Asurvo
Industry framework

Run HITRUST with
confidence.

The HITRUST Common Security Framework is a certifiable framework that provides a comprehensive, flexible approach to regulatory compliance and risk management by harmonizing standards including HIPAA, HITECH, PCI DSS, ISO 27001, and NIST.

Who it's for

Healthcare organizations and vendors that need certifiable assurance.

Scope

Multi-standard harmonized control set

Category
Industry

How Asurvo helps

What you get for HITRUST.

Harmonizes multiple standards in one assessment
e1, i1, and r2 assessment types
Inheritance and control maturity scoring
Cross-mapped to HIPAA and ISO 27001

Healthcare assurance

Choosing and passing the right HITRUST assessment

The HITRUST CSF is maintained by HITRUST, an organization that also runs the assurance program built around it. Its value is harmonization: rather than answering separate questionnaires for HIPAA, NIST, ISO, and PCI requirements, an organization is assessed once against a control set that incorporates many authoritative sources, and HITRUST issues a report that relying parties can review. Health systems and payers frequently ask their technology vendors for a HITRUST certification before sharing protected health information.

How the assurance model differs from a typical audit

In a SOC 2 examination, a CPA firm issues the report. In HITRUST, an authorized External Assessor firm tests your controls and submits results through MyCSF, HITRUST's assessment platform. HITRUST then performs its own quality assurance review before issuing the certification. That extra review is a real schedule item: plan for it rather than treating fieldwork completion as the finish line.

e1, i1, or r2

Version 11 of the CSF aligned HITRUST's validated assessments into a tiered portfolio. Each tier asks for more requirements and more rigorous scoring, and relying parties often specify which one they will accept.

Assessment, Certification validity, Control set, Good fit when comparison
e1 (essentials)1 yearA fixed, foundational set of cybersecurity hygiene requirementsLower-risk vendors, or a first step toward higher assurance
i1 (implemented)1 yearA larger fixed set of leading-practice requirements, scored on implementationCustomers want moderate assurance without a risk-tailored scope
r2 (risk-based)2 years, with an interim assessmentTailored to your risk factors and selected authoritative sources, scored across maturity levelsLarge health systems, payers, or contracts that name r2 explicitly

Requirement counts per tier change between CSF releases, so confirm the current numbers in MyCSF for the version you select. Before committing, ask your key customers which assessment they accept; buying an r2 when an i1 would satisfy every contract is an expensive mistake, and the reverse can cost a renewal.

Scoring and maturity

The r2 evaluates requirements against a maturity model built on five levels: policy, procedure, implemented, measured, and managed. A control that works in practice but has no written procedure scores lower than you might expect. The e1 and i1 concentrate on whether requirements are implemented. Where scores fall short, HITRUST requires corrective action plans (CAPs) with owners and dates, which are tracked through to closure.

Inheritance: do less work twice

HITRUST's inheritance program lets you pull in results from service providers that hold their own HITRUST assessments, such as major cloud platforms, for requirements they perform on your behalf. Inherited requirements still need to be mapped to your scope, and shared requirements still need your half tested. Identifying inheritance candidates early in MyCSF can meaningfully reduce the number of requirements your assessor tests directly.

Timeline from decision to certificate

  1. Confirm the target assessment with customers and contracts.
  2. Define scope in MyCSF: systems, facilities, and organizational units, plus risk factors for an r2.
  3. Run a readiness assessment to identify gaps; many organizations use an external assessor for this step too.
  4. Remediate and let controls operate. HITRUST expects remediated controls to run for a defined period before validated testing, so fixes made the week before fieldwork are unlikely to count.
  5. Validated assessment fieldwork by the external assessor, including sampling and evidence review.
  6. HITRUST quality assurance and issuance of the report and certification, followed by CAP tracking and, for r2, the interim assessment.

Evidence packages assessors test

Maturity level, Evidence example comparison
PolicyApproved, dated policy statement covering the requirement, with review history
ProcedureDocumented steps, roles, and frequency, such as an access review procedure
ImplementedSystem configurations, tickets, logs, and samples showing the control operating across the scope
MeasuredMetrics or tests that check whether the control is effective
ManagedRecords of acting on those metrics: trend reviews, fixes, and improvement decisions

Pitfalls to plan around

  • Scoping too broadly, so every corporate system is subject to requirements meant for the platform that stores PHI.
  • Policies that say "annually" while evidence shows a review two years ago.
  • Underestimating QA turnaround and letting a prior certification lapse.
  • Forgetting the r2 interim assessment, which is required to keep the two-year certification valid.
  • Assuming a HIPAA risk analysis alone satisfies HITRUST's risk management requirements.

How Asurvo fits a HITRUST program

Asurvo supports the HITRUST CSF alongside HIPAA, ISO 27001, NIST SP 800-53, and PCI DSS with automated cross-mapping, so a single access review or vulnerability scan is credited wherever it applies. The evidence library tracks versions, approvals, and expiry dates, which helps keep policy and procedure evidence current through a two-year cycle, and the audit workspace tracks assessor requests and CAPA through remediation. Healthcare teams can see the broader picture on the healthcare industry page.

FAQ

Frequently asked questions

Is HITRUST required by HIPAA?

No. HIPAA does not require HITRUST certification. HITRUST is a voluntary framework and assurance program, but many healthcare organizations require it contractually from vendors because it gives them an independently validated, standardized view of a vendor's controls, including controls that address HIPAA Security Rule expectations.

What is the difference between HITRUST e1, i1, and r2?

They are tiers of validated assessment. The e1 covers foundational cybersecurity requirements and the i1 a broader fixed set of leading practices; both certifications last one year. The r2 is tailored to the organization's risk factors, scored on a five-level maturity model, and valid for two years with an interim assessment in between.

Can a HITRUST assessment be done without an external assessor?

Readiness or self-assessments can be completed internally in MyCSF, but they do not result in certification. Validated assessments that lead to e1, i1, or r2 certification must be performed by an authorized HITRUST External Assessor firm, and results are reviewed by HITRUST's quality assurance team before the report is issued.

How does inheritance work in HITRUST?

If a service provider you rely on has its own HITRUST assessment, you can request to inherit its scores for requirements it performs for you, through MyCSF. This reduces testing for requirements fully handled by the provider. Shared requirements still need your portion evidenced, and inheritance only applies where the provider's assessment covers the relevant services.

Does ISO 27001 or SOC 2 work carry over to HITRUST?

Much of it does. HITRUST incorporates ISO, NIST, and other sources, so controls and evidence from an ISO 27001 or SOC 2 program often address a large portion of HITRUST requirements. The main extra effort tends to be healthcare-specific requirements, maturity documentation for an r2, and meeting HITRUST's own evidence and scoping rules.

Ready to run HITRUST on Asurvo?

Book a walkthrough and see the framework live.