HITRUST
Become a leader in compliance with HITRUST certification.
HITRUST empowers organizations in highly regulated industries to build and demonstrate a mature cybersecurity and compliance strategy. As one of the top assessors in the world, we’ve helped over three hundred clients successfully achieve HITRUST certification.
We can help you during any part of your HITRUST journey.

Proactive, strategic audit harmonization
The HITRUST CSF is the only comprehensive, prescriptive security framework that pulls from over 50 authoritative security standards and is proven to reduce risk.
Pursuing HITRUST with A-LIGN enables organizations to:
- Differentiate in highly regulated and saturated markets as leaders in security and compliance.
- Reduce overall audit fatigue with an expert compliance partner to sync timelines and minimize redundancies.
- Choose from three levels of HITRUST certification, tailored to the organization’s size, complexity, and needs.
Your dedicated resource for HITRUST AI services
As AI adoption accelerates, the need for responsible governance and risk management becomes crucial. HITRUST’s AI Risk Management Assessment and AI Cybersecurity Assessment provide structured approaches to evaluate and manage AI-related risks, ensuring secure, transparent, and ethical AI practices for organizations across all sectors – not just healthcare.
HITRUST services
Readiness assessment
We examine your organization’s environment and flow of data between systems that are in-scope, identify gaps for control, and provide recommendations for remediation.
Validated 1-Year (e1) Assessment
The e1 is the cybersecurity essentials assessment with 44 control requirements and is meant for low-risk organizations that want to ensure they are maintaining good cybersecurity hygiene.
Implemented 1-Year (i1) Assessment
The i1 Assessment is suitable for moderate assurance and results in a 1-year certification if requirements are met. There are 219 static controls in an i1 Assessment and only the Implemented maturity is tested. Once your assessment has been submitted to myCSF, we will review, validate and submit the assessment to HITRUST for approval.
Risk-Based 2-Year (r2) Assessment
This validated assessment focuses on a comprehensive risk-based specification of controls with a very rigorous approach to evaluation, suitable for high assurance requirements. A minimum of three of five maturities must be addressed during the r2 Assessment, Policy, Process, and Implemented. This certification is issued for two years with an Interim Assessment required during the one-year anniversary of the certification. Similar to the i1 Assessment, we will review and validate your assessment scores and will submit your final assessment to HITRUST for approval.
Interim assessment testing
If an r2 assessment was completed we will test a subset of requirements including 19 controls from the prior r2 assessment and determine the progress of any Corrective Action Plans. This ensures the ongoing effectiveness of those controls to identify and document any scope changes that may impact your HITRUST certification.
HITRUST risk & advisory services
The
HITRUST AI security assessment
This assessment helps organizations manage AI-related cybersecurity risks and integrates with HITRUST e1, i1, and r2 assessments via the “Cybersecurity for AI Systems” compliance factor in MyCSF. Based on ISO/IEC 23894:2023 and the NIST AI Risk Management Framework, it includes 51 controls for AI governance.
The assessment provides a report with strengths and improvement areas, adaptable for various AI stages, supporting self-assessment or HITRUST validation.
HITRUST AI risk management assessment
This assessment provides a structured approach to managing AI-related risks, supporting responsible AI governance. The HITRUST AI Security Assessment includes tailored controls for AI challenges, based on multiple authoritative sources, and allows control inheritance from AI solution providers.
Why A-LIGN
As one of the top HITRUST assessors in the market and a leader in HITRUST AI certifications,
FEATURED CASE STUDY
HealthBridge Boosts Compliance Program with HITRUST Certification
If you’re going to serve patients and healthcare providers, they need to trust that their data is safe. HealthBridge, a healthcare payments organization based in Grand Rapids, Michigan is steadfast in their commitment to protecting the confidentiality, integrity, and availability of sensitive data. To maintain the highest security and privacy standards in their operations, HealthBridge decided to pursue HITRUST r2 Certification with
Get started with A-LIGN
Are you ready to start your compliance journey?