ThetaRho
ThetaRho sells a clinical intelligence platform in three deliberately separated layers, and it will sell you any of them. A normalisation layer converts raw data from athenahealth, Epic, Cerner, Meditech, health exchanges reached through CommonWell and TEFCA, wearable and remote monitoring devices and public research corpora including PubMed into clean FHIR R4 resources, deduplicated and reconciled into a single view and annotated with RxNorm, LOINC, SNOMED CT, ICD-10 and MeSH. An AI layer adds semantic embeddings and clinical natural language processing so that a query for blood pressure medications returns ACE inhibitors, ARBs and calcium channel blockers even where those words never appear in the record. An application layer sits on top, and the company states that any EHR vendor, health system or clinical AI company can build on the first two layers rather than rebuilding normalisation themselves. Two applications are its own. RISA retrieves a patient's longitudinal record when a physician opens the chart and surfaces only what matters for that visit. DataDoc is a natural language chat window embedded directly in the athenahealth patient chart, letting a clinician ask for medications, labs, history, conditions and outside records rather than clicking to find them. Both are carried on the athenahealth Marketplace, with RISA described as certified there. The company is unusually direct about its own framing, arguing that clinical AI which knows medicine but not the patient is really just search, and positioning its work as the context retrieval that precedes physician judgement rather than as a substitute for it. It also does something almost nothing else in this index does: it names the models it runs on, citing Llama, Aloe and GPT models for clinical question answering grounded in patient data with traceable citations. That candour is credited on the transparency axis. The same sentence, however, ends with the claim that nothing is hallucinated, which is an absolute assertion of a kind this index treats as unfalsifiable, and both halves are recorded.
Capability Axes
The company draws the line itself: clean data alone is not intelligence, and the layer it sells as its differentiator is the one that adds medical ontologies, semantic embeddings and clinical natural language processing on top of normalised records. Its two shipped applications are both generative and both would not exist without the model layer. The normalisation work underneath is genuine infrastructure and is the kind of asset this index grades down elsewhere when it IS the product, but here it is explicitly positioned as the foundation rather than the offering, and the commercial pitch is the reasoning built on it.
Verification is designed in at the answer level. Clinical question answering is described as grounded in the patient's own data with traceable citations, every response verifiable and every source linked, sitting on top of a platform that maintains a complete audit trail and data lineage. That combination lets a clinician check any statement and lets an organisation reconstruct where a piece of data came from, which is more than most of this category offers. Held at B because no confidence signal, routing threshold or abstention behaviour is published, and because the company's own framing substitutes an assertion for a control: stating that nothing is hallucinated describes a desired property rather than a mechanism that enforces it. Ask what happens when the record does not contain the answer, and whether the system says so or produces something anyway.
One of the better disclosures in this category, undercut by one sentence. ThetaRho NAMES THE MODELS IT RUNS ON, citing Llama, Aloe and GPT models for clinical question answering, which is the fourth vendor anywhere in this index to answer the whose model is it question and the only one to name an open medical model family. It also names its full ontology stack rather than gesturing at standards, listing RxNorm for medications, SNOMED CT for diagnoses, LOINC for laboratory results, MeSH for research concepts and ICD-10, and it describes a complete audit trail and data lineage. Responses are described as grounded in patient data with traceable citations and every source linked. Held at B rather than A for two reasons: no accuracy figure, benchmark or evaluation methodology exists for any of it, and the same sentence that describes the grounding concludes that nothing is hallucinated. That is an absolute claim, unfalsifiable as written, and it sits oddly against a category where the dominant failure mode is silent omission. Publishing a measured rate instead would move this to A.
External technical validation without customer outcome data. Both products are carried on the athenahealth Marketplace and RISA is described as certified there, which means a major EHR vendor applied its own review before listing, and that is a real signal of the kind this index credits. Physician testimonials appear on the company's site and are unattributed. Beyond that, no customer is named, no funding is disclosed, no deployment scale is stated, and no accuracy, time saving or outcome measure of any kind was located. For a platform positioning itself as infrastructure others build on, the absence of any named organisation building on it is the gap to press.
No retention period, training use statement or de identification posture was located. Not Rated reflects absent retrieval. The scope makes the questions material: the platform assembles records from EHRs, health information exchanges via CommonWell and TEFCA, and patient generated data from wearables and remote monitoring devices, which is a broader estate per patient than a chart based product holds. Establish what is retained, for how long, and whether patient generated data is treated differently from clinical data.
HIPAA compliance is claimed specifically for the intelligence layer API, which the company describes as versioned and HIPAA compliant, with no business associate agreement terms published. That is the standard middle rung. One question the layered architecture raises: because third parties are invited to build applications on layers one and two, establish who holds the agreement when a clinician uses somebody else's product running on this platform, and whether the buyer's BAA reaches ThetaRho or stops at the application vendor.
No SOC 2, HITRUST, ISO 27001 or other attestation was located, and no trust centre or security page was found. Not Rated reflects absent retrieval. The company does describe a complete audit trail and data lineage for compliance, which is a security relevant capability rather than an attestation, and should not be read as one.
No FDA clearance, device authorisation or clinical decision support exemption analysis was located. Not Rated reflects absent retrieval. The company's own positioning arguably helps its case here and is worth noting: it frames the product as context work performed before physician judgement rather than as the judgement itself, and describes retrieval and surfacing rather than recommendation. That is a coherent scoping argument, but it should be documented by the vendor rather than inferred from a blog post.
The grade describes disclosure. Positives first: naming the underlying models is itself a governance disclosure, since a buyer cannot reason about model behaviour without knowing which models are involved, and citation plus audit trail supports accountability after the fact. Against that, no fairness, subgroup or demographic performance disclosure of any kind was located, no evaluation framework is described, and no responsible AI documentation exists. The claim that nothing is hallucinated is the specific problem: an absolute assurance offered in place of a measurement discourages exactly the scrutiny a governance programme is supposed to invite, and a buyer should treat it as a prompt to ask for the measured rate rather than as a reassurance.
Strong on breadth and standards, thin on evidenced deployment. Four EHRs are named explicitly, athenahealth, Epic, Cerner and Meditech, alongside health exchange connectivity through both CommonWell and TEFCA, patient generated data from wearables and remote monitoring devices, and public research corpora. Everything is normalised to FHIR R4 with deduplication and reconciliation across sources, and annotated against a named ontology stack, which is real interoperability engineering rather than a claim of seamless integration. Two products are carried on the athenahealth Marketplace with RISA described as certified. Held at B because athenahealth is the only integration externally corroborated, the other three EHRs are named but not evidenced, and no customer deployment is described anywhere.
A hosted, versioned API is the described delivery model for the intelligence layer, with applications running on top of it, which establishes cloud delivery and no customer hosted option. Nothing further is published: no cloud provider, region, residency commitment or statement about where assembled records are processed. Graded C because the delivery model is clear and the residency picture is entirely absent.
No price, tier or pricing mechanism was located. Not Rated is the house convention for absent pricing rather than a low grade. The layered model makes the commercial question unusually important: establish whether you are buying an application, API access to the intelligence layer, or the normalisation infrastructure, because those are three different products with three different cost structures sold under one name.
Broad rather than deep, and broad across two dimensions that rarely appear together. On the clinical side the products are specialty agnostic and ambulatory led through the athenahealth install base, with the company offering demonstrations framed around a buyer's own specialty. On the customer side it addresses three distinct buyer types with the same stack: clinicians using its own applications, and separately EHR vendors, health systems and other clinical AI companies building on the layers beneath. Graded B rather than A because no specialty specific behaviour or instrument level depth was located, and because coverage does not extend to inpatient or post acute settings.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
Not published
|
Undisclosed. Sold as clinician facing applications, as API access to the intelligence layer, and as normalisation infrastructure for other builders. | Not published. HIPAA compliance is claimed for the intelligence layer API. Establish who holds the agreement if you reach the platform through a third party application built on it. | Not published. Two products are carried on the athenahealth Marketplace, and the company positions the platform as removing the need for others to rebuild normalisation infrastructure, but no fee structure is stated for any layer. | Vendor Published |
No price, tier or pricing mechanism was located, so commercial transparency is Not Rated per the house convention rather than graded down. The layered architecture makes scope the first question rather than the last. Establish which layer you are buying, because three genuinely different products are sold under one name: a clinician facing application such as RISA or DataDoc, API access to the intelligence layer, or the underlying FHIR normalisation infrastructure. Those carry different cost structures, different integration work and different lock in, and a proposal that does not say which one is being priced cannot be compared to anything. Then establish three more things. Whether marketplace procurement through athenahealth is available, since that route sometimes carries published pricing and a faster path than direct contracting. What the data source connections cost, since health exchange connectivity through CommonWell and TEFCA and patient generated data ingestion may be separately priced from the core platform. And what happens to the normalised, ontology annotated record if the relationship ends, because the value created by normalisation compounds over time and portability of that asset is worth writing into the contract rather than discovering later.