Photo: Unsplash
HITRUST compliance checklist
HITRUST is the most prescriptive framework in this space, and that cuts both ways. Unlike SOC 2, where you design your own controls, HITRUST hands you specific requirement statements you must satisfy. There is far less ambiguity about what to build, and far less room to argue your way out of a gap.
This checklist covers the decisions that determine how much work you are taking on, the domains you will be assessed against, and how the scoring model actually decides whether you certify.
Key takeaways
- HITRUST publishes the CSF, a framework that harmonises HIPAA, ISO 27001, NIST, PCI DSS and others into one set of requirement statements, so one assessment can evidence several obligations.
- There are three assessment types. e1 covers 44 requirement statements, i1 covers 182, and r2 is tailored by risk factors and commonly runs into the hundreds.
- Only r2 uses the full maturity model. e1 and i1 are scored on implementation alone, which is why they are dramatically less work.
- A certification requires validation by a HITRUST Authorized External Assessor. You cannot self-certify.
- e1 and i1 certifications are valid for one year. r2 is valid for two, with an interim assessment in between.
What HITRUST actually is
Three things get conflated, so it is worth separating them:
- The HITRUST CSF is the framework: a library of control requirements mapped to dozens of underlying authoritative sources.
- MyCSF is the platform you must use. Assessments are scoped, scored, evidenced and submitted through it. This is not optional and it carries a subscription cost.
- HITRUST certification is the outcome, issued by HITRUST itself after an Authorized External Assessor validates your assessment and HITRUST performs its own quality review.
The reason healthcare buys into this: HIPAA tells you to be reasonable and appropriate without telling you what that means. HITRUST turns that into testable requirement statements, which is why health systems and payers increasingly ask vendors for it by name rather than accepting a HIPAA self-attestation.
Step 1: choose your assessment type
This is the decision that determines your cost and timeline. Choose wrong and you either overspend or produce a certificate your customer does not accept.
| e1 | i1 | r2 | |
|---|---|---|---|
| Full name | Essentials, 1-year | Implemented, 1-year | Risk-based, 2-year |
| Requirement statements | 44 | 182 | Tailored, commonly 300 or more |
| Scoring | Implementation only | Implementation only | Full maturity model |
| Tailored to your risk? | No, fixed set | No, fixed set | Yes, via risk factors |
| Validity | 1 year | 1 year | 2 years, with interim assessment |
| Typical effort | Months | 4 to 8 months | 9 to 18 months |
| Use when | Lowest-risk vendors, or establishing a baseline | The common middle choice for SaaS vendors to healthcare | A large customer contractually requires r2, or you handle high volumes of sensitive data |
Practical guidance: ask your customer which one they will accept, in writing, before you scope anything. Many vendors assume r2 is required because it is the most recognised, spend a year on it, and discover an i1 would have closed the deal. Equally, some large health systems will only accept r2, and an i1 in that situation is a wasted year.
Step 2: scope the assessment in MyCSF
Scoping happens inside MyCSF and is driven by risk factors you declare about your organisation and system:
- Organisational factors: size, revenue, number of records held
- System factors: whether the system is internet-facing, whether it transmits or stores sensitive data, transaction volumes, number of interfaces
- Regulatory factors: which regimes apply, such as HIPAA, HITECH, state privacy laws, PCI DSS
For r2, these factors directly determine how many requirement statements you are assessed against. Declaring a broader scope or higher-risk profile than you need is the most common self-inflicted cost increase in HITRUST.
Checklist for this step:
- System boundary defined and documented, including which environments and data stores are in scope
- Risk factors answered accurately and defensibly, since your assessor will challenge them
- Inheritance identified where you rely on an underlying provider that holds its own HITRUST certification, which can reduce your evidence burden materially
- Scope agreed with your external assessor before you begin remediation
Step 3: work the 19 assessment domains
HITRUST organises requirements into 19 assessment domains. Your score is calculated per domain, and a weak domain can block certification even if your overall average looks healthy.
| Domain | What it covers | Where vendors commonly fall short |
|---|---|---|
| Information Protection Program | Governance, programme structure, risk management | Programme documented but not demonstrably operating |
| Endpoint Protection | Malware defence, device hardening | Coverage gaps on contractor devices |
| Portable Media Security | Removable media controls | No policy enforcement, only a policy |
| Mobile Device Security | MDM, BYOD controls | Personal devices accessing data outside MDM |
| Wireless Security | Wireless network controls | Guest network segregation |
| Configuration Management | Baselines, change control | No documented hardening baseline |
| Vulnerability Management | Scanning, patching, remediation SLAs | Scanning without tracked remediation |
| Network Protection | Segmentation, perimeter, monitoring | Flat internal networks |
| Transmission Protection | Encryption in transit | Legacy integrations without TLS |
| Password Management | Authentication controls | Service accounts exempt from policy |
| Access Control | Authorisation, least privilege | Access reviews not performed on cadence |
| Audit Logging and Monitoring | Log generation, retention, review | Retention period undefined, logs never reviewed |
| Education, Training and Awareness | Security and privacy training | Completion not tracked to individuals |
| Third Party Assurance | Vendor risk management | Vendor register with no assessments |
| Incident Management | Detection, response, reporting | No evidence of the plan being exercised |
| Business Continuity and Disaster Recovery | Continuity planning, testing | Plan exists, test never performed |
| Risk Management | Risk assessment and treatment | Assessment performed once |
| Physical and Environmental Security | Facility controls | Cloud-hosted vendors ignoring office controls |
| Data Protection and Privacy | Privacy controls, data handling | No record of data flows |
Step 4: understand how scoring works
This is the part that surprises people, and it is the single biggest difference between HITRUST and every other framework here.
e1 and i1: implementation only
Each requirement statement is evaluated on whether it is implemented. Straightforward, and closer to how a SOC 2 auditor thinks.
r2: the full maturity model
Each requirement statement is scored across five maturity levels:
- Policy. Is the requirement stated in an approved policy?
- Procedure. Is there a documented procedure describing how it is carried out?
- Implemented. Is it actually in place and operating?
- Measured. Do you measure whether it is working, with metrics?
- Managed. Do you act on those measurements to improve?
The consequence is that a control can be fully implemented and still score poorly. If it works in production but is not written into a policy, has no documented procedure, and nobody measures it, three of the five levels score low. Domain scores are calculated from these levels, and HITRUST requires each domain to reach a defined threshold for certification.
This is why r2 is so much heavier than it first appears. Levels 4 and 5 in particular demand a measurement and improvement discipline that many otherwise well-run security programmes simply do not have.
Gaps become Corrective Action Plans (CAPs). A small number of CAPs will not necessarily block certification, but each needs an owner, a remediation plan and a date, and they are followed up.
Step 5: external assessor validation
- Select a HITRUST Authorized External Assessor. Only firms on HITRUST's authorised list can validate an assessment.
- Run a readiness assessment first. This is a self-assessment in MyCSF, ideally reviewed by your assessor, and it tells you your likely score before you pay for validation. Skipping it is how organisations discover a failing domain during the validated assessment.
- Remediate, then generate evidence. For r2, remember that levels 4 and 5 need a measurement history, so leaving remediation until the last month caps your score regardless of what you fixed.
- Validated assessment. Your assessor tests requirement statements and reviews evidence.
- HITRUST quality assurance review. HITRUST performs its own QA on the submitted assessment. This step takes weeks and can send items back.
- Certification issued, and listed if you choose.
Timeline and cost
| e1 | i1 | r2 | |
|---|---|---|---|
| Readiness to certification | 2 to 4 months | 4 to 8 months | 9 to 18 months |
| Cost drivers | MyCSF subscription, assessor fees | MyCSF, assessor fees, remediation | MyCSF, assessor fees, remediation, measurement programme |
| Relative total cost | Lowest | Moderate | Several times an i1 |
Costs to budget for in all three cases: the MyCSF subscription, external assessor fees, internal effort, and remediation. For r2, add the cost of building measurement and improvement practices that may not exist today.
Note the renewal cadence: e1 and i1 require annual recertification, so the cost recurs yearly rather than being a one-off.
Where HITRUST projects go wrong
- Choosing r2 when the customer would accept i1. Confirm in writing first.
- Scoping risk factors too broadly, inflating the requirement count for no commercial benefit.
- Treating r2 like SOC 2. Implementing controls without policies, procedures, metrics and improvement evidence caps your maturity score.
- Leaving remediation late. Levels 4 and 5 need history, and history cannot be backdated.
- Skipping the readiness assessment. Paying for validation without knowing your score is an expensive way to find a failing domain.
- Ignoring one weak domain. Per-domain thresholds mean a single neglected area can block certification.
- Forgetting the annual renewal. e1 and i1 lapse after a year, and a lapsed certificate can breach a customer commitment.
How SecureSlate helps
SecureSlate maintains one control set mapped across frameworks, so the policies, procedures and evidence behind a HITRUST domain also serve your SOC 2 and ISO 27001 obligations. Access reviews, vendor assessments, training completion and vulnerability remediation are tracked continuously with dated records, which is what the higher maturity levels require and what teams most often cannot produce retroactively.
Related guides:
- 9 practical benefits of HITRUST certification
- SOC 2 compliance checklist
- ISO 27001 checklist
- Access review template
- Risk assessment template
FAQ
What is the difference between e1, i1 and r2?
e1 assesses 44 requirement statements, i1 assesses 182, and both are scored on implementation only. r2 is tailored to your declared risk factors, commonly covers several hundred requirement statements, and is scored across the full five-level maturity model. e1 and i1 certifications last one year; r2 lasts two with an interim assessment.
Can we self-certify HITRUST?
No. You can perform a readiness self-assessment in MyCSF, but certification requires validation by a HITRUST Authorized External Assessor followed by HITRUST's own quality review.
Is HITRUST required for HIPAA compliance?
No. HIPAA does not require HITRUST or any certification. HITRUST is a voluntary framework that many covered entities and business associates use to demonstrate HIPAA-aligned controls, and some health systems require it contractually from vendors.
Does HITRUST replace SOC 2?
Not usually. They serve different audiences, and many vendors are asked for both. There is substantial control overlap, so a single well-maintained control set can support both assessments.
How long does HITRUST certification last?
e1 and i1 certifications are valid for one year. r2 certifications are valid for two years, with an interim assessment at roughly the one-year mark.
Do we have to pay for MyCSF?
Yes. Assessments are scoped, scored and submitted through MyCSF, and the subscription is a required cost separate from your assessor fees.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory, or professional advice. HITRUST CSF requirements, assessment types, and scoring rules are revised over time; verify current details against official HITRUST guidance and the CSF version applicable to your assessment. Consult a HITRUST Authorized External Assessor and qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds
