Skip to main content

Is Pretty Good AI HITRUST certified?

Yes. The Pretty Good AI platform has attained HITRUST i1 certification. HITRUST i1 is the bar healthcare providers are typically held to. Below is what the certification covers, what it saves your security reviewer, and what i1 requires beyond a HIPAA program or a SOC 2 report.

The short answer

The Pretty Good AI platform holds a HITRUST Implemented, 1-year (i1) certification, issued on August 12, 2026 and valid through August 12, 2027. The assessment ran against HITRUST CSF v11.8.0 and covered the platform residing at Amazon Web Services. A HITRUST Authorized External Assessor tested 182 requirement statements across 19 domains, and HITRUST reviewed that work before issuing the certification. The letter is available to your security team on request.

Read the certification announcement.

The certification at a glance

Certification
HITRUST Implemented, 1-year (i1)
Framework
HITRUST CSF v11.8.0
Issued
August 12, 2026
Valid through
August 12, 2027
Platform in scope
Pretty Good AI, residing at Amazon Web Services
Facility in scope
AWS data center, Oregon, United States
Requirements assessed
182 requirement statements across 19 domains
Validated by
A HITRUST Authorized External Assessor, with quality assurance review by HITRUST

What HITRUST i1 enables for your practice

  • A shorter security review

    Your reviewer starts from a certification HITRUST issued after an outside assessor tested the evidence, instead of a questionnaire answered in our own words. Healthcare vendor-risk teams commonly ask for HITRUST because it answers most of what a custom questionnaire asks.

  • One assessment that maps to the rules you already track

    HITRUST curates the i1 requirements for high coverage of the HIPAA Security Rule, NIST SP 800-171, the FTC GLBA Safeguards Rule, the NAIC Data Security Law and other best-practice sources. One certification answers questions framed against several of them.

  • Evidence that was tested, not described

    The assessor inspected access lists, logs, configurations, sample items, policies, procedures and diagrams, and interviewed the people running the controls. HITRUST then reviewed that work before it issued anything.

  • Controls that move with current threats

    HITRUST updates the i1 requirement set using cyber threat intelligence, and includes controls selected specifically for threats being actively targeted today, such as ransomware and phishing.

  • An answer that stays current

    The certification is valid for one year, through August 12, 2027, and is renewed annually. It holds only while there is no security breach of the assessed environment and no significant change to the controls behind it.

How HITRUST i1 compares with HIPAA and SOC 2

HIPAA tells you what to protect. SOC 2 tells you an auditor checked the controls a vendor chose. HITRUST i1 tells you which controls were required, how each one scored, and that HITRUST itself checked the result.

QuestionHIPAASOC 2 Type IIHITRUST i1
Who defines the controlsThe Security Rule sets standards, and many implementation specifications are addressable, so each organization decides how to meet them.The vendor writes its own controls against the AICPA Trust Services Criteria and chooses which criteria beyond security are in scope.HITRUST prescribes the requirement statements: 182 of them in i1, across 19 domains.
Who checks themNo outside check is required. HHS OCR enforces it, typically after a complaint or a breach.A CPA firm tests whether the controls the vendor described operated over a period.A HITRUST Authorized External Assessor tests every requirement against evidence.
How results are scoredNot scored.An auditor's opinion, with any exceptions noted. There is no numeric pass mark.Each requirement is scored from 0 to 100 on implementation, and every domain must average at least 83.
Central reviewNone.None beyond the audit firm.HITRUST runs its own quality assurance review of the assessment before issuing.
What you receiveA vendor statement and a signed BAA.An audit report, shared under NDA.A certification letter issued by HITRUST, with a defined scope, valid for one year.

Controls i1 requires that HIPAA and SOC 2 leave to the vendor

HIPAA and SOC 2 let a vendor decide how specific its controls are. i1 writes the specifics down. A sample of what the 182 requirement statements ask for, each one scored by the assessor against evidence from our environment:

Access control

  • Multi-factor authentication for privileged accounts, and for remote access to standard accounts
  • Administrators use a separate standard account for everyday work
  • Every user ID, including service accounts, is assigned to a named individual
  • Periodic review of all accounts and privileges, including shared and system accounts

Endpoints and network

  • Default-deny host-based firewalls on workstations and servers
  • Deny-all, permit-by-exception traffic rules at managed network interfaces
  • Intrusion detection or prevention at the network perimeter
  • Blocking access to known malicious addresses and domains

Email and phishing

  • SPF records published, with receiver-side verification enabled
  • Email filtering that blocks suspicious messages and unnecessary file types
  • Dedicated phishing awareness training as part of onboarding

Configuration and vulnerabilities

  • Vulnerability scanning, with each finding risk-assessed and remediated
  • Annual technical security configuration checks
  • Separation of production from development and test environments
  • A maintained list of authorized software, and application allow-listing

Logging and monitoring

  • Audit records carry a unique user ID, the data subject, the function performed and the time
  • At least two synchronized time sources, so log timestamps agree
  • Protected access to audit logs and audit tools, and a defined log review process

Resilience and incident response

  • Offline or immutable backups, stored at a distance from the primary site and tested
  • A business continuity plan with an owner, reviewed at least annually
  • An incident handling capability that is tested and exercised regularly

Data protection and third parties

  • Covered information encrypted wherever it is stored, including laptops and portable devices
  • Production patient data kept out of test environments
  • Documented security requirements for every supplier with access to information
  • Annual review of service-level agreements against monitoring records

Where i1 sits among HITRUST assessments

e1 (Essentials, 1-year)
Foundational cybersecurity hygiene. A starting point.
i1 (Implemented, 1-year)
A curated set of 182 best-practice requirements, refreshed for current threats. This is the certification Pretty Good AI holds, and the bar healthcare providers are typically held to.
r2 (Risk-based, 2-year)
A tailored assessment whose requirement set is built from the organization's own risk factors and regulatory profile.

The certification covers our platform. It does not make your practice compliant on its own, and it sits alongside the rest of our posture: HIPAA safeguards with a signed BAA, and SOC 2 Type II and ISO/IEC 27001 audit reports. The full picture is on HIPAA compliance and security.

Frequently asked questions

Is Pretty Good AI HITRUST certified?
Yes. The Pretty Good AI platform has attained HITRUST i1 certification. HITRUST certifies systems rather than companies, which is why the certification names the platform. The HITRUST Implemented, 1-year (i1) certification was issued on August 12, 2026 and is valid through August 12, 2027. It covers the Pretty Good AI platform residing at Amazon Web Services in Oregon, United States, assessed against HITRUST CSF v11.8.0.
What is HITRUST i1?
HITRUST i1 is a validated assessment and certification against a curated set of 182 HITRUST CSF requirements across 19 domains. An Authorized External Assessor tests each requirement, HITRUST reviews the assessment, and the certification is valid for one year. It is the bar healthcare providers are typically held to.
How is HITRUST i1 different from SOC 2 Type II?
In SOC 2 the vendor writes its own controls and a CPA firm gives an opinion on whether they operated. In HITRUST i1 the requirement statements are prescribed by HITRUST, each one is scored, every domain must average at least 83, and HITRUST reviews the assessor's work before it issues a certification. Pretty Good AI has both, and the SOC 2 Type II audit report is available on request.
How is HITRUST different from HIPAA compliance?
HIPAA is a law. Its Security Rule sets safeguards but leaves much of the how to each organization, and no outside party certifies it. HITRUST i1 prescribes specific controls with high coverage of the HIPAA Security Rule and has an independent assessor test them. Pretty Good AI also signs a Business Associate Agreement before any patient data is touched.
What does the HITRUST certification cover?
The Pretty Good AI platform, the multi-tenant conversational AI application suite that handles patient calls, texts and related workflows, residing at Amazon Web Services in Oregon. The scope section of the certification letter lists the platform, the facility and the outsourced services considered in the assessment.
Can we see the certification letter?
Yes. The HITRUST i1 certification letter, including its scope section, is available to your security team on request. Email contact@prettygoodai.com and ask for the HITRUST letter.
Does HITRUST replace our vendor security questionnaire?
Often it answers most of it. Many healthcare security teams accept a HITRUST certification in place of large parts of a custom questionnaire. Send us whatever is left and we will answer it directly.
How often is the HITRUST certification renewed?
Every year. The i1 certification is valid for one year from the date of the letter, and remains valid only while there is no breach of the assessed environment and no significant change to the controls it covers.

Ask for the HITRUST letter

The HITRUST i1 certification letter with its scope section, alongside the SOC 2 Type II report, the ISO/IEC 27001 audit report and the BAA. Send them to your security reviewer before the demo if that is the order that suits your process.

Certification details last reviewed 2026-10-08. Reporting a vulnerability? See our responsible disclosure policy.