What Is the HITRUST Framework?

Also called: HITRUST CSF

Related problems: A hospital or health plan customer requires HITRUST certification; Answering long healthcare security questionnaires one by one; Not sure whether an e1, i1 or r2 assessment is the right fit; Need evidence that a vendor protects patient data beyond a HIPAA statement

The HITRUST Framework, usually called the HITRUST CSF, is a security and privacy control framework maintained by HITRUST, an organization originally formed in US healthcare. It brings controls from many standards and regulations, such as HIPAA, NIST publications and ISO/IEC 27001, into one library, and offers assessments that can lead to a HITRUST certification. Its e1, i1 and r2 assessments give buyers a common way to compare a vendor’s security against a defined level of assurance. This entry is an overview for buyers; requirements depend on the customer contract and the assessment chosen.

At a glance

  • HITRUST CSF is a harmonized control framework, and HITRUST assessments test an organization against a defined subset of it.
  • Three core validated assessments can lead to certification: e1 (foundational), i1 (leading practices) and r2 (risk-based, tailored).
  • Validated assessments are tested by an authorized external assessor and quality-reviewed by HITRUST before a report is issued.
  • It is voluntary, but many healthcare customers ask vendors for it, especially for systems handling patient data.
  • Certification covers a defined scope of systems and locations, so the scope matters as much as the badge.

What problem it solves

Healthcare organizations share patient data with hundreds of vendors: EHR hosting, billing, contact centers, cloud platforms, analytics. HIPAA requires safeguards but does not define a certification, so hospitals and health plans each sent their own questionnaires, and vendors answered them in different ways. HITRUST gives both sides a shared framework and a third-party-tested report, so a vendor can show its controls once in a format customers recognize.

For a mid-market vendor or buyer, HITRUST matters most when selling into large health systems or payers, which often name it in contracts, and when evaluating providers that will hold protected health information.

How it works

Framework. The HITRUST CSF organizes requirements into domains such as access control, encryption, incident management and third-party assurance, and maps them to authoritative sources. It is updated regularly to reflect new threats and standards.

Scoping. The organization defines the systems, facilities and services in scope. For r2, factors such as data volumes and regulatory requirements tailor which controls apply.

Readiness. Many organizations start with a self-run readiness assessment to find gaps before paying for validation.

Validated assessment. An authorized external assessor tests the controls, collecting evidence and scoring them. HITRUST performs quality assurance on the assessor’s work, then issues a report and, where scores meet the thresholds, a certification letter.

Inheritance and maintenance. Organizations can inherit results for controls performed by a provider with its own HITRUST assessment, where supported. Certifications expire, and r2 requires an interim assessment partway through its term.

Assessment levels

Assessment Typically suits How it is validated Validity and evidence
Readiness (self-assessment) Organizations preparing for certification Performed by the organization, optionally with an advisor Internal report; no certification
e1 (essentials) Lower-risk vendors and startups needing baseline assurance External assessor testing plus HITRUST quality review One-year certification and report
i1 (implemented) Vendors needing moderate assurance against leading practices External assessor testing plus HITRUST quality review One-year certification and report
r2 (risk-based) Higher-risk vendors and organizations with large or sensitive data sets External assessor testing of a tailored control set plus HITRUST quality review Two-year certification with interim assessment

Control counts and scoring rules change with framework versions, so confirm the current details with HITRUST or your assessor.

When it matters for buyers

  • When selling to hospitals, health plans or large healthcare partners. Ask early which assessment they accept.
  • When choosing a cloud, colocation, CCaaS or MSP provider for health data. A provider’s HITRUST report can support your own assessment.
  • When deciding between HITRUST, SOC 2 and ISO/IEC 27001. Customers in healthcare may prefer HITRUST; others may not recognize it.
  • When a vendor says it is “HITRUST compliant.” That is not a certification; ask for the assessment type, scope and date.

Our governance, risk and compliance overview covers assessors and tools that support HITRUST programs.

Questions to ask vendors

  • Which HITRUST assessment do you hold (e1, i1 or r2), and when does it expire?
  • Does the scope cover the specific service, systems and locations we’d use?
  • Can we see the report or certification letter, and were any corrective action plans required?
  • Which controls can we inherit from you for our own assessment?
  • What other reports do you have, such as SOC 2 or ISO/IEC 27001, and how do they map?
  • Will you sign a business associate agreement for protected health information?

How it differs from HIPAA

HIPAA is a US law that requires covered entities and business associates to protect health information; it sets outcomes but offers no certification. HITRUST is a voluntary framework and assessment program that many organizations use to show how they meet HIPAA and other requirements. A HITRUST certification does not make an organization HIPAA compliant on its own, and HIPAA still requires a business associate agreement (BAA) with vendors handling protected health information. HITRUST also overlaps with SOC 2, ISO/IEC 27001 and the NIST Cybersecurity Framework (NIST CSF), and a HITRUST report can replace many answers in a security questionnaire.

Frequently Asked Questions

Is HITRUST required by HIPAA?
No. HIPAA does not require any particular certification. HITRUST is a voluntary framework that many healthcare organizations use to show how they protect health information, and some hospitals, health plans and partners require it of their vendors by contract.
What is the difference between e1, i1 and r2?
They are increasing levels of assurance. The e1 covers a small set of foundational controls, the i1 a larger fixed set of leading-practice controls, and the r2 a risk-based set tailored to the organization's systems, data and regulatory factors. The e1 and i1 certifications are valid for one year; the r2 for two, with an interim check.
Who performs a HITRUST assessment?
For a validated assessment that can lead to certification, an authorized HITRUST External Assessor firm tests the controls, and HITRUST reviews the work for quality before issuing a report and, if scoring thresholds are met, a certification. Organizations can also run readiness assessments themselves, which do not result in certification.
Is HITRUST only for healthcare?
No. It started in healthcare and remains most common there, but the framework maps many standards and regulations and is used in other sectors. Whether a customer will accept it in place of SOC 2 or ISO/IEC 27001 depends on that customer.
Can our HITRUST certification rely on our cloud provider's?
Often, in part. HITRUST lets organizations inherit results for controls performed by a provider that has its own HITRUST assessment, where the provider supports it. You still assess the controls you operate, so ask providers what they make available for inheritance.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.