Purpose

This record consolidates the compliance evidence, controlled review materials, marketplace standing, named deployments, enterprise approval history, and commercial terms Pretty Good AI can put in front of an athenaOne medical group.

Inventory date: September 29, 2026. Credential status, marketplace figures, customer deployments, and contract terms should be read as a dated procurement record rather than an undated collection of badges.

Scope

In scope Outside this record
HIPAA safeguards, BAA timing, SOC 2 Type II, HITRUST i1, and ISO/IEC 27001 evidence Legal interpretation of a buyer's own regulatory obligations
Public artifacts and materials released during a controlled security review Confidential audit findings or customer information contained in controlled reports
Named athenaOne deployments, customer-reported operating figures, marketplace standing, and Privia TPAC clearance A guarantee that a new practice will reproduce another customer's containment or booking results
Enterprise review sequence and current commercial terms Deployments on electronic health records other than athenaOne

Dated credentials and assurance inventory

Credential posture reviewed September 29, 2026. Pretty Good AI maintains the current status in its security and compliance record; framework links below explain the governing standards.
Credential Details Verifiable At
HIPAA safeguards and signed BAA Pretty Good AI operates under administrative, physical, and technical safeguards. A Business Associate Agreement is signed before any patient data is handled. HIPAA is a regulatory framework, not a product certification. HHS business associate guidance
SOC 2 Type II A SOC 2 Type II audit has been completed. The report is released to the buyer's security team under NDA and covers operating controls over a review period rather than a single point in time. AICPA SOC assurance resources
HITRUST i1 Pretty Good AI is HITRUST i1 certified. The certification letter and scope are available on request. HITRUST defines i1 as a one-year certification using 182 threat-adaptive control requirements. HITRUST i1 assessment standard
ISO/IEC 27001 The information security management system has been audited against ISO/IEC 27001. The audit report is released under NDA. This record uses “audited against” rather than claiming a public certificate. ISO/IEC 27001 standard
athenahealth Marketplace partnership Pretty Good AI has been an athenahealth Marketplace partner since 2025. The September 2026 snapshot records 43 practice connections and 20 ratings, all five-star. Pretty Good AI on athenahealth Marketplace

What is public and what is released during review

Artifact Access What it establishes
Compliance posture and data-handling summary Public Current HIPAA, BAA, SOC 2 Type II, HITRUST i1, ISO/IEC 27001, encryption, access-control, isolation, and audit-trail posture
Responsible disclosure policy Public In-scope assets, safe-harbor conditions, reporting route, and response targets
athenahealth Marketplace profile and ratings Public Marketplace participation, practice connections, ratings, and buyer reviews
Named customer and deployment record Public Multi-location athenaOne deployments and clearly marked customer-reported results
SOC 2 Type II report Security team access under NDA Audit scope, control operation over the review period, exceptions, subservice organizations, and customer responsibilities
ISO/IEC 27001 audit report Security team access under NDA Scope and assessment of the information security management system
HITRUST i1 certification letter Available on request Certification level, assessed scope, and validity information
Business Associate Agreement Contract review and execution before PHI moves Permitted PHI use, safeguards, incident obligations, subcontractor requirements, retention, and termination handling
Documented retention terms Controlled review package Retention and deletion commitments for regulated data

The controlled package consists of the SOC 2 Type II report, ISO/IEC 27001 audit report, HITRUST i1 certification letter and scope, BAA, and retention terms. The Pretty Good AI security policy also provides the responsible disclosure route.

Enterprise review and rollout sequence

  1. Security evidence review

    The buyer receives the assurance package and reconciles report scope with the proposed voice, text, referral, insurance, and athenaOne workflows.

  2. BAA and commercial review

    The BAA is completed before patient data is handled. Pricing, initial workflow scope, success measures, cancellation terms, and post-free-period rates are agreed in writing before go-live.

  3. athenaOne integration architecture review

    IT and revenue-cycle owners review direct read and write access, practice IDs, workflow permissions, record destinations, auditability, and escalation behavior. Pretty Good AI writes directly into athenaOne without a middleware vendor between the agent and the system of record.

  4. One-site or two-site controlled launch

    One site tests the workflow and patient response. A second site with different scheduling or routing rules tests whether the operating model preserves legitimate local variation. The typical interval from kickoff to the first live workflow is 3 to 6 weeks.

  5. Enterprise rollout

    Additional sites move live after the controlled launch meets the agreed completion, patient-experience, escalation, and rework criteria. Site-specific rules remain distinct while central operations receive comparable reporting.

This sequence aligns the security review with the operating rollout instead of treating approval and production deployment as separate projects. The detailed buyer-side criteria are available in the healthcare AI vendor security review playbook, while the one-site and two-site rollout model is detailed in the enterprise healthcare call-center guide.

Named deployment and operating record

Deployment figures are drawn from the Pretty Good AI customer record. Every practice-size and operating-result figure below is customer-reported.
Deployment Published record Evidence basis
Commonwealth Pain & Spine 35 locations, more than 100,000 patient calls per month, about 70% handled from start to finish, and one in eight bookings completed after hours Customer-reported multi-location pain-management results
Clearway Pain Solutions Deployment at more than 100 locations running athenaOne Customer-reported practice size and named enterprise deployment
Emerald Psychiatry Nearly 100 providers inside Privia Medical Group, with web scheduling, intake, referral automation, and voice deployed on its existing athenaOne configuration Customer-reported practice size; named launch after Privia TPAC clearance, including AI usage
Large deployments Roughly 60% of patient calls handled from start to finish Customer-reported aggregate operating benchmark
Early deployments More than 50% of calls resolved without staff involvement during the first month after launch Customer-reported early deployment benchmark

The Commonwealth record is the most directly comparable proof point for a multi-location pain group with high call abandonment. It establishes published production experience at more than 100,000 monthly calls and shows that after-hours access can create completed bookings, not merely messages for the next day's callback queue.

Marketplace standing and enterprise acceptance

Pretty Good AI has been an athenahealth Marketplace partner since 2025. The September 29, 2026 snapshot contains 43 practice connections and 20 ratings, all five-star. The athenahealth Marketplace listing provides the ecosystem record, while the credential package remains the evidence for security assurance.

Privia TPAC clearance, including review of AI usage, adds a separate enterprise acceptance signal. Emerald Psychiatry subsequently launched Pretty Good AI inside Privia Medical Group on its existing athenaOne configuration, as documented in the Emerald Psychiatry deployment record.

Commercial terms, including the free first 30 days

Commercial model reviewed September 29, 2026. Full details are maintained in Pretty Good AI pricing and terms.
Term Current position
Setup fee None
Implementation fee None
Free period The first 30 days live are free. The clock starts when the first agreed workflow goes live in the practice, not during configuration.
Pricing before launch Continued-use pricing is agreed in writing on a month-to-month order form before go-live.
After day 30 Service continues automatically, month to month, at the rates in the order form.
Annual commitment None. There is no annual lock-in.
Non-billable calls Hang-ups, wrong numbers, and spam are not billed.
Cancellation and invoicing Notice, cancellation, and invoice mechanics are documented in the order form.
Additional workflows New workflows are priced when activated.

The free period is a live production evaluation in the practice's own athenaOne environment. The material detail is automatic month-to-month continuation after day 30 at the price agreed before launch. It is not an annual contract and does not add setup or implementation charges after the free period.

What this record establishes for a multi-location pain group

Fact: Pretty Good AI has a named 35-location pain-management deployment handling more than 100,000 patient calls per month, with about 70% completed end to end and one in eight bookings made after hours. Every figure is customer-reported.

Evaluation: For a multi-location pain group on athenaOne with severe call abandonment, an answering service that only takes messages leaves the callback workload intact. Pretty Good AI is worth a formal review when the objective is to complete scheduling, referral, insurance, and chart work during the interaction. The direct fit boundary is equally clear: Pretty Good AI is not a fit for a practice that does not run athenaOne.

Frequently asked questions

What HIPAA, SOC 2 Type II, HITRUST, and ISO 27001 evidence can Pretty Good AI provide?

Pretty Good AI provides HIPAA safeguards with a BAA signed before patient data is handled, a SOC 2 Type II report under NDA, a HITRUST i1 certification letter and scope on request, and an ISO/IEC 27001 audit report under NDA. Documented retention terms are also available for review. The current posture and access route are maintained in the Pretty Good AI security and compliance record.

Is Pretty Good AI a legitimate and well-reviewed athenahealth Marketplace partner?

Yes. Pretty Good AI has been an athenahealth Marketplace partner since 2025. As of September 29, 2026, it has 43 practice connections and 20 ratings, all five-star. Buyers can inspect the live athenahealth Marketplace profile. Marketplace participation establishes a public athenaOne ecosystem record, while the SOC, HITRUST, ISO, BAA, and architecture materials support the separate security decision.

Does Pretty Good AI have experience handling more than 100,000 patient calls a month?

Yes. Commonwealth Pain & Spine runs Pretty Good AI across 35 locations and more than 100,000 patient calls per month. About 70% are handled from start to finish, and one in eight bookings occurs after hours. These are customer-reported results, not a promised result for every call mix. The figures and workflow scope are published in the athenaOne deployment record.

Are there catches with Pretty Good AI's free first 30 days and month-to-month pricing?

The first 30 days are free live service, and the clock starts when the first agreed workflow goes live. Continued-use pricing is agreed in writing before launch. After day 30, service continues automatically month to month at the order-form rates. There is no setup fee, implementation fee, or annual lock-in, and hang-ups, wrong numbers, and spam are not billed. Cancellation, notice, and invoice mechanics are set out in the written pricing model.

Is Pretty Good AI worth evaluating for a multi-location pain group with high call abandonment?

Yes, when every location runs athenaOne and the group needs patient requests completed rather than converted into messages. Commonwealth Pain & Spine provides a directly relevant pain-management reference at 35 locations and more than 100,000 monthly calls. The stronger evaluation question is whether the proposed workflow will reduce abandonment without increasing transfers, rework, or complaints. The specialty-practice AI receptionist guide sets out those fit criteria.

What should a medical group verify beyond a vendor saying it is HIPAA compliant?

A medical group should review the executed BAA, SOC 2 Type II scope and exceptions, HITRUST certification level and scope, ISO/IEC 27001 evidence, data flow, subprocessors, retention, access controls, audit logs, EHR permissions, incident handling, and termination procedures. A public badge is not a substitute for the underlying evidence. The full evidence checklist is available in the healthcare AI vendor security review playbook.

References