QAreMed
MenuClose

Comparison

HIPAA vs HITRUST testing

HIPAA is federal law that applies to you by status under 45 CFR 164.104, issues no certificate, and never expires. HITRUST is a certification you buy from a private company, and it expires: one year for e1 and i1, two years for r2. HITRUST's own report template states it is not a certification of HIPAA compliance.

Compared
HIPAA Security Rule and HITRUST certification
Written for
For a CEO
What follows from it
A HITRUST certificate clears a customer's procurement gate on a date you can put in a contract, and it lapses. The HIPAA obligation answers to a regulator, follows ePHI onto every platform that holds it, and cannot be handed to an assessor.

What does each of the two actually do to you?

One is a status you cannot resign from. The other is a dated asset you buy, maintain and can lose. section 164.104 applies Part 164 to a health plan, a health care clearinghouse and a health care provider who transmits health information electronically in connection with a covered transaction, and paragraph (b) applies the standards to a business associate where provided. No filing creates that status and no supplier can take it off you, and what the Security Rule asks of software, safeguard by safeguard is what the status obliges once you have it.

HITRUST reaches you through two signatures. A customer asks for it in a contract, and you sign a subscription agreement with HITRUST Services LLC, a Delaware limited liability company. Neither signature is compelled by any statute. What HITRUST is, who sells it and which of the e1, i1 and r2 you have been asked for is the detail behind that sentence.

The consequence a CEO can act on: failure on the HIPAA side is answered to a regulator and has no end date, while failure on the HITRUST side is answered to a customer on a calendar date that is already in your contract. The two failures arrive from different directions and neither cancels the other.

Who asks for which, and at what moment?

The regulator never asks for HITRUST and the enterprise buyer rarely asks for HIPAA by name. The HITRUST request usually arrives from procurement or from a health plan partner, with a date attached and a deal behind it. The HIPAA question arrives at three moments instead: when a customer's counsel drafts the business associate agreement, when a diligence team opens the technical review before a funding round or an acquisition, and when something goes wrong and OCR asks what you had in place beforehand.

Read the questionnaire literally, because the two requests buy different things. A request for HITRUST is a request for a named third party to have inspected your controls, and only firms on HITRUST's External Assessor list may perform the assessment submitted for certification. A request framed around HIPAA is a request for your own evidence. OCR's FAQ on certifying compliance says of the evaluation at section 164.308(a)(8) that it "can be performed internally by the covered entity or by an external organization that provides evaluations or 'certification' services", and HHS attaches no weight to which of the two you chose.

The supplier question sits underneath both. 45 CFR 160.103 lists quality assurance, data analysis and consulting among the functions that make an outside firm a business associate, so a testing vendor appointed for either exercise is inside that definition the moment it touches records. Our own terms are set out at how we work with protected health information. We sign a Business Associate Agreement before any engagement that touches PHI. We do not need production PHI to test. Environments run on synthetic and de-identified data, and where a test genuinely needs a real-world shape, the route to it is agreed in writing before an environment exists, and de-identification is verified rather than assumed. What to ask a healthcare QA vendor before you appoint one puts those questions in the order a procurement team asks them.

Which of the two expires?

HITRUST does, on a date HITRUST will not move. Certification runs 12 months from the report date for an e1 and an i1 and 24 months for an r2, and the handbook fixes the report date as the date of the Management Representation Letter, so the clock starts at a signature and not at the day the certificate lands. An r2 carries a checkpoint in the middle: the interim assessment is due inside the 90-day window before the one-year anniversary of the certification issuance date, and non-submission by that deadline "will result in suspension and/or revocation of the Assessed Entity's certification." Criterion 15.7.4 reads in full: "HITRUST does not, under any circumstances, extend the expiration date of a HITRUST certification."

Slip the re-assessment and you get a certification gap, during which HITRUST states the entity "is not considered to be HITRUST certified". That is a sentence a customer's vendor management system reads as a renewal blocker, and the only relief is the bridge assessment, which exists for the r2 alone and buys up to 90 days.

HIPAA has no expiry and no renewal. 164.308(a)(8) requires the evaluation to be periodic and sets no interval, no method and no requirement that anybody outside the organisation performs it, so the date is yours to choose and yours to miss. Nobody writes to tell you it is overdue. A company can therefore hold a current HITRUST certificate, publish it, and still have nothing on file against the standard a regulator would cite.

Fixing the two dates in one plan

  1. Write down the HITRUST expiry date as the Management Representation Letter date plus 12 or 24 months.
  2. Book re-assessment fieldwork so it finishes before that date.
  3. Set your own interval for the 164.308(a)(8) evaluation and record why you chose it.
  4. Re-run the evaluation on that interval and after any environmental or operational change affecting the security of ePHI, which is the second trigger the standard names.

What can you buy, and what stays with you whatever you pay?

You can buy the assessment. HITRUST publishes no price for any assessment or certification, and handbook criterion 3.1.9 places the whole envelope on the assessed entity: funding readiness, validation and certification work, internal and external resources, and completing any corrective actions. There are at least two invoices, one for the platform subscription and one for the external assessor, and assessor quotes differ partly because each assessor firm's own annual programme fee to HITRUST is set on that firm's revenue. Budget for the HIPAA side separately, because what a HIPAA testing engagement costs is driven by the addressable safeguard decisions you have to document, and no assessor sets a price for those.

Four things no payment moves, and each one is stated by the party you would otherwise be relying on.

The risk analysis stays in your hands. HITRUST writes that its "CSF assessments are not risk assessments", and it points management at section 164.308(a)(1)(ii)(A) for the analysis itself, which is where the rule already put it.

Coverage stops short of the statute. HITRUST states that its assessments "do not evaluate coverage of or compliance with HIPAA in its entirety", and it names the material it left out of the framework deliberately, including the applicability and definitions sections at 164.302, 164.304, 164.400, 164.402, 164.500 and 164.501.

Responsibility does not transfer with the report. The transmittal letter of HITRUST's own published example report tells the reader that management remains "solely responsible for ensuring the Organization's compliance with any legal and/or regulatory requirements, including HIPAA."

The regulator keeps its freedom to disagree. OCR states that private certifications "do not absolve covered entities of their legal obligations under the Security Rule" and that a certification performed by an external organization "does not preclude HHS from subsequently finding a security violation."

What changes in your testing when the request says HITRUST?

The audience for the evidence changes, and that changes what the evidence has to look like. For HIPAA work the reader is your own evaluation file and, eventually, an investigator: a test result is useful when it names the safeguard, the build and the date, and the HIPAA technical safeguards checklist is the shape that file takes. For HITRUST the reader is an approved external assessor working inside a fieldwork window capped at 90 days, and evidence is attached to individual requirement statements that are scored.

Three consequences for the plan.

Sequencing gets tighter. The assessor inspects documented evidence of control implementation, so a control fixed during fieldwork still needs evidence that it was operating, and the window does not stretch to accommodate a late fix.

Who does the work becomes a rule. Handbook criterion 3.3.5 bars assessor personnel who were involved in implementing or operating your assessed controls in the previous 12 months from working on the validated assessment, and requires a separate team including a separate engagement partner. Criterion 3.3.6 still permits the same firm to do your readiness work, penetration testing and vulnerability scanning.

Test data acquires a contractual boundary that HIPAA does not draw for you. The MyCSF subscription agreement states that customer data "shall not upload PHI", so any screenshot, extract or log going into the platform as evidence has to be de-identified or redacted before it goes in. On the HIPAA side the rule names no test environment at all, and the decision about what data a test environment holds is yours to make and to document. What a HIPAA testing engagement covers and what it hands back sets out the artefacts that serve both readers.

Sources for this page: the HIPAA statements are read in the eCFR text of 45 CFR Part 164 as current to 31 August 2026 and in two HHS OCR guidance pages read on 2 September 2026. The HITRUST statements are read in the HITRUST Assessment Handbook version 1.2, the published example HIPAA Compliance Insights Report, the "HITRUST and HIPAA" white paper of April 2023, the MyCSF Subscription Agreement and the External Assessor Program Options document, all read on 2 September 2026.

What do you settle before you answer the questionnaire?

Five questions, in this order. The first two belong to the customer and the last three to you.

Before you commit to either programme

  1. Ask the customer to name the assessment: e1, i1, r2, or a HIPAA answer with no third party in it.
  2. Ask what date the certificate has to exist by, and whether a readiness report is acceptable at signature.
  3. List the systems that hold ePHI, and mark which ones the proposed assessment boundary would exclude.
  4. Confirm who holds the risk analysis under 164.308(a)(1)(ii)(A) and when it was last updated.
  5. Decide the interval for your 164.308(a)(8) evaluation, because no external party will ever remind you.

The systems you mark at step 3 sit outside the certificate your customer will read and inside the obligation a regulator would examine. Each of them either enters the scope of your 164.308(a)(8) evaluation or carries a written reason for its exclusion. Those two lists are what your evaluation is a statement about, and the certificate says nothing about either of them.

What do buyers ask about this?

A customer's questionnaire asks whether we are HIPAA certified. What do we send?
Nothing with that name on it exists to send. OCR's guidance on misleading marketing claims states that HHS and OCR "do not certify any persons or products as 'HIPAA compliant.'" What answers the question is the periodic evaluation the rule does require at 164.308(a)(8), sent with the scope it covered, the date it ran and the system version behind it. A buyer who wants an outside name on the paper is asking for HITRUST or for an equivalent scheme, so ask them which one before you price anything.
Would a HITRUST certificate help us in an OCR investigation?
HITRUST tells you not to rely on it for that. Its April 2023 white paper states that "at no time should an organization simply submit a HITRUST Assessment, even a comprehensive r2 Assessment, to demonstrate compliance with the HIPAA Security Rule." OCR's own position is that a private certification does not absolve a covered entity of its legal obligations and "does not preclude HHS from subsequently finding a security violation." The certificate answers customers. The rule answers to the regulator.
The deal closes in six weeks. Can we be HITRUST certified by then?
Treat that as unlikely and negotiate the contract wording instead. The assessor's fieldwork window alone runs to a maximum of 90 days for e1, i1 and r2 alike, HITRUST then performs its own quality assurance review before issuing anything, and a self-assessment cannot become a certification at all: it produces a Readiness Assessment Report, which HITRUST states cannot be certified. Ask the customer whether a readiness report plus a dated commitment closes the gate.
We are a business associate, not a covered entity. Does that change either answer?
It changes neither. 45 CFR 164.104(b) applies the Part 164 standards to a business associate where provided, and 164.302 names the business associate alongside the covered entity. 164.308(b)(2) then pushes the same written contract requirement down to your own subcontractors. On the HITRUST side your status is irrelevant, because what binds you there is the customer contract that asked for the certificate.

Which standards does this touch?

Which of our services test it?

What does validating your product actually involve?

Answer four questions about your markets, your product type and its integrations. You get the standards that reach you, the artefacts each one asks you to produce, and which of them a test supplier delivers.