HITRUST Assessment

Aprio is an Authorized External Assessor Organization, conducting validated assessments and submitting to HITRUST for certification. 

Credentials & Frameworks

SOC 1 AICPA
SOC 2 AICPA
SOC 3 AICPA
ISO 27001 Accredited CB
ISO 27701 Accredited CB
ISO 9001 Accredited CB
ISO 22301 Accredited CB
ISO 42001 Accredited CB
PCI DSS QSA
CMMC C3PAO
FedRAMP Independent Assessor
GovRAMP 3PAO
Death Master File Accredited
HIPAA Accredited
C5 Accredited
CCPA Accredited
CSA STAR Cloud Security Alliance
NIST Accredited
IRAP Advisory
DORA Accredited
NIS2 Advisory
ISMAP Advisory
NYDFS Accredited

HITRUST e1.

HITRUST i1. 

HITRUST r2.

Achieve certification across HITRUST compliance tiers

HITRUST certification is one of the most rigorous security credentials in the market. Its also one of the most demanded in healthcare, healthtech, and any industry where customers need assurance that sensitive data is protected, especially Protected Health Information (PHI). But the HITRUST certification requirements are exacting. Between evolving assessment options and extensive documentation, many companies find that the road to certification drains internal resources and focus from core operations.

Aprio is an Authorized External Assessor Organization that conducts validated assessments across all three HITRUST certification tiers. For organizations navigating the full r2 certification, Aprio is a validation partner who understands HITRUST’s scoring process and how to structure the self-assessment so it clears the scoring threshold on the first pass. For organizations earlier in the process, Aprio can help you find the most efficient path to meet your requirements, including:

  • HITRUST e1. Entry-level certification evaluating 44 foundational controls. Annual assessment, implementation evidence only.

  • HITRUST i1. Mid-tier certification covering 182 requirement statements. Full assessment every two years with rapid re-certification in year two. Implementation evidence only, fixed scope.

  • HITRUST r2. The most comprehensive HITRUST certification, covering 230-3,000 requirement statements, depending on scope. Requires evidence of policies, procedures, and implementation. Full assessment every two years with an interim assessment in year two.

  • SOC 2 + HITRUST. A combined approach for organizations that need to demonstrate compliance and satisfy customer requirements at lower cost and complexity than a standalone HITRUST r2.

Our HITRUST Assessment Process

Aprio guides organizations through every stage of the HITRUST validated assessment lifecycle:

  • Readiness Assessment

    An evaluation of your current controls against HITRUST CSF requirements. Identifies gaps before the formal assessment process begins.

  • MyCSF Setup & Configuration

    Configuration of the HITRUST r2 MyCSF platform to match how your controls actually operate, ensuring your self-assessment is structured correctly before validation begins.

  • Corrective Action Plan (CAP)

    The External Assessor evaluates each required CAP for specific quality and feasibility standards, including Specificity, Clarity, and Measurability. You must demonstrate an explicit ability to track and measure progress against the CAP over time.

  • Remediation Support

    Aprio can assist you with the remediation of HITRUST CAPs and/or help with your implementation of the necessary criteria for your HITRUST requirements.

  • Validated Assessment

    Formal assessment conducted by Aprio as a HITRUST Authorized External Assessor. Includes review of your self-assessment, on-site or remote validation, and submission to HITRUST for scoring.

  • HITRUST Certification

    Issued directly by HITRUST once Aprio’s validated assessment is submitted and the scoring threshold is met.

The Two Phases of Compliance

Your Phase

MyCSF Readiness

The quality of your self-assessment in MyCSF sets the pace for everything that follows. Organizations that take time to invest in a thorough, accurate self-assessment and have corrective action plans documented for any gaps can move ahead to the validated assessment much quicker.

Aprio's Phase

Validated Assessment

Once your self-assessment is in order, Aprio’s authorized assessors conduct the full validated assessment, reviewing your self-assessment, testing controls, conducting interviews, and submitting the completed assessment to HITRUST for scoring and certification.

Pursuing multiple frameworks? HITRUST controls overlap with:

Frequently Asked Questions

How long does HITRUST certification take?

Most organizations reach validated assessment readiness in 6–18 months, depending on existing controls, scope complexity, and which certification tier you’re pursuing: e1, i1, or r2.

What is HITRUST CSF?

The HITRUST Common Security Framework (CSF) is a certifiable security and privacy framework that incorporates requirements from HIPAA, NIST, ISO 27001, PCI DSS, and other standards into a single unified control set. It is increasingly required by enterprise customers and regulated industries as proof of security posture.

Who needs HITRUST certification?

HITRUST certification is most commonly required in healthcare and healthtech, where enterprise customers, payers, and business associates require independent validation of security and privacy controls. It has expanded beyond healthcare to any industry where customers handle sensitive data and face regulatory scrutiny, including financial services, technology, and life sciences.

What is the difference between HITRUST and SOC 2?

SOC 2 is an audit report issued by a licensed CPA firm that evaluates controls against the Trust Services Criteria.

HITRUST is a certifiable framework that incorporates requirements from multiple standards including HIPAA, NIST, and ISO 27001, and is issued by HITRUST directly based on a validated assessment.

SOC 2 is more widely required across industries. HITRUST carries more weight in healthcare and highly regulated environments where a single comprehensive credential is preferred over multiple separate certifications.

Six people sit around a table in a modern office, working on laptops and documents, engaged in discussion. Plants and office supplies are on the table.

Let’s talk HITRUST.

Tell us about your organization and what your customers are asking for. We’ll tell you what tier makes sense and what your assessment looks like. Scope Your HITRUST Assessment