By Compyl Research · Last reviewed September 2026
HITRUST is a certifiable security framework built by the HITRUST Alliance. Its control catalog, the HITRUST CSF, harmonizes requirements from HIPAA, NIST, ISO 27001, PCI DSS and dozens of other authoritative sources into one set of prescriptive, scored requirement statements. Unlike HIPAA — a law with no certification — HITRUST produces a report from an approved external assessor, which is why healthcare payers, health systems and their vendors increasingly ask for it by name.
Key takeaways
- HITRUST is prescriptive where other frameworks are not. HIPAA says “implement reasonable and appropriate safeguards”. HITRUST tells you what the safeguard is, at what level of rigor, and scores how well you did it.
- “HITRUST levels” means three different things. Assessment types (e1, i1, r2), control maturity levels (the five PRISMA levels used in scoring), and domain scores. Most confusion about HITRUST traces back to conflating them.
- There are three assessment types, not three steps. e1, i1 and r2 are separate products with different scope, rigor and validity periods. You pick the one that matches the assurance your customers are asking for.
- It is scored, and the threshold is per domain. Every assessment domain has to reach the required rating. A single weak domain produces a validated report rather than a certification, even when the overall average looks healthy.
- The framework moves. HITRUST releases CSF updates on a regular cadence and closes off older versions for new assessments — CSF v11.8.0 became the required version for new e1 and i1 assessments on 7 May 2026. Scoping against a superseded version is a common and expensive mistake.
What does HITRUST stand for?
HITRUST originally stood for the Health Information Trust Alliance. The organization now uses HITRUST as a standalone name, because the framework long ago stopped being healthcare-only: it is used by SaaS vendors, financial services firms, and any organization whose customers demand certified assurance rather than a self-attestation.
Two things are worth separating. HITRUST is the organization — the HITRUST Alliance — which maintains the framework, accredits external assessors, runs the MyCSF platform and performs quality assurance on every submitted assessment. The HITRUST CSF is the framework itself: the control catalog and the scoring methodology.
What is the HITRUST CSF?
The CSF is a harmonized control framework. Rather than inventing new requirements, it maps and reconciles existing authoritative sources — HIPAA Security and Privacy Rules, the NIST Cybersecurity Framework and SP 800-53, ISO/IEC 27001 and 27002, PCI DSS, state privacy laws and many others — into a single set of requirement statements, so that one assessment can evidence compliance against several regimes at once.
Three design choices distinguish it from the frameworks it draws on:
- It is tailored by scope factors. The requirement set you are assessed against is generated from your organization’s characteriztics — size, systems, data volumes, regulatory exposure, geography. Two companies running the same assessment type can face materially different requirement sets.
- It is scored rather than pass/fail. Each requirement is evaluated on maturity, not merely presence.
- It is externally quality-assured. A validated assessment is performed by an approved external assessor and then reviewed by HITRUST itself before a report is issued. That second review is why the report carries weight with third parties.
What do “HITRUST levels” actually mean?
This is the single most confused topic in HITRUST, and it is worth being precise, because the same word describes three unrelated things.
| What people mean by “level” | What it actually is | Where it applies |
|---|---|---|
| “The three HITRUST levels” | The three assessment types: e1, i1 and r2. They are different products, not sequential stages, though many organizations do progress through them. | Choosing which assessment to run |
| “Control maturity levels” | The five PRISMA maturity levels used to score each requirement: Policy, Procedure, Implemented, Measured, Managed. | How each requirement is scored in an r2 |
| “Our domain scores” | The rating each assessment domain receives, which determines whether the result is a certification or a validated report. | Whether you pass |
If someone tells you they are “working towards HITRUST Level 2”, ask which of the three they mean. The answers point at completely different pieces of work.
What are the e1, i1 and r2 assessments?
HITRUST offers three validated assessment types, each aimed at a different level of assurance.
| e1 — Essentials | i1 — Implemented | r2 — Risk-based | |
|---|---|---|---|
| Requirement statements | 44, a fixed baseline | 182 in the current CSF release, a fixed baseline | Tailored to your scope factors; typically several hundred and sometimes far more |
| What it evaluates | Whether foundational controls are implemented | Whether controls are implemented — implementation maturity only | Full control maturity across policy, procedure, implementation, measurement and management |
| Validity | 1 year | 1 year | 2 years, with an interim assessment in between |
| Typically requested for | Low-risk vendors; organizations establishing a baseline | Moderate-risk vendors; the most commonly requested type for SaaS suppliers to health systems | High-risk relationships and organizations holding large volumes of sensitive data or PHI |
| Practical character | Entry point. Addresses the threats that account for most incidents — ransomware, phishing, credential attacks. | The workhorse. Substantial but achievable for a mid-sized company with a functioning security program. | The heavy one. Materially more effort, and the only type that examines whether controls are measured and managed over time. |
There is also a rapid assessment option for e1 and i1 used in some vendor-assurance contexts. It uses the same underlying requirements but a different delivery model.
The important structural point: e1 and i1 evaluate implementation only. The r2 is the only assessment that scores whether a control is documented in policy, supported by procedure, implemented, measured and actively managed. That is why an r2 is not simply “a bigger i1” — it asks a different question about every control.
How is a HITRUST assessment scored?
Scoring is where HITRUST differs most sharply from an ISO certification or a SOC 2 opinion.
In an r2, each requirement is evaluated at five maturity levels drawn from the NIST PRISMA model, and each level carries a different weight:
| Maturity level | Weight | What it asks |
|---|---|---|
| Policy | 15 | Is the requirement addressed in approved policy? |
| Procedure | 20 | Is there documented procedure explaining how it is carried out? |
| Implemented | 40 | Is it actually operating across the assessed scope? |
| Measured | 10 | Is its effectiveness measured? |
| Managed | 15 | Are the measurements acted on? |
Each level is rated on a five-point compliance scale — Non-Compliant, Somewhat Compliant, Partially Compliant, Mostly Compliant, Fully Compliant — reflecting the proportion of the required elements present. Those ratings roll up into a score per requirement, then per assessment domain.
Certification depends on the domain scores, not the overall average. Every assessment domain must reach at least a rating of 3. Fall below that in a single domain and HITRUST issues a validated report rather than a certification — a legitimate deliverable, but not the thing your customer asked for. Individual controls scoring below the certification threshold can be addressed through corrective action plans and still permit certification, provided every domain clears the bar.
The implication for planning is specific: the readiness work that matters most is finding your weakest domain, not raising your average.
What does a HITRUST engagement involve?
A validated assessment runs through six stages, and the first two determine most of the outcome.
- Scoping. You define the systems, facilities and data in scope and answer the scope factor questions that generate your requirement set. Getting this wrong in either direction is the most expensive error available: too broad and you assess systems nobody asked about, too narrow and the report does not cover what your customer needs.
- Readiness assessment. An unvalidated self-assessment against the generated requirement set to find gaps before an assessor does. Organizations that skip this stage generally discover their weakest domain during the validated assessment, when remediation is slowest and most disruptive.
- Remediation. Closing the gaps found in readiness — usually a mixture of writing and approving policy, documenting procedure, and evidencing that controls actually operate. For an r2, remediation frequently means establishing measurement where none existed.
- Validated assessment. An approved external assessor tests the controls and validates your scores in MyCSF, HITRUST’s assessment platform.
- HITRUST quality assurance. HITRUST reviews the submitted assessment itself. This step is what makes the report portable — the recipient is relying on HITRUST’s review, not only the assessor’s judgment.
- Report issuance and maintenance. An e1 or i1 report is valid for a year; an r2 for two, with an interim assessment in between to confirm the program is still operating.
Two operational realities are worth planning for. HITRUST retires CSF versions for new assessments on a published schedule, so a project that drifts can find its target version closed — new e1 and i1 assessments moved to CSF v11.8.0 on 7 May 2026. And because r2 certification is a two-year cycle with an interim checkpoint, HITRUST is a continuous program rather than an annual event.
How do you choose the right assessment type?
Start with the request, not the framework. In practice:
- Ask what the customer actually requires. Health systems and payers frequently specify the assessment type in their vendor requirements. If they have asked for i1, an e1 will not satisfy them, and an r2 is over-delivery you pay for.
- Match the type to the data you hold. Large volumes of PHI, or a role where a failure in your systems propagates to many downstream organizations, points to r2 regardless of what is being asked for today.
- Be honest about measurement. If your controls are implemented but nothing measures their effectiveness, an r2 will expose that at the Measured and Managed levels. Either build the measurement first or start with i1.
- Consider the cycle you can sustain. An annual i1 that stays current beats an r2 that lapses.
A common and sensible path is e1 or i1 first, establishing the documentation and evidence discipline, then r2 when a customer relationship justifies it.
How is HITRUST different from HIPAA?
They are different categories of thing. HIPAA is federal law: it applies to covered entities and business associates whether or not they do anything about it, and there is no HIPAA certification — no body issues one, and any vendor claiming to be “HIPAA certified” is describing a self-assessment or a training course. HITRUST is a voluntary framework that produces a third-party report, and it is one of the practical ways an organization demonstrates that its HIPAA safeguards are real.
The relationship in one line: HIPAA tells you that you must protect PHI; HITRUST tells you specifically how, and gives you something to hand a customer that proves you did. See our fuller comparison of HITRUST vs HIPAA.
How does HITRUST relate to SOC 2?
SOC 2 is an attestation performed by a CPA firm against the Trust Services Criteria, with the controls largely defined by the organization being examined. HITRUST is a certification against a prescriptive control set defined by HITRUST and scored on maturity. SOC 2 asks “are the controls you described operating effectively?”; HITRUST asks “do you meet these specific requirements, and how mature is each one?”
Because the underlying controls overlap heavily, most organizations pursuing both map them once and evidence them once. There is also a combined report option that covers both in a single engagement. Our guide to HITRUST to SOC 2 mapping covers the common criteria and where the two diverge.
What drives HITRUST cost and effort?
Effort is driven by scope factors, assessment type, and how much of your program already exists in documented, evidenced form. The variables that matter most:
- Scope. Systems, facilities, data volumes and geographies feed the scope factors that generate your requirement count. Narrow, well-defined scope is the single largest lever.
- Assessment type. e1, i1 and r2 differ by an order of magnitude in requirement count and in the maturity levels examined.
- Starting maturity. An organization with approved policies, documented procedures and continuous evidence collection is largely doing readiness work; one without them is building a program and assessing it at the same time.
- Remediation. Unknown until readiness is complete, and the reason readiness is worth doing early.
- Ongoing maintenance. The annual or interim cycle, not just the first certification.
The questions to put to an assessor before signing anything: what requirement count does our scope generate, what is included in the quoted engagement and what is billed separately, who performs readiness, what happens if a domain falls short, and what does the maintenance cycle look like in year two? Our guide to HITRUST certification cost works through the structure in more detail.
Why do HITRUST projects stall?
- Scope decided by convenience rather than by the customer requirement. The most common cause of a report that does not satisfy the person who asked for it.
- Skipping readiness. Gaps found by an external assessor cost more and take longer to close than gaps found internally.
- Policy without procedure. A very common r2 failure: the policy exists and the control operates, but nothing documents how, so two of the five maturity levels score badly.
- No measurement. Measured and Managed together carry a quarter of the weight, and they are the levels most organizations have never built.
- Evidence assembled retrospectively. HITRUST examines whether controls operate across the assessed period. Evidence gathered in the final month describes the final month.
- Targeting a CSF version that closes mid-project. Check the current release and the announced deadlines before you scope.
- Treating certification as the finish line. An r2 has an interim assessment; e1 and i1 expire annually.
How Compyl helps with HITRUST
Most of the work in a HITRUST engagement is holding evidence, policies and control ownership together across a long cycle — and doing it in a way that also serves the other frameworks a business is subject to. Compyl maps a single control set across HITRUST, SOC 2, ISO 27001, HIPAA and the rest, so a control is evidenced once and satisfies several requirements; keeps policies, owners and review cycles in one place so the Policy and Procedure maturity levels are demonstrable rather than reconstructed; and collects evidence continuously, which is the only way the Measured and Managed levels ever score well.
Book a demo to see how Compyl supports a HITRUST program end to end.
HITRUST FAQs
What does HITRUST stand for?
Originally the Health Information Trust Alliance. The organization now uses HITRUST as a standalone name, reflecting that the framework is used well beyond healthcare by any organization whose customers require certified security assurance.
Is HITRUST certification mandatory?
No. HITRUST is a voluntary framework. It becomes effectively mandatory through contracts: many health systems, payers and large enterprises require a specific HITRUST assessment type from vendors handling their data.
What is the difference between HITRUST e1, i1 and r2?
e1 assesses 44 foundational requirements and is valid for one year. i1 assesses a fixed baseline of 182 requirements in the current CSF release, examines implementation only, and is valid for one year. r2 uses a requirement set tailored to your scope factors, scores full control maturity across all five levels, and is valid for two years with an interim assessment in between.
How long does HITRUST certification last?
An e1 or i1 certification is valid for one year from issuance. An r2 certification is valid for two years, with an interim assessment during the second year to confirm the program is still operating as assessed.
What score do you need to pass HITRUST?
Certification depends on domain scores. Every assessment domain must reach at least a rating of 3. If any domain falls below that, HITRUST issues a validated report rather than a certification. Individual controls below the certification threshold can be handled through corrective action plans provided every domain clears the bar.
Is HITRUST the same as HIPAA compliance?
No. HIPAA is law and has no certification; HITRUST is a voluntary framework that produces a third-party report. Achieving HITRUST certification is strong evidence that your HIPAA safeguards are implemented, but the two are not interchangeable and HITRUST does not on its own establish HIPAA compliance.
Can HITRUST replace a SOC 2 report?
Not automatically — some customers specifically require a SOC 2 attestation from a CPA firm. Because the control sets overlap substantially, many organizations pursue both and evidence them once, and a combined engagement option exists.
Which HITRUST CSF version should we assess against?
The current release. HITRUST retires older versions for new assessments on a published schedule — new e1 and i1 assessments moved to CSF v11.8.0 on 7 May 2026 — so confirm the current version and any announced deadlines at scoping, not at submission.
Do we need an external assessor?
For a validated assessment, yes. Readiness work can be done internally or with an advisor, but the validated assessment must be performed by a HITRUST-approved external assessor and is then quality-assured by HITRUST before a report is issued.