Welvie Leverages Long-Term Partnership for HITRUST Compliance
  • Services
    • Links
      • SOC ASSESSMENTS
        • SOC 1
        • SOC 2
      • ISO CERTIFICATIONS
        • ISO 27001
        • ISO 27701
        • ISO 22301
        • ISO 42001
      • HEALTHCARE ASSESSMENTS
        • All Healthcare
        • HITRUST
        • HIPAA
      • Federal Assessments
        • All Government
        • FedRAMP
        • StateRAMP
        • FISMA
        • CMMC
        • NIST 800-171
      • PCI Assessments
        • PCI DSS
        • PCI SSF
      • Cybersecurity
        • Penetration testing
        • Red team services
        • Ransomware preparedness assessment
        • Social engineering
        • Vulnerability assessment service
      • Privacy
        • GDPR
        • CCPA/CPRA
      • International Services
      • Additional Services
        • Microsoft SSPA
        • NIS2 Directive
        • C5 Attestation
        • SOX 404
        • CSA STAR
        • Business Continuity & Disaster Recovery
        • Limited Access Death Master File
    • FEATURED RESOURCES
      • What is SOC 2? Complete Guide to SOC 2 Reports and Compliance

        SOC 2

        Menlo Security reduces evidence collection time by 60% with consolidated audit approach 

        ISO 27001SOC 2

        ISO 42001 Checklist – Prepare for AI Compliance 

        ISO 42001

        CMMC Buyer’s Guide: How To Choose a C3PAO

        CMMC
  • Technology
  • About Us
    • Our Company
    • Meet our team
    • Board of Directors
    • Partners
    • Events
    • Careers
  • Resources
  • A-SCEND Login
  • Careers
CONTACT US

Welvie Leverages Long-Term Partnership to Maintain HITRUST Compliance and Power Growth

by: A-LIGN 5 min

HITRUST

  • SHARE
cs welvie 1 0

Welvie is a health care decision-support company. Its platform offers online health education, data services, and consumer outreach to national and regional health insurance companies and third-party administrators (TPAs). Since Welvie was founded in 2008, security and compliance have become important considerations as expectations from clients and the growing threat environment increased.

With limited resources and a distributed workload, Welvie formed a dedicated team to oversee compliance and security. Their commitment to continuous improvement led them to establish a robust security and compliance program and pursue HITRUST Certification.

With their partnership with A-LIGN, Welvie has implemented technical controls and streamlined their processes to become a high-scoring organization within the HITRUST framework.

The Challenge: Seeking an Experienced Partner for Long-Term Growth

Prior to A-LIGN, Welvie worked with another Third Party Assessment Organization (3PAO) to achieve HITRUST Certification. However, after the initial certification, they searched for an assessor that could better serve their unique needs to fortify their compliance program, including:

  • Extensive Framework Knowledge: Because Welvie started pursuing HITRUST Certification when it was still new, other third-party assessors did not have a comprehensive understanding of the framework that A-LIGN provides.
  • Support in an Increasing Threat Landscape: With a heightened risk of attack in this digital age, Welvie needed a trusted assessor to help them bolster their security to comply with HITRUST CSF standards.
  • Continuous Improvement: Welvie required a partner that fostered improvement and long-term growth through their assessments. Beyond a point-in-time assessment, Welvie wanted support throughout their compliance journey to achieve excellence for their security program.

We push each other to be better through this partnership. … Working with A-LIGN is a partnership. You’re not my vendor. You’re not somebody I tell what to do or you tell me what to do. You’re somebody who cares about my business.

Angela Loehr Merek

VP of Account Services

The Solution: Growing Together and Scaling Compliance

After researching other 3PAOs who had ample experience with HITRUST CSF, Welvie ultimately pursued a partnership with A-LIGN beginning in 2018. Welvie chose A-LIGN as their trusted HITRUST assessor due to A-LIGN’s established relationship with the certification body and deep understanding of the framework from hundreds of prior assessments.

HITRUST has fine-tuned and improved their framework to ensure evaluated entities are protected in the heightened threat landscape. As the framework evolves, companies undergoing HITRUST Certification are required to adjust their controls. A-LIGN assisted Welvie to ensure the correct and updated policies were implemented for Welvie to earn a high score on their assessment.

Throughout the relationship, A-LIGN has continuously improved its tools for understanding, collecting, and scoring evidence, resulting in assessment experiences that became more streamlined, faster, and easier over time. These tools have informed the development of A-SCEND, A-LIGN’s compliance management software, which Welvie has successfully leveraged in its last several assessments.

Welvie also found great value in A-LIGN’s close partnership with HITRUST. The HITRUST organization provides support, suggests improvements, and offers an open line of communication for customers undergoing certification. The A-LIGN team works closely with HITRUST by participating in committees, annual meetings, and workshops and keeping on top of the latest evolutions of the framework.


For example, when HITRUST announced the changes to its Measured and Managed assessment, many businesses were unsure how to proceed. Welvie consulted with A-LIGN to ensure they were prepared for the changes brought on by the new methodology and requirements. Because of A-LIGN’s knowledge and relationship with HITRUST, Welvie gained a competitive advantage in the field and developed a highly effective program to monitor, measure and manage Welvie’s security program.

As Welvie continues to partner with A-LIGN for their HITRUST Certification, they strive to ensure the proper controls are in place to comply with HITRUST CSF, strengthen their defenses against cyber-attacks, and serve as a mentor for small businesses looking to build their own compliance programs.

About Welvie

Welvie’s online decision-making programs My Surgery (surgery decision support), My Life Letters (advance care planning), and My Immunity Score (building stronger immunity health) help build health literacy — the ability for consumers to understand health information and services and use that knowledge to enhance their health. Their programs have been implemented across the country by health plans, large employers, and government agencies.

  • Services
  • Software
  • About us
  • Partners
  • Careers
  • ISO Certificate Directory
  • Privacy Policy
  • Cookie Policy
  • Impartiality and Inquiries
  • Acceptable Use Policy
  • Sitemap
CONTACT US

Price and Associates CPAs, LLC dba A-LIGN ASSURANCE is a licensed certified public accounting firm registered with the Public Company Accounting Oversight Board (PCAOB). A-LIGN Compliance and Security, Inc. dba A-LIGN is a leading cybersecurity and compliance professional services firm.

A-LIGN 2025. All rights reserved.

  • Services
    • SOC ASSESSMENTS
      • SOC 1
      • SOC 2
    • ISO CERTIFICATIONS
      • ISO 27001
      • ISO 27701
      • ISO 22301
      • ISO 42001
    • HEALTHCARE ASSESSMENTS
      • All Healthcare
      • HITRUST
      • HIPAA
    • Federal Assessments
      • All Government
      • FedRAMP
      • StateRAMP
      • FISMA
      • CMMC
      • NIST 800-171
    • PCI Assessments
      • PCI DSS
      • PCI SSF
    • Cybersecurity
      • Penetration testing
      • Red team services
      • Ransomware preparedness assessment
      • Social engineering
      • Vulnerability assessment service
    • Privacy
      • GDPR
      • CCPA/CPRA
    • Additional Services
      • Microsoft SSPA
      • NIS2 Directive
      • C5 Attestation
      • SOX 404
      • CSA STAR
      • Business Continuity & Disaster Recovery
      • Limited Access Death Master File
  • Technology
  • About Us
    • Our Company
    • Meet our team
    • Board of Directors
    • Partners
    • Events
    • Careers
  • Resources
  • A-SCEND Login
  • Careers
CONTACT US

Notifications