Skip to main content

Is Pretty Good AI HIPAA compliant?

Yes. HIPAA safeguards with a BAA in place before any patient data is touched. SOC 2 Type II and ISO 27001 audit reports are available upon request. HITRUST i1 certified. Below is the full posture, what we deliberately do not do, and the questions worth asking every vendor on your list.

The short answer

HIPAA is not a certification, so what a practice can verify is the safeguards, the signed BAA, and the audits behind them. Pretty Good AI operates under HIPAA safeguards, signs a BAA before touching patient data, and has completed SOC 2 Type II and ISO/IEC 27001 audits with reports available on request. HITRUST i1 certified. Patient data is encrypted in transit and at rest and written straight into your athenaOne record, with no middleware vendor holding a copy along the way.

Where we stand on each framework

HIPAA

Safeguards and a signed BAA

HIPAA is a set of safeguards and a contract, not a certificate. We operate under HIPAA administrative, physical and technical safeguards, and a Business Associate Agreement is signed before any patient data is touched.

SOC 2 Type II

Type II audited, report available on request

Type II covers how the controls actually operated over a period, not how they looked on one day. The audit report goes to your security team on request, under NDA. Role-based access controls, audit trails and per-customer isolation are part of that scope.

ISO/IEC 27001

Audited, report available on request

The information security management system has been audited against ISO/IEC 27001. As with SOC 2, the report is available to your team on request rather than published on a web page.

HITRUST i1

Certified

HITRUST i1 certified. HITRUST i1 is the bar healthcare providers are typically held to, validating implemented security controls on a one-year cycle. The certification letter, including its scope section, is available to your security team on request.

GDPR

Supported privacy position

Data handling is aligned to GDPR principles. Most United States practices on athenaOne do not need it, but the position is documented if your organization does.

How patient data is handled

  • Encryption in transit and at rest

    Patient communications and data transfers are encrypted in transit and at rest, including the voice and secure two-way text channels.

  • Per-customer isolation

    Your practice data is isolated to your practice. It is not pooled with another customer for convenience.

  • Role-based access and audit trails

    Access is scoped by role, and activity is logged. Near real-time athenaOne synchronization is written with full auditability, so the record shows what happened and when.

  • Documented retention

    Data retention is documented rather than assumed, and PHI handling is covered by the BAA you sign.

  • One integration, not a chain of middlemen

    We hold production read and write access to 680+ athenaOne APIs and talk to athenaOne directly. There is no middleware vendor sitting between your record and us, which means one BAA and one place to audit instead of a chain of them.

What Pretty Good AI does not do

  • We do not make clinical decisions. Symptom screening routes by urgency to the on-call path your practice defines, and clinical judgment stays with your care team.
  • We collect patient payments on the Pretty Good AI web scheduler, and we send secure payment links through your practice's existing payment portal wherever that is the rail your billing team wants. Balances, documented payment plans and follow-up run to your billing team's rules.
  • We do not connect to other electronic health records. Pretty Good AI is built for athenaOne practices only, so the security review covers one integration rather than a general-purpose connector.

Six questions to ask any AI vendor before you sign

Ask us these too. A vendor that cannot answer them quickly is telling you something.

01 Will you sign a BAA, and when?
The answer should be yes, and before any patient data moves. If a BAA arrives after go-live, patient data moved without a contract covering it.
02 Are you SOC 2 Type II, or Type I?
Type I is a point in time. Type II is how the controls held up over a period. Ask which one, and ask to read the report.
03 Which HITRUST certification, and at what scope?
A marketplace badge does not tell you which assessment, which systems, or when. Ask for the certification letter and read the scope section. HITRUST i1 certified.
04 Who else touches the data on the way to our EHR?
Every middleware hop is another company holding PHI, another BAA, and another breach surface you inherit.
05 Is our data isolated from your other customers?
Ask it plainly. Pooled data is a design decision, not an accident, and you want to know which decision was made.
06 What happens to our data if we leave?
Retention and deletion should be documented before you sign, not negotiated while you are trying to exit.

Frequently asked questions

Is Pretty Good AI HIPAA compliant?
Yes. HIPAA is not a certification, so the accurate answer is about safeguards and contract: Pretty Good AI operates under HIPAA administrative, physical and technical safeguards, encrypts patient communications and data transfers in transit and at rest, and signs a Business Associate Agreement before any patient data is touched.
Does Pretty Good AI sign a BAA?
Yes. A Business Associate Agreement is signed before any patient data is touched, not after go-live. The BAA covers PHI handling and documented data retention.
Is Pretty Good AI SOC 2 certified?
Pretty Good AI has completed a SOC 2 Type II audit, and the report is available to your security team upon request under NDA. Type II covers how controls operated over a period of time, not a single day.
Is Pretty Good AI HITRUST certified?
HITRUST i1 certified. HITRUST i1 is the bar healthcare providers are typically held to, validating implemented security controls on a one-year cycle. The certification letter is available on request, alongside HIPAA safeguards with a BAA and the SOC 2 Type II and ISO/IEC 27001 audit reports.
Is Pretty Good AI ISO 27001 certified?
The information security management system has been audited against ISO/IEC 27001, and the audit report is available upon request under NDA.
Where does patient data go when the AI answers a call?
It goes to your athenaOne record. Pretty Good AI holds production read and write access to athenaOne APIs and writes back directly, with near real-time synchronization and full auditability. There is no middleware vendor in between holding a copy, which is why the security review covers one integration and one BAA.
Is our practice data kept separate from other customers?
Yes. Pretty Good AI uses per-customer isolation, along with role-based access controls and comprehensive audit trails, all within the scope of the SOC 2 Type II audit.
Does Pretty Good AI make clinical decisions?
No. Clinical decisions remain with your care team. Symptom screening routes by urgency to the on-call path your practice defines. Pretty Good AI automates the front-office work around a clinical workflow, not the clinical judgment inside it.
What security documentation can we get before signing?
The SOC 2 Type II report and the ISO/IEC 27001 audit report are available upon request, normally under NDA, along with the BAA and documented data retention terms. Email contact@prettygoodai.com and ask for the security package.

Ask for the security package

SOC 2 Type II report, ISO/IEC 27001 audit report, the BAA and our retention terms. Send them to your security reviewer before the demo if that is the order that suits your process.

Compliance posture last reviewed 2026-09-17. Reporting a vulnerability? See our responsible disclosure policy.