Skip to main content

HITRUST CSF Readiness Checker

The HITRUST Common Security Framework (CSF) is a certifiable framework that provides organizations with a comprehensive, flexible, and efficient approach to regulatory compliance and risk management. This tool evaluates your readiness across access control, HR security, risk management, security policy, endpoint protection, and network protection.

United States
23 Questions
6 Categories
Progress: 0/23

Access Control

0/5

Human Resources Security

0/4

Risk Management

0/4

Security Policy

0/4

Endpoint Protection

0/4

Network Protection

0/2

Access Control

Assessment of user identification, authentication, and access lifecycle management.

20 pts

Q1

Do you enforce unique user identification and authentication for every individual who accesses information systems, with no shared or generic accounts permitted in production?

critical
5 pts

Q2

Do you implement multi-factor authentication for remote access, privileged accounts, and access to systems processing sensitive data (ePHI, PII)?

critical
5 pts

Q3

Do you perform formal access reviews at least quarterly, comparing actual user privileges to authorized privileges, and revoking access that is no longer justified?

high
4 pts

Q4

Do you have a documented provisioning and de-provisioning process that ensures access is granted based on approved requests and removed within 24 hours of termination or role change?

high
3 pts

Q5

Do you enforce password policies that meet HITRUST requirements (minimum 8 characters, complexity, 90-day rotation for non-MFA accounts, lockout after failed attempts)?

medium
3 pts
VertiComply

Build HIPAA-compliant healthcare applications with AI-powered code generation.

Product

Features

Pricing

Tools

Company

About

Blog

Contact

Legal

Privacy

Terms

Compliance

© 2026 VertiComply. All rights reserved.

Built for HIPAA + SOC 2 Type II

About the HITRUST Compliance Checker

This readiness checker scores your organisation against the HITRUST CSF, the certifiable framework most commonly demanded by US health systems and payers of their vendors. HITRUST harmonises HIPAA, NIST, ISO 27001, PCI DSS and others into a single control set organised across 19 domains, then scales the requirement count to the assessment type: e1 for essential cybersecurity hygiene, i1 for a moderate one-year implemented assessment, and r2 for the risk-based two-year certification whose requirement count varies with your risk factors. Scoring here weights the domains that appear most often in r2 findings, and it weights evidence quality heavily — HITRUST scores each requirement on a maturity scale covering policy, procedure, implementation, measurement and management, so an organisation that does the right thing without a written policy and a measurement mechanism still scores poorly.

What this HITRUST assessment covers

The 23-question assessment scores 100 points across 6 weighted categories. Each category reflects a distinct HITRUST control domain.

Access Control · 20 pts · 5 questions

Assessment of user identification, authentication, and access lifecycle management.

Human Resources Security · 14 pts · 4 questions

Evaluation of background screening, agreements, and security awareness training.

Risk Management · 18 pts · 4 questions

Assessment of risk management program, methodology, and vendor risk processes.

Security Policy · 14 pts · 4 questions

Evaluation of security policy coverage, review processes, and exception management.

Endpoint Protection · 16 pts · 4 questions

Assessment of endpoint security, encryption, patching, and configuration management.

Network Protection · 18 pts · 2 questions

Evaluation of network segmentation, intrusion detection, and boundary monitoring.


Common HITRUST compliance gaps

The patterns we see most frequently in HITRUST self-assessments and remediation work. Each is the kind of finding an auditor flags first.

The assessment type was chosen before the driver was understood. e1, i1 and r2 differ by an order of magnitude in effort and in what a customer will accept. Discovering after six months that the health system contract requires r2 is an expensive way to learn this.

Policy and procedure maturity is ignored. HITRUST scores each requirement across five maturity levels, and policy and procedure are two of them. Teams with strong technical implementation routinely score low because nothing is written down and nothing is measured.

Inheritance is not used. Controls satisfied by a cloud provider's own HITRUST certification can often be inherited, substantially reducing scope. Organisations that assess every control from scratch on inheritable infrastructure do a large amount of avoidable work.

Scope is drawn around the company rather than the platform. HITRUST scope should follow the systems and facilities that handle the regulated data in the service being certified. Over-broad scope inflates requirement count and cost.

Corrective action plans are opened without owners or dates. CAPs are a normal part of certification, but they must be specific and tracked. Vague CAPs are themselves a finding.

The interim assessment is forgotten. An r2 certification runs two years with a required interim assessment at one year. Organisations that treat certification as a one-off discover the lapse when a customer asks for a current certificate.


What to do with your HITRUST results

Your score is a starting point — these are the steps that convert the assessment into actionable remediation.

Confirm which assessment type your customers actually require, in writing, before scoping anything.

Map inheritable controls from your cloud provider first — it is the single largest scope reduction available.

Write the policies and procedures that back your technical controls. This is usually the fastest available maturity-score improvement.

Define scope around the specific platform and data flows being certified, not the whole organisation.

Plan for the External Assessor engagement early; validated assessment capacity is limited and lead times affect certification dates.


HITRUST compliance FAQ

What is the difference between HITRUST e1, i1 and r2?

e1 is a one-year assessment covering essential cybersecurity hygiene with a small fixed requirement set. i1 is a one-year implemented assessment with a larger fixed set, aimed at moderate assurance. r2 is the risk-based, two-year certification whose requirement count is tailored by organisational, system and regulatory risk factors, and it is the one large health systems and payers most often require.

Is HITRUST certification required by HIPAA?

No. HHS does not require or endorse any certification, and HIPAA has no certification regime. HITRUST is a market expectation rather than a legal one — but it is a strong one, because many health systems and payers use it to discharge their own vendor due-diligence obligations.

How long does HITRUST certification take?

For r2, commonly nine to eighteen months from readiness work to certification for an organisation without an existing programme, driven mainly by the maturity evidence requirement and External Assessor availability. e1 and i1 are considerably faster. Certification is issued by HITRUST after review of the validated assessment, not by the assessor.

Can we inherit controls from AWS, Azure or Google Cloud?

Yes, where the provider maintains its own HITRUST certification and the control is genuinely their responsibility under the shared responsibility model. Inheritance is configured in MyCSF and can remove a meaningful share of the assessment burden, particularly across physical, environmental and infrastructure controls.

Build it instead of buying it

Generate a HITRUST-compliant healthcare app with the controls built in

VertiComply generates production-ready healthcare applications with HITRUST controls scaffolded from the first commit — no add-on tier, no platform lock-in, code exported to your GitHub.

Start free