QAreMed
MenuClose

Standard

HITRUST testing requirements and the e1, i1 and r2 assessments

HITRUST is a commercial certification sold by HITRUST Services LLC, a Delaware company, not a regulation. You are being asked for one of three assessments: e1, i1 or r2. A HITRUST certificate lasts one year for e1 and i1 and two years for r2. HITRUST's own report template states the assessment is not a certification of HIPAA compliance.

Issued by
HITRUST Services LLC, a Delaware limited liability company
Edition
HITRUST CSF v11.8.0, available 8 May 2026; Assessment Handbook version 1.2, enforced on submissions from 15 April 2026
Applies in
United States, International
Source
Publisher catalogue entry, checked 2 September 2026

What is HITRUST, and who are you buying it from?

A private company in Texas. The MyCSF Subscription Agreement, the contract an assessed organisation signs, defines the counterparty in one line: "'HITRUST' means HITRUST Services LLC, a Delaware limited liability company." Version 3 of that agreement took effect on 1 August 2025. The Terms of Use adds that the site "is operated by HITRUST, located at 6175 Main St, Suite 400, Frisco, Texas 75034", and puts any dispute under Texas law in the courts of Collin County. HITRUST was founded in 2007 by Daniel Nutkis, who still runs it, and on 17 March 2025 the investment firm Brighton Park Capital announced a growth investment in the business.

HITRUST binds nobody by law. Its own framework documentation places the CSF downstream of legislation: the Introduction to the HITRUST CSF v11.8.0 says on page 5 that the CSF "normalizes security and privacy requirements for organizations, including federal legislation (e.g., HIPAA), federal agency rules and guidance (e.g., NIST), state legislation (e.g., California Consumer Privacy Act), international regulation (e.g., GDPR), and industry frameworks (e.g., PCI, COBIT)". You are bound to it because you signed a subscription agreement and because a customer asked, and by nothing else.

The corporate name is worth getting right in your own contracts, because HITRUST's own documents do not agree on it. The body of the Terms of Use ends "© 2024 HITRUST Alliance. All rights reserved." while the footer of that same page reads "© 2026 HITRUST Services LLC | All rights reserved". The External Assessor Program Options PDF says "© 2024 HITRUST Services Corp.", and the published HIPAA Insights sample report names "HITRUST Alliance, Inc." The authority among these is the subscription agreement, because it is the only one of these documents that is a contract you become party to, and it names HITRUST Services LLC.

Two published descriptions of the framework's size do not reconcile, and you will meet both. The Introduction to the CSF v11.8.0 states on page 5 that the framework "contains 14 control categories, comprised of 49 control objectives and 156 control specifications", and those three figures check out against the table of contents of the framework document itself. HITRUST's overview page instead advertises "2,500+ requirements across 19 domains". Nothing HITRUST publishes maps the 19 assessment domains onto the 14 control categories. For your planning the domain is the unit that matters, because the Assessment Handbook scores certification by domain and samples the interim assessment by domain.

The count of standards the framework absorbs moves depending on which page you read: 75 on page 10 of the Introduction to the CSF v11.8.0, "more than 60" two pages later in the same PDF, "over 70" on the framework page, and "60+" in the site navigation. Quote 75 if you have to quote one, because it is the only figure tied to a named framework version and followed by an enumerated list. Every figure on this page was read on 2 September 2026.

Which of the three assessments have you been asked for?

Ask the customer for the letter and the number, because e1, i1 and r2 differ in the evidence you have to produce and in how long the certificate then lasts. HITRUST's own definitions: the e1 is "HITRUST Essentials, 1-year", covering "fundamental cybersecurity practices, or 'good cybersecurity hygiene'"; the i1 is "HITRUST Implemented, 1-year", which "addresses a broader range of active cyber threats than the e1 assessment"; the r2 is "HITRUST Risk-based, 2-year", which "provides the highest level of assurance for situations with greater risk exposure due to data volumes, regulatory compliance, or other risk factors". A fourth product, the Targeted assessment, is described by HITRUST as "a non-certifiable self-assessment" and answers no customer asking for certification.

The three nest. HITRUST calls them a traversable portfolio: every requirement in the e1 sits inside the i1, and every requirement in the i1 sits inside the r2 baseline.

The requirement counts are version-bound and have already moved once. Advisory HAA 2023-004 of 17 January 2023 introduced the e1 with 44 requirements. Advisory HAA 2025-005 of 18 December 2025 states that "the size of the e1 baseline for v11.7 is 43 requirement statements" and that "the size of the i1 baseline remains 182 requirement statements". The v11.8.0 advisory of 7 May 2026 reworded two baseline requirement statements and did not restate either total; HITRUST's e1 and i1 product pages still showed 43 and 182 when they were read on 2 September 2026. Write the count with the CSF version and the date beside it, every time.

The r2 has no published count, because the set is generated for you: the assessed entity completes a risk-based scoping questionnaire in MyCSF, and "a customized set of HITRUST CSF control references and requirement statements will be generated". Any r2 figure quoted by a consultancy is that consultancy's own sample.

The Yes and No rows in the table below are condensed from the comparison table in chapter 4 of the HITRUST Assessment Handbook version 1.2, which is the page worth reading before you choose. The counts come from advisory HAA 2025-005 of 18 December 2025, the maturity row from handbook chapter 4.2 and the certification averages from criterion 15.1.2. All of it was read on 2 September 2026.

HITRUST e1, i1 and r2 assessments compared on requirement statements, maturity scoring, certification threshold, validity, carve-outs and assessor fieldwork window.
e1i1r2
Requirement statements, CSF v11.743182Generated from your scoping questionnaire
Maturity levels scored per requirement1, Implemented1, Implemented5: Policy, Procedure, Implemented, Measured, Managed
Domain average needed to certify838362
Certificate valid for1 year1 year2 years
Interim assessment requiredNoNoYes, at 12 months
Cloud provider requirements can be carved outYesYesNo
Must use the newest CSF version at creationYesYesNo
Bridge certificate available after expiryNoNoYes
NIST Cybersecurity Framework certification availableNoNoYes
Assessor fieldwork window, maximum90 days90 days90 days

Two of those rows catch technical teams out. Requirements performed by your cloud service providers on your behalf can be excluded from an e1 or an i1 and cannot be excluded from an r2, so moving up to the r2 pulls everything you had inherited back into your own evidence. Only the e1 and the i1 must run against the current CSF version, so an r2 keeps the CSF version it was created under when HITRUST publishes a newer one.

The certification threshold looks backwards until you read the maturity row. The r2, the highest assurance product, certifies at a domain average of 62 while the e1 and i1 need 83. The r2 average is taken across five maturity levels per requirement, from written policy through to measured and managed operation, where the e1 and i1 score only whether the control is implemented. That is where the effort difference between an i1 and an r2 comes from.

A requirement statement is also not one piece of evidence. Criterion 8.1.2 of the handbook states that "regardless of the assessment type or CSF version, ALL evaluative elements in each requirement statement in an assessment must be addressed", and each statement contains one or more enumerated elements. Budget against evaluative elements rather than against the headline 43 or 182.

Does a HITRUST certificate show that you comply with HIPAA?

No, and the clearest statement of that comes from HITRUST. The example HIPAA Compliance Insights Report that HITRUST publishes as its own template says under Limitations of Assurance, on page 24: "This report therefore supports the Organization communicating the status of controls supporting HIPAA Compliance and is not a certification of HIPAA Compliance". Page 14 of the same report says "HITRUST assessments do not evaluate coverage of or compliance with HIPAA in its entirety", because the CSF holds only security and privacy controls while HIPAA reaches further. What HITRUST incorporated is named precisely: portions of 45 CFR part 164, subparts C, D and E.

HITRUST's own white paper goes further. "HITRUST and HIPAA", April 2023, tells organisations on page 7: "At no time should an organization simply submit a HITRUST Assessment ... to demonstrate compliance with the HIPAA Security Rule." The cover of that same 12-page document advertises a "HIPAA-Compliant PROGRAM that Meets Safe Harbor Requirements". HITRUST's Insights Reports marketing page says its HIPAA report helps healthcare organisations "align policies, prepare for audits, and clearly demonstrate regulatory compliance".

Where those sentences disagree, the report template and the body of the white paper are the authority, for a reason you can give a customer in one line: the disclaimer travels with the report your customer receives, and the marketing sentence stays on the website. The marketing pages are the weaker source in a plainer sense as well. On 2 September 2026 HITRUST's own regulatory compliance page was still serving unreplaced placeholder copy, opening with the headline "HITRUST Empowers You to Get Certified lorem".

Three consequences for a digital health company:

  • The obligation stays with you. The transmittal letter of the Insights report states that "Management of the Organization is also solely responsible for ensuring the Organization's compliance with any legal and/or regulatory requirements, including HIPAA."
  • The risk analysis is not covered. HITRUST writes that "HITRUST CSF assessments are not risk assessments" and that management remains responsible for the analysis under section 164.308(a)(1)(ii)(A), which sits among the requirements the HIPAA Security Rule puts on software.
  • Scope decides what the certificate says about you. In HITRUST's own worked example the certified organisation "did not configure the accompanying HITRUST r2 assessment to include consideration of the HIPAA Breach Notification Rule or HIPAA Privacy Rule", and HITRUST tells relying parties to check the scope against the organisation's HIPAA obligations.

Safe harbor is a separate mechanism and it does not run through the certificate. HITRUST's white paper routes it through the NIST Cybersecurity Framework: HITECH as amended by H.R. 7898 asks an organisation to show recognised security practices in place for no less than the previous 12 months, and HITRUST's route to that is the r2 plus the NIST Cybersecurity Framework report, an r2-only paid add-on issued when the NIST-mapped requirements average 70 or higher on each Core Function and Category. Where the request reached you through a customer's security questionnaire rather than from a regulator, how a HITRUST request differs from a HIPAA one covers what that questionnaire is asking for.

An Insights Report is not a second certificate. HITRUST describes the ten of them, covering HIPAA, PHIPA, NIST SP 800-171, CMMC Level 1, Ransomware, NY OHIP, GovRAMP, HICP, HPH CPG and AI Risk Management, as "add-ons that repackage those certified results in the language of specific frameworks".

What does the certificate commit you to after it is issued?

A cycle that does not stop, and a date you cannot move. An e1 or i1 certification report is valid for 12 months from the date of the report and an r2 report for 24 months, and the handbook fixes what the report date is: "the date of the report is the same date as the Management Representation Letter."

The r2 carries a checkpoint in the middle. Chapter 15.4 of the handbook requires an interim assessment to be completed and submitted to HITRUST inside the 90-day window before the one-year anniversary of the certification issuance date, and criterion 15.4.10 repeats the same deadline. It samples one randomly selected requirement statement from each assessment domain plus every requirement statement that resulted in a required corrective action plan, and your external assessor tests all of it. HITRUST then checks four things: that the scope has not changed significantly, that no security events have hit the certified environment, that no maturity scores in the sample have dropped, and that the corrective action plans are progressing. Progress has a number attached: criterion 15.4.9 says that "barring extenuating circumstances, 50% or more of required CAPs must be started and/or complete".

Miss the interim and the certificate goes. Criterion 15.4.10 ends: "Non-submission of an interim assessment by the deadline will result in suspension and/or revocation of the Assessed Entity's certification." An interim submitted with incomplete testing is sent back to the assessor, and if that pushes it past the deadline HITRUST may suspend the certification. If HITRUST concludes at the interim that you no longer meet the requirements, it sends a letter "asking it to remove any references to its HITRUST certification from its literature and website". Advisory HAA 2026-001 of 13 January 2026 announced an option to use an e1 or i1 in lieu of an interim assessment in handbook chapter 15.4; the chapter text published on HITRUST's manual host does not describe how that substitution works, so confirm it with your assessor before you plan around it.

Between assessments you owe HITRUST information. Criteria 3.1.10 and 3.1.11 make the assessed entity responsible for communicating significant changes to the certified environment to HITRUST on a timely basis, and for communicating actual or suspected security events involving that environment to HITRUST and to its external assessor. A breach reportable to a federal or state agency therefore has a third recipient your incident plan probably does not name. HITRUST tracks five statuses for a validated assessment: Not Certified, Certified, Expired, Suspended and Revoked.

The i1 has a lighter second year that the e1 does not. HITRUST samples 60 requirement statements from the parent assessment, including every statement that needed a corrective action plan last time, and if scores are lowered on two or fewer of them the sample is accepted with no further testing in that set. The e1 is never eligible for this rapid recertification, because criterion 15.5.2 excludes any core set of 60 or fewer statements. The i1 rapid recertification also requires an eligible MyCSF subscription.

What does HITRUST cost?

HITRUST publishes no price for anything. No pricing page appears in its sitemap, the product pages route to a contact form, and the blog post that web indexes still title "How Much Does HITRUST Cost? Pricing Guide" returned HTTP 404 on 2 September 2026. Anyone quoting you a HITRUST list price is quoting themselves.

There are at least two bills. The subscription agreement makes you pay the fees in an Order Form for the platform, states that "payment obligations are non-cancelable and Fees paid are non-refundable", and lets HITRUST raise those fees each year on not less than 60 days written notice before the term expires. Separately you pay the external assessor for the fieldwork. Handbook criterion 3.1.9 puts the whole envelope on the assessed entity: funding the assessment effort, "including assessments for readiness, validation and/or certification, internal and/or external resources, and completing any corrective actions". Assessor quotes vary partly because the assessor's own annual programme fee to HITRUST is set on that firm's annual revenue.

Internal effort is the part nobody invoices. The one cost-shaped article on HITRUST's site is a guest post by Sean Dowling of the assessor firm Accorian, dated 22 September 2025, and its estimates are Accorian's rather than HITRUST's: 15 to 20% of subject matter expert time diverted for 6 to 9 months, at least 15% of a full-time equivalent across 4 to 5 key stakeholders, and 60 to 90 days of control operation before final fieldwork. HITRUST's own timeline claims sit on its product pages, and one of them contradicts itself: the e1 page promises assurance in as few as 4 to 6 weeks in its benefits section and around 30 days on average in its FAQ, the i1 page says most companies finish within 6 to 12 months, and no HITRUST page gives a duration for the r2.

What can testing check here, and what can it not?

Testing produces the evidence the external assessor inspects. All three assessment types require an authorised External Assessor to inspect documented evidence to validate control implementation, and that assessor works from HITRUST's own illustrative procedures: criterion 8.1.1 requires external assessors to use them "as the basis for their more detailed assessment Test Plans". Anything a test can demonstrate, such as access control behaviour, transmission protection, logging and the operation of a monitoring control, becomes a scored requirement statement with your evidence attached to it.

Four things testing cannot do here. It cannot produce the certificate, because HITRUST performs its own quality assurance review of the assessor's submission and issues the certification itself. It cannot come from a self-assessment, because a readiness assessment gets no HITRUST quality assurance review and, in HITRUST's words, "cannot be certified". It cannot reach the maturity levels an r2 scores above Implemented, which are written policy and procedure evidence rather than system behaviour. And it cannot be run by whoever built the controls: criterion 3.3.5 bars assessor personnel involved in the implementation or operation of your assessed controls in the prior 12 months from working on your validated assessment, while criterion 3.3.6 lets the same firm do your readiness work, penetration testing and vulnerability scanning.

Test data has a hard boundary in this programme. The MyCSF subscription agreement closes its definition of customer data with the sentence "Customer Data shall not upload PHI", so evidence going into the platform has to be de-identified or redacted first. Where a test team would work inside a system that holds real patient data, the terms come first, and they are raised at how we work with protected health information.

Which artefacts will the assessor ask for?

The assessor asks for the six documents listed below. Settle the scope boundary before any of the other five, because it fixes which facilities and platforms they have to cover. HITRUST describes its assessments as "scoped based on a defined boundary inclusive of specified physical facilities and IT platforms" and instructs relying parties to evaluate that boundary against the organisation's obligations, so your customer can read the boundary and see what you left out of it.

Before you commit to a HITRUST assessment

  1. Ask the customer which assessment they need: e1, i1 or r2, and by what date.
  2. Ask whether the HIPAA Privacy Rule and Breach Notification Rule must be in the scope.
  3. Draw the boundary. List the physical facilities and the IT platforms inside it.
  4. Check your assessor is on HITRUST's External Assessor list, not only on the readiness list.
  5. Remove anyone who built or ran the in-scope controls in the last 12 months from the assessment team.
  6. Get two quotes: one from HITRUST for the platform, one from the assessor for fieldwork.
  7. Put the interim date in the calendar on the day an r2 certificate is issued.

Where does a HITRUST programme come apart?

  • The customer said "HITRUST" and the company bought an e1, while the questionnaire behind the request wanted r2 evidence. The letter and the number are the whole specification, and the certificate names which one you hold.
  • The scope excluded the Privacy Rule and the Breach Notification Rule, which HITRUST permits, and the customer read the scope section of the report.
  • An i1 was upgraded to an r2, and the cloud provider requirements that had been carved out of the i1 came back as the company's own evidence.
  • The interim assessment was treated as a task for month 24. It is due in the 90-day window before month 12, and non-submission suspends or revokes the certificate.
  • Corrective action plans from the validated assessment were parked, and the interim found fewer than half of them started.
  • The consultancy that wrote the policies was engaged for the validated assessment, and criterion 3.3.5 disqualified the team that knew the environment.
  • Evidence was collected per requirement statement rather than per evaluative element, and the assessor returned the sample with elements unaddressed.
  • A reportable security incident went to regulators and customers and not to HITRUST, which criterion 3.1.11 requires.

HITRUST advertises a "99.62% breach-free rate among HITRUST-certified environments" and attributes it to its own 2026 Trust Report, describing what certified organisations reported for 2025. It is HITRUST's own published measure of its own product, and it says nothing about the controls inside your scope.

How do we work alongside a HITRUST assessment?

We are not a HITRUST External Assessor and we neither issue nor influence certificates. What we produce is the technical evidence that sits under the requirement statements an assessor scores, in the form the illustrative procedures expect: executed test cases against the access, transmission, logging and monitoring behaviour of your product, with results tied to a build and a date.

Most of that work overlaps with testing against the HIPAA technical safeguards and with PHI security testing, because the security requirement statements in the e1 and i1 baselines and the HIPAA Security Rule are answered by the same controls. Where the deadline is already fixed by a customer contract, preparing for an audit covers the order to work in when the evidence has to exist before the fieldwork window opens.

Every count, threshold, deadline and quotation on this page was read from HITRUST's own published documents on 2 September 2026: the Assessment Handbook version 1.2, the Introduction to the HITRUST CSF v11.8.0, the numbered advisories at hitrustalliance.net/advisories, the example HIPAA Compliance Insights Report, the "HITRUST and HIPAA" white paper of April 2023 and the MyCSF Subscription Agreement. HITRUST publishes changes to the framework and to the assurance programme only through those numbered advisories, so that index is where to check whether a number here has moved. Two of those documents need care. The Assessment Handbook PDF linked from HITRUST's framework page is version 1.1 and carries a 2024 copyright, while HITRUST quality assurance has enforced version 1.2 criteria on submissions since 15 April 2026, so work from the live version 1.2 text. And advisory HAA 2026-002 is date-stamped 7 May 2026 while its own first sentence says CSF v11.8.0 became available on 8 May 2026, which matters if you are counting the days to a version deadline.

What do you receive?

Scope boundary listing the physical facilities and IT platforms assessed
Tells a relying party what the certificate covers, which HITRUST's own report says they have to evaluate
Evidence for every evaluative element inside each requirement statement
Criterion 8.1.2 requires all elements to be addressed, not the statement as a whole
Policy and procedure documents for each requirement in an r2
Policy and Procedure are two of the five maturity levels an r2 scores per requirement
Corrective action plans carrying a progress status
At the interim the assessor concludes whether half or more of the required CAPs are started or complete
Management Representation Letter
Carries the report date, and the report date is the day the certificate starts running
A HIPAA risk analysis held outside the assessment
HITRUST states its assessments are not risk assessments and leaves that obligation with management

What do buyers ask about this?

Can we run the assessment ourselves?
No. A self-assessment produces a HITRUST Readiness Assessment Report, which HITRUST states cannot be certified and gets no HITRUST quality assurance review. Only a firm on HITRUST's approved External Assessor list may perform the validated assessment that is submitted for certification, and HITRUST issues the certificate itself after reviewing that submission.
Our security consultancy says it does HITRUST. Is that enough?
Check which list the firm is on. HITRUST licenses two kinds of firm, and it states that Readiness Licensees are not authorized to perform validated assessments, which are required for certification. Check the people too: handbook criterion 3.3.5 bars anyone involved in implementing or operating your assessed controls in the previous 12 months from the assessment team.
What happens if we score below the certification threshold?
You get a report and no certificate. HITRUST calls these validated-only reports, and criterion 15.1.3 requires each one to state that certification thresholds were not met. Read on 2 September 2026, the thresholds are a domain average of 83 for the core e1 and i1 requirement statements, and 62 for every requirement statement in an r2.
Do we have to use HITRUST's own platform?
HITRUST publishes no sentence making MyCSF mandatory, and it describes no route around it: scoping, scoring, assessor validation, submission, quality assurance and reporting all happen inside the platform. The MyCSF subscription agreement states that customer data uploaded to the platform must not include PHI.

Which standards does this touch?

Which of our services test it?

What does it get confused with?

What does validating your product actually involve?

Answer four questions about your markets, your product type and its integrations. You get the standards that reach you, the artefacts each one asks you to produce, and which of them a test supplier delivers.