Medical Imaging AI

Nanox.AI Vendor Risk Profile

Nanox.AI is a subsidiary of Nano-X Imaging that provides a suite of FDA-cleared AI-based algorithms designed to analyze routine medical CT scans for incidental findings, including cardiac (coronary artery calcium) and musculoskeletal (vertebral compression fractures) conditions.

Verification pendingApprovedModerate RiskYesHIPAA: Yes

Risk Score

/100

AI Trust

/100

Compliance Overview

HIPAA Compatible

Yes

BAA Available

Yes

Hosting Model

—

Healthcare Focused

Yes

Approval Status

Approved

Risk Level

Moderate Risk

Last Reviewed

2026-08-18

Last Verified

Verification pending

Review Frequency

Quarterly

Verification reflects VNDRIQ's latest automated source check. Editorial review is a separate human assessment.

AI & Data Policies

AI Training Policy

Nanox states that AI models are developed using proprietary datasets; customer data usage for model training is subject to specific BAA terms.

Data Retention Policy

Configurable based on customer requirements and regulatory compliance.

Support Access Risk

—

Approved Use Cases

Clinical decision support for the identification of incidental findings in routine CT scans, specifically for coronary artery calcium (HealthCCSng) and vertebral compression fractures (HealthOST).

Restricted Use Cases

Use is restricted to the specific indications cleared by the FDA; AI output is intended to support, not replace, clinical judgment.

Deployment & Data Residency

Deployment Type

Cloud-based / SaaS

Model Type

—

Deployment Environment

—

Hosting Regions

—

Available Regions

—

Data Residency

—

Customer Data Residency Options

—

Cross-Border Data Transfer

—

Data Residency Controls

—

Security & Compliance

SOC 2

Yes

ISO 27001

Yes

ISO 42001

—

HIPAA Documentation

—

Encryption

AES-256 at rest and TLS 1.2+ in transit

SSO

Yes

MFA

Yes

Private Networking

—

Private Endpoints

—

Subprocessors

—

Incident Notifications

—

Security Whitepaper

—

Executive Summary

Primary Use Cases

Nanox.AI is a subsidiary of Nano-X Imaging that provides a suite of FDA-cleared AI-based algorithms designed to analyze routine medical CT scans for incidental findingsincluding cardiac (coronary artery calcium) and musculoskeletal (vertebral compression fractures) conditions.

Key Procurement Considerations

Product MaturityCustomer Support InformationCompliance DocumentationVendor-documented restrictions — verify applicability

Vendor Trust Score

Limited Trust Data

9

/100

HIPAA Readiness40
BAA Availability0*
Security Controls0*
Governance Documentation0*
Transparency0*
Product Maturity0*
Healthcare Focus33
Integration Readiness19
Customer Support Information0*
Compliance Documentation0*

Informational framework based on publicly available and registry data. Not a certification or guarantee. Asterisks indicate categories with limited registry data.

Security & Compliance Dashboard

Standardized view of available registry security information. Not Verified indicates the registry has no documented data.

HIPAA StatusNot Verified
BAA AvailabilityNot Verified
SOC 2Not Verified
ISO 27001Not Verified
HITRUSTNot Verified
Encryption at RestNot Verified
Encryption in TransitNot Verified
Single Sign-On (SSO)Not Verified
Multi-Factor AuthNot Verified
Audit LoggingNot Verified
Role-Based AccessNot Verified
Data ResidencyNot Verified
Public Security DocsNot Verified
Incident ResponseNot Verified

AI Governance Maturity

Foundational4/100

Minimal governance documentation; early-stage controls.

Foundational
Developing
Established
Advanced
Leading

Assessed Indicators

Governance Documentation
Human Oversight
AI Policies
Compliance Transparency
Risk Management
Security Controls
Operational Governance

Procurement Risk Considerations

Informational considerations for procurement evaluation, not definitive ratings.

Governance Maturity

Foundational

Elevated Consideration

Security Readiness

0/100 security controls

Elevated Consideration

Compliance Readiness

0/100 compliance documentation

Elevated Consideration

Integration Complexity

API not verified — verify integration path

Moderate Consideration

Operational Complexity

Not Verified

Vendor Transparency

0/100 transparency

Elevated Consideration

Healthcare Experience

Healthcare focus not verified

Moderate Consideration

Documentation Completeness

0/100 governance docs

Elevated Consideration

Vendor Lifecycle & Change History

Available registry milestones. Detailed change tracking expands as the registry matures.

Profile Updated

2026-08-26

Last Registry Review

2026-08-18

Registry Added

2026-08-18

Regulated Use Assessment

Healthcare

Healthcare Focused

Yes

HIPAA Compatibility

Yes

BAA Availability

Yes

Financial Services

SOC 2

Yes

ISO 27001

Yes

VNDRIQ does not classify vendors as HIPAA Compliant, SEC Compliant, or FINRA Approved unless official evidence exists. Vendor suitability depends on each organization's governance requirements, contractual obligations, deployment model, risk tolerance, and applicable regulations.

Review Notes

Nanox maintains a portfolio of FDA-cleared AI solutions. Specific clearances include HealthCCSng for coronary artery calcium and HealthOST for vertebral compression fractures.

Quick Facts

Category

Medical Imaging AI

Headquarters

Petach Tikva, Israel

Year Founded

2018

Deployment Type

Cloud-based / SaaS

Website

nanox.vision/
Pending Verification

Risk Score

/100

AI Trust Score

/100

Last Reviewed

2026-08-18

Last Verified

Verification pending

Request Vendor Evaluation

Get a structured risk assessment and governance recommendation for Nanox.AI.

Vendor Governance

Approval Tier

Approved

BAA Verification

Not Started

PHI Exposure

Medium

AI Risk Level

Medium

Last Review

2026-08-18

Next Review Due

2026-11-18

Verification Status

Pending Review

Next Review Date

2026-11-18

Review Frequency

Quarterly

Vendor Completeness Score

100/100

Complete

Website Present

+20

Category Assigned

+15

Approval Status Present

+15

BAA Status Present

+15

PHI Exposure Classified

+10

Risk Level Present

+10

Review Date Present

+10

Verification Notes Present

+5

Trust & Transparency

Last Reviewed Date

2026-08-18

Review Frequency

Quarterly

Vendor Verification Process

Every vendor is reviewed against public documentation, trust centers, and contract evidence before classification.

Editorial Independence Statement

VNDRIQ classifications are independent of vendor relationships. Ratings reflect available evidence and governance risk only.

Registry Update Policy

The registry is reviewed on a monthly cycle. All updates are editor-reviewed before publication; no automated public data changes.

Editorial Methodology

Vendors are evaluated across compliance, security, AI governance, and enterprise readiness. Each review follows a standardized 12-point checklist covering website, HIPAA, BAA, security, compliance, AI capabilities, deployment, pricing, product changes, ownership, integrations, and documentation.

Trust Signals

Editorial Review StatusPending Review
Last Reviewed2026-08-18
Last Updated2026-08-26
Verification DateNot Verified
Registry ConfidenceNot Verified
Governance MaturityFoundational
Trust Score9/100
Compliance SnapshotNot Verified
Security SnapshotNot Verified

Vendor Benchmarking

Comparison against registry averages where supported. Benchmarks are informational and based on registry data.

Governance Maturity4 ↑ 0 vs avg 4
Security Readiness0 ↑ 0 vs avg 10
Documentation Completeness0 ↑ 0 vs avg 0
Integration Readiness19 ↑ 9 vs avg 10
Healthcare Specialization33 ↑ 18 vs avg 15
Compliance Transparency0 ↑ 0 vs avg 7
Overall Trust Score9 ↑ 0 vs avg 9
This vendorRegistry average

Ask VNDRIQ About This Vendor

Ask questions about Nanox.AI using registry data.

Ask VNDRIQ About Healthcare AI Vendors

Explore healthcare AI vendors, compare capabilities, identify documentation gaps, and understand procurement and governance considerations using information from the VNDRIQ registry.

Suggested prompts

VNDRIQ provides vendor intelligence and educational procurement support. Responses do not constitute legal, medical, cybersecurity, compliance, or procurement advice. Vendor information may be incomplete, vendor-reported, under review, or subject to change.

Do not enter patient information, PHI, passwords, or sensitive data.

VNDRIQ vendor ratings are for operational risk screening and governance support. Final approval should include legal, compliance, security, and contract review before any PHI or regulated data is shared. Risk classifications are based on available public information and internal review at time of last verification.