What is HITRUST certification?

HITRUST certification is a validated cybersecurity credential that HITRUST, a private assurance organization founded in 2007, issues against its HITRUST Framework (CSF) (HITRUST, About us, page opened October 4, 2026). HITRUST says the framework maps to more than 60 standards (HITRUST, Become an Assessor, page opened October 4, 2026). Customers such as health plans and hospital systems may require it from vendors as independent validation of security controls.

HITRUST reports a 99.62 percent breach-free rate among HITRUST-certified environments (HITRUST, page opened October 4, 2026). That is HITRUST's own figure, and IHS has not tested it.

HITRUST certification is a private program. HHS states that no HIPAA Security Rule standard requires a covered entity to certify its compliance (HHS FAQ on certification, page opened October 3, 2026).

Who licenses HITRUST work, and what does IHS do?

HITRUST states that any organization performing HITRUST readiness assessments or advisory services must be licensed by HITRUST as an External Assessor or a Readiness Licensee, and that only External Assessors perform the validated assessments submitted for certification (HITRUST, Become an Assessor, page opened October 4, 2026). IHS is in neither program, so IHS does not offer HITRUST readiness, gap assessment, advisory or MyCSF work.

IHS does the work outside that licensed scope, and your organization engages and contracts with the licensed firm directly:

  • Policy and procedure architecture and governance: IHS drafts the security policies and procedures, governance charters and committee records your program needs.
  • HIPAA risk analysis: IHS conducts or updates your HIPAA Security Rule risk analysis, which is separate from any HITRUST assessment.
  • Evidence organization: IHS organizes your evidence by control so your team can answer your assessor's requests.
  • Project and process management: IHS runs the project plan for your HITRUST effort.
  • Coordination with your licensed firm: IHS tracks the assessor's requests and coordinates your team's answers. Your team and the assessor do the assessment work.
  • Customer contract terms: IHS reads the security and vendor risk terms in your health plan and PBM contracts so your team and your licensed firm start from what your customers ask for. This is a contract reading, not legal advice.
  • Coordinated accreditation work: where you pursue HITRUST alongside URAC or ACHC accreditation, IHS plans the policy work so one set of documents serves both efforts where their requirements overlap.

What are the HITRUST e1, i1 and r2 assessments?

HITRUST offers three assessment levels, and your customer contracts usually tell you which one you need. Each row below summarizes what HITRUST publishes on its own pages (page opened October 4, 2026).

LevelControlsValidityTiming HITRUST describes
e143 foundational controlsOne year, renewed annuallyHITRUST says the average is about 30 days and some finish in a few weeks, depending on readiness
i1182 curated controls with a fixed control setOne year, with a lighter recertification in year two (about 60 core controls)HITRUST says most companies finish within 6 to 12 months
r2Risk-based, tailored to your environment and scopeTwo years, with an interim assessment after year one and a full assessment at the endHITRUST gives no single figure on the page IHS read

IHS gives no cost figure for any level. Assessor fees and HITRUST fees are set by HITRUST and the licensed firm you hire.

Which HITRUST level does your customer require?

Your customer contract answers it. If a contract says HITRUST certification is required without naming a level, ask the customer which level it means before you scope the work. IHS can pull the security terms out of your payer and health plan contracts so the level you and your licensed firm choose matches what your customers require, because a certificate at a lower level than your customer requires may not meet the contract.

What is the HITRUST certification process?

HITRUST certification runs in phases, and the licensed firm you engage leads the HITRUST-specific steps. IHS's part in each phase is below.

Phase 1: Scoping and readiness assessment

You set the scope (systems, locations and business processes), choose the level your customers require and have your controls checked for gaps against the framework. A HITRUST-licensed firm performs this readiness assessment. IHS gathers the system, policy and contract information the scoping needs.

Phase 2: Remediation

Your organization closes the gaps the licensed firm found. IHS drafts the policies, procedures and governance records those gaps call for, for your leaders to approve, and your IT and security staff make the technical control changes. Some gaps need only documentation and others need new technical controls, so remediation timelines vary.

Phase 3: Pre-assessment check

Before the validated assessment, you and your licensed firm decide whether the evidence is ready. IHS keeps the evidence organized and the project on schedule while that runs.

Phase 4: Validated assessment

A HITRUST External Assessor performs the validated assessment, reviews your evidence, tests your controls and scores them. IHS organizes your evidence, tracks the assessor's requests and coordinates your team's answers.

Phase 5: HITRUST review and certification decision

HITRUST describes its i1 certification as including centralized HITRUST quality assurance (HITRUST, i1 assessment, page opened October 4, 2026). Your licensed firm explains any findings and your team remediates them.

What does HITRUST support cost?

The cost has three parts: HITRUST and assessor fees, IHS's foundations work and your internal time. HITRUST and your licensed firm set the first part, and you contract with the firm directly. IHS sets a fixed fee for each engagement after a free discovery session, because scope, number of sites and gap severity change the work. The HITRUST Certification Cost Guide goes through the drivers.

Which regulatory changes bear on a HITRUST effort?

HHS published a notice of proposed rulemaking on January 6, 2025 to change the HIPAA Security Rule. The proposal addresses multi-factor authentication, network segmentation and written verification from business associates (Federal Register, 90 FR 898, page opened October 4, 2026). This page does not report whether the rule has been finalized, so check the Federal Register for its current status.

NIST publishes the Cybersecurity Framework, now at version 2.0, as federal guidance for managing cybersecurity risk (NIST Cybersecurity Framework, page opened October 4, 2026). HITRUST describes a separate add-on report that maps an r2 assessment to NIST CSF 2.0 (HITRUST NIST CSF 2.0, page opened October 4, 2026).

What this is not

  • IHS is not a HITRUST licensee, External Assessor or Readiness Licensee. IHS does not perform HITRUST readiness assessments, gap assessments, advisory services or validated assessments, and it does not work in MyCSF for you.
  • IHS is not an accrediting or certifying body. IHS drafts, and your organization's named contact, assessor and HITRUST handle all submissions. IHS does not communicate with HITRUST for you.
  • This page is not legal advice, and no engagement guarantees a certification.

Frequently asked questions

What does HITRUST certification mean?

It is a credential from HITRUST, a private assurance organization, showing that an independent External Assessor validated your security controls against the HITRUST Framework. HHS states that no HIPAA Security Rule standard requires a covered entity to certify its compliance.

Does IHS perform HITRUST assessments?

No. IHS is not a HITRUST licensee. A HITRUST-licensed firm that you engage performs the readiness assessment and the validated assessment. IHS builds the policies, governance, HIPAA risk analysis and evidence behind your effort and manages the project.

Do I need a HITRUST External Assessor?

Yes, for certification. HITRUST states that only External Assessors perform the validated assessments submitted for certification. Compare assessors on turnaround and healthcare experience before you sign. IHS coordinates with the one you choose.

How do I find an authorized External Assessor?

HITRUST lists External Assessors and Readiness Licensees on its Find an External Assessor page (page opened October 4, 2026). Your organization chooses and contracts with the firm.

Which level should I pursue: e1, i1 or r2?

Start with what your customer contracts require. The e1 has 43 controls, the i1 has 182 and the r2 is tailored to your risk profile, per HITRUST's pages. IHS can read your contracts for the required level, and your licensed firm advises on the choice.

How long is a HITRUST certification valid?

HITRUST says e1 and i1 certifications last one year. An r2 certification lasts two years, with an interim assessment at the one-year point and a full assessment at the end. Plan the next assessment well before the current certificate ends.

Does HITRUST certification replace HIPAA compliance?

No. HIPAA is a legal obligation and HITRUST is a voluntary certification, and they operate in parallel. HHS states that no HIPAA Security Rule standard requires a covered entity to certify its compliance.

Who is this not for?

An organization that wants IHS to perform a HITRUST readiness or validated assessment, advise on HITRUST scoring or work in MyCSF is not a fit, because HITRUST licenses that work. IHS is also not the right resource for legal advice.

Work with IHS on the program behind your HITRUST certification

IHS works with healthcare vendors, specialty pharmacies, health plans, PBMs and health information exchanges on the policies, governance, HIPAA risk analysis and evidence behind a HITRUST effort, and manages the project alongside the HITRUST-licensed firm you engage. A free discovery session reviews your current policies, the security terms in your customer contracts and the work your licensed firm has scoped.

Schedule a Free Discovery Session

Talk with IHS's CEO

A 30-minute introductory meeting with Thomas G. Goddard, JD, PhD, to scope what your organization needs.

Schedule a Free Discovery Session