The HITRUST CSF is maintained by HITRUST, an organization that also runs the assurance program built around it. Its value is harmonization: rather than answering separate questionnaires for HIPAA, NIST, ISO, and PCI requirements, an organization is assessed once against a control set that incorporates many authoritative sources, and HITRUST issues a report that relying parties can review. Health systems and payers frequently ask their technology vendors for a HITRUST certification before sharing protected health information.
How the assurance model differs from a typical audit
In a SOC 2 examination, a CPA firm issues the report. In HITRUST, an authorized External Assessor firm tests your controls and submits results through MyCSF, HITRUST's assessment platform. HITRUST then performs its own quality assurance review before issuing the certification. That extra review is a real schedule item: plan for it rather than treating fieldwork completion as the finish line.
e1, i1, or r2
Version 11 of the CSF aligned HITRUST's validated assessments into a tiered portfolio. Each tier asks for more requirements and more rigorous scoring, and relying parties often specify which one they will accept.
Requirement counts per tier change between CSF releases, so confirm the current numbers in MyCSF for the version you select. Before committing, ask your key customers which assessment they accept; buying an r2 when an i1 would satisfy every contract is an expensive mistake, and the reverse can cost a renewal.
Scoring and maturity
The r2 evaluates requirements against a maturity model built on five levels: policy, procedure, implemented, measured, and managed. A control that works in practice but has no written procedure scores lower than you might expect. The e1 and i1 concentrate on whether requirements are implemented. Where scores fall short, HITRUST requires corrective action plans (CAPs) with owners and dates, which are tracked through to closure.
Inheritance: do less work twice
HITRUST's inheritance program lets you pull in results from service providers that hold their own HITRUST assessments, such as major cloud platforms, for requirements they perform on your behalf. Inherited requirements still need to be mapped to your scope, and shared requirements still need your half tested. Identifying inheritance candidates early in MyCSF can meaningfully reduce the number of requirements your assessor tests directly.
Timeline from decision to certificate
- Confirm the target assessment with customers and contracts.
- Define scope in MyCSF: systems, facilities, and organizational units, plus risk factors for an r2.
- Run a readiness assessment to identify gaps; many organizations use an external assessor for this step too.
- Remediate and let controls operate. HITRUST expects remediated controls to run for a defined period before validated testing, so fixes made the week before fieldwork are unlikely to count.
- Validated assessment fieldwork by the external assessor, including sampling and evidence review.
- HITRUST quality assurance and issuance of the report and certification, followed by CAP tracking and, for r2, the interim assessment.
Evidence packages assessors test
Pitfalls to plan around
- Scoping too broadly, so every corporate system is subject to requirements meant for the platform that stores PHI.
- Policies that say "annually" while evidence shows a review two years ago.
- Underestimating QA turnaround and letting a prior certification lapse.
- Forgetting the r2 interim assessment, which is required to keep the two-year certification valid.
- Assuming a HIPAA risk analysis alone satisfies HITRUST's risk management requirements.
How Asurvo fits a HITRUST program
Asurvo supports the HITRUST CSF alongside HIPAA, ISO 27001, NIST SP 800-53, and PCI DSS with automated cross-mapping, so a single access review or vulnerability scan is credited wherever it applies. The evidence library tracks versions, approvals, and expiry dates, which helps keep policy and procedure evidence current through a two-year cycle, and the audit workspace tracks assessor requests and CAPA through remediation. Healthcare teams can see the broader picture on the healthcare industry page.