HITRUST e1.
HITRUST i1.
HITRUST r2.
Achieve certification across HITRUST compliance tiers
HITRUST certification is one of the most rigorous security credentials in the market. Its also one of the most demanded in healthcare, healthtech, and any industry where customers need assurance that sensitive data is protected, especially Protected Health Information (PHI). But the HITRUST certification requirements are exacting. Between evolving assessment options and extensive documentation, many companies find that the road to certification drains internal resources and focus from core operations.
Aprio is an Authorized External Assessor Organization that conducts validated assessments across all three HITRUST certification tiers. For organizations navigating the full r2 certification, Aprio is a validation partner who understands HITRUST’s scoring process and how to structure the self-assessment so it clears the scoring threshold on the first pass. For organizations earlier in the process, Aprio can help you find the most efficient path to meet your requirements, including:
-
HITRUST e1. Entry-level certification evaluating 44 foundational controls. Annual assessment, implementation evidence only.
-
HITRUST i1. Mid-tier certification covering 182 requirement statements. Full assessment every two years with rapid re-certification in year two. Implementation evidence only, fixed scope.
-
HITRUST r2. The most comprehensive HITRUST certification, covering 230-3,000 requirement statements, depending on scope. Requires evidence of policies, procedures, and implementation. Full assessment every two years with an interim assessment in year two.
-
SOC 2 + HITRUST. A combined approach for organizations that need to demonstrate compliance and satisfy customer requirements at lower cost and complexity than a standalone HITRUST r2.