BlueSteel Cybersecurity

CSF ยท e1, i1, r2

HITRUST

HITRUST is what large health systems ask for when a BAA and a HIPAA risk analysis are not enough. It is prescriptive where HIPAA is not, which makes it more work and also makes it a clearer answer to a customer's security review.

What the engagement covers

Healthcare organisations and their vendors. Typical timeline: 9 to 18 months for r2, less for e1 and i1.

  • Choosing the right assessment type, because e1, i1 and r2 are very different amounts of work and buyers do not always specify
  • Scoping the assessment boundary and the systems in it
  • Control implementation against the CSF requirement statements
  • MyCSF administration and evidence management
  • External assessor coordination through validation

Phases

Where an engagement sits at any point, in the language your assessor uses.

  • Assessment type selection and readiness
  • Control implementation
  • Validated assessment with an external assessor
  • Certification issued

Related reading

Common questions

Which HITRUST assessment do we actually need?

It depends on what the customer asking for it will accept. e1 covers foundational cybersecurity practices, i1 is a moderate assurance assessment, and r2 is the risk based certification most large health systems mean when they say HITRUST. Ask the customer before scoping, because the difference between i1 and r2 is months of work.

Does HITRUST replace HIPAA compliance?

No, but it demonstrates it. HITRUST CSF maps to HIPAA among other authoritative sources, so a HITRUST certification is strong evidence of HIPAA control coverage. The Security Rule risk analysis obligation still stands on its own.

Can we go straight to r2?

You can, and some organisations should. But if the deadline is short, e1 or i1 can satisfy a customer sooner and build the evidence base that makes r2 shorter later.

START HERE

Do not guess how far away you are.

A scored assessment against the HITRUST control set gives you your gap, your timeline and your cost. Fixed price from $15,000, two to four weeks, quoted before any work starts. Most clients then continue into a Virtual CISO engagement or managed compliance, which within 90 days takes 25% off the first year. Nothing obliges you to.

See what an assessment covers

5.0 out of 5

Across 17 verified client reviews on Clutch.

  • Quality 4.9
  • Schedule 5.0
  • Cost 4.9
  • Willing to refer 5.0

Read the reviews

Start with a scope

Bring the deadline and who is asking for it. Thirty minutes.