it holds a business associate agreement with its cloud infrastructure provider.
Nothing new is required in the imaging estate. The software processes studies on existing scanners of any manufacturer and returns them to the existing archive, so the deployment question is network placement rather than capital equipment.
Still not published, and worth asking for: specific cloud regions and whether any processing occurs outside the country of origin, the tenancy model and whether customer data is logically or physically separated, a subprocessor list beyond the infrastructure provider, and backup and disaster recovery posture.
One item belongs on the deployment checklist rather than only in the privacy review. The optional image sharing program described on the safety axis requires an online deployment to operate, so an offline on premise installation forecloses it architecturally.
Nothing published on price, and a value proposition that is unusually quantifiable, which makes the silence more conspicuous rather than less.
No rate card, no pricing basis, no statement of whether the model is per scanner, per site, per study or subscription, no term, no minimum and no volume banding. Sales run through enterprise imaging agreements. The company is private, with growth capital raised in 2026, so no filing obligation supplies what the website does not.
What makes this worth more than a one line note is that the return here is measurable in a way most categories are not. The product sells throughput and dose. Both are countable. Published implementation work reports acquisition time reduced by about a quarter, injected activity reduced by more than a third, and average daily patient throughput up by roughly five cases. A department can therefore calculate what the capability is worth to it with real precision, and still cannot compare that against a price without entering a sales process.
The pricing basis is the substantive question and not a detail, because it determines whether the vendor's incentive aligns with the buyer's. A per study fee scales with the volume the software is being bought to increase. A per scanner or subscription fee does not. Two buyers with identical scan volumes can reach opposite conclusions depending on which structure they are offered, and nothing published indicates which exists.
Ask for the pricing basis before the return on investment model, and ask specifically whether the fee scales with study volume.
Bounded by modality rather than by specialty, stated clearly, and broader in claim than in published evidence.
The scope is honest about what exists and what does not. Positron emission tomography and magnetic resonance imaging are cleared and in the field. A computed tomography product is disclosed as pending clearance rather than described as available, which is the correct treatment and better than several peers manage.
Because this is acquisition and reconstruction software rather than a diagnostic classifier, it is not bounded by clinical specialty at all. It processes whatever the scanner produces. That is a genuine architectural difference from detection products and it means the relevant coverage question is not which disease but which acquisition: which scanner models, field strengths, sequences, body regions and tracers the models were validated against.
That is where the claim outruns the evidence. The current generation product is described as supporting all radiotracers approved by the Food and Drug Administration. The published literature covers a much narrower set, principally fluorodeoxyglucose with smaller cohorts for gallium 68 PSMA-11 and fluorine 18 FDOPA. Support and validation are different claims and only one of them is documented.
The same gap applies on the magnetic resonance side, where no published statement of validated anatomies or sequences was retrieved.
Held at B for that distance between claim and evidence. Ask which tracers, sequences and anatomies at your site were represented in validation, and treat anything outside that as a local verification task.
What Changed
Material product, regulatory, evidence and commercial changes at Subtle Medical, each verified against a live source and tagged to the capability axis it bears on. Funding rounds and awards are not product changes and are not logged.
Subtle Medical received FDA clearance for SubtleHD (PET), a next generation AI PET image enhancement product for PET/CT and PET/MR systems. The company states it supports all FDA approved radiotracers, enables up to 75 percent faster PET imaging on existing scanners, improves SUVmax quantitation accuracy, allows radiologist adjustable denoising levels, and incorporates anatomical CT data into reconstruction. It extends prior clearances covering SubtlePET and SubtleHD (MR).
Compared With
Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.
Announced Deployments
Publicly announced health system deployments and partnerships. This is a record of announcements, not an assessment of deployment success or scale.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
Contact the vendor
|
Enterprise imaging agreements | — | — | Vendor Published |
Sold through enterprise imaging agreements, typically scoped by scanner or site. No rate card published.