The Claim Under Test
The claim that sells almost every AI product into a medical practice is that it saves clinicians about two hours a day. The best independent evidence measures the benefit in minutes. A randomised crossover clinical trial published in the Journal of the American Medical Informatics Associationin 2026 — 33(5):990–999, 160 clinicians enrolled and 136 analysed — compared two ambient scribe products head to head and found reductions in time-in-notes of 5.89 and 9.07 minutes per day. It found no meaningful reduction in after-hours work, the pajama time that drives most of the burnout conversation, for either product.
That is not a debunking. The same trial found something genuinely valuable: both tools reduced personal and work-related burnout on the Copenhagen Burnout Inventory, with no meaningful difference between them, and safety concerns were minimal — though users emphasised the need for careful note editing. Workflow satisfaction improved more with one product than the other, by 0.60 points on a seven-point scale. The trial identifies the two products only as Product A and Product B, so nobody can honestly attach a vendor name to those results, and we will not.
The second claim under test is economic rather than clinical. The Peterson Health Technology Institute assessed ambient scribes across eight large health systems — CommonSpirit Health, Intermountain Health, Mass General Brigham, MultiCare, Ochsner Health, Providence, UC San Diego Health and Yale New Haven Health — and published its findings on 25 March 2025. The conclusion was that AI-powered scribes likely improve clinician burnout but that the financial impact is unclear. That is the closest thing to an independent economic evaluation this category has, and it comes from organisations with more measurement capacity than any independent practice will ever have. If they could not demonstrate a clear financial return, a six-provider group should be sceptical of a vendor who promises one on a slide.
So this article does something different from the rankings you have already read. It does not score accuracy, because no independent benchmark of these products exists — not one, for any product in this market. It scores what a practice owner can verify without leaving their desk: what integrations the vendor publishes, what certifications sit on a page you can open, whether a BAA is offered publicly, whether a price is published at all, whether the product is standalone or locked to a suite, and who owns the company today according to public record. Every cell in the table below carries a citation or the literal words not publicly disclosed, and every one of them is re-checkable on the day you sign. That is more than any competing list can say about a single accuracy figure.
If you want the wider framing before the vendor-by-vendor detail, our cross-industry review of AI agents in 2026 applies the same refusal-to-score-marketing method across ten verticals, and the pattern holds everywhere: the read surface is wide, the write surface is narrow, and the numbers that sell the software are the ones nobody has audited.
How We Ranked, and What We Refused to Rank On
We scored eight attributes, every one of which a reader can re-check at a public URL, and we refused to score anything a vendor publishes about its own performance. That refusal is not modesty. It is the only defensible position available, because in this market every accuracy, deflection, containment, resolution-rate and ROI figure in circulation was published by the company selling the software, without a methodology, a denominator or a third-party audit.
The methodology block — checked 2026-08-23, and how to re-check it
What we scored.Documented public integrations, read from the vendor's own site or press release. Whether a BAA is publicly offered. SOC 2, HITRUST and ISO 27001 status as published on a reachable vendor page. Pricing transparency — published price versus contact sales. Standalone versus locked to a suite. Ownership and funding from public record. Data residency and retention commitments. Whether any independent evaluation of the product exists.
What we refused to score. Accuracy. Deflection rate. Containment rate. Resolution rate. ROI. Time saved. Hours returned. Patient-satisfaction lift. Every published figure for these in this market is vendor marketing about itself.
What we excluded, and why. Vendors that sell to health plans rather than to practices. Vendors whose product requires a health system or an EHR licence a practice does not hold. Vendors whose own trust and pricing pages could not be reached, where filling the cell would have meant copying a review site. Each exclusion is named in its own section below rather than quietly dropped.
Date checked: 23 August 2026.Every compliance and pricing cell was read off the vendor's own page on that date. Vendors change pages without notice, so treat each cell as a claim with a timestamp. To re-check: open the trust or security page, the pricing page and the integrations page for each vendor, and compare what you find to the table. If a page has moved, that is data too — five of the vendors here have trust or security URLs that returned 404 on the date we checked.
What an independent benchmark would look like, and what exists instead
No independent benchmark of accuracy, deflection, containment or resolution rate exists for any AI agent sold to medical practices. That is a precise claim, not a blanket denial, and the distinction matters because independent evaluation in this vertical genuinely does exist — it just does not measure the thing vendors are selling. Three things exist and should not be confused with one another.
- Peer-reviewed randomised trials of the modality: The JAMIA 2026 crossover trial is real, randomised, independent of the vendors, and measures minutes-in-notes and burnout. It tells you what ambient scribing does. It does not tell you which product to buy, because the products are anonymised as Product A and Product B.
- An independent economic assessment: The Peterson Health Technology Institute's March 2025 assessment across eight large health systems concluded that scribes likely improve burnout while the financial impact is unclear. It is an assessment of a category, not a ranking of vendors, and the announcement page carries no percentages — so no percentage should be attributed to it.
- A customer-satisfaction survey: Best in KLAS 2026, released 4 February 2026, ranked Abridge first in Ambient AI at 94.7 points with Ambience second at 94.4, and CodaMetrix first in Autonomous Coding. KLAS is a third-party research firm surveying customers about satisfaction. It is not a measurement of what the software outputs. A vendor can rank first in KLAS and still have published no accuracy measurement at all — which is exactly the situation here.
What happened the one time a regulator audited a vendor's AI metrics
There is a reason to hold vendor performance numbers at arm's length that is stronger than professional caution: the one time a US federal regulator audited a public company's published AI performance metrics, it found them materially misleading. In In the Matter of Presto Automation Inc., Securities Act Release No. 11352, Exchange Act Release No. 102177, Admin. Proc. File No. 3-22413, entered 14 January 2025, the SEC addressed a drive-thru voice AI product the company had told investors delivered “over 94% accuracy even in noisy environments” and 95%–99% automated order completion.
The product “lacked the capability to take orders on their own and required substantial human involvement,” with “human order takers located abroad (primarily in the Philippines and India), who processed the vast majority of drive-thru orders.”
— SEC, In the Matter of Presto Automation Inc., Release No. 33-11352 (14 January 2025), ¶3
Four things must be said precisely about that order, because it is frequently mis-summarised. Presto consented without admitting or denying the findings. The remedy was a cease-and-desist order with no civil penalty — it was not a fine. The findings are against Presto only; the order's “Supplier A” is Hi Auto, against whom the SEC made no findings whatsoever. And Presto Automation Inc. is a different entity from Presto Phoenix Inc., which acquired assets in December 2024.
The lesson generalises cleanly to healthcare. This is what happened the one time anyone independently checked whether a vendor's published AI performance metric described the product it was sold as describing. It is why we score only what a buyer can verify, and why the most useful question you can ask a healthcare AI vendor is not “what is your accuracy rate” but “who measured it, against what denominator, and can I see the methodology.”
The numbers we refuse to print
Several figures dominate the sales conversation in this category and none of them should travel. We list them here so that you recognise them when a vendor puts one in a deck, and so that you can ask the one question that ends the conversation: what is the primary source?
| The claim | Where it comes from | Why we do not print it |
|---|---|---|
| "$200 per no-show" and "$150 billion a year in missed appointments" | Circulates unattributed across scheduling-vendor content | No methodology, sample or denominator has ever been published for either figure. We could not locate a primary source, so we do not print them as fact. |
| "$47,000 a year lost to no-shows"; "32–38% of dental calls missed" | Dental practice-marketing content | Same defect. No published methodology, no sample, no denominator. |
| Any phone-abandonment benchmark — "7% abandonment", "85% of callers never call back" | Sold alongside voice agents | No primary source exists for either. Note that one vendor in this very roster publishes an "81% decrease in abandonment rate" — a vendor figure measuring a benchmark that has no source of its own. |
| "$25–$118 per claim rework"; "50–65% of denied claims are never reworked" | Attributed to MGMA across revenue-cycle marketing | We could not locate a primary MGMA publication supporting either figure, so we do not repeat them. |
| "Saves clinicians about two hours a day" | Freed's own marketing | Contradicted by the peer-reviewed randomised evidence: 5.89 and 9.07 minutes per day, and no meaningful reduction in after-hours work. |
| "97% resolution rates", "90%+ first-call resolution", "$4.3M per 100 providers" | Assort Health's own pages | Vendor-published, with no methodology, no denominator and no third-party audit. We attribute them to the vendor or we drop them. |
| "100% answer rates across calls, texts, and chat" | Hello Patient's homepage | An unfalsifiable absolute. No system answers 100% of anything; a claim that cannot fail cannot be evidence. |
| "97.7 customer satisfaction score"; "first third-party validated, CFO-approved ROI" | Ambience's Series C announcement | An ROI claim whose validation is not itself published is not a validated ROI claim. |
| "95% of generative-AI pilots fail" | An MIT-affiliated report widely cited as a base rate | Built on 52 interviews and 153 conference surveys, scoped to custom-built tools. It is not a base rate for buying software. |
| "Physicians spend 13 hours a week on prior authorisation" attributed to a vendor | Vendor press coverage | The number is real and we use it — cited to the AMA survey that produced it, not to the vendor that repeated it. |
Claims we identified and refused during this review, checked 23 August 2026. Each is named rather than silently omitted, so a reader can recognise it in the wild.
Two price-shaped refusals belong in the same category. Third-party review and reseller sites publish per-user monthly figures for Suki, Nabla and Microsoft Dragon Copilot; none of those is a vendor-published price, they vary widely between sources, and we do not reprint them. EHR-integration consultancies circulate an annual figure for Epic's Vendor Services programme; Epic does not publish it, so neither do we. In both cases the honest cell is not publicly disclosed, and a buyer should treat any article that prints a confident number as one that copied a review site.
The no-show economics deserve their own note because they are the single most common justification offered for a patient phone agent. We work through why those figures fail and what a practice can measure instead in our analysis of scheduling agents and no-show claims. The short version: build the business case on your own historical no-show rate and your own fill rate, both of which you already have, rather than on an industry figure whose denominator nobody has ever published.
The Comparison Table
Here is the entire ranking in one table, with a citation or the words “not publicly disclosed” in every cell. Nothing in it is our opinion of output quality, because output quality is exactly what nobody has measured. The ordering reflects how much of a buyer's due diligence each vendor makes possible before a sales call, which is the only proxy available and is more honest than a fabricated score.
| Product | Named EHR / PM integrations (vendor-published) | Certifications on a reachable vendor page | BAA stated publicly | Published price | Independent evaluation |
|---|---|---|---|---|---|
| 1. Freed | "EHR push" named as a Premier-tier feature; no EHR vendors named | SOC 2 Type 1 and Type 2, HIPAA, HITECH (getfreed.ai/pricing) | Yes — organisation-wide BAA, scoped to group plans | Yes — full published tier card, $39 / $79 / $104 annual or $119 monthly; Groups custom | None found |
| 2. Hello Patient | ModMed, AdvancedMD, NextGen, Zenoti, eClinicalWorks, athenahealth, Veradigm, Avimark, Cornerstone, Clockwise, Ottehr, Pulse, Braze, Customer.io | HIPAA, SOC 2 Type II (homepage badges) | Not publicly disclosed | Not publicly disclosed | None found |
| 3. Suki | Epic, Oracle Health, athenahealth, MEDITECH | SOC 2 Type 2, HIPAA (homepage) | Not publicly disclosed | Not publicly disclosed; suki.ai/pricing returned 404 on 2026-08-23 | None found |
| 4. Nabla | None published | SOC 2 Type II, ISO 27001, HIPAA, GDPR (nabla.com/security). Only vendor publishing a customer-selectable data region | Not publicly disclosed | Not publicly disclosed | None found for the product |
| 5. Abridge | None published on site; Epic and Oracle Health integrations widely reported | SOC 2 Type 1 and Type 2, HIPAA, CCPA, TX-RAMP (trust.abridge.com) | Support article states a standard BAA is available (secondary) | Not publicly disclosed | Best in KLAS 2026 #1 Ambient AI — a satisfaction survey, not an accuracy measurement |
| 6. Adonis | Epic, athenahealth, NextGen, Modernizing Medicine | HIPAA and AICPA badges; SOC 2 type not stated | Not publicly disclosed | Not publicly disclosed | None found |
| 7. Assort Health | Epic, athenahealth (named in its Series C release) | None published; assorthealth.com/security returned 404 on 2026-08-23 | Not publicly disclosed | Not publicly disclosed | None found |
| 8. Microsoft Dragon Copilot | Epic including Epic Rover, PowerScribe One; athenahealth and MEDITECH partner pages exist | None named on the product page checked 2026-08-23 | Not publicly disclosed | Not publicly disclosed; partner pricing guide sits behind partner login | None verified; a 2025 preprint names its predecessor product as a study arm |
| 9. Ambience Healthcare | Epic, Oracle Cerner, athenahealth (vendor's own Series C release) | None reachable — /security, /trust and /legal all returned 404 on 2026-08-23 | Not publicly disclosed | Not publicly disclosed | Best in KLAS 2026 second in Ambient AI |
| 10. Humata Health | None published | None published on the homepage as of 2026-08-23 | Not publicly disclosed | Not publicly disclosed | None found |
All cells read off the vendor's own pages on 23 August 2026. Blank is never assumed — where a vendor does not publish something, the cell says so.
Read the table in two directions. Down the pricing column it tells you how much of this market expects you to enter a sales process before learning a number — which is a strategy choice, not a scandal, but it is a cost you should price into your evaluation timeline. Across the integrations column it tells you something more actionable: the vendors that name specific practice-management systems are the ones built for an independent practice, and the vendors that name only Epic are built for health systems that happen to sell to you as well.
One column deserves a warning. “Certifications on a reachable vendor page” is a measure of disclosure, not of security. A vendor with an empty cell may well hold a SOC 2 report behind a sales NDA. What the empty cell tells you is that you will have to ask, that you should ask early, and that the answer belongs in the contract rather than in an email.
The Ten, Part One: Documentation Copilots
Six of the ten are ambient documentation products, and every one of them is a copilot rather than an agent — it drafts, and a clinician signs. Nothing enters the record unattended in any of them. That is not a weakness in the products; it is the correct design given the constraint explained further down this page, and a vendor claiming otherwise is either running inside the EHR or overselling.
1. Freed — the only vendor in this market that publishes a price
What it does. Ambient scribing aimed squarely at solo clinicians and small independent practices. It is the only major ambient product in this review whose purchase path is self-serve, which is why it belongs at the top of a ranking written for practices rather than for health systems.
What is verifiable. The pricing page, fetched 23 August 2026, publishes a complete tier card: Starter at $39/month for one clinician with up to 40 notes per month; Core at $79/month with unlimited notes, a template builder and clinical evidence answers, free for residents, students and trainees; Premier at $104/month billed annually or $119/month billed monthly, adding visit summaries, patient instructions, letters and referrals, EHR push integration, dictation, and ICD-10 and CPT coding; and Groups at custom pricing with MA users, SSO, admin dashboards and a dedicated account manager. The same page states HIPAA compliance, SOC 2 Type 1 and Type 2, HITECH compliance, and an organisation-wide BAA available for group plans. Corporate status: independent, with a $30M Series A led by Sequoia announced on the company's own press page.
What is not disclosed.No named EHR integrations. “EHR push integration” appears as a Premier-tier feature but the vendor names no specific EHRs, so a buyer must confirm their own system in a trial. HITRUST is not claimed. No independent evaluation of the product exists.
The design fact worth calling out. Even at the most transparent vendor in this market, the write path is a paid upgrade. EHR push sits in the top individual tier. That is not a pricing trick — it is the economics of the constraint in §7 showing up on a price card.
Who it fits. Solo practitioners and small groups who want to evaluate without a sales cycle, and any practice that wants a published price to anchor negotiations with a larger vendor. Who it does not.Solo buyers who need a BAA — the organisation-wide BAA is scoped to group plans, so confirm your own coverage in writing before you upload a single encounter. Also: we refuse the vendor's own “saves clinicians about 2 hours per day” claim, which the randomised evidence contradicts by roughly an order of magnitude.
2. Suki — four named EHRs, and the clearest illustration of the write constraint
What it does. Ambient documentation, dictation, coding support, and — the interesting part — ambient order staging. The product stages orders for clinician sign-off rather than placing them.
What is verifiable. The homepage, fetched 23 August 2026, names Epic, Oracle Health, athenahealth and MEDITECH and states that the platform is SOC 2 Type 2 certified and HIPAA compliant. Corporate status: Suki AI, Inc. remains independent and private, not acquired. Trade reporting puts total funding around $168M and notes a Zoom Ventures strategic investment in January 2025 and a Wolters Kluwer partnership embedding UpToDate content; treat the round figures as trade press rather than filings.
What is not disclosed.No BAA statement on the homepage. No HITRUST, no ISO 27001. No published price — suki.ai/pricing returned a 404 on the date we checked. Third-party review sites converge on per-user monthly figures; those are not Suki's prices and we do not print them. No independent evaluation of the product exists.
Why the staging detail matters. Order staging rather than order entry is the tell that a vendor has read the same regulation we have. It is the single cleanest illustration in this whole roster of what the read-only certified API actually does to product design: the model can determine what the order should be, and a licensed human still has to commit it.
Who it fits. Practices on Epic, Oracle Health, athenahealth or MEDITECH who want documentation and coding in one product and are prepared to run a sales process. Who it does not. Practices on specialty PM systems not on that list, and buyers who need a price before a demo.
3. Nabla — the only vendor publishing a customer-selectable data region
What it does. Ambient documentation across specialties. The product is called Nabla Copilot, which is an unusually honest name in a market that has renamed everything an agent.
What is verifiable. The security page, fetched 23 August 2026, states that the information security programme follows the criteria set forth by the SOC 2 Type II and ISO 27001 frameworks and has obtained the associated certifications, and references HIPAA and GDPR. The same page states that databases are located in the region you choose when you create your organisation. Nabla is the only vendor in this entire roster that publishes a customer-selectable data region, and for a practice with any cross-border exposure or a payer contract with residency language, that is a genuine, checkable differentiator rather than a marketing phrase.
What is not disclosed. No named EHR integrations. No BAA, retention or model-training commitment on the security page; the vendor directs to a separate trust centre we did not fetch. No HITRUST. No published price. Two 2026 changes a stale roster would miss, both from trade reporting rather than filings: Nabla appointed a new CEO in July 2026, and holds an exclusive strategic partnership with AMI, Yann LeCun's company, which raised a very large round in March 2026. Neither is a problem; both are things a buyer signing a multi-year contract should know.
Who it fits. Practices whose compliance officer or payer contract asks where the data physically sits, and practices that want ISO 27001 alongside SOC 2 Type II. Who it does not. Practices that need a named integration with a specific EHR before committing, since Nabla publishes none.
4. Abridge — the fullest trust centre, and the KLAS caveat
What it does. Ambient capture of the clinical encounter, draft note generation and coding support, deployed predominantly at health systems.
What is verifiable. The trust centre at trust.abridge.com, fetched 23 August 2026, lists CCPA, HIPAA, SOC 2 Type 1, SOC 2 Type 2 and TX-RAMP, and states that its products are covered by a SOC 2 Type 2 report validated by an independent third-party auditor for security and confidentiality. It also names data-service subprocessors including Zendesk, Amplitude, Sentry, OpenAI and Google Cloud — a level of subprocessor disclosure no other vendor here matches, and something your compliance review will need. Corporate status: Abridge AI, Inc. is independent and not acquired, with a large Series E and a 2026 extension reported by the trade press.
What is not disclosed.No named EHR integration list on Abridge's own site — Epic and Oracle Health integrations are widely reported and one case-study URL references Cerner, but we could not reach an Abridge page asserting an integration list. HITRUST is not listed. ISO 27001 is not listed. Data residency and retention are not published on the trust centre page. No published price. The BAA position comes from a support article rather than the trust centre, so treat it as a strong indication to confirm in writing rather than as a published commitment.
The KLAS caveat, stated precisely. Abridge was ranked #1 in Best in KLAS 2026 for Ambient AI at 94.7 points, its second consecutive year, with Ambience second at 94.4. KLAS is a third-party research firm that surveys customers about satisfaction. It is not a measurement of what the software outputs. Abridge can be genuinely the best-liked product in its category and still have no published accuracy measurement — and it does not have one, because none exists for anybody.
Who it fits. Larger groups and practices affiliated with a health system already running it, and any buyer whose compliance function wants named subprocessors. Who it does not.Small independent practices wanting self-serve evaluation. We also refuse, as neutral fact, the customer figures on Abridge's own pages — documentation-effort reduction, work-satisfaction, wRVU and urgent-capacity percentages attributed to named health systems. Those are vendor-published, without methodology or denominator, and they are the vendor's claims rather than findings.
5. Microsoft Dragon Copilot — and the acquisition trap this market keeps falling into
What it does. Ambient documentation plus dictation, embedded in the EHR, with reported extension into nursing workflows during 2026.
What is verifiable.Microsoft's own product page, fetched 23 August 2026, presents Dragon Copilot as the successor to Dragon Medical One and carries a migration section for existing Dragon Medical One customers. It names Epic — including Epic Rover for nurses — and PowerScribe One for radiology, and partnership pages exist for athenahealth and MEDITECH. Ownership is unambiguous and on public record: Nuance Communications is a Microsoft company, and Dragon Copilot is a Microsoft product.
The trap. DAX Copilot is not mentioned on the current product page at all.The independent “Nuance DAX” and “DAX Copilot” product names are retired. Any 2026 ranking still listing DAX Copilot as a distinct product is working from a roster that was not re-checked — and if the roster is stale, so is everything else in that article.
What is not disclosed. The product page carries only generic “trusted compliance, enterprise-grade security” language, with no named SOC 2, HITRUST or ISO certificate on the page we checked. Microsoft-wide compliance programmes exist elsewhere, but transplanting them onto this product without a URL is exactly the sloppiness this methodology refuses. No published price: the partner pricing and licensing guide sits behind partner login, and the reseller figures circulating publicly are not Microsoft prices.
Who it fits.Practices already deep in the Microsoft estate, on Epic, or migrating from Dragon Medical One — where the migration path is the whole argument. Who it does not. Small independent practices, which will find themselves at the thin end of an enterprise-first sales motion.
6. Ambience Healthcare — integrations named, trust page unreachable
What it does. Ambient documentation combined with coding and clinical documentation integrity. Secondary reporting describes an ICD-10 CDI assistant from September 2025 and longitudinal-record reading from February 2026; treat those as trade press, not vendor commitments.
What is verifiable. Its own Series C announcement, dated 29 July 2025, states that the platform integrates directly with Epic, Oracle Cerner, athenahealth and other major EHRs. That is the vendor's own claim about integration existence on the vendor's own page, which is worth citing as such. The same announcement names a $243M Series C co-led by Oak HC/FT and a16z with the OpenAI Startup Fund, Kleiner Perkins, Optum Ventures and others; valuation was not stated in the announcement, and the widely-reported post-money figure is trade press. Corporate status: independent.
What is not disclosed — and this is the finding. ambiencehealthcare.com/security, /trust and /legal all returned 404 on 23 August 2026, and trust.ambiencehealthcare.com returned a page title with no content. The homepage names no certification. For a vendor processing clinical encounters, no reachable compliance page is not a research gap — it is precisely the kind of thing this methodology exists to surface, and it is a question to put in writing before a pilot.
Who it fits. Multi-specialty groups that want documentation and coding support in one product and have the compliance capacity to run a proper vendor questionnaire. Who it does not.Practices that need published compliance evidence up front. We also refuse, as neutral fact, the “97.7 customer satisfaction score” and the claim of being the first ambient solution with third-party validated, CFO-approved ROI — an ROI claim whose validation is not itself published is not a validated ROI claim, and it is the exact species of assertion this article exists to decline.
The Ten, Part Two: Patient Access and Revenue
The other four are the products that are genuinely agentic — on the conversation leg. A patient phone agent holds a conversation, applies rules and reaches an outcome without a human in the loop, which is real autonomy. What happens next, when that outcome has to become a row in your schedule or your billing system, is bounded by the same constraint that bounds the scribes. The correct mental model is autonomous conversation, discretionary write.
7. Hello Patient — fourteen named integrations, the best-documented list in the roster
What it does.An AI assistant branded “Mia” handling calls, texts and chat: round-the-clock scheduling, insurance verification, intake collection, bill pay, no-show reconnection and recall campaigns.
What is verifiable. Its site, fetched 23 August 2026, names fourteen integrations: ModMed, AdvancedMD, NextGen, Zenoti, eClinicalWorks, athenahealth, Avimark, Cornerstone, Clockwise, Veradigm, Ottehr, Pulse, Braze and Customer.io. That is the best-documented integration list in this entire review, and the composition is the interesting part: these are specialty and independent-practice PM systems, not Epic. Avimark and Cornerstone are veterinary systems, which tells you where the platform came from. Homepage badges state HIPAA compliant and SOC 2 Type II certified. Corporate status: independent, not acquired, with a $22.5M Series A reported in September 2025 — small relative to its nearest competitor, which is worth saying out loud.
What is not disclosed.No BAA statement. No HITRUST. No published price — the call to action is “Book a Call.” No independent evaluation. We refuse its “100% answer rates across calls, texts, and chat” claim outright: an absolute that cannot fail is not evidence, and its companion appointment-lift figure is unaudited.
Who it fits.Independent and specialty practices on ModMed, AdvancedMD, NextGen, eClinicalWorks, Veradigm or athenahealth — this is the vendor in the set most obviously built for you rather than for a health system. Who it does not. Epic-based practices, and buyers whose procurement requires vendor scale as a continuity hedge.
8. Adonis — four named ambulatory integrations on the revenue side
What it does.Its own site, fetched 23 August 2026, describes an AI-powered platform that identifies revenue risk early and automates resolution across denials, delays and payer friction — revenue-cycle intelligence plus automated resolution work.
What is verifiable. Named integrations: Epic Systems, athenahealth, NextGen Healthcare and Modernizing Medicine. That set is genuinely ambulatory-practice shaped, and after Hello Patient it is the best match in this roster to an independent practice's actual stack. Corporate status: independent, with a $40M Series C announced 25 March 2026 led by Quadrille Capital with General Catalyst and Bling Capital, and total funding reported above $95M.
What is not disclosed. Badges shown are HIPAA Compliant and AICPA. The AICPA mark usually implies a SOC report, but SOC 2 Type II is not stated and we do not upgrade an unspecified mark. No HITRUST. No BAA statement. No published price. No independent evaluation.
Read the “agentic RCM” label carefully. This is a mixed product: denial prediction is machine learning, resolution work is agent-shaped, and eligibility and status checks are classic automation of the kind practices have bought for fifteen years. All three are useful. Only one of them is new. Asking a vendor which of the three each demo screen represents is a fast way to find out how much of the pitch is engineering and how much is renaming.
Who it fits. Practices on Epic, athenahealth, NextGen or Modernizing Medicine with enough denial volume that a dedicated denial workflow pays for itself. Who it does not. Small practices whose denial volume does not justify a platform, and anyone who needs SOC 2 Type II confirmed on a public page before a pilot.
9. Assort Health — the largest funded, and the least disclosed
What it does.Specialty-specific inbound patient phone handling — scheduling, intake, triage, referrals, refills and payment resolution — across a claimed 23-plus specialties, now positioned as an agentic operating system for the patient journey.
What is verifiable. Its own press page, fetched 23 August 2026, announces a $120M Series C on 24 June 2026 led by Menlo Ventures at a $1.2B valuation, with total funding above $222M. That release names Epic and athenahealth as integrations. Corporate status: independent, and now a unicorn. One small flag worth knowing: a PR Newswire correction notice exists on that Series C, so cite the corrected release rather than the original.
What is not disclosed — and for this product it matters most. No SOC 2, HITRUST or HIPAA certification statement appears on the homepage or the Series C release, and assorthealth.com/security returned 404 on 23 August 2026. This is a vendor that answers patient calls and touches PHI on every one of them. The homepage also claims deep integration across 15-plus platforms while naming none beyond the two above; an unnamed count is not a documented integration. No published price.
The claims we refuse.Assort publishes an unusually large set of performance figures: resolution rates, first-call resolution, referrals scheduled without staff intervention, appointment-volume lift, labour-capacity increase, per-100-provider revenue capture, hold-time reductions and an abandonment-rate reduction. All are vendor-published without methodology or denominator, and the abandonment figure is doubly refused — it is a vendor ROI claim measuring a phone benchmark that has no primary source of its own. None appears in this article as fact.
Who it fits. Larger specialty groups on Epic or athenahealth with call volume that justifies a heavyweight vendor, and buyers who weight funding as a continuity signal. Who it does not.Practices whose compliance review requires published certification before a pilot — you will be asking for everything under NDA.
10. Humata Health — the only prior-auth vendor with a stated small-practice product
What it does.Prior-authorisation automation. It is included here for one specific reason: in July 2026 it introduced a standalone prior-authorisation platform described as built for independent practices, regional health centres and specialty clinics — the only prior-auth vendor in this review that has explicitly built for the small-practice buyer rather than the health system.
What is verifiable. Corporate status: independent, with a $25M round led by Blue Venture Fund and LRVHealth alongside Optum Ventures, .406 Ventures, Highmark Ventures and VentureforGood, per trade reporting. Separately and on public record, Humata was selected by CMS as a technology partner for the WISeR model in Oklahoma.
The conflict a buyer should be told about.A prior-authorisation AI vendor working on the payer and CMS side of the transaction while also selling automation to practices is a structural position worth understanding before you sign. It is not an accusation — it is a matter of public record and it belongs in your diligence questions, alongside how data flows between the two engagements.
What is not disclosed. No named integrations on humatahealth.com as of 23 August 2026. No SOC 2, HITRUST or HIPAA claim on the homepage.No published price. No independent evaluation. This is the thinnest disclosure profile in the ranked ten, and it is ranked tenth for exactly that reason — it earns its place on product fit for the audience, not on transparency.
Who it fits. Specialty practices with heavy prior-authorisation volume that want a vendor whose product is actually scoped to them. Who it does not. Practices whose compliance posture requires published certification, and any practice that has not first read the timing point in the regulatory section below — because the infrastructure that makes prior-auth automation clean is a 2027 payer obligation, not a 2026 practice capability.
Who We Refused to Rank, and Why
Several of the best-known names in healthcare AI appear in “best agents for medical practices” lists and cannot be bought by a medical practice. Every company below is real and confirmed trading as of 23 August 2026. None of them belongs in this ranking, and saying why is more useful to a practice owner than three more table rows would have been.
Group one: they sell to your payer, not to you
- Cohere Health: Independent; a $90M Series C led by Temasek in May 2025, around $200M total, and it acquired ZignaAI in September 2025 — another dead name to know. It sells prior-authorisation technology to health plans. A practice experiences Cohere from the other side of a payer portal and cannot buy it. Its published speed and volume figures are vendor claims about a payer-side product and appear nowhere in this article as fact.
- Anterior: Independent; $40M announced February 2026 from Sequoia, NEA, FPV and Kinnevik, $64M total since 2023, with deployments at a health plan and an integration with HealthEdge. It automates utilisation-management review — which is to say, it automates the other side of your prior authorisation. Its chief executive's estimate of how much prior-auth administrative work language models can absorb has been widely repeated as a finding; it is an executive's estimate, and we treat it as one.
- Infinitus Systems: Independent, not acquired, around $103M raised. Its own site lists more than fifty clients dominated by payers and pharmaceutical companies — UnitedHealthcare, Aetna, Optum, Amgen, Novartis, Pfizer. Provider-facing agents exist, but the centre of gravity is payer and life sciences, and no compliance certification appears on the homepage.
Group two: they require a health system or an EHR licence
- CodaMetrix: The compliance benchmark for this entire market and unbuyable by a practice. Its own site publishes SOC 2 Type II, HITRUST and AWS badges — the only HITRUST mark in this whole review — and it was ranked first in Best in KLAS 2026 for Autonomous Coding. It was spun out of Mass General Brigham in 2019 and serves large health systems exclusively, with no ambulatory-practice offering. Use it as the standard against which you measure the vendor selling to you: if CodaMetrix can publish HITRUST and SOC 2 Type II, asking your vendor why it publishes neither is a fair question.
- Latent Health: Independent, with an $80M Series A co-led by Spark Capital and Transformation Capital around March 2026, and growth from four to more than forty-five health-system partners. Enterprise health systems only. Note one detail: the thirteen-hours-a-week prior-authorisation figure that appears in its press coverage is real and independently sourceable to the AMA survey — so cite the AMA, which measured it, rather than the vendor that repeated it.
- Epic's own agents — Art, Penny and Emmie: Introduced as persona-based agents at HIMSS 2026 alongside a no-code agent-building tool for customers. They require an Epic licence and are structurally unavailable to most independent practices. The customer figures presented on the conference stage — discharge-summary speed, prior-auth submission time, billing-message reduction — are conference anecdotes without published methodology and are not repeated here. Their real value to a practice owner is the opposite of what they were meant to demonstrate: Epic's own agents can write to Epic, and yours cannot on the same terms. That is the constraint in the next section, illustrated by the vendor that owns it.
Group three: real products we considered and did not rank
Eight more products were checked and left out of the ten. Each exclusion has a reason a reader can evaluate, and in several cases the product may be right for you even though it did not survive a disclosure-based ranking.
- Heidi Health: Independent, with a $16.6M Series A follow-on announced 26 June 2026 led by Headline, and a free tier. Left out because disclosure is thin where it counts: its pricing page publishes tier names (Free, Clinician, Teams, Enterprise) but the dollar amounts did not render when we checked, and SOC 2 and ISO 27001 are not stated on that page — only HIPAA and GDPR are referenced. It is also Melbourne-domiciled, which is a real evaluation factor for a US practice because it changes the BAA and discovery posture. Worth a trial, not a table row.
- DeepScribe: Independent and active, around $60M raised, with a 2026 push into oncology including a Flatiron Health partnership and a named cancer-centre deployment. Left out on process grounds: we could not fetch its own trust and pricing pages before publication, and filling those cells from review sites would have broken the rule this article is built on.
- Parakeet Health: Active, with patient-access automation across voice, SMS, fax and email and named deployments including a large dermatology group. Left out for a reason an operator can check independently: a $3M seed in October 2024 and no further round found as of 23 August 2026, in a category where a direct competitor just raised $120M. That is a material continuity risk for a practice signing a multi-year contract. Watch it; do not sign a three-year term yet.
- Notable: Independent, around $123M raised across four rounds, roughly 258 employees, with no new round found in 2026. It markets an AI agent workforce across patient access, revenue cycle and contact centre. Left out because it publishes almost nothing checkable: no named integrations behind its connector hub, no explicit HIPAA claim on the homepage, and a SOC 2 badge whose type is unspecified. It also predates the agent era, and the RPA-and-workflow lineage is visible in the language.
- Tennr: Independent, with a $101M Series C led by IVP in June 2025 and outbound calling added in 2026. Its own description is honest in a useful way — it classifies and routes inbound patient data from any source including fax, portal and internal order — because it tells you that the referral problem is a document problem. Left out because it names no integrations at all on its own site, which for a product whose entire value is moving data between systems is a notable gap, and because its badge reads SOC II without specifying a type.
- healow Genie (eClinicalWorks): Actively marketed in 2026 and structurally interesting: an EHR vendor's own contact-centre agent does not need the certified API, because it is already inside the walls. That is the strongest argument in this whole market for a suite-native agent. Left out because it is suite-locked in practice while marketed as EHR-agnostic — two claims that sit awkwardly together — and because no compliance claim appears on the product page. If you are an eClinicalWorks practice, evaluate it first anyway; the constraint that limits everyone else does not apply inside the suite.
- Commure: The second acquisition trap in this market. Commure acquired Athelas in 2023, then Augmedix — previously NASDAQ-listed as AUGX — in 2024, and Memora Health in December 2024. On commure.com today, Augmedix survives only inside a historical customer quote and Athelas only as a product name. Any 2026 list ranking Augmedix or Memora Health as live independent products is ranking dead names. Left out because it claims 60-plus EHR integrations without naming one, and no certification is stated on the homepage. Breadth assembled by acquisition this quickly carries real integration debt; weigh it yourself.
- Affineon Health: Left out on continuity: the last verified public milestone is a white-label programme from early 2025 and no 2026 company news surfaced. Included in this list anyway because the workflow it targets — agentic triage of the clinician inbox, grouping and trending results, drafting patient messages, handling refills — is the most under-served workflow in this entire category. If you are commissioning a custom build rather than buying a product, the inbox is where we would start.
The Binding Constraint: Certified API Access Is Read-Only
The certified API that every EHR must expose is read-only by regulation, and that single fact decides more about what an AI agent can do in your practice than any model choice ever will. Criterion §170.315(g)(10) of the ONC Health IT Certification Program — Standardized API for patient and population services — requires read capability and excludes write. The wording is identical on ONC's test-method page and in its API Resource Guide, both of which we fetched on 23 August 2026.
“‘Read’ services include those that allow authenticated and authorized third-party applications to view EHI through a secure API. These services specifically exclude ‘write’ capabilities, where authenticated and authorized third-party applications would be able to create or modify EHI through a secure API.”
— ONC/ASTP — Standardized API for patient and population services, §170.315(g)(10) test method
Every EHR certified to the Base EHR definition must expose USCDI data over HL7 FHIR R4 and US Core for reading. No certification criterion obliges any EHR to let a third-party agent write. That is a direct consequence of the regulation rather than an inference about any particular vendor, and it produces one sentence a practice owner can carry into every sales meeting:
What Epic actually publishes — stated carefully
It would be easy and wrong to turn this into “Epic forbids writes.” Epic does not. Its own FHIR developer site, fetched 23 August 2026, publishes Create and Update operations for a bounded, enumerated set of resources — including AllergyIntolerance (Create), DocumentReference (Create and Update), Observation (Create and Update), QuestionnaireResponse (Create), and BodyStructure for radiotherapy volume (Create and Update). Write endpoints exist. What exists is a named list, not general chart write access, and anything beyond that list is simply not documented as available.
Epic also documents the deployment path plainly: you can test through the open sandbox or by working with a particular Epic Community Member, and its Vendor Services programme is an optional paid tier offering the ability to request individualised assistance with an app's data exchange. Epic does not publish that programme's fee. Consultancy blogs circulate a figure; we do not print it, because a number that only exists on third-party blogs is not a price, it is a rumour with a currency symbol.
Three consequences that show up in the products
- 1.Every ambient scribe in this ranking is a copilot, and that is correct design: Abridge, Dragon Copilot, Ambience, Suki, Nabla, Freed, Heidi and DeepScribe all draft; a clinician signs; nothing enters the record unattended. In 2026 the word agent in this market usually means a language model in a workflow that a human still approves. That is not a criticism — given the read-only certified floor it is the only architecture that ships.
- 2.Suki's order staging is the constraint made visible: Staging an order for clinician sign-off rather than placing it is not a product limitation the vendor is apologising for. It is the shape the regulation forces, and a vendor whose demo shows an order appearing in the chart unattended is either running inside the EHR or should be asked to explain, in writing, which agreement permits it.
- 3.Suite-native agents escape the constraint, which is their strongest argument: An EHR vendor's own agent does not need the certified API because it is on the inside. That is why healow Genie inside eClinicalWorks, or Epic's own persona agents inside Epic, can do things a third party structurally cannot. The trade is lock-in, and it is a real trade rather than an obvious mistake. If you are already committed to a suite, evaluate the suite's own agent first.
The architectural implications of building on a read-only floor — where the human commit step sits, how audit trails have to be structured, what a BAA actually has to cover — are worked through in detail in our guide to HIPAA-compliant AI agent architecture, which is the companion piece to this ranking for anyone considering a custom build rather than a purchase.
One forward-looking note, hedged because it deserves to be. ASTP/ONC's HTI-4 final rule adopted prior-authorisation certification criteria, and those criteria are themselves read and query shaped rather than write shaped. A further rule, HTI-5, is a proposedderegulatory action that would cut certification criteria — proposed, not in force. Do not let a vendor describe either as a reason the write constraint is about to disappear.
The Regulatory Map, With Status Precision
Four regulatory facts decide whether an agent you buy in 2026 is legal, useful and future-proof — and in this area the difference between proposed, in force, vacated and enjoined is the difference between good advice and a lawsuit. Every status below was verified on 23 August 2026.
CMS-0057-F binds payers, not practices — and that is the timing lesson
The CMS Interoperability and Prior Authorization Final Rule, published in the Federal Register on 8 February 2024 and effective 8 April 2024, applies to exactly six categories of payer: Medicare Advantage organisations, state Medicaid fee-for-service, state CHIP fee-for-service, Medicaid managed care plans, CHIP managed care entities, and qualified health plan issuers on the federally facilitated exchanges. Stand-alone dental QHPs and SHOP-only QHPs are excluded.
From 1 January 2026, impacted payers owe prior-authorisation decision timeframes of 72 hours expedited and 7 calendar days standard, plus denial-reason and public-reporting duties, with QHP issuers on the exchanges excluded from those timeframes. From 1 January 2027, they must operate four FHIR APIs: Patient Access, Provider Access, Payer-to-Payer and Prior Authorization.
There is no direct obligation on physician practices anywhere in this rule. And that is the single most useful thing this article can tell you about prior-auth agents: a prior-authorisation agent sold to your practice today is automating against payer portals and faxes, because the standardised payer API does not exist yet. The infrastructure that would make these agents clean arrives in January 2027 — on the payer's side, not yours. Buy accordingly, and be suspicious of any contract term longer than the gap.
The HIPAA Security Rule NPRM is still only proposed — the 2003 rule governs
The proposed rule titled “HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information” was published on 6 January 2025 under RIN 0945-AA22, with comments due 7 March 2025. Its action line reads: notice of proposed rulemaking. As of August 2026 no final rule has been issued; roughly 4,745 comments were received, provider groups have asked HHS to withdraw or scale it back, and the Unified Agenda now shows a target for final action in 2027, slipped from an earlier 2026 target.
The 2003 Security Rule governs today.Any vendor selling you readiness for new HIPAA security requirements is selling readiness for a proposal. That may still be sensible — encryption, multi-factor authentication and asset inventories are good practice regardless — but it is not compliance with a rule that exists.
FDA Clinical Decision Support guidance — reissued in January 2026, and silent on AI
FDA's final guidance on Clinical Decision Support Software, docket FDA-2017-D-6569, was issued in January 2026 and re-issued later that month, superseding the 28 September 2022 version. We flag this one as corroborated by law-firm analyses rather than by FDA's own page, which returned 404 to our automated fetches on the date we checked; verify it yourself before relying on the detail.
The reported substance matters for anyone buying documentation software that is quietly growing clinical features. Enforcement discretion now extends to decision support offering a singlerecommendation where clinically appropriate, reversing the 2022 posture that required multiple options. Software drafting diagnostic summaries from a clinician's own findings can stay non-device where the provider remains in the loop and output derives from established sources. Time-critical decision-making restrictions moved from the third criterion to the fourth — relocated, not relaxed.
The silence is the finding.The guidance says nothing about AI-enabled products and nothing about patient-facing decision support. Documentation and administrative agents sit outside the device conversation. A tool that starts recommending a diagnosis or a treatment is walking toward a line FDA has not drawn for AI, and the four statutory criteria — including the requirement that a clinician can independently review the basis for the recommendation — are what decide which side of it you are on.
If your agent dials or texts a patient, the TCPA is already the binding law
FCC Declaratory Ruling 24-17, adopted unanimously and released 8 February 2024, holds that AI-generated voices are artificial voicesunder the Telephone Consumer Protection Act. The ruling expressly refuses any carve out of technologies that purport to provide the equivalent of a live agent. Callers must obtain prior express consent — prior express written consent for marketing calls — identify themselves and disclose the party responsible for the call, and offer opt-out.
The trap is what happened next. Insurance Marketing Coalition v. FCC (11th Cir., 24 January 2025) vacated only Part III.Dof the 2023 Order — the one-to-one consent provision — and the court's own footnote states that the 2012 Order is not at issue. The prior express written consent requirement survives. Anyone who tells you the TCPA got easier for AI callers has inverted the law, and that is advice a practice could act on and get sued for. One narrow consent provision was vacated; the underlying written-consent regime and the artificial-voice classification both stand, and a patient-facing voice agent is squarely inside them.
Colorado: two laws land on 1 January 2027, and both reach patient-facing agents
SB 26-189, Automated Decision-Making Technology, was signed on 14 May 2026 and repeals and reenacts the 2024 Colorado AI Act provisions with new requirements for automated decision-making technology in consequential decisions. It takes effect 1 January 2027, and healthcare is named among the covered domains alongside employment, housing, financial services, insurance, education and government benefits. The Colorado Attorney General filed proposed rules on 11 August 2026, with written comments accepted through 26 October 2026.
HB 26-1263, Conversational Artificial Intelligence Service Operator Requirements, was signed on 29 May 2026 and also takes effect 1 January 2027. It requires operators of publicly available conversational AI to estimate user age by commercially reasonable methods, protect minors, disclose to users that they are interacting with AI, implement suicidal-ideation and self-harm crisis protocols, and report those protocols annually to the Attorney General. The bill does not specifically exempt healthcare or patient-facing chatbots and applies to any AI system accessible to the general public.
For a Colorado practice, those are two concrete build requirements rather than compliance abstractions: an AI-disclosure line at the top of every patient conversation, and a tested crisis-escalation path that reaches a human. Both belong in the vendor contract and in your acceptance testing, not in a policy document nobody reads.
One honest limitation on the regulatory picture: state AI law is moving fast and we verified Colorado specifically. We did not run a state-by-state sweep, and we will not list other states' AI-in-healthcare laws from memory. Check your own state before deploying a patient-facing agent, and treat Colorado as the shape of what is coming rather than as the only jurisdiction that will have something to say.
Finally, a status note on the payer-side pledge you may have heard about. On 23 June 2025 more than sixty health insurers pledged voluntary prior-authorisation reform on a staggered timetable running through 1 January 2027. It is a voluntary pledge, not a rule. In the AMA's own survey, only 33% of physicians believed it would make a meaningful difference. Do not let it into a business case as though it were an obligation.
A Worked Example You Can Check
What follows is an illustrative scenario, not a client outcome. Every number in it comes from a named primary source cited on this page, and you can rebuild the arithmetic yourself in ten minutes. We do not print invented client results. An article that refuses an unsourceable industry statistic and then asserts an unverifiable client outcome has destroyed its own standing, and a worked scenario costs nothing while delivering the same concreteness.
Now the part a vendor will not put on the slide. In that same survey, only 24% of physicians report that their EHR offers electronic prior authorisation for prescription medications, and physicians report the telephone as the most commonly used method for completing prior authorisations for medical services. The standardised payer prior-authorisation API that would let software do this cleanly is a 1 January 2027 obligation on payers under CMS-0057-F — not on you, and not yet.
So an agent you buy for that 12-provider practice in 2026 is working the same portals and the same phone lines your staff work. It may well do it faster, at any hour, without a queue and without turnover. But it is not integrating with a standard; it is automating a phone call and a web form, and those break when a payer redesigns a portal. That changes three things in how you should buy it: contract length (shorter than the 2027 transition), success measurement (submission success rate per payer, tracked daily, not an ROI figure supplied by the vendor), and staffing plan (the exception queue is the job, and somebody has to own it).
There is a second number in that survey that belongs in every evaluation and appears in almost none of them: 60% of physicians are concerned that AI increases, or will increase, prior-authorisation denial rates. The profession's own measured scepticism, from a named body, with a sample and a date. If you are deploying an AI prior-auth agent while your payer deploys an AI utilisation-management reviewer — which is precisely what Anterior and Cohere Health sell — you are not automating a negotiation, you are automating both sides of one. Set expectations accordingly.
What a practice usually already owns before an agent arrives
Most practices already hold part of this stack, and the door an agent needs is often one a different vendor already has a key to. The dental practice website we built for BH Dental Corp in Beverly Hills books appointments through a NexHealth scheduling integration and collects patient information on HIPAA-compliant intake forms, with insurance verification information and patient-portal integration alongside it. The write into the schedule runs through a practice-management integration, not through a certified API — which is exactly the point of the previous section. Before you buy a second vendor to reach your schedule, find out which of your current vendors already can, and what their contract says about a third party doing it through them.
What Breaks First
These systems fail in predictable ways, and the failures are all detectable if you decide in advance what you are watching. The operational mistake practices make is not choosing the wrong vendor — it is deploying without a detection signal and a rollback, so that the first sign of trouble is a complaint rather than a metric.
| Failure mode | Detection signal | Rollback |
|---|---|---|
| Note quality drifts after a silent model update | Rising edit time per note; clinicians quietly reverting to dictation | Pin the vendor's model version if the contract permits it. Otherwise re-baseline a weekly sample of notes and make drift a contractual notice obligation. |
| The write path is withdrawn or re-priced at renewal | Integration-partner notice; failed writes accumulating in a queue | Keep the drafting path independent of the write path so the agent degrades to draft-and-paste rather than stopping. |
| A phone agent mishandles a clinical or crisis disclosure | Transcript sampling; any keyword-triggered transfer that did not complete | Hard-coded escalation to a staffed human line, tested weekly. The crisis protocol is a build requirement, not a configuration setting. |
| Prompt injection through an inbound fax, referral packet or patient message | Anomalous tool calls in the agent audit log; outbound messages with no matching staff action | Remove a leg of the trifecta: the agent that reads untrusted documents does not hold a write credential. |
| A prior-auth agent silently fails against a changed payer portal | Submission success rate tracked per payer, daily | Queue and alert rather than retry. A human works the exception queue; volume in that queue is your health metric. |
| Consent gap on outbound AI calls | Complaints, opt-out requests, demand letters | Consent audit before launch; artificial-voice disclosure at the top of every call; documented opt-out honoured within one business day. |
| Duplicate writes on retry | Duplicate appointments or charges surfacing in daily reconciliation | Idempotency keys derived from business intent and persisted before the call; daily read-back against the system of record. |
Build the detection column into your weekly operations review before go-live. A signal nobody looks at is not a control.
Prompt injection is unsolved, and healthcare is unusually exposed
Any agent that reads untrusted input is exposed to prompt injection, and no vendor has solved it — including the ones that say they have. Healthcare has a particular problem here because the untrusted input is constant and arrives in formats nobody controls: inbound faxes, referral packets, scanned insurance cards, patient portal messages, payer correspondence, uploaded records from an outside practice. Every one of those is content authored by someone outside your organisation that an agent is being asked to read and act on.
The correct framing is blast-radius reduction, not prevention. The exposure requires three things together: the agent holds access to sensitive data, it processes untrusted content, and it can communicate outward or take an action that could exfiltrate or damage. Remove any one leg and the exposure collapses. In a practice that usually means the agent that reads inbound documents does not hold the credential that writes to the chart or sends the message; a second, narrower step with a human in it does. That is less elegant than the architecture diagram in the sales deck, and it is the one that survives both a security incident and a compliance review.
Be sceptical of detection claims specifically. A vendor telling you it catches 95% of injection attempts is quoting a number that would be a failing grade in any other area of application security, and it is a number nobody has independently verified in this market either. Ask instead what the agent is permitted to do if a detection fails, because that answer is auditable and the detection rate is not.
The Human-in-the-Loop Boundary
An agent may draft the note and stage the order; a licensed clinician must sign both before either enters the record. That sentence is the whole boundary in one line, and it is worth writing into your vendor contract rather than assuming it. The table below expands it into the specific actions a practice has to place on one side or the other before go-live.
| The agent may act alone | Needs human review before it lands | Must never act |
|---|---|---|
| Answer an inbound call, identify the caller, and state that it is an AI | Book, move or cancel an appointment that writes to the schedule | Give clinical advice or triage acuity without a licensed clinician |
| Read the chart through the certified FHIR API | File any note, order or charge into the record | Adjudicate or deny a clinical request |
| Draft a clinical note from the encounter | Clinician signature on every note before it enters the chart | Send a patient message about results unreviewed |
| Draft a patient message or assemble a prior-authorisation packet | Clinician or authorised staff review before submission or send | Refill a controlled substance |
| Check eligibility and gather the payer's documentation requirements | Submit the prior authorisation | Alter a diagnosis or the problem list |
| Flag a denial and assemble the appeal evidence | Staff approval before the appeal is filed | Route a self-harm disclosure without the crisis protocol Colorado HB 26-1263 requires |
Derived from §170.315(g)(10) and the 2026 regulatory picture. Every line is defensible from a source cited on this page.
Two lines in that table deserve emphasis because they are the ones practices get wrong. The first is the disclosure line: from 1 January 2027 a Colorado practice must tell a caller they are speaking with AI, and the FCC has already classified an AI voice as an artificial voice for TCPA purposes — so disclosure is not a courtesy, it is a build requirement in at least one state and a defensive posture everywhere. The second is the crisis-protocol line. A patient who discloses self-harm on a phone line answered by software needs a tested path to a human, and Colorado HB 26-1263 will require the protocol and an annual report on it. Build it before you need it and test it on a schedule.
Notice what the left-hand column also implies about value. Answering the call, identifying the caller, reading the chart, gathering documentation requirements and drafting the packet is the overwhelming majority of the labour in most of these workflows. The commit step is seconds. Any vendor that needs to remove the human commit step to make its ROI work has an ROI problem, not a regulatory one.
Cost and Timeline
For most independent practices the right first move is buying a product with a published price and measuring it against your own baseline — not commissioning a build. A custom agent earns its cost when the workflow is genuinely yours, when no product integrates with the system you actually run, or when the write path you need exists only through a partner agreement a product vendor has not signed. Below are our bands for when that is the case.
| Engagement | Range | Timeline | What it includes |
|---|---|---|---|
| Discovery and workflow audit | $9k–$22k | 2–4 weeks | Workflow census, write-path check against each vendor's published documentation, baseline measurement of the workflow you intend to automate, build-versus-buy recommendation |
| Single-workflow agent | $28k–$70k | 4–9 weeks | One workflow end to end, with the human commit step designed in, an audit trail, an evaluation harness and a rollback path |
| Multi-workflow platform with system integration | $70k–$180k | 9–16 weeks | Several workflows, read and write paths where the EHR vendor supports them, integration onboarding support, drift test suite in CI, reporting pack |
| Enterprise / multi-site / regulated build | $180k–$420k+ | 14–24 weeks | Multi-site rollout, per-location isolation, full audit pipeline with attribution that survives a compliance review, step-up authorisation, disaster recovery and restoration testing |
Senior-led delivery runs $150 to $225 per hour, and ongoing retainers run $2,500 to $9,500 per month, covering model and dependency upgrades, integration monitoring as your EHR and PM vendors ship releases, evaluation expansion, incident response and a quarterly technical review. Every engagement carries a 30-day post-launch warranty, full source-code and IP ownership transfers to you, and you receive a written scope with a fixed-price phased proposal within 5 business days of the discovery call. Book that call at calendly.com/frenchydigital/discovery-call or call +1 (424) 272-5601, and bring your EHR name, your PM system, your monthly call volume and your denial rate.
Those bands are ours. They are not an industry benchmark, and you should read them exactly the way this article has asked you to read every vendor number on this page: as one firm's published figures, checkable against a written proposal, rather than as a market rate somebody measured.
On sequencing, the order that works is unglamorous. Measure the baseline before you buy anything — minutes per note, calls abandoned, prior-auth submission success by payer, denial rate — because without it you will be arguing about a vendor's numbers instead of your own. Run one workflow, not four. Keep the human commit step. Give the exception queue an owner by name. And re-check the vendor's compliance and pricing pages at renewal, because in this market they change without notice and the cell that was true in August may not be true in February.
Red Flags When Evaluating a Vendor
Each of these is checkable in a single meeting, and each one has appeared in this market during this review. None of them proves a vendor is bad. All of them are questions whose answers belong in writing before you sign.
- An accuracy, resolution or containment rate presented as a neutral fact: Ask who measured it, against what denominator, and whether you can see the methodology. In this market the honest answer is always that the vendor measured it about itself. That is not disqualifying — publishing it as though a third party had measured it is.
- An ROI figure whose third-party validation is not itself published: One vendor in this roster describes itself as the first ambient solution with third-party validated, CFO-approved ROI, and does not publish the validation. Ask for the report, the validator's name and the scope. If the answer is that it is under NDA, the claim should be under NDA too.
- An unfalsifiable absolute: 100% answer rates. Never places a patient on hold. Every call answered promptly. A claim that cannot fail is marketing language wearing a metric's clothes, and its presence tells you something about how the rest of the deck was written.
- A count of integrations with no names attached: 60-plus EHRs. Deep integration across 15-plus platforms. An unnamed count is not a documented integration. Ask for the list, then ask to speak to a reference on your specific system — because integration with an EHR family is not integration with your instance of it.
- No reachable trust, security or compliance page: Five vendors in this review publish no certification on any page we could reach. That may mean a report exists behind an NDA. It means you ask early, you get the report before the pilot rather than after, and the certification and its scope go in the contract.
- A SOC 2 badge with no type specified: SOC 2 Type I is a point-in-time design assessment; Type II tests operating effectiveness over a period. Three vendors here show a SOC 2 mark without stating the type. Do not upgrade it for them — ask which one, over what period, and by which auditor.
- A write claim with no contract behind it: Ask the direct question: which agreement permits your product to write into our EHR, what is its term, and what does the product do if that access is withdrawn at renewal? A vendor that cannot answer crisply has either not done it before at your EHR or is describing an integration they intend to build.
- A dead product name in the vendor's own competitive deck: If a vendor's comparison slide still lists DAX Copilot, Augmedix, Memora Health or App Orchard as live products, the deck predates several acquisitions. It is a small thing that tells you how recently anyone checked anything.
- Silence about funding history in a category where capital moved: Two vendors we looked at have had no visible new capital since 2024 in a market where a direct competitor raised $120M in June 2026. That is not a reason to avoid them; it is a reason to shorten the contract term, ask about runway and escrow, and avoid making them the single point of failure in patient access.
- A pitch that needs the human out of the loop to work: If removing clinician sign-off is what makes the ROI model close, the model is wrong. The certified API is read-only, the commit step takes seconds, and the labour saving lives in everything before it.
Limitations and What We Could Not Verify
Here is what this article does not know, stated plainly, because a ranking that refuses vendor claims and then hides its own gaps has learned nothing.
- Every compliance and pricing cell is a timestamp, not a permanent fact: All of them were read off vendor pages on 23 August 2026. Vendors change pages without notice. Each cell is re-checkable at the URL given in the sources list, and you should re-check before you sign rather than trusting a table you found in an article.
- Absence of published evidence is not evidence of absence: Five vendors publish no compliance certification on any page we could reach — Ambience, Assort Health, Humata Health, healow Genie and Commure. Several may well hold certificates behind a sales NDA. What we can report is what is published, and we report exactly that.
- SOC 2 type is unstated by three vendors: Tennr, Notable and Adonis display a SOC 2 or AICPA mark without specifying Type I or Type II. This article does not upgrade an unspecified mark to Type II, and neither should your evaluation.
- Funding figures are trade press, not filings: Round sizes and valuations here come from company announcements and trade reporting rather than from regulatory filings. Where a figure came only from trade press we have said so. Treat valuations in particular as directional.
- Three products were dropped for verification reasons, not quality reasons: DeepScribe and Parakeet Health could not be verified from their own trust and pricing pages within this review, and Affineon Health produced no 2026 company news. Any of the three may be right for you. None of them could be ranked on published evidence.
- Two FDA dates rest on secondary corroboration: FDA's own guidance and town-hall pages returned 404 to our automated fetches on the date we checked, so the January 2026 issuance and re-issuance of the Clinical Decision Support guidance are corroborated by law-firm client alerts rather than by FDA's page. The guidance is real; verify the dates yourself before relying on them.
- We did not survey state AI law beyond Colorado: Colorado is the verified example in this article. State AI regulation is moving quickly and we will not list other states' requirements from memory. Check your own state before deploying a patient-facing agent.
- No accuracy, deflection or containment figure appears here as fact: Not because we did not look, but because none is independently verifiable. The precise claim is this: independent randomised trials of ambient scribing exist and we cite one; an independent benchmark of product accuracy does not exist for any product in this ranking.
None of this argues against buying. It argues for buying the way you would buy any other clinical or operational system: measure your baseline first, run one workflow, keep the human commit step, put the compliance answers in the contract rather than the email, and re-check the vendor's published facts at renewal. The practices that get value out of this technology are the ones that found out what they were permitted to do before they found out what the model could do.
And the boundary holds throughout. An agent reads, gathers, drafts, checks and proposes. A licensed person commits anything that enters the chart, changes a clinical decision, or goes to a patient under your name. That is not caution for its own sake — it is the only architecture that survives a prompt injection, a compliance review and a bad week, and it happens to be the one that actually ships.
Want This Checked Against Your Own Practice?
Book a free 60-minute discovery call with Frenchy Digital — a senior-led Black-owned Los Angeles agency. You leave with a workflow census, a write-path check against every vendor you are considering, a baseline measurement plan, and a fixed-price phased proposal within 5 business days. Call +1 (424) 272-5601.
Want This Checked Against Your Own Practice?
Book a free 60-minute discovery call. You leave with a workflow census, a write-path check against each vendor you are considering, and a fixed-price phased proposal within 5 business days.
1517 S Bentley Ave Unit 204, Los Angeles CA 90025
Frequently Asked Questions
Sources & References
- 1ONC/ASTP — Standardized API for patient and population services test method (§170.315(g)(10))↗
- 2ONC Health IT Certification Program — API Resource Guide, HL7 FHIR API criterion §170.315(g)(10)↗
- 3CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F), Federal Register, 8 February 2024↗
- 4HIPAA Security Rule NPRM, Federal Register, 6 January 2025, RIN 0945-AA22 (proposed, not final)↗
- 5Colorado SB 26-189 — Automated Decision-Making Technology (signed 14 May 2026, effective 1 January 2027)↗
- 6Colorado HB 26-1263 — Conversational AI Service Operator Requirements (signed 29 May 2026, effective 1 January 2027)↗
- 7Colorado Attorney General — ADMT Act rulemaking (proposed rules filed 11 August 2026)↗
- 8FCC Declaratory Ruling 24-17 — AI-generated voices are artificial voices under the TCPA (released 8 February 2024)↗
- 9SEC — In the Matter of Presto Automation Inc., Securities Act Release No. 11352 (14 January 2025)↗
- 10American Medical Association — 2025 AMA Prior Authorization Physician Survey (n=1,000, fielded December 2025)↗
- 11Chowdhury A et al. — Comparing ambient scribes: a randomized crossover clinical trial, JAMIA 2026;33(5):990–999↗
- 12Peterson Health Technology Institute — AI-Powered Scribes Alleviate Clinician Burnout; Financial Impact Unclear (25 March 2025)↗
- 13Best in KLAS 2026 — Ambient Speech segment↗
- 14Abridge Trust Center (SOC 2 Type 1 and Type 2, HIPAA, CCPA, TX-RAMP)↗
- 15Nabla — security and compliance (SOC 2 Type II, ISO 27001, customer-selected data region)↗
- 16Freed — pricing page (the only published price card in the roster)↗
- 17Epic on FHIR — developer documentation and published resource operations↗
- 18Epic on FHIR — OAuth 2.0 documentation (sandbox testing, Community Member deployment, Vendor Services)↗
- 19Ambience Healthcare — $243M Series C announcement, 29 July 2025 (names Epic, Oracle Cerner, athenahealth)↗
- 20Assort Health — $120M Series C announcement, 24 June 2026↗
- 21Suki — product site (Epic, Oracle Health, athenahealth, MEDITECH; SOC 2 Type 2)↗
- 22Adonis — product site (Epic, athenahealth, NextGen, Modernizing Medicine)↗
- 23Hello Patient — product site (fourteen named PM and EHR integrations)↗
- 24Microsoft — Dragon Copilot product page (successor to Dragon Medical One)↗
- 25CodaMetrix — SOC 2 Type II and HITRUST badges, health-system-only positioning↗

