01Introduction
Hospitals and health plans often ask vendors for more than a HIPAA attestation. HITRUST certification has become the common shorthand for proven security in US healthcare. See healthcare.
02What is HITRUST?
It offers three assessment levels of increasing assurance: e1 (essential, one year), i1 (implemented, one year) and r2 (risk-based, two years). The higher-assurance assessments include requirements for penetration testing and vulnerability management.
03How HITRUST works
Certification follows a readiness, validation and QA cycle.
- 1.
Scope
Define the systems in scope and, for r2, tailor controls to risk factors.
- 2.
Readiness
Self-assess in the HITRUST MyCSF platform and close gaps.
- 3.
Validated assessment
An external assessor tests controls and evidence, including penetration test reports.
- 4.
QA and certify
HITRUST reviews the assessment and issues certification, with interim reviews for r2.
04Threats and risks
Certification risk comes mostly from evidence gaps.
Evidence gaps
Controls that exist but lack documented proof of operation.
Scope creep
Systems added after scoping that aren't covered.
Stale tests
Pentest reports too old or too narrow to satisfy assessors.
Sales blockers
Healthcare deals stall without certification.
05How Parameter helps
Parameter supplies the testing evidence HITRUST assessors look for.
Current pentest reports
The pentesting agents produce dated, scoped reports on every release.
Remediation proof
Retests on fix show findings closed within the assessment period.
Code and dependencies
Sentinel and Supply Chain cover secure development controls.

