Verigo Global
//HITRUST
Healthcare Truste1 · i1 · r2

HITRUST CSF, certified with confidence.

The certifiable trust framework for healthcare information — one control set that harmonizes HIPAA, ISO 27001, NIST, and more. Verigo takes you from scoping and readiness to a validated assessment, and through HITRUST quality assurance to certification itself.

At a glance
Authority
HITRUST Alliance
Protects
PHI & sensitive data
Assessments
e1 · i1 · r2
Typical timeline
6–12 months to certified
40+Authoritative sources harmonized
19CSF control domains
e1 · i1 · r2Three assessment types
2 yrr2 certification validity
Why HITRUST exists

One framework instead of a dozen overlapping mandates.

Healthcare organizations face a tangle of overlapping obligations — HIPAA, ISO 27001, NIST, PCI DSS, and more — each with its own language and evidence. The HITRUST CSF harmonizes all of them into a single certifiable control set, so you implement once and demonstrate alignment to many.

Crucially, HITRUST is certifiable and independently validated — not a self-attestation. An authorized External Assessor tests your evidence and HITRUST itself performs quality assurance before certification, giving buyers objective proof rather than a promise.

For health-tech vendors, IT contractors, and anyone supporting HIPAA-covered entities, a HITRUST credential has become the credential vendor-risk teams ask for by name.

Why it carries weight

Validated, not self-declared.

A validated HITRUST assessment is tested by an authorized External Assessor and quality-assured by HITRUST before any certification is granted. That two-stage independence is exactly why a HITRUST report answers vendor-risk diligence where a self-attestation cannot.

PHI

Protected Health Information — the patient data HIPAA-covered entities and their partners are bound to safeguard.

CSF

Common Security Framework — the harmonized, certifiable control set that maps to 40+ authoritative sources.

The three assessment types

Three credentials. Rising assurance.

HITRUST scales the depth of assessment to the assurance you need. Your customers, data sensitivity, and risk profile decide which credential is right.

e1

Essentials, 1-year

44 requirementsFoundational hygiene

A foundational cybersecurity baseline covering the most critical, high-impact controls. The fastest route to a validated HITRUST credential and a natural entry point before stepping up to i1 or r2.

How it’s assessed
Validated assessment, annual
i1

Implemented, 1-year

182 requirementsLeading practices

A threat-adaptive assessment built around leading security practices and the controls that counter prevalent threats. Substantial assurance with a moderate, predictable lift — the most common starting point for health-tech vendors.

How it’s assessed
Validated assessment, annual
Most recognized
r2

Risk-based, 2-year

300+ tailoredComprehensive assurance

The most rigorous, expandable assessment — control selection scales to your organizational, system, and regulatory risk. The gold-standard credential most healthcare buyers and partners expect.

How it’s assessed
Validated assessment every 2 years, interim at year 1
Coverage

One control set, mapped to many authorities.

The HITRUST CSF harmonizes 40+ authoritative sources into 19 control domains. Implement the framework once and demonstrate alignment across every authority it maps to.

Authorities harmonized
HIPAAISO 27001NIST SP 800-53NIST CSFPCI DSSGDPRSOC 2 (TSC)FedRAMPCIS ControlsCOBIT+ 30 more
The 19 CSF control domains
Information Protection Program
Access Control
Endpoint Protection
Portable Media Security
Mobile Device Security
Wireless Security
Configuration Management
Vulnerability Management
Network Protection
Transmission Protection
Password Management
Audit Logging & Monitoring
Education, Training & Awareness
Third Party Assurance
Incident Management
Business Continuity & DR
Risk Management
Physical & Environmental Security
Data Protection & Privacy
The roadmap to certification

From scoping to certified.

A clear, sequenced path to a validated HITRUST certification — with the remediation and maturity-scoring phases that carry the weight. Durations are indicative for a mid-market environment.

2–3 wks
Scope & select
Define the system boundary and choose the right assessment type — e1, i1, or r2.
3–5 wks
Readiness assessment
Benchmark your environment against every required CSF control and score the gaps.
3–9 mo
Remediate
Implement controls, write policies, and stand up evidence inside MyCSF.
2–4 wks
Maturity scoring
Score each requirement across the five PRISMA maturity levels and close shortfalls.
4–8 wks
Validated assessment
An authorized External Assessor tests and validates your control evidence.
4–8 wks
HITRUST QA & certify
HITRUST performs quality assurance, issues the report, and grants certification.
Seeking certification

If you’re pursuing HITRUST, start here.

A HITRUST credential is won or lost in the decisions you make before remediation begins. Choose the right assessment type and scope, and the path is direct. Get them wrong, and cost and timeline balloon. These are the three things to get right first.

Pick the right assessment type

e1, i1, and r2 differ sharply in scope, effort, and the assurance they convey. Choosing the tier your customers and risk actually require is the single biggest decision — over-reach and you burn months; under-reach and the credential won’t satisfy your buyers.

Scope the boundary and inherit

A tightly defined system boundary keeps the assessment focused on what matters. We help you map where PHI lives and leverage control inheritance from your cloud and service providers so you don’t re-prove controls someone else already owns.

Score maturity honestly, then remediate

HITRUST scores every requirement across five PRISMA maturity levels — policy, procedure, implemented, measured, managed. An honest self-score before validation is worth far more than an optimistic one. We score, prioritize by risk, and close gaps before an assessor arrives.

Outputs

What you walk away with.

Every HITRUST engagement produces the concrete artifacts an assessor and HITRUST QA expect — and a program that keeps generating them long after certification.

Readiness & gap report

An independent benchmark of your environment against the CSF requirements for your chosen tier — gaps scored by risk and effort, with a prioritized remediation roadmap.

Validated MyCSF object

A complete assessment object in the MyCSF platform — every requirement scored across the five PRISMA maturity levels, with evidence mapped requirement by requirement.

HITRUST CSF certification

The validated certification report and letter for your assessment type — the recognized, shareable credential your customers, partners, and regulators expect.

Corrective Action Plans

Tracked, dated CAPs for any requirement not yet fully met, with named owners and target dates — the structured path to closing gaps after validation.

Inheritance & evidence package

Policies, procedures, and configurations organized for reuse — plus the inheritance relationships that cut duplicate effort across cloud and service-provider controls.

HITRUST QA coordination

End-to-end coordination with your External Assessor and the HITRUST quality-assurance review, managing exceptions through to a clean, issued certification.

Client voices

Trusted on the HITRUST journey.

A few words from the security and compliance leaders we’ve guided to a validated HITRUST certification. Illustrative of typical engagements.

Verigo took our r2 from a daunting 300-control wall to a sequenced plan we could actually execute. They scoped the boundary tightly, set up inheritance with our cloud provider, and we cleared HITRUST QA on the first pass.

DR
Dana Reyes
CISO · Regional health-tech platform

We needed a credible credential fast to unblock an enterprise health system deal. Verigo guided us through i1 in under five months and coached our control owners so the validation interviews were a non-event.

MV
Marcus Vale
VP Engineering · Clinical data SaaS vendor

What set them apart was the honesty of the maturity scoring. They told us where we really stood across the PRISMA levels before the assessor ever saw it — no surprises, no scramble at the end.

PN
Priya Nair
Director of Compliance · Healthcare BPO provider
HITRUST questions

Good to know before we start.

Questions on scope, assessment types, or the validated-assessment process? A senior practitioner will walk you through it.

The HITRUST CSF is a certifiable control framework that harmonizes more than forty authoritative sources — including HIPAA, ISO 27001, NIST SP 800-53, NIST CSF, PCI DSS, and GDPR — into a single, prescriptive, and scalable set of control requirements. Rather than reconciling overlapping mandates yourself, you implement one framework and demonstrate alignment to all of them at once.

Trust is the deliverable

Ready to earn your HITRUST certification?

Tell us who you serve and what data you handle. We'll confirm the right assessment type, scope your boundary, and lay out a fixed-price path to a validated HITRUST certification — and through HITRUST QA itself.