Clinical systems · QHIN & clinical data network
Health Gorilla
Health Gorilla is a health data network and designated QHIN that lets EHR vendors and care organizations request patient records from national exchange networks through FHIR APIs.
Strong fit
- EHR vendors that need TEFCA access through a designated QHIN
- Value-based care organizations that want outside records pulled from national exchange networks
- California organizations that take part in the state Data Exchange Framework
Weak fit
- Buyers that cannot take on vendor risk while lawsuits over patient-record requests are open
- Small practices that only need fax and Direct messaging
- Teams that want analytics and care-gap tools built on top of the records
Bottom line
Health Gorilla is a health data network company in Coral Gables, Florida. EHR vendors, value-based care groups, and digital health companies use it to request patient records from national exchange networks and to connect to TEFCA, the federal framework for nationwide record exchange. It was among the first networks designated as a Qualified Health Information Network under TEFCA. Lawsuits over how some customers requested records are still open, which holds the score down.
Score breakdown
Weights: Outcomes 35% · Product 30% · Implementation 20% · Pricing clarity 15%.
Health Gorilla was co-founded in 2014 in Silicon Valley by Steve Yaskin and is now based in Coral Gables, Florida. Bob Watson, a longtime health IT chief executive, became executive chairperson and CEO in November 2024. Its network connects customers to national exchange networks, labs, and California's Data Exchange Framework, and delivers records as FHIR data through its APIs. In April 2025 the company said it connected more than 220 million patients and 147,000 care sites.
In January 2026 Epic and several health systems sued Health Gorilla and other data companies in federal court in California. The complaint alleges that some record requests were labeled as treatment while the records went to law firms. In August 2026 a federal panel combined nine patient class actions involving the company into one case in the Southern District of Florida.
Compare Particle Health when a digital health company wants a similar national records API, Kno2 when the job also includes fax, Direct messaging, and post-acute connectivity, and Zus Health when the team wants the records kept as one shared patient record.
Competitor landscape
| Vendor | Overall | Ease of implementation |
|---|---|---|
| Particle Health | 7.4 | 7.0 |
| Kno2 | 7.3 | 7.3 |
| Zus Health | 7.2 | 7.0 |
| Metriport | 7.2 | 7.2 |
| Redox | 7.1 | 6.8 |
| Health Gorilla | 6.9 | 6.8 |
| 1upHealth | 6.7 | 6.5 |
Pricing
| Item | Detail |
|---|---|
| Model | Enterprise contracts for network access and APIs, usually tied to the volume of record requests and the networks used. |
| What usually drives cost | Query volume, which networks and data types are included, and whether the customer connects as a TEFCA participant. |
| What to ask in diligence | Price per patient query or per month at your volume, onboarding fees, and what the contract says about permitted purposes for record requests. |
| Published pricing | No public list price. |
Prerequisites for purchase
| Need | Why it matters |
|---|---|
| What you need to get Health Gorilla to function | |
| Permitted purpose for every query documented | Record requests must match the purpose claimed. |
| Patient identity matching approach | Bad matches return the wrong records. |
| Legal review of network terms | TEFCA and Carequality rules bind the customer. |
| Engineering team for FHIR APIs | Records arrive as data, not a finished screen. |
| Plan for storing outside records | Someone has to decide what enters the chart. |
| What will maximize your value | |
| Query before visits, not in bulk | Targeted requests return more useful records. |
| Track match and return rates | Shows whether the network is paying off. |
| Review the open litigation with counsel | Contract terms may change as cases move. |
| Deal-breakers | |
| Cannot document permitted purpose | |
| No engineers for the API | |
| Cannot accept open litigation risk | |
Value creation time frame
| # | Stage | Typical range |
|---|---|---|
| 1 | Contract and legal review | 4-8 weeks |
| 2 | API integration and testing | 6-12 weeks |
| 3 | Production queries | 2-4 weeks |
Methodology
| Weight | Factor | What it measures |
|---|---|---|
| 35% | Customer outcomes | Whether buyers get measurable operational or clinical-workflow results after go-live |
| 30% | Product | Capability depth, reliability, and fit for the job the category actually buys |
| 20% | Implementation | How hard it is to stand up, integrate, train, and stabilize |
| 15% | Pricing clarity | Whether a buyer can model total cost without a mystery quote |
| Label | Meaning |
|---|---|
| Highly recommend | Strong outcomes and product with manageable caveats |
| Recommend | Solid fit for the right buyer; know the tradeoffs |
| Conditional | Only with a specific use case or heavy caveats |
| Not recommended | Avoid for most buyers in this category |
Read our full methodology for how we weight scores and assign recommend labels.