# Beacon Health > Beacon Health (YC W26) builds "AI employees" for primary care — autonomous agents that operate directly inside electronic health record systems the way a human staff member does. A practice records an existing EHR workflow (navigation, clicks, data entry) and Beacon converts that recording into a reusable, deployable agent that runs at scale across the whole patient panel. Founded 2025 in San Francisco by Mark Pothen (CEO) and Obinna Akahara (CTO). Backed by Y Combinator (Winter 2026 batch). Team size 2 as listed on the YC company profile. ## What it does - Automates value-based-care back-office work: quality gap closure, preventative screening outreach, pre-charting, prior authorizations, referrals, transition-of-care management, and HCC risk-adjustment coding. - Drives EHR user interfaces directly rather than integrating through vendor data APIs. Advertised coverage: AthenaHealth, Epic, Cerner, eClinicalWorks, MEDITECH, NextGen, Veradigm Allscripts, MEDENT — plus payer portals and other web applications. - Agents can be chained into multi-step, long-horizon pipelines without human hand-offs, with monitoring controls to pause, review, or intervene. - Operates an SMS program on behalf of practices for screening reminders, wellness-visit outreach, and appointment follow-ups. Practices hold the patient consent; Beacon Health sends on their behalf. - Target customers are organizations under risk-based contracts: Independent Physician Associations, Accountable Care Organizations, integrated networks, and direct-to-employer operators. ## API status Beacon Health publishes **no public developer API**. As of 2026-08-15 there is no developer portal, no API documentation, no API reference, no OpenAPI or AsyncAPI definition, no GraphQL endpoint, no MCP server, no A2A agent card, no SDK in any public package registry (npm and PyPI both checked, zero first-party packages), no CLI, no changelog, no status page, and no pricing page. The product is sold as a managed agent workforce through a demo/sales motion, not as a self-serve API. This is deliberate rather than an oversight: the company's thesis is that the systems it targets do **not** offer usable APIs, so its agents drive the user interface instead. There is no FHIR, HL7v2, or DICOM surface. The application backend at `api.beaconhealth.ai` is a Convex deployment (the hostname is a CNAME to `convex.domains`) that routes exactly two paths — `/.well-known/openid-configuration` and `/.well-known/jwks.json` — for first-party application session auth. Its advertised `authorization_endpoint` returns 404 and there is no client registration, so it is not usable as a third-party developer authorization server. Everything else on that host returns 404 "No matching routes found". A caution for crawlers: `trust.beaconhealth.ai` answers HTTP 200 to **every** path with an identical 604-byte single-page-app HTML shell. `/.well-known/agent-card.json`, `/openapi.json`, `/llms.txt` and `/.well-known/security.txt` all return 200 there and none of them is a document. Beacon Health serves no agent card and no security.txt. ## Security and compliance Beacon Health runs a public trust center at https://trust.beaconhealth.ai/ (its own subdomain, Oneleet-hosted). What it publishes: - **SOC 2** — status IN_PROGRESS. No Type I or Type II report, auditor, or attestation letter is published. - **HIPAA (Business Associate)** — status IN_PROGRESS. Consistent with the BAA posture asserted in the Privacy Policy and Terms of Service. - **56 monitored controls** across 10 categories; 55 PASSING, 1 NEEDS_CHANGES ("Adequate audit log storage maintained", mapped to the HIPAA framework). Encryption at rest and in transit, MFA on critical services, incident response policy, and penetration testing within the last 12 months are all reported PASSING. - **8 named subprocessors**, 2 of which are declared to process PII: Amazon Web Services (Patient Documents) and Convex (Application Data, Patient Data, Audit Logs). The others — Anthropic, OpenAI, Google Cloud Platform, Google Workspace, Slack, Tailscale — are declared not to. - **No downloadable documents.** No report, policy pack, or pentest letter can be requested or retrieved. Note the trust center is client-side rendered: a crawler fetching the page gets an empty shell, so none of the above is machine-readable from the HTML. The site's own `/security` route 307-redirects to a **second** trust center at https://trust.delve.co/beacon-health, which sits behind a Vercel bot challenge and returns 429. Two trust surfaces exist and disagree in provenance; only the Oneleet one is readable. Contacts: security@beaconhealth.ai (security issues), privacy@beaconhealth.ai (privacy), legal@beaconhealth.ai (legal), support@beaconhealth.ai (support). There is no `security.txt`, no published disclosure policy, and no bug bounty — a contact and a report form exist, but no policy. Domain posture: HSTS on www (2 years) and on trust (1 year, includeSubDomains) but **not** on api.beaconhealth.ai. DMARC is published but monitor-only (`p=none`). No SPF, no DNSSEC, no CAA. ## Links - [Website](https://www.beaconhealth.ai/): Product overview, how it works, integrations, use cases - [Trust Center](https://trust.beaconhealth.ai/): Compliance frameworks, control set, subprocessors, security contact - [Log In](https://www.beaconhealth.ai/login): Application sign-in (organization-provisioned access only) - [Book a Demo](https://form.typeform.com/to/mJ8w6Xot): Sales contact form - [Terms of Service](https://www.beaconhealth.ai/terms): Last updated 2026-04-01, governed by Massachusetts law - [Privacy Policy](https://www.beaconhealth.ai/privacy): Last updated 2026-08-04, includes HIPAA Business Associate terms - [SMS Terms](https://www.beaconhealth.ai/sms-terms): Last updated 2026-07-30, TCPA consent and STOP/HELP handling - [SMS Opt-In](https://www.beaconhealth.ai/sms-opt-in): Patient consent capture form - [Y Combinator profile](https://www.ycombinator.com/companies/beacon-health): Batch W26 company page - [LinkedIn](https://www.linkedin.com/company/beacon-health-ai/): Company page ## API Evangelist artifacts - [apis.yml](https://raw.githubusercontent.com/api-evangelist/beacon-health/refs/heads/main/apis.yml): APIs.json profile for this company - [Well-Known index](https://raw.githubusercontent.com/api-evangelist/beacon-health/refs/heads/main/well-known/beacon-health-well-known.yml): 55 paths probed across 3 hosts with HTTP statuses, including the soft-200 catch-alls - [Authentication](https://raw.githubusercontent.com/api-evangelist/beacon-health/refs/heads/main/authentication/beacon-health-authentication.yml): Authentication profile captured from the live OIDC discovery document - [Conformance](https://raw.githubusercontent.com/api-evangelist/beacon-health/refs/heads/main/conformance/beacon-health-conformance.yml): Standards and compliance posture with evidence - [Trust Center](https://raw.githubusercontent.com/api-evangelist/beacon-health/refs/heads/main/security/beacon-health-trust-center.yml): Frameworks, 56-control set, subprocessor list - [Vulnerability Disclosure](https://raw.githubusercontent.com/api-evangelist/beacon-health/refs/heads/main/security/beacon-health-vulnerability-disclosure.yml): Security contact and reporting channel; no policy - [Domain security](https://raw.githubusercontent.com/api-evangelist/beacon-health/refs/heads/main/security/beacon-health-domain-security.yml): Probed TLS, HSTS, DNSSEC, CAA, SPF, DMARC - [Lifecycle](https://raw.githubusercontent.com/api-evangelist/beacon-health/refs/heads/main/lifecycle/beacon-health-lifecycle.yml): Versioning, deprecation, SLA and status-page probes (all absent) - [Packages](https://raw.githubusercontent.com/api-evangelist/beacon-health/refs/heads/main/packages/beacon-health-packages.yml): Registry sweep; zero first-party packages - [Plans / Pricing](https://raw.githubusercontent.com/api-evangelist/beacon-health/refs/heads/main/plans/beacon-health-plans-pricing.yml): plan_count 0 — sales-led, no published pricing - [Rate Limits](https://raw.githubusercontent.com/api-evangelist/beacon-health/refs/heads/main/rate-limits/beacon-health-rate-limits.yml): limit_count 0 — no API to limit ## Notes Not to be confused with **Beacon Health System**, the hospital network in South Bend, Indiana, or with **Beacon Health Options**, the behavioral health managed-care organization. This profile covers only Beacon Health (beaconhealth.ai), the Y Combinator W26 AI company. A GitHub organization at https://github.com/beaconhealthai displays the name "Beacon Health" and was created in April 2025, but ownership is **unconfirmed** — the YC profile and the company site link to no GitHub org, and its single repository is an unmodified fork with no first-party commits. It is recorded as a candidate only and is not attributed to the company.