Skip to main content
Athenahealth logo

Athenahealth

Regulatory evidence

Athenahealth, Inc. is a privately held American company that provides cloud-based SaaS healthcare technology and network-enabled services

athenahealth.comHealthcareLast verified 21 Sep 2026

Athenahealth against third-party requirements

For each regulation, how many of the requirements it places on your vendors Athenahealth’s public evidence reaches. Open one for every item with its date and source.

Documents on the trust centre

What the vendor lists, typed; public items can be read now, the rest are available on request.

11 documents listed on Athenahealth’s trust centre

trust.athenahealth.com
  • HITRUST report
    • athenahealth 2024 HITRUST v9.6 Certification Letteron request · seen 21 Sep 2026
    • athenahealth 2025 HITRUST v9.6 Bridge Certification Letteron request · seen 21 Sep 2026
  • PCI DSS attestation of compliance
    • athenahealth PCI Infrastructure PenTest Attestation - Aug 2026on request · seen 21 Sep 2026
    • athenahealth PCI Infrastructure Pentest Attestation- Jan 2026on request · seen 21 Sep 2026
    • athenaOne PCI DSS 4.0.1 Certification Attestation - April 2026on request · seen 21 Sep 2026
  • Penetration test report
    • athenahealth athenaOne Application Suite Pentest Attestation - Sept 2025on request · seen 21 Sep 2026
    • athenahealth Cloud Infrastructure PenTest Attestation - April 2026on request · seen 21 Sep 2026
  • Security policy or overview
    • athenahealth Statement of Security Standards - athenaOne - 2025on request · seen 21 Sep 2026
    • athenahealth Statement of Security Standards - athenaOne Mobile - 2025on request · seen 21 Sep 2026
    • athenahealth Statement of Security Standards - Data View - 2025on request · seen 21 Sep 2026
    • athenahealth Statement of Security Standards - Population Health- 2025on request · seen 21 Sep 2026

What the vendor says

Answers the vendor publishes to questions buyers ask, quoted with the link to where it says so.

  • Use of customer data to train models

    How is ML/LLM training data controlled, validated, separated from production data, and governed by staff training?

    Training data is separated from production data, vetted and validated before use, monitored and audited, and access is limited to staff with a business need. Staff also receive responsible AI training, and adversarial training and poisoning defenses are used where applicable.

    as of 21 Sep 2026Source

  • Use of customer data to train models

    Can customer data or prompts be used to train models?

    In-house models are trained on vetted, reliable data from athenahealth’s environment, with a preference for de-identified PHI/PII.

    as of 21 Sep 2026Source

  • Data retention and deletion

    What happens to customer data over time, including retention, purge, training use, and termination?

    Customer data use is governed by the Master Service Agreement (MSA) and related contracts.

    as of 21 Sep 2026Source

All articles

This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.