Suki AI AI Vendor Risk Profile
Ambient voice-AI assistant for clinical documentation, coding, and command-driven EHR workflows. Founded 2017 by Punit Soni (ex-Google, Motorola, Flipkart). HIPAA + SOC 2 Type II + BAA available; PHI de-identified to HIPAA Safe Harbor before LLM inference. Used by 400+ healthcare systems including FMOL Health and McLeod Health. $168M raised total, $70M Series D October 2024 (Hedosophia).
Risk overview
Risk score: 43/100
Risk tier: Elevated
Safety rating: 57/100 (higher is better)
Lower risk scores indicate lower assessed risk.
Last verified: May 18, 2026 Fresh
Risk dimensions
| Dimension | Risk score |
|---|---|
| Data Handling | 72/100 |
| IP Exposure | 16/100 |
| Jurisdiction | 13/100 |
| Security | 40/100 |
| Regulatory Compliance | 60/100 |
| Transparency | 70/100 |
| Business Stability | 24/100 |
| Dependency Chain | 43/100 |
| Agent Governance | Not assessed |
Analyst summary
Rating: Recommended
Suki is the AI clinical-documentation specialist with the most mature compliance posture: HIPAA, SOC 2 Type II, BAA available, and an explicit data-flow design where PHI is de-identified to HIPAA Safe Harbor standards before any LLM provider sees it. 400+ healthcare systems on the customer roster (FMOL Health, McLeod Health) and $168M raised including a $70M Series D in October 2024 (Hedosophia-led).
Bottom line: Strong default pick for US health systems adopting AI clinical documentation. Compliance posture is appropriate and the Safe-Harbor de-identification architecture is a genuine design choice rather than a compliance checkbox. Watch for any product expansion that pushes Suki into clinical-decision territory — that crosses the EU AI Act high-risk line.
Strengths
- HIPAA + SOC 2 Type II + BAA available — full healthcare compliance baseline
- Safe Harbor de-identification before LLM inference reduces PHI exposure surface
- Customer encounters explicitly excluded from training
- Public subprocessor list and DPA
- 400+ healthcare system deployments including large multi-thousand-provider customers
- Voice-command integration extends beyond transcription to ordering, charting, navigation
Concerns
- No FedRAMP authorization — not appropriate for VA, IHS, or DoD clinical workloads
- No ISO 27001 — non-US healthcare buyers may need supplementary attestations
- EU AI Act classifies clinical decision support as high-risk; if Suki expands beyond documentation into recommendation, regulatory burden rises
- Operates atop upstream LLM providers — supply-chain risk on those providers carries through
- US-only data residency — not suitable for non-US healthcare deployments
Best for
- US health systems and large group practices replacing or augmenting scribe services
- Healthcare CIOs needing AI voice scribing with BAA and SOC 2 Type II
- Multi-thousand-provider systems wanting EHR-integrated voice workflows
Avoid if
- Your deployment is outside the US
- You require FedRAMP authorization (VA, IHS, DoD)
- Your data classification policy prohibits PHI being processed in US cloud, even with de-identification and BAA
Citations
- Data Handling — Hipaa Baa Available
- Security Compliance — Hipaa Compliant
- Security Compliance — Soc2 Type2
- Vendors — Founded Year
- Vendors — Funding Total Usd
- Data Handling — Third Party Sharing Details