VUNO
South Korean medical AI company whose flagship DeepCARS predicts in-hospital cardiac arrest within 24 hours for patients in general wards, using only four routinely collected vital signs drawn from the EMR: blood pressure, heart rate, respiratory rate, and temperature. Distinctive in this index for operating on biosignals rather than images, in a market where Korean medical AI was largely image based, and for the deployment scale it has reached in one national system, more than 48,000 hospital beds across South Korea including 20 tertiary general hospitals. Approved by Korea's MFDS in 2021 and holding US FDA Breakthrough Device Designation since 2023 while pursuing 510(k) clearance.
Capability Axes
An AI Health Index grade measures what a buyer can verify from public sources on the date shown. It is not a rating of how good the product is. A vendor can build an excellent system and grade low on an axis because it publishes nothing an outsider can check. How grades read
The deep learning model is the product. DeepCARS converts four routinely charted vital signs into a 0 to 100 risk score, and there is no hardware, monitoring device, or services layer being sold alongside it. The company's own framing makes the centrality explicit: this was the first biosignal based AI medical device to commercialize in a Korean market where medical AI research had been almost entirely image analysis.
Produces a risk score for a rapid response team to act on, so the human decides whether and how to intervene. The oversight question here is specific to early warning systems and worth naming: a deterioration score that fires too often produces alarm fatigue and gets ignored, while one tuned too conservatively misses patients.
The company positions the tool as enabling timely intervention rather than triggering automated escalation, and the deployment context is general wards where nursing staff, not the algorithm, mobilize the response.
Inputs and outputs are stated with precision, four named vital signs producing a 0 to 100 score over a 24 hour horizon, and discrimination is published rather than asserted: AUROC 0.860 on internal validation and 0.905 on external validation from a multicenter study of 173,368 patients. Publishing external validation performance separately from internal, and having the external figure be the higher one, is a meaningful disclosure.
Model architecture detail beyond deep learning on vital sign sequences is not published, and no calibration or alert rate data was located, which matters more than discrimination for an early warning system.
Nothing identifies any party in the chain: no model or model family, no hosting arrangement, no sub processor list, no residency statement, and no retention or deletion position was located in two passes. The privacy statement indicates a functioning programme, with commitments beyond a legal minimum, an internal privacy committee and recurring staff awareness activity, and that is worth recording even though it answers none of the questions this axis asks.
One omission carries more weight here than the general enumeration gap, and it follows from something creditable the company does. The product range spans medical imaging across several modalities and biosignal data, and the company has a substantial published clinical research output built on patient records. Publishing validation studies is good practice and this index credits it elsewhere.
It also means two distinct data uses run inside one organisation: data processed on behalf of a customer, and data used to develop and publish. A company doing both should be able to state plainly what separates them, and nothing retrieved describes that separation. Ask for the retention schedule in writing, ask directly whether your own images and biosignals train or improve models, and ask what governs the data behind the published studies and how it was obtained.
Among the better evidenced deterioration prediction tools in this index, and the evidence is genuinely independent of the vendor's marketing. Peer reviewed publications appear in Resuscitation, the Journal of the American Heart Association, and Critical Care Medicine, with a multicenter validation of 173,368 patients.
Crucially there is a PROSPECTIVE multicenter validation published in Critical Care in 2023, co-authored across Seoul National University Hospital, Seoul National University Bundang, Inha, and Dong-A University Hospital, testing prediction of cardiac arrest or unplanned ICU transfer and reporting superiority over traditional early warning scores. Prospective evidence is rare in this category, where most tools rest on retrospective cohorts. Deployment across 48,000 plus beds adds real world scale, though all published evidence is from Korean cohorts, so US generalization is untested.
The privacy statement commits to commercially reasonable efforts to secure personal information and describes measures beyond the legal minimum, supported by an internal privacy committee and recurring staff awareness activity. That indicates a functioning privacy programme rather than a boilerplate policy.
Nothing published, however, addresses the questions a buyer needs answered. There is no retention period, no deletion procedure, no end of contract data disposition, no subprocessor list, no residency statement, and no position on whether patient data processed through the products is used to develop or improve the models.
That last omission carries more weight here than for most vendors. The product range spans medical imaging across several modalities, including brain magnetic resonance, chest radiography, fundus photography and computed tomography, together with biosignal data including electrocardiography, and the company has a substantial published clinical research output drawn from patient data. A company that publishes validation studies built on patient records should be able to state plainly what separates the data it uses for research from the data it processes on behalf of a customer. That separation is not described anywhere retrieved.
Buyers should ask for the retention schedule in writing, ask directly whether their own images and biosignals train or improve the models, and ask what governs the data used in the company's published studies.
No HIPAA position of any kind was located: no statement, no business associate agreement, and no terms addressing the relationship.
For the company's established business that is coherent rather than a failure, and the note should not be read as one. VUNO is a Seoul company whose installed base is domestic, with more than a hundred Korean hospitals using its products, operating under Korean data protection law. A vendor selling into its home market has no occasion to publish a HIPAA position, and its absence says nothing about the quality of the underlying data handling.
The reason this still grades at the bottom is that the company's stated commercial direction has moved ahead of its published compliance posture. It holds a United States clearance for one product, states an intention to direct sales and marketing at US medical institutions, and is pursuing further authorisations in the United States, Europe and Japan. A vendor selling into US hospitals becomes a business associate the moment it processes patient data on their behalf, and nothing published indicates whether it will execute the agreement that requires.
This is the axis most likely to move as the expansion proceeds. United States buyers should treat it as an opening question rather than a late one: ask whether the company will sign a business associate agreement, which legal entity signs it, and whether US patient data is processed or stored outside the United States.
The company's privacy statement asserts that it has obtained recognised privacy and information security certifications, as applicable, but it names none of them. A certification claim that does not identify the certification, the governing standard or the assessor cannot be verified and does not function as assurance, and the qualifier as applicable weakens it further. This index treats an unnamed certification claim as weaker than silence, because it invites a buyer to assume an attestation exists where none may.
Credit is due for the parts of the programme that are described concretely, and they are more specific than many vendors offer: simulated phishing exercises, information security awareness campaigns and internal privacy committee meetings. Those are real administrative controls and they indicate an operating security function rather than a policy document sitting unread.
What is absent is any independent attestation, trust centre, controls table, encryption statement, penetration testing statement or subprocessor list. A separate targeted search for a named certification returned nothing.
Buyers should ask which certifications are held, under which standard, and issued by whom. They should also ask specifically whether a Korean domestic information security certification is held, since a domestic scheme unfamiliar to a United States or European procurement reviewer still carries real assurance value if the scope is right, and may be the thing this statement is gesturing at.
VUNO's regulatory position is split across its product line, and a buyer must check the specific product rather than the company. That split is the reason for this grade and the reason the detail matters.
Cleared in the United States: VUNO Med-DeepBrain, a brain magnetic resonance imaging quantification tool, received FDA 510(k) clearance in October 2023, the company's first US clearance. Marked in Europe: five solutions hold Class IIa CE marks, covering bone age assessment, brain quantification, chest radiography, fundus imaging and lung computed tomography, so those products can be sold across the European Union and in markets that recognise the CE mark. Approved at home: Korea's Ministry of Food and Drug Safety has authorised multiple products, four of the five CE marked solutions on the basis of clinical trials.
The flagship deterioration product sits differently, and this is where buyers most often conflate things. VUNO Med-DeepCARS, a cardiac arrest prediction tool, is approved and reimbursed in Korea, where the company states it was the first software based medical product to obtain both certification and the right to bill for its use, and it is in routine clinical use across tens of thousands of Korean hospital beds. In the United States it holds Breakthrough Device Designation granted in 2023 and is pursuing clearance, with studies underway. A designation is a commitment to a review pathway, not an authorisation, so a US hospital cannot deploy that product clinically on the strength of it.
Buyers should ask which specific product they are purchasing and in which jurisdiction it is authorised. A US clearance for one imaging product does not extend to the deterioration product or to any other item in the range.
Multicenter validation across several independent Korean tertiary hospitals addresses site level generalization, and the prospective design tests the model in live conditions rather than on curated retrospective data. What is absent is any demographic subgroup analysis, and the concern is concrete for this product class: vital sign based deterioration models are known to perform differently across age, sex, and comorbidity profiles, and the entire published evidence base is drawn from a single national population, which leaves performance in a more heterogeneous US population undocumented.
Two disclosures put this in the band and one absence keeps it there, and the absence is technical enough to be worth explaining. The disclosures: inputs and outputs are stated precisely, with four named vital signs producing a bounded score over a stated twenty four hour horizon, and discrimination is published for internal and external validation separately, with the external figure drawn from a multicentre study of more than one hundred and seventy thousand patients and coming out higher than the internal one.
Publishing external validation as a distinct number is what separates a model that has been tested outside its development setting from one that has not, and reporting it separately rather than blending the two is a deliberate act of clarity. The absence is calibration.
Discrimination measures whether the model ranks patients correctly relative to each other; calibration measures whether a stated score corresponds to a real probability, and for an early warning system the second matters more, because the score drives a threshold and a threshold drives an alert. A model with excellent discrimination and poor calibration produces alerts at the wrong rate, and alert rate is the number that determines whether nurses keep responding.
No calibration data, no alert rate and no warranty, indemnity or remediation commitment was located. Ask for calibration, alerts per patient day at the recommended threshold, and performance in the population you serve.
Integration is the deployment mechanism rather than a feature, since the model consumes vital signs directly from the electronic medical record and returns scores into ward monitoring workflows. The company frames the reliance on only four routinely collected vital signs as itself an adoption advantage, because no new instrumentation, device, or documentation burden is required, which is a genuine interoperability argument. No named EHR connector list or API documentation was located, and Korean hospital EMR integration does not automatically transfer to Epic or Oracle Health environments.
No deployment architecture is described. Nothing published states whether the products run on premise inside the hospital, in a vendor hosted cloud, or through an integration with existing imaging infrastructure, and no cloud provider, hosting arrangement, implementation timeline or availability commitment was located. No data residency commitment of any kind was found, which is the more consequential half of this axis for a vendor headquartered in one jurisdiction and actively selling into others.
Adoption is nonetheless well evidenced and this record should not be read as thin. More than a hundred Korean hospitals use the products, and the cardiac arrest prediction product is described as being in routine clinical use across tens of thousands of hospital beds. Reimbursement in the home market is a further genuine deployment enabler, since a product a hospital can bill for clears an adoption barrier that most clinical artificial intelligence tools never clear.
Adoption at that scale is evidence the software works in production; it is not a description of how it is deployed. Buyers outside Korea should establish where their imaging and biosignal data is processed and stored, whether any deployment option keeps it inside their own jurisdiction, what integration is required with their existing imaging systems, and who supports it.
No pricing is published. The company is listed on the Korean exchange, which brings financial disclosure obligations absent from private competitors and gives a buyer some visibility into vendor stability, but nothing on per bed, per hospital, or subscription cost. US pricing is likely unsettled given the product is pre clearance there.
Deliberately narrow: general hospital wards, predicting cardiac arrest and unplanned ICU transfer in admitted inpatients. That is a high value setting, since deterioration on general wards is where rapid response teams are supposed to intervene and frequently do not in time, but it does not extend to ICU, emergency department triage, or outpatient monitoring. The broader company portfolio includes imaging products, though DeepCARS is the flagship and the basis of this record.
What Changed
Material product, regulatory, evidence and commercial changes at VUNO, each verified against a live source and tagged to the capability axis it bears on. Funding rounds and awards are not product changes and are not logged.
Researchers from VUNO published a peer-reviewed study in the American Journal of Neuroradiology validating a machine learning algorithm that uses automated brain MRI volumetry to differentiate frontotemporal dementia from Alzheimer's disease. The model, trained on 758 subjects and externally validated on 89 subjects, achieved 91.4 percent accuracy internally and significantly reduced interpretation time for experienced radiologists.
Compared With
Each comparison carries a written verdict, the buyer conditions that favor each vendor, and a graded side by side. Pairs that cross a category boundary are grouped separately, and their verdicts state where the boundary sits rather than manufacturing a head to head.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | BAA Tier | Implementation | Source |
|---|---|---|---|---|
|
Contact the vendor; not yet FDA cleared for US clinical use
|
Undisclosed. No per bed, per hospital, or subscription rates published. | Not disclosed. A Korea headquartered vendor now selling into US hospitals through a Massachusetts office would need business associate terms established directly. | Not disclosed. The company frames reliance on only four routinely collected vital signs as reducing adoption cost, since no new instrumentation or documentation burden is required, though EMR integration work still applies. | Vendor Published |
No pricing is published. As a company listed on the Korean exchange, VUNO carries financial disclosure obligations absent from private competitors, which gives a buyer visibility into vendor stability but nothing on cost. The decisive commercial fact for a US buyer is not price but availability: DeepCARS holds FDA Breakthrough Device Designation and is still pursuing 510(k) clearance, so it cannot be deployed clinically in the US today regardless of terms. US pricing is likely unsettled for that reason. Korean deployment across 48,000 plus beds demonstrates the product can be bought at scale in its home market.