Skip to main content

Press Release

Pretty Good AI attains HITRUST i1 certification for its athenaOne-native patient communication platform

The Pretty Good AI platform has attained HITRUST i1 certification, validated by an authorized external assessor against 182 requirement statements and reviewed by HITRUST before issue.

i1 HITRUST Certified badge

SAN FRANCISCO, CA, October 8, 2026 — Pretty Good AI today announced that its platform has attained HITRUST Implemented, 1-year (i1) certification. The certification covers the Pretty Good AI platform residing at Amazon Web Services, and was issued after a HITRUST Authorized External Assessor tested 182 requirement statements across 19 domains and HITRUST completed its own quality assurance review of that work.

Pretty Good AI builds AI front-office automation natively on athenaOne, handling patient phone calls, secure two-way texting, web scheduling and self-check-in, forms and fax for healthcare organizations. That work runs on protected health information, which makes the security review a gate on every new deployment rather than an afterthought.

What the certification changes for a practice’s security review

Healthcare vendor-risk teams routinely ask for HITRUST because it answers most of what a custom security questionnaire asks, and it answers it with evidence an outside assessor tested rather than a vendor’s own description of itself. HITRUST curates the i1 requirement set for high coverage of the HIPAA Security Rule, NIST SP 800-171, the FTC GLBA Safeguards Rule and other sources, so one certification speaks to questions framed against several of them.

The i1 requirement set is threat-adaptive: HITRUST updates it using cyber threat intelligence and includes controls selected for threats being actively targeted now, such as ransomware and phishing. Each requirement is scored from 0 to 100 on implementation, and every domain has to average at least 83 to certify.

For a practice evaluating Pretty Good AI, the practical effect is a shorter review with a defined scope to read. The certification letter, including its scope section, is available to a security team on request.

“

“Every practice we talk to has to decide whether to let a vendor near its patient data, and they are right to make that hard. HITRUST i1 means an authorized assessor tested 182 controls against our actual environment and HITRUST checked the assessor's work before anything was issued. That is a different conversation than handing someone a questionnaire we filled out ourselves. It takes weeks out of a security review, and it holds us to a control set that gets updated as the threats change rather than one we wrote once.”

Kevin Henrikson

Co-founder at Pretty Good AI

Where i1 sits, and what it does not claim

HITRUST offers three assessment tiers: e1 for foundational hygiene, i1 for a curated best-practice requirement set refreshed against current threats, and r2 for a tailored risk-based assessment on a two-year cycle. i1 is the tier healthcare providers are typically held to.

The certification is valid for one year and is renewed annually. It holds only while there is no security breach of the assessed environment and no significant change to the controls behind it. It covers the platform, and it does not make a practice compliant on its own.

The certification sits alongside the rest of Pretty Good AI’s posture: Pretty Good AI signs a HIPAA Business Associate Agreement (BAA) before any patient data is touched, and SOC 2 Type II and ISO/IEC 27001 audit reports are available on request. The full picture, including what i1 requires that a HIPAA program or a SOC 2 report leaves to the vendor, is on the HITRUST i1 certification page.

Practices on athenaOne that want the certification letter or the audit reports can reach Pretty Good AI at contact@prettygoodai.com.


About Pretty Good AI

The AI operations platform built exclusively for athenaOne practices. From referral and intake to billing. It unlocks provider hours and new patient growth. From booking, payments & support to integrations with other tools, so organizations operate smarter, faster, with fewer errors. Our athenaOne-native platform combines flexible logic, strong oversight, and secure data handling to deliver reliable automation that scales. Learn more at prettygoodai.com


Media Contact

Jacky Kirkland
press@prettygoodai.com