CSF ยท e1, i1, r2
HITRUST
HITRUST is what large health systems ask for when a BAA and a HIPAA risk analysis are not enough. It is prescriptive where HIPAA is not, which makes it more work and also makes it a clearer answer to a customer's security review.
What the engagement covers
Healthcare organisations and their vendors. Typical timeline: 9 to 18 months for r2, less for e1 and i1.
- Choosing the right assessment type, because e1, i1 and r2 are very different amounts of work and buyers do not always specify
- Scoping the assessment boundary and the systems in it
- Control implementation against the CSF requirement statements
- MyCSF administration and evidence management
- External assessor coordination through validation
Phases
Where an engagement sits at any point, in the language your assessor uses.
- Assessment type selection and readiness
- Control implementation
- Validated assessment with an external assessor
- Certification issued
Related reading
- Placeholder: HITRUST article
Pulled from the legacy archive until this section is migrated.
- Placeholder: HITRUST article
Legacy URL preserved.
Common questions
Which HITRUST assessment do we actually need?
It depends on what the customer asking for it will accept. e1 covers foundational cybersecurity practices, i1 is a moderate assurance assessment, and r2 is the risk based certification most large health systems mean when they say HITRUST. Ask the customer before scoping, because the difference between i1 and r2 is months of work.
Does HITRUST replace HIPAA compliance?
No, but it demonstrates it. HITRUST CSF maps to HIPAA among other authoritative sources, so a HITRUST certification is strong evidence of HIPAA control coverage. The Security Rule risk analysis obligation still stands on its own.
Can we go straight to r2?
You can, and some organisations should. But if the deadline is short, e1 or i1 can satisfy a customer sooner and build the evidence base that makes r2 shorter later.
START HERE
Do not guess how far away you are.
A scored assessment against the HITRUST control set gives you your gap, your timeline and your cost. Fixed price from $15,000, two to four weeks, quoted before any work starts. Most clients then continue into a Virtual CISO engagement or managed compliance, which within 90 days takes 25% off the first year. Nothing obliges you to.
Start with a scope
Bring the deadline and who is asking for it. Thirty minutes.