Frequently asked questions

Assessment Types: e1, i1, and r2

What is the difference between HITRUST e1, i1, and r2 assessments?

HITRUST offers three certification tracks. e1 (Essential) covers 43 implemented controls with a 1-year certification validity. It is the entry-level credential for vendors whose customers require a baseline HITRUST certification. i1 (Implemented 1-Year) covers approximately 182 implemented controls and is the most common requirement in health plan and hospital system vendor contracts. r2 (Risk-Based 2-Year) covers 200+ controls using full five-level PRISMA maturity scoring and is required by the most demanding health plans and federal contractors.

The key difference between tiers is not just control count. r2 applies full maturity scoring — policy, procedure, implemented, measured, and managed — while e1 and i1 evaluate only the "implemented" maturity level. This means r2 requires an organization to demonstrate not just that a control exists, but that it is measured and managed as an ongoing operational process.

Which HITRUST assessment level does my health plan customer require?

Most health plan and hospital system vendor contracts specify i1 or above. If your contract says "HITRUST certification required" without specifying level, the procurement team almost always means i1. Federal contractor work, PBM contracts under CAA 2026, and large health system integrations are increasingly specifying r2. e1 is accepted for lower-risk vendor relationships where customers want a credential but the risk profile does not warrant i1 or r2. IHS can pull the security terms out of your contracts so you and your licensed HITRUST firm choose the level your customers require.

Is e1 worth pursuing, or should I go straight to i1?

e1 is worth pursuing if: (a) your current health plan contracts specifically accept e1, (b) you need a HITRUST credential quickly for a contract deadline and cannot complete i1 in time, or (c) you are pursuing HITRUST for the first time and want to build internal familiarity with the framework before scaling to i1. If your primary goal is to satisfy health plan and hospital system vendor credentialing requirements, i1 is the practical minimum — many payers do not accept e1 as satisfying their vendor risk management requirements. Starting at i1 avoids the cost of re-doing work to upgrade from e1.

What is the certification validity period for each tier?

HITRUST lists e1 and i1 certifications as valid for one year and r2 certification as valid for two years (HITRUST, r2 Assessment, page opened October 3, 2026). For r2, HITRUST describes an interim assessment at the one-year mark and a full reassessment when the two years end. For i1, HITRUST describes a reduced-effort recertification route for the second year (HITRUST, i1 Assessment, page opened October 3, 2026).

What types of organizations pursue HITRUST certification?

The certification covers any organization handling PHI or providing services to healthcare entities: health plans, specialty pharmacies, PBMs, health information exchanges, hospitals, credentialing vendors, health IT firms, and adjacent technology providers. Many US hospitals and health plans have adopted the HITRUST CSF in some capacity, creating downstream demand for vendor certification.

Cost and Timeline

How much does HITRUST e1 certification cost?

Approximately $35,000–$50,000 all-in. This includes: HITRUST MyCSF report credits (~$6,000), external Authorized Assessor fees (variable, typically $20,000–$35,000 for e1), and consulting/readiness preparation. Internal FTE hours: 150–300 hours. Timeline: 3–4 months. Sources: HITRUST Alliance pricing guide; Cloudticity 2024 cost analysis.

How much does HITRUST i1 certification cost?

Cost varies with scope, assessor, and readiness.This includes: HITRUST MyCSF report credits, external Authorized Assessor fees (variable), and consulting/readiness preparation. Internal FTE hours: 250–500 hours. GRC automation platforms can reduce manual evidence-gathering labor. HITRUST Inheritance from cloud providers can reduce assessor billable hours. Timeline: 6–9 months.

How much does HITRUST r2 certification cost?

$100,000–$500,000+ all-in, depending on organizational complexity. Enterprise three-year cycle (advisory, labor, remediation, assessor): $400,000–$800,000. HITRUST MyCSF report credits: ~$9,000. External assessor fees: the largest variable, driven by scope size, infrastructure complexity, and geographic footprint. Internal FTE: 300–600+ hours. A primary PM should budget 300–400 hours; 4–5 SMEs from IT, DevOps, HR, and Legal should budget 150–200 hours each. HITRUST Inheritance reduced external assessor billable hours by 14% on r2 in 2024. Timeline: 12–15 months. Sources: Sprinto 2026 cost guide; HITRUST Alliance pricing.

What are the ongoing costs of maintaining HITRUST certification?

Annual ongoing costs include: MyCSF portal subscription, GRC automation tooling (if used), external assessor fees for annual re-assessment (e1/i1) or i1 year-two recertification, and internal FTE time for continuous evidence maintenance. Repeat certifications cost significantly less than initial certifications because most policy documentation and control evidence carries forward. Organizations that invest in systematic evidence management during the initial certification cycle typically see lower costs on renewal assessments.

Certification Process

What is a HITRUST External Assessor and is one required?

Yes — HITRUST certification requires a Validated Assessment conducted by a firm authorized and trained by the HITRUST Alliance. Without a Validated Assessment from an authorized assessor, an organization cannot receive a HITRUST certification. IHS is not a HITRUST licensee, so IHS does not perform HITRUST readiness or validated assessments. IHS organizes your evidence and coordinates with the assessor you engage. Assessors vary in healthcare industry experience, response time and methodology.

What is the HITRUST MyCSF portal?

MyCSF is HITRUST's proprietary assessment management platform through which all assessments are conducted, scored, and submitted. Organizations use it to define scope, enter control responses, upload evidence, and manage assessor communications. External Assessors access the same portal to review and score submissions. HITRUST Quality Review is conducted within the portal before certification is issued. MyCSF portal report credits (HITRUST's direct fees) are separate from assessor and consulting fees.

What is HITRUST Inheritance and how does it reduce my certification burden?

HITRUST Inheritance allows organizations to inherit pre-assessed security controls from HITRUST-authorized cloud providers (AWS, Azure, Google Cloud). Rather than your external assessor re-testing controls your cloud provider has already been independently assessed on, you inherit their validated findings. HITRUST Inheritance reduced external assessor billable hours by 14% on r2 and 23.4% on i1 in 2024 (2025 HITRUST Trust Report). To leverage Inheritance, your environment must be on a qualifying cloud platform and the specific services in scope must be covered by the provider's authorization. Your HITRUST-licensed firm can tell you which of your controls are eligible.

How does i1 recertification work in year two?

HITRUST's i1 page describes a year-two recertification that covers about 60 core controls instead of the full 182 (HITRUST, i1 Assessment, page opened October 3, 2026). For r2, HITRUST describes an interim assessment at the one-year mark.

What happens if my assessment receives a Corrective Action Required result?

A Corrective Action Required (CAR) finding means one or more controls did not meet the minimum scoring threshold. The organization must remediate and resubmit evidence through MyCSF before HITRUST Quality Review can issue a certification decision. CAR findings do not disqualify an organization — they extend the timeline by 1–4 months depending on complexity. Thorough mock assessments before engaging an external assessor are the most effective way to minimize CAR exposure.

How do we share our HITRUST results with a customer?

HITRUST runs a Results Distribution System for this. HITRUST says customers and partners can pull current assessment data through the system without waiting for a report file (HITRUST Results Distribution System, page opened October 3, 2026). Ask each customer how it wants to receive the results.

Can a small startup get HITRUST certified?

Yes. HITRUST's e1 page names startups and small businesses among the organizations it fits, and it presents e1 as a starting point for later i1 or r2 work. The e1 uses 43 controls. An e1 certification lasts one year and is renewed each year (HITRUST e1, page opened October 3, 2026). Check which level your customers' contracts name first. A contract that names i1 or r2 may not accept an e1.

Does HIPAA require a HITRUST certification?

No. HHS says no Security Rule standard or implementation specification requires a covered entity to certify its compliance. The Security Rule requires a periodic evaluation under 45 CFR 164.308(a)(8), which the entity can do itself or hire an outside organization to do, and HHS does not recognize private certifications for the Security Rule (HHS, Are we required to certify our organization's compliance with the Security Rule?, page opened October 3, 2026). Customers may still require HITRUST by contract.

Regulatory and Compliance Overlap

Does HITRUST certification satisfy HIPAA Security Rule requirements?

HITRUST certification is not a legal substitute for HIPAA compliance, but it provides substantial evidence of compliance with HIPAA Security Rule requirements. HITRUST CSF v11.7.0 maps directly to the HIPAA Security Rule overhaul effective May 2026 — including mandatory MFA, universal PHI encryption, 24-hour breach reporting, and annual penetration testing. Organizations with current HITRUST r2 or i1 will satisfy most new mandatory HIPAA controls by default. HIPAA is a legal obligation administered by HHS OCR; HITRUST is a voluntary certification. They operate in parallel, not as substitutes.

What is the current HITRUST CSF version?

HITRUST CSF v11.7.0, released December 18, 2025 (HAA 2025-005). Legacy v11.6.0: new e1/i1 assessment creation disabled March 31, 2026; all submission on v11.6.0 fully disabled June 30, 2026 (HAA 2025-006). Any organization starting a HITRUST engagement in 2026 must use v11.7.0.

What is the CAA 2026 HITRUST requirement for PBMs?

The Consolidated Appropriations Act (CAA) 2026 added transparency and reporting requirements for PBMs. CAA's security and transparency standards are driving PBMs into HITRUST r2 certification cycles. r2 is the only HITRUST tier providing the depth of control validation required to demonstrate compliance with CAA's standards. IHS has existing PBM client relationships and can plan a PBM's HITRUST policy work alongside its PBM accreditation work. A HITRUST-licensed firm performs the HITRUST assessments.

HITRUST vs. Other Frameworks

How does HITRUST compare to SOC 2 for healthcare organizations?

SOC 2 is an AICPA attestation based on Trust Service Criteria, widely accepted across all industries. HITRUST is healthcare-specific, mapped to HIPAA, and required by health plans and hospital systems in vendor contracts. SOC 2 is generally faster and less expensive than HITRUST i1 or r2. Many organizations pursue both. If your primary customers are health plans or hospital systems, HITRUST is the relevant standard — SOC 2 alone will not satisfy health plan vendor credentialing requirements in most cases. See the full comparison at HITRUST vs. SOC 2 vs. HIPAA.

What frameworks does HITRUST CSF incorporate?

HITRUST CSF v11.7.0 harmonizes: HIPAA Security Rule, NIST Cybersecurity Framework 2.0, NIST SP 800-53, ISO/IEC 27001:2022, SOC 2 Trust Service Criteria, CIS Controls v8, and PCI DSS. This is the primary argument for HITRUST over framework-specific certifications: one certification provides evidence of compliance with multiple frameworks simultaneously, reducing the total cost of demonstrating security compliance to multiple customers with different contractual requirements.

Business Case and ROI

What is the ROI on HITRUST certification?

Enterprise Strategy Group analysis, cited by HITRUST Alliance, documents a 464% ROI over three years for HITRUST-certified organizations. Drivers: avoided breach costs (healthcare average $10.93M per incident), cyber insurance premium savings (up to 25%), accelerated B2B sales cycles with health plan customers, and reduced internal compliance labor. The ROI case is strongest for organizations that handle significant PHI volumes and have health plan or hospital system customers who require HITRUST as a vendor contract prerequisite.

Does HITRUST certification lower cyber insurance premiums?

Yes. HITRUST-certified organizations report up to 25% preferred premium discounts and enhanced coverage terms (HITRUST Alliance, hitrustalliance.net/cyber-insurance). Cyber insurers use HITRUST certification as evidence of security control implementation. For an organization paying $200,000 annually in premiums, a 25% reduction represents $50,000/year — partially or fully offsetting the cost of e1 or i1 certification over the certification cycle.

What is the 99.62% breach-free statistic?

HITRUST says 99.62% of its certified environments are breach-free (HITRUST, page opened October 3, 2026). This is the primary published risk-reduction metric for HITRUST certification. For context: healthcare has the highest average breach cost of any industry at $10.93M per incident (IBM 2024). The certification does not make breach impossible, but it requires the implementation and validation of controls specifically designed to prevent the most common breach vectors.

Work With IHS on the Program Behind Your HITRUST Certification

IHS works with healthcare vendors, specialty pharmacies, health plans, PBMs and health information exchanges on the policies, governance, HIPAA risk analysis, evidence and project management behind a HITRUST effort. HITRUST runs two licensing programs, External Assessor and Readiness Licensee, and keeps readiness and advisory work on its framework with the firms in them (HITRUST, Become an Assessor, page opened October 3, 2026). IHS is not a HITRUST licensee, so a HITRUST-licensed firm you engage performs those assessments. IHS has worked on a HITRUST certification project.

Schedule a Free Discovery Session

Talk with IHS's CEO

A 30-minute introductory meeting with Thomas G. Goddard, JD, PhD, to scope what your organization needs.

Schedule a Free Discovery Session