HITRUST Certification & Compliance | HITRUST CSF Requirement
  • Services
    • Links
      • SOC ASSESSMENTS
        • SOC 1
        • SOC 2
      • ISO CERTIFICATIONS
        • ISO 27001
        • ISO 27701
        • ISO 22301
        • ISO 42001
      • HEALTHCARE ASSESSMENTS
        • All Healthcare
        • HITRUST
        • HIPAA
      • Federal Assessments
        • All Government
        • FedRAMP
        • StateRAMP
        • FISMA
        • CMMC
        • NIST 800-171
      • PCI Assessments
        • PCI DSS
        • PCI SSF
      • Cybersecurity
        • Penetration testing
        • Red team services
        • Ransomware preparedness assessment
        • Social engineering
        • Vulnerability assessment service
      • Privacy
        • GDPR
        • CCPA/CPRA
      • International Services
      • Additional Services
        • Microsoft SSPA
        • NIS2 Directive
        • C5 Attestation
        • SOX 404
        • CSA STAR
        • Business Continuity & Disaster Recovery
        • Limited Access Death Master File
    • FEATURED RESOURCES
      • What is SOC 2? Complete Guide to SOC 2 Reports and Compliance

        SOC 2

        Menlo Security reduces evidence collection time by 60% with consolidated audit approach 

        ISO 27001SOC 2

        ISO 42001 Checklist – Prepare for AI Compliance 

        ISO 42001

        CMMC Buyer’s Guide: How To Choose a C3PAO

        CMMC
  • Technology
  • About Us
    • Our Company
    • Meet our team
    • Board of Directors
    • Partners
    • Events
    • Careers
  • Resources
  • A-SCEND Login
  • Careers
CONTACT US

HITRUST

Become a leader in compliance with HITRUST certification.  

HITRUST empowers organizations in highly regulated industries to build and demonstrate a mature cybersecurity and compliance strategy. As one of the top assessors in the world, we’ve helped over three hundred clients successfully achieve HITRUST certification.  

We can help you during any part of your HITRUST journey.  

GET STARTED
Badge HITRUST Dark Background 1 0
About Services Why A-LIGN Resources Case Study

Proactive, strategic audit harmonization

The HITRUST CSF is the only comprehensive, prescriptive security framework that pulls from over 50 authoritative security standards and is proven to reduce risk. A-LIGN defines high quality – from the expertise of our assessors to the thoroughness and accuracy of our audit process, ensuring a smooth path to certification.

Pursuing HITRUST with A-LIGN enables organizations to:

  • Differentiate in highly regulated and saturated markets as leaders in security and compliance.
  • Reduce overall audit fatigue with an expert compliance partner to sync timelines and minimize redundancies.
  • Choose from three levels of HITRUST certification, tailored to the organization’s size, complexity, and needs.

Your dedicated resource for HITRUST AI services

As AI adoption accelerates, the need for responsible governance and risk management becomes crucial. HITRUST’s AI Risk Management Assessment and AI Cybersecurity Assessment provide structured approaches to evaluate and manage AI-related risks, ensuring secure, transparent, and ethical AI practices for organizations across all sectors – not just healthcare.  

HITRUST services

Readiness assessment
e1 Assessment
i1 Assessment
r2 Assessment
Interim assessment testing
HITRUST risk & advisory services
HITRUST AI security assessment
HITRUST AI risk management assessment

Readiness assessment

We examine your organization’s environment and flow of data between systems that are in-scope, identify gaps for control, and provide recommendations for remediation.

Validated 1-Year (e1) Assessment

The e1 is the cybersecurity essentials assessment with 44 control requirements and is meant for low-risk organizations that want to ensure they are maintaining good cybersecurity hygiene.

Implemented 1-Year (i1) Assessment

The i1 Assessment is suitable for moderate assurance and results in a 1-year certification if requirements are met. There are 219 static controls in an i1 Assessment and only the Implemented maturity is tested. Once your assessment has been submitted to myCSF, we will review, validate and submit the assessment to HITRUST for approval.

 

Risk-Based 2-Year (r2) Assessment

This validated assessment focuses on a comprehensive risk-based specification of controls with a very rigorous approach to evaluation, suitable for high assurance requirements. A minimum of three of five maturities must be addressed during the r2 Assessment, Policy, Process, and Implemented. This certification is issued for two years with an Interim Assessment required during the one-year anniversary of the certification. Similar to the i1 Assessment, we will review and validate your assessment scores and will submit your final assessment to HITRUST for approval.

Interim assessment testing

If an r2 assessment was completed we will test a subset of requirements including 19 controls from the prior r2 assessment and determine the progress of any Corrective Action Plans. This ensures the ongoing effectiveness of those controls to identify and document any scope changes that may impact your HITRUST certification.

HITRUST risk & advisory services

The A-LIGN Advisory Team will review your company’s policy and procedure documents and evaluate them against the HITRUST CSF standard. We will share any gaps identified and will remediate those gaps by updating and documenting the policies and procedures accordingly to meet the HITRUST CSF specifications. If your company needs policies and procedures created, we can design and document those appropriately after performing interviews to understand the control environment. We can also assist in documenting non-technical controls such as Risk Assessment, Incident Response, Disaster Recovery, and more.

HITRUST AI security assessment

This assessment helps organizations manage AI-related cybersecurity risks and integrates with HITRUST e1, i1, and r2 assessments via the “Cybersecurity for AI Systems” compliance factor in MyCSF. Based on ISO/IEC 23894:2023 and the NIST AI Risk Management Framework, it includes 51 controls for AI governance.

The assessment provides a report with strengths and improvement areas, adaptable for various AI stages, supporting self-assessment or HITRUST validation. A-LIGN offers readiness assessments and certification submissions to HITRUST.

HITRUST AI risk management assessment

This assessment provides a structured approach to managing AI-related risks, supporting responsible AI governance. The HITRUST AI Security Assessment includes tailored controls for AI challenges, based on multiple authoritative sources, and allows control inheritance from AI solution providers.

Why A-LIGN

As one of the top HITRUST assessors in the market and a leader in HITRUST AI certifications, A-LIGN’s unmatched experience, deep accreditation, and a strong partnership with the HITRUST Alliance serves as a foundation throughout every organization’s compliance journey.  

1k+ HITRUST assessments completed
900+ HIPAA assessments
300+ HITRUST clients certified
5.7k global clients

The A-LIGN team has been awesome. I have recommended A-LIGN more times than I can count.”

James Goff

Head of IT Security at Nuxeo

Achieving HITRUST Certification as quickly and efficiently as possible at a minimal cost was really key for us.”

Jason Wheeler

VP of Cyber and Network Security at HealthBridge

Working with A-LIGN is a partnership. You’re not my vendor. You’re not somebody I tell what to do or you tell me what to do. You’re somebody who cares about my business.”

Angela Loehr Merek

VP of Account Services at Welvie

A-LIGN did a phenomenal job and I was incredibly impressed with the auditing process. Their auditors made it easy for us and Solera has become A-LIGN’s biggest fan!”

Bruce Hoffman

Chief Compliance Officer at Solera Health

The A-LIGN team has been awesome. I have recommended A-LIGN more times than I can count.”

James Goff

Head of IT Security at Nuxeo

Achieving HITRUST Certification as quickly and efficiently as possible at a minimal cost was really key for us.”

Jason Wheeler

VP of Cyber and Network Security at HealthBridge

Working with A-LIGN is a partnership. You’re not my vendor. You’re not somebody I tell what to do or you tell me what to do. You’re somebody who cares about my business.”

Angela Loehr Merek

VP of Account Services at Welvie

A-LIGN did a phenomenal job and I was incredibly impressed with the auditing process. Their auditors made it easy for us and Solera has become A-LIGN’s biggest fan!”

Bruce Hoffman

Chief Compliance Officer at Solera Health

The A-LIGN team has been awesome. I have recommended A-LIGN more times than I can count.”

James Goff

Head of IT Security at Nuxeo

RESOURCES

resource feature What is HITRUST 1 0
Blog

What is HITRUST? Complete Guide to HITRUST Certification

HITRUST
resource feature HITRUST AI security assessment 1 0.png
Blog

The HITRUST AI Security Assessment: Explained

HITRUST
resource feature Welvie 1 0
Case Study

Welvie Leverages Long-Term Partnership to Maintain HITRUST Compliance and Power Growth

HITRUST
FEATURED CASE STUDY

HealthBridge Boosts Compliance Program with HITRUST Certification

If you’re going to serve patients and healthcare providers, they need to trust that their data is safe. HealthBridge, a healthcare payments organization based in Grand Rapids, Michigan is steadfast in their commitment to protecting the confidentiality, integrity, and availability of sensitive data. To maintain the highest security and privacy standards in their operations, HealthBridge decided to pursue HITRUST r2 Certification with A-LIGN.

VIEW CASE STUDY
resource feature HealthBridge 1 0

RELATED SERVICES

HIPAA

SOC 2

ISO 27001

A lign Convergence background

Get started with A-LIGN

Are you ready to start your compliance journey? A-LIGN is ready to assist with any of your compliance, cybersecurity, and privacy needs.

  • Services
  • Software
  • About us
  • Partners
  • Careers
  • ISO Certificate Directory
  • Privacy Policy
  • Cookie Policy
  • Impartiality and Inquiries
  • Terms of Use
  • Sitemap
CONTACT US

Price and Associates CPAs, LLC dba A-LIGN ASSURANCE is a licensed certified public accounting firm registered with the Public Company Accounting Oversight Board (PCAOB). A-LIGN Compliance and Security, Inc. dba A-LIGN is a leading cybersecurity and compliance professional services firm.

A-LIGN 2024. All rights reserved.

  • Services
    • SOC ASSESSMENTS
      • SOC 1
      • SOC 2
    • ISO CERTIFICATIONS
      • ISO 27001
      • ISO 27701
      • ISO 22301
      • ISO 42001
    • HEALTHCARE ASSESSMENTS
      • All Healthcare
      • HITRUST
      • HIPAA
    • Federal Assessments
      • All Government
      • FedRAMP
      • StateRAMP
      • FISMA
      • CMMC
      • NIST 800-171
    • PCI Assessments
      • PCI DSS
      • PCI SSF
    • Cybersecurity
      • Penetration testing
      • Red team services
      • Ransomware preparedness assessment
      • Social engineering
      • Vulnerability assessment service
    • Privacy
      • GDPR
      • CCPA/CPRA
    • Additional Services
      • Microsoft SSPA
      • NIS2 Directive
      • C5 Attestation
      • SOX 404
      • CSA STAR
      • Business Continuity & Disaster Recovery
      • Limited Access Death Master File
  • Technology
  • About Us
    • Our Company
    • Meet our team
    • Board of Directors
    • Partners
    • Events
    • Careers
  • Resources
  • A-SCEND Login
  • Careers
CONTACT US

Notifications