- What they do
- Assessor
- Which standards
- On the public register for CSA STAR, FedRAMP, StateRAMP, HITRUST.
- Standards
- Pricing
- Not published
Framework Information Security & Privacy
HITRUST
HITRUST is a private assurance program built on the HITRUST CSF, a control framework that harmonizes HIPAA, NIST, ISO, PCI and many other sources. It is used mostly by healthcare organizations and their vendors, but the framework is industry neutral.
There are three validated assessment types: e1 (Essentials, about 44 requirements, one-year certification), i1 (Implemented, 182 threat-adaptive requirements, one-year certification) and r2 (Risk-based, tailored scope, two-year certification with an interim assessment at twelve months).
Assessments are recorded in the MyCSF platform, validated by an Authorized External Assessor, and then reviewed by HITRUST's own quality assurance team before a certification report is issued.
In writing, an assessed entity needs the policy and procedure documents behind every in-scope requirement, because HITRUST scores policy, procedure, implementation and (for r2) measured and managed maturity levels separately.
That means a documented scope and system inventory, a policy set covering the CSF domains, procedures that match practice, and implementation evidence sampled by the assessor. CSF v11 is current; e1 and i1 assessments must be created on v11.7.0 or later since March 31, 2026 (verify the current version advisory).
Who has to comply
Voluntary and contractual. Health plans, hospital systems and payers often require HITRUST certification from vendors handling PHI; some cloud and SaaS providers pursue it for market access. No statute requires it.
What the assessor asks to see
Scope definition and system inventory in MyCSF; policies and procedures for each in-scope requirement statement; implementation evidence per control (configurations, screenshots, access reviews, logs, training records); prior assessment results and corrective action plans; inheritance letters from cloud providers; management representation letter; for r2, measurement and management evidence for higher maturity scores.
Where the requirement sits: HITRUST CSF PRISMA maturity: Policy (~15%), Procedure (~20%), Implemented (~40%), Measured (~10%), Managed (~15%) - verify weights against current i1/r2 scoring
Assessment types
e1: foundational, fixed requirement set, one-year certification, suited to lower-risk entities. i1: leading-practice set of 182 requirements updated for current threats, one-year certification. r2: risk-tailored scope with maturity scoring across policy, procedure, implemented, measured and managed levels, two-year certification with an interim review.
Work done for e1 or i1 can be carried forward into the larger assessments.
What AllyMatter does here
Evidence for the Policy and Procedure maturity levels of HITRUST.
AllyMatter publishes this site.
Assessors
Who assesses HITRUST
A HITRUST Authorized External Assessor organization (approved and trained by HITRUST) performs validated assessments; HITRUST itself performs quality assurance and issues the certification. Self-assessments are available for readiness only. Accredited by HITRUST authorizes and periodically requalifies External Assessor organizations; no national accreditation body is involved.
Public register of assessors: https://hitrustalliance.net/find-an-external-assessor
- What they do
- Assessor
- Which standards
- On the public register for CSA STAR, FedRAMP, StateRAMP, HITRUST.
- Standards
- Pricing
- Not published
- What they do
- Assessor
- Which standards
- On the public register for FedRAMP, StateRAMP, HITRUST.
- Standards
- Pricing
- Not published
- What they do
- Assessor
- Which standards
- On the public register for HITRUST.
- Standards
- Pricing
- Not published
- What they do
- Assessor
- Which standards
- On the public register for HITRUST.
- Standards
- Pricing
- Not published
Consultants
Who helps with HITRUST
Yes. HITRUST Readiness Licensees and many Authorized External Assessor firms sell readiness services (scoping, gap assessment, policy writing, MyCSF setup, remediation). The readiness firm and the validating assessor can be the same organization in HITRUST's model, subject to independence requirements, or different firms.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
- What they do
- Enterprise multi-framework
- Who they help
- Tevora is an enterprise multi-framework based in Irvine, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Software
Tools for HITRUST
Tools that name this framework in their own material.
Related reading
- HITRUST CSF: e1, i1, r2 - what's the difference?Compares the three assessment types by effort, requirement count and validity period, so you can tell which one a customer is asking for.Cloud Security Alliance
- Everything you need to know about HITRUST v11An authorized external assessor explains the threat-adaptive control model, inheritance between assessments, and how validation and QA actually run.Coalfire
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for HITRUST
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of HITRUST in AllyMatter
Approve the policies HITRUST asks for, keep every version, and record a named acknowledgment from each person who has to read them.