athenahealth · Trust Center

Athenahealth Trust Center

Trust center

athenahealth runs a dedicated trust center at trust.athenahealth.com, hosted on Vanta, and separately publishes a plain-language certifications page on its own corporate site. The two are complementary: the corporate page NAMES the certifications and is fully machine-readable; the trust center holds the actual attestation documents and gates them behind a request form.

athenahealth maintains a public trust center documenting HITRUST CSF Certified, PCI DSS, SOC 1 (SSAE 18), EPCS (Electronic Prescriptions for Controlled Substances), DirectTrust HISP accreditation, DirectTrust CA/RA accreditation, Kantara full-service Credentialing Service Provider, EHNAC accreditation, and ONC Certified Health IT, 2015 Edition compliance.

HealthcareEHRElectronic Health RecordsPractice ManagementRevenue Cycle ManagementPatient PortalFHIRCare CoordinationInteroperabilityHL7
Trust center:

Certifications & Compliance

HITRUST CSF CertifiedPCI DSSSOC 1 (SSAE 18)EPCS (Electronic Prescriptions for Controlled Substances)DirectTrust HISP accreditationDirectTrust CA/RA accreditationKantara full-service Credentialing Service ProviderEHNAC accreditationONC Certified Health IT, 2015 Edition

Source

Trust Center

Raw ↑
generated: '2026-08-14'
method: probed
source: https://trust.athenahealth.com/, https://www.athenahealth.com/hitrust,
  https://www.athenahealth.com/onc-certified-health-it
description: >-
  athenahealth runs a dedicated trust center at trust.athenahealth.com, hosted on Vanta, and
  separately publishes a plain-language certifications page on its own corporate site. The two are
  complementary: the corporate page NAMES the certifications and is fully machine-readable; the
  trust center holds the actual attestation documents and gates them behind a request form.
trust_center:
  url: https://trust.athenahealth.com/
  verified: true
  http_status: 200
  content_type: text/html
  fetched: '2026-08-14'
  platform: Vanta
  platform_evidence: >-
    Page is served from a Vanta-built SPA — data-signature-manifest-url points at
    assets.vanta.com, og:image at app.vanta.com/doc, and the document carries a Vanta slug id
    (pvi3eaq3v84f6ph50je5).
  self_description: >-
    "The Trust Center is a self-service portal that allows clients to request and download our
    latest security certifications attestations and audit reports on a by request basis. If you
    require additional assistance in regards to a specific security or risk related question,
    please contact your athenahealth Customer Success Team member or a member of the Trust and
    Assurance team." (verbatim from the page's own meta description)
  documents_gated: true
  gating: request-based — attestations and audit reports are downloadable only on request
  machine_readable_certification_list: false
  machine_readable_note: >-
    The trust center body is a 5,337-byte SPA shell; the certification tiles are rendered
    client-side and no anonymous JSON endpoint returns them. Every /api/* path probed on
    trust.athenahealth.com and app.vanta.com returned the same shell. The certifications recorded
    below therefore come from athenahealth's own corporate certifications page, which IS readable,
    not from the trust center.
certifications:
- name: HITRUST CSF Certified
  body: Health Information Trust Alliance (HITRUST)
  published: true
  source: https://www.athenahealth.com/hitrust
  quote: Common Security Framework (CSF) Certified status from the Health Information Trust
    Alliance (HITRUST)
- name: PCI DSS
  body: PCI Security Standards Council
  published: true
  source: https://www.athenahealth.com/hitrust
  quote: Payment Card Industry - Data Security Standards (PCI-DSS) enforced by the PCI Standards
    Council
- name: SOC 1 (SSAE 18)
  body: AICPA / independent auditor
  published: true
  source: https://www.athenahealth.com/hitrust
  quote: SOC 1 report demonstrating conformance with the Statement on Standards for Attestation
    Engagements No. 18 (SSAE 18)
  note: >-
    athenahealth advertises SOC 1, not SOC 2. SOC 1 is a financial-reporting controls report; it is
    NOT the security/availability report a software buyer usually means by "SOC 2". Recorded
    exactly as published.
- name: EPCS (Electronic Prescriptions for Controlled Substances)
  body: DEA-approved third-party certification authority
  published: true
  source: https://www.athenahealth.com/hitrust
- name: DirectTrust HISP accreditation
  body: DirectTrust
  published: true
  source: https://www.athenahealth.com/hitrust
- name: DirectTrust CA/RA accreditation
  body: DirectTrust
  published: true
  source: https://www.athenahealth.com/hitrust
- name: Kantara full-service Credentialing Service Provider
  body: Kantara Initiative
  published: true
  source: https://www.athenahealth.com/hitrust
- name: EHNAC accreditation
  body: Electronic Healthcare Network Accreditation Commission
  published: true
  source: https://www.athenahealth.com/hitrust
  covers: HIPAA, HITECH/ARRA, ACA, Omnibus Rule and applicable state legislation
- name: ONC Certified Health IT, 2015 Edition
  body: Office of the National Coordinator for Health Information Technology (ASTP/ONC)
  published: true
  source: https://www.athenahealth.com/onc-certified-health-it
  note: >-
    athenahealth additionally publishes an HTI-1 Predictive Decision Support Intervention (PDSI)
    Intervention Risk Management disclosure, aligned to the NIST AI Risk Management Framework and
    the ASTP/ONC FAVES principles (fair, appropriate, valid, effective, safe). That is an AI
    governance disclosure, and it is unusual to see one published at all.
caveat_published_by_provider: >-
  athenahealth's own page carries the qualifier "Certifications may vary depending on product or
  service line" — the certifications above are not uniformly claimed across athenaOne,
  athenaPractice, athenaFlow, athenaIDX and epocrates.
absent:
  soc2: not claimed on any athenahealth public page
  iso27001: not claimed on any athenahealth public page
  fedramp: not claimed on any athenahealth public page
  note: Absence here means athenahealth does not publish the claim, not that no such control exists.