HITRUST e1, i1 or r2 for Florida Healthcare

CMBNetworks LLC | Posted

Most healthcare businesses in South and Central Florida do not go looking for HITRUST. It finds them. A medical billing company in Broward, a telehealth startup in Orlando, or a lab services vendor in Tampa lands a contract with a hospital system or a health plan, and the security review comes back with a line item that says HITRUST certification is required before signing or at the next renewal.

The first question most owners ask is how much it costs. The better first question is which HITRUST assessment the customer is actually asking for, because there are three of them and the difference in effort between the smallest and the largest is measured in months, not weeks.

The three assessments in plain terms

The e1 is the entry level. It covers a small set of foundational security controls, roughly 44 requirements under the current version of the HITRUST CSF, and the certification is good for one year. It tells a customer you have basic hygiene in place: access control, patching, backups, incident response, and so on. For a small vendor with limited access to patient data, it can be enough.

The i1 is the middle tier and the one we see requested most often for vendors that handle PHI but are not hosting a hospital's core systems. It is a fixed set of about 180 requirements built around current threats, also valid for one year. It is a real assessment with real evidence requirements, and most small organizations need a readiness period before they are able to pass it.

The r2 is the full risk-based assessment. The requirement set is tailored to your organization based on scoping factors like the volume of records you handle, your systems, and your regulatory exposure, so it is almost always larger than the i1. It also scores whether your policies and procedures are documented and followed, not only whether a control exists. The certification runs two years with an interim assessment in the first year. This is what large payers and health systems ask for when a vendor stores a lot of PHI or connects directly into their environment.

Let the contract decide, not the sales pitch

Before engaging an assessor, get the requirement in writing from the customer. Ask them which assessment they accept and whether they will take a lower tier now with a commitment to move up later. A lot of Florida organizations overbuy here. A 25-person company that pursues an r2 when the customer would have accepted an i1 can spend a year and a significant budget on work that did not need to happen yet.

Underbuying causes the opposite problem. An e1 will not satisfy a customer whose vendor risk team requires an r2, and finding that out after the report is issued means starting over. Under the current HITRUST framework, though, work done for a lower tier carries forward. Controls you validated for an i1 count toward an r2 later, so starting smaller is not wasted effort if the growth path is planned from the beginning.

One more point worth knowing. HITRUST is not a HIPAA certification, and there is no such thing as an official one. Covered entities and business associates still need their own HIPAA Security Rule risk analysis on file. A HITRUST certification helps prove that your controls are in place, but it does not replace the risk analysis OCR expects to see if there is ever a breach or complaint.

What to have in place before an assessor shows up

Scope comes first. Decide which systems, applications, and locations touch PHI and keep the assessment boundary as tight as the business allows. A clean scope is the single biggest factor in how long an assessment takes and what it costs.

Next, check what you can inherit. If your platform runs in AWS, Azure, or Google Cloud, a portion of the physical and infrastructure controls can be inherited from the provider through HITRUST's inheritance program, which takes real work off your plate.

Then close the evidence gaps. Assessors do not accept "we do that" as proof. They want screenshots, configuration exports, access review records, training logs, and signed policies with dates on them. In our experience, small organizations usually have more of the controls than they think. What they are missing is the records. A readiness assessment against the target tier will surface those gaps while there is still time to fix them without a failed report on file.

CMBNetworks helps South and Central Florida healthcare practices and vendors get ready for HIPAA/HITRUST, from scoping and choosing the right assessment tier to closing evidence gaps before the assessor arrives. The practice is led by a former HITRUST Lead Assessor who has seen these assessments from both sides of the table. Start a conversation.