Massive Bio has made its inaugural strategic investment in Rivvi. Read the announcement

← Glossary

Definition · Allowed AI at work

HITRUST

HITRUST is a security and privacy assurance program run by the HITRUST Alliance. It is built on the HITRUST CSF, a control framework that maps HIPAA, NIST, ISO, and other standards into one set of requirements. Organizations earn HITRUST certification through validated assessments at three levels, e1, i1, and r2, each more rigorous than the last.

What HITRUST is

The HITRUST Alliance is a private organization founded in 2007. Its framework, the HITRUST CSF, combines requirements from HIPAA, NIST, ISO 27001, PCI DSS, and other sources into one set of controls. Many health systems and payers ask vendors for HITRUST certification because one assessment answers many frameworks at once.

HITRUST offers three validated assessments. The e1 covers essential cybersecurity hygiene and is valid for one year. The i1 adds a broader set of leading-practice controls and is also valid for one year. The r2 is tailored to the organization's risk factors, is the most comprehensive, and is valid for two years with an interim review. An authorized external assessor performs each one, and HITRUST reviews the results.

HIPAA does not require HITRUST, and HHS does not certify HIPAA compliance. HITRUST certification is strong evidence of mature safeguards, but a vendor handling PHI still needs a BAA. HITRUST differs from SOC 2: HITRUST certifies against prescriptive controls, while SOC 2 is a CPA attestation against broader criteria. Some vendors hold both.

Questions

HITRUST, answered

What is the difference between HITRUST e1, i1, and r2?
They are three levels of assurance. The e1 covers foundational cybersecurity controls and lasts one year. The i1 covers a broader leading-practice control set and lasts one year. The r2 is risk-based, tailored to the organization, the most rigorous, and lasts two years with an interim assessment.
Is HITRUST required for HIPAA compliance?
No. HIPAA requires safeguards, a risk analysis, policies, and BAAs, but it does not require any certification. HITRUST is voluntary. Some buyers, especially large health systems and payers, require it in vendor contracts, which makes it a commercial requirement rather than a legal one.
HITRUST vs SOC 2: which is better?
Neither is better in general. HITRUST is a certification against prescriptive, healthcare-focused controls. SOC 2 is a CPA attestation against the AICPA Trust Services Criteria. Health systems often prefer HITRUST, while SOC 2 is more widely recognized across industries. Ask buyers which one their vendor review accepts.

Try it on your own data today.

Free to start. Most teams are using it the same day.