What HITRUST CSF is
The HITRUST CSF is a security and privacy control framework maintained by HITRUST. It draws requirements from many authoritative sources, such as HIPAA, NIST publications and ISO standards, into one control set. HITRUST also runs an assurance program in which an authorized external assessor validates controls and HITRUST reviews the work before issuing a certification.
Organizations that handle sensitive data, especially health information, often pursue HITRUST certification because customers ask for it. Health systems and payers use it to review vendors, and one certification can answer several customer questionnaires. The framework itself is not a law, and adopting it does not on its own establish compliance with every source it draws from.
Key facts
Three assessment types
e1, i1 and r2 offer increasing levels of assurance. The right one depends on what your customers ask for and on your risk profile.
MyCSF
HITRUST's platform for scoping assessments, recording control results, attaching evidence and submitting work for review.
Authorized external assessor
A validated assessment is performed by an External Assessor organization authorized by HITRUST. HITRUST then performs quality assurance and issues the result.
Readiness assessment
Organizations can run a readiness or self-assessment in MyCSF before the validated assessment to find gaps early.
Inheritance
Where a service provider holds a HITRUST certification, some control results can be inherited through HITRUST's inheritance program. Your own configuration still needs evidence.
Corrective action plans
Gaps found during a validated assessment may need corrective action plans, which HITRUST expects to be tracked to completion.
How the work runs with us
We help define the systems, facilities, data and teams in scope and confirm which assessment type your customers expect. We identify service providers whose controls may be inherited. You receive a scope statement and a plan with dates.
We compare current controls with the HITRUST requirements for your chosen assessment, often using a readiness assessment in MyCSF. For r2 we also review policy and procedure documentation, because those are scored. Each gap is recorded with its risk and the effort to close it.
We turn the gaps into a prioritized remediation plan. Our engineers implement or improve technical controls such as access control, logging, vulnerability management, encryption and backups. We write or update policies and procedures where needed.
We organize evidence by requirement so it is ready to load into MyCSF, and test selected controls before fieldwork. During the validated assessment we help your team answer assessor requests and work through corrective action plans. Retainers are available for interim assessments and ongoing support.
What you receive
Each engagement has a fixed scope agreed in writing. The deliverables below are typical. The exact set depends on your scope.
Scope and approach
- Scope statement for systems, sites and data
- Recommended assessment type with reasoning
- Inheritance candidates listed
Gap assessment
- Status for each requirement in scope
- Gaps ranked by risk and effort
- Owner suggested for each item
Remediation
- Prioritized remediation plan
- Controls implemented by our engineers
- Policies and procedures written or updated
Evidence
- Evidence organized by requirement
- Control test results before fieldwork
- Support during assessor requests
Control areas we help implement
These areas appear across HITRUST assessment types. We work inside your existing systems where possible.
Access control and identity
Single sign-on, multi-factor authentication, least privilege and access reviews. We can deploy Keycloak privately where it fits.
Logging and monitoring
Central logging, alerting and log review records. We can deploy Wazuh privately where it fits.
Vulnerability management
Scanning, patch timelines and exception tracking. Penetration testing supports requirements for technical testing.
Encryption
Encryption at rest and in transit, with key management recorded.
Incident response
Incident plan, roles and exercises. We also offer incident response training.
Backup and recovery
Backup coverage, restore tests and business continuity plans.
Vendor risk
Third-party inventory, security reviews and contract requirements.
Policies and procedures
Written policies and procedures that match how controls operate, which matter most for r2 scoring.
HITRUST e1, i1 and r2 compared
A summary based on HITRUST's published descriptions. Requirements change between CSF versions, so confirm current details with HITRUST and your assessor.
| Topic | e1 | i1 | r2 |
|---|---|---|---|
| Purpose | Essential cybersecurity hygiene | Leading security practices | Risk-based, expanded assurance |
| Control set | Smallest fixed set | Larger fixed set | Tailored to your risk factors and selected regulatory sources |
| What is evaluated | Implementation of controls | Implementation of controls | Maturity of policy, procedure and implementation, with optional measured and managed levels |
| Certification validity | One year | One year | Two years, with an interim assessment in the first year |
| Typical fit | Startups and lower-risk vendors | Organizations needing moderate assurance | Organizations handling higher-risk data or with customers who require r2 |
Who does what
We scope the work, assess gaps, implement agreed controls, write or update policies, organize evidence and test controls before fieldwork. Your team owns the controls, runs them day to day and approves what goes into MyCSF.
We do not issue HITRUST certifications and do not perform the validated assessment. An External Assessor organization authorized by HITRUST performs the assessment, and HITRUST reviews it and issues the certification. We work alongside your assessor and your compliance platform, and we do not promise any assessment outcome.
Common questions
How long does it take?
It depends on the assessment type, the size of the scope and how much remediation is needed. We agree a plan with dates during scoping. HITRUST also sets its own steps for review after the assessor submits.
Which assessment should we choose?
Start with what your customers ask for. We compare that with your risk profile and current controls and recommend an assessment type during scoping. Your team makes the final choice.
Can you be our external assessor?
No. We provide readiness and implementation support. The validated assessment must be performed by an External Assessor organization authorized by HITRUST, which you engage directly.
Can we inherit controls from our cloud provider?
Often, if the provider participates in HITRUST's inheritance program for the services you use. We help identify inheritable controls and the evidence your own configuration still needs.
Can you sign an NDA?
Yes. We sign an NDA on request before reviewing documents or systems.
Do you help after certification?
Yes. Engagements have a fixed scope, and we offer retainers for corrective action plans, interim assessments and evidence upkeep.
How to prepare
Gather current policies and procedures, a list of systems and sites in scope, network and data flow diagrams, a list of key vendors and any certifications they hold, and recent audit, risk assessment or penetration test reports.
Note which customers asked for HITRUST and which assessment type they named. Tell us whether you already have a MyCSF subscription or an assessor selected, and name owners for identity, infrastructure, security operations and vendor management.

