HomeFrameworksInformation Security & PrivacyHITRUST

Framework  Information Security & Privacy

HITRUST

HITRUST is a private assurance program built on the HITRUST CSF, a control framework that harmonizes HIPAA, NIST, ISO, PCI and many other sources. It is used mostly by healthcare organizations and their vendors, but the framework is industry neutral.

There are three validated assessment types: e1 (Essentials, about 44 requirements, one-year certification), i1 (Implemented, 182 threat-adaptive requirements, one-year certification) and r2 (Risk-based, tailored scope, two-year certification with an interim assessment at twelve months).

Assessments are recorded in the MyCSF platform, validated by an Authorized External Assessor, and then reviewed by HITRUST's own quality assurance team before a certification report is issued.

In writing, an assessed entity needs the policy and procedure documents behind every in-scope requirement, because HITRUST scores policy, procedure, implementation and (for r2) measured and managed maturity levels separately.

That means a documented scope and system inventory, a policy set covering the CSF domains, procedures that match practice, and implementation evidence sampled by the assessor. CSF v11 is current; e1 and i1 assessments must be created on v11.7.0 or later since March 31, 2026 (verify the current version advisory).

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedPolicy set v3by name, on record
Policy Level Fully Metwith AllyMatter
Certify the Modern WayThe policy layer under every HITRUST control, acknowledged
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every name on record
Who read which version, and when
03
Hand the assessor the trail
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

Voluntary and contractual. Health plans, hospital systems and payers often require HITRUST certification from vendors handling PHI; some cloud and SaaS providers pursue it for market access. No statute requires it.

What the assessor asks to see

Scope definition and system inventory in MyCSF; policies and procedures for each in-scope requirement statement; implementation evidence per control (configurations, screenshots, access reviews, logs, training records); prior assessment results and corrective action plans; inheritance letters from cloud providers; management representation letter; for r2, measurement and management evidence for higher maturity scores.

Where the requirement sits: HITRUST CSF PRISMA maturity: Policy (~15%), Procedure (~20%), Implemented (~40%), Measured (~10%), Managed (~15%) - verify weights against current i1/r2 scoring

Assessment types

e1: foundational, fixed requirement set, one-year certification, suited to lower-risk entities. i1: leading-practice set of 182 requirements updated for current threats, one-year certification. r2: risk-tailored scope with maturity scoring across policy, procedure, implemented, measured and managed levels, two-year certification with an interim review.

Work done for e1 or i1 can be carried forward into the larger assessments.

What AllyMatter does here

Evidence for the Policy and Procedure maturity levels of HITRUST.

AllyMatter publishes this site.

Assessors

Who assesses HITRUST

A HITRUST Authorized External Assessor organization (approved and trained by HITRUST) performs validated assessments; HITRUST itself performs quality assurance and issues the certification. Self-assessments are available for readiness only. Accredited by HITRUST authorizes and periodically requalifies External Assessor organizations; no national accreditation body is involved.

Public register of assessors: https://hitrustalliance.net/find-an-external-assessor

A-LIGNOn the public register
What they do
Assessor
Which standards
On the public register for CSA STAR, FedRAMP, StateRAMP, HITRUST.
Standards
CSA STARFedRAMPStateRAMPHITRUST
Pricing
Not published
CoalfireOn the public register
What they do
Assessor
Which standards
On the public register for CSA STAR, FedRAMP, StateRAMP, HITRUST.
Standards
CSA STARFedRAMPStateRAMPHITRUST
Pricing
Not published
Prescient SecurityOn the public register
What they do
Assessor
Which standards
On the public register for FedRAMP, StateRAMP, HITRUST.
Standards
FedRAMPStateRAMPHITRUST
Pricing
Not published
SchellmanOn the public register
What they do
Assessor
Which standards
On the public register for HITRUST.
Standards
HITRUST
Pricing
Not published
BARR Advisory, P.A.On the public register
What they do
Assessor
Which standards
On the public register for HITRUST.
Standards
HITRUST
Pricing
Not published

Consultants

Who helps with HITRUST

Yes. HITRUST Readiness Licensees and many Authorized External Assessor firms sell readiness services (scoping, gap assessment, policy writing, MyCSF setup, remediation). The readiness firm and the validating assessor can be the same organization in HITRUST's model, subject to independence requirements, or different firms.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

TevoraIrvine, CA, USANot yet verified
What they do
Enterprise multi-framework
Who they help
Tevora is an enterprise multi-framework based in Irvine, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Software

Tools for HITRUST

Tools that name this framework in their own material.

Related reading

  1. HITRUST CSF: e1, i1, r2 - what's the difference?Compares the three assessment types by effort, requirement count and validity period, so you can tell which one a customer is asking for.Cloud Security Alliance
  2. Everything you need to know about HITRUST v11An authorized external assessor explains the threat-adaptive control model, inheritance between assessments, and how validation and QA actually run.Coalfire

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for HITRUST

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of HITRUST in AllyMatter

Approve the policies HITRUST asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.