HITRUST Assessment & Certification Services

HITRUST Authorized External Assessor

HITRUST certification helps organizations demonstrate that their security and privacy controls meet rigorous, industry-recognized requirements. Built on the HITRUST CSF®, the certification provides a comprehensive approach to managing cybersecurity, privacy, and regulatory obligations through a single, certifiable framework.

For healthcare organizations, business associates, technology companies, and other organizations that handle sensitive information, HITRUST certification strengthens customer trust, supports regulatory compliance, and helps meet the growing security expectations of clients, partners, and regulators.

If your organization has been asked to become HITRUST® certified, or you’re proactively strengthening your cybersecurity program, LBMC can guide you through every step of the assessment and certification process. 

What Is a HITRUST Assessment?

A HITRUST assessment evaluates your organization’s security controls against the HITRUST CSF®, a certifiable framework that harmonizes multiple regulatory and industry standards.

It provides a structured, measurable way to:

  • Identify control gaps
  • Validate security maturity
  • Demonstrate compliance to customers and regulators

Who Needs a HITRUST Assessment?

HITRUST is commonly required for organizations that:

  • Handle sensitive healthcare or regulated data
  • Work with healthcare providers, payers, or vendors
  • Need to meet client or contractual security requirements
  • Want to align multiple frameworks into a single certification
  • Are preparing for audits, M&A, or enterprise growth

LBMC has helped countless organizations reach their HITRUST Certified goal. And, yes, we have learned many lessons along the way. 

If you’re asking, “Do I need to get HITRUST certified?”—we’re here to guide you every step of the way. Are you ready for it?

Streamline Audits. Strengthen Compliance.

Quickly assess whether your organization is ready for HITRUST® and where gaps may exist.

HITRUST Services

HITRUST Scoping and Assessment Selection

The assurance program allows for independent certification or validation against the framework. These engagements must be performed by trained and vetted external assessors, experienced in healthcare information security. We can help your organization with the critical step of understanding and defining your scope, as well as selecting the best assessment scoping strategy for your organization.

Readiness and Gap Assessment

LBMC Cybersecurity’s experts ensure that your organization is prepared for HITRUST as you embark on the journey of certification, establishing a well-known and generally accepted security framework across any industry. We provide readiness assessments, project management, remediation assistance, score improvement guidance, and more.

Certification (Validation, Interim, & Rapid Recertification Assessments)

Ready to certify or have a certification in place? LBMC can help you. An interim assessment is required one year after certification to evaluate the organization’s current state against the HITRUST CSF. LBMC Cybersecurity provides this service and submits an Annual Review Letter. 

Bridge Assessments

In response to COVID-19 related challenges, extensions for certification periods are permitted. LBMC, with a decade of experience and the most seasoned team in the industry, offers external assessment services to guide you through the bridge process. 

A More Connected HITRUST Certification Experience

HITRUST 15 Years Authorized External Assessor

LBMC is an authorized reseller of the HITRUST MyCSF® platform, giving organizations the option to coordinate their HITRUST subscription and renewal alongside assessment and related advisory services through one established LBMC relationship.

Organizations that purchase or renew their HITRUST subscription through LBMC receive the same HITRUST subscription pricing, with no additional cost for using LBMC as the reseller. HITRUST remains the certification body and MyCSF platform provider, while LBMC helps coordinate the process and provides assessment and advisory support.

  • One relationship from subscription through certification. Instead of managing separate procurement processes for your HITRUST subscription and LBMC assessment services, you can coordinate those needs through LBMC.
  • Greater visibility into your HITRUST investment. LBMC can provide a clearer view of subscription fees, assessment services, and related advisory support, helping you understand the broader cost of pursuing or maintaining certification.
  • More coordinated support. LBMC works within the HITRUST ecosystem to help address questions, resolve issues, and keep the certification process moving.
  • Guidance from a team that understands your environment. For existing LBMC clients, our knowledge of your business, risks, and compliance program can reduce ramp-up time and support more tailored guidance.

The reseller option is available both to organizations beginning their HITRUST journey and existing HITRUST clients approaching renewal.

Why Organizations Choose LBMC for HITRUST

As a select group of HITRUST Authorized External Assessor® organizations recognized by the HITRUST Alliance, LBMC Cybersecurity participated in the effort to integrate security standards from the Centers for Medicare and Medicaid Services (CMS) and NIST into the HITRUST framework.

In 2010, LBMC Cybersecurity became one of the first HITRUST Authorized External Assessor® organizations, establishing a long-standing role in what has become the gold standard for security and privacy assessments. As the leader of the “10-year club,” LBMC is the longest-serving external assessor, backed by one of the most experienced teams in the industry. Our experts have helped shape and apply the HITRUST CSF® over time, bringing deep knowledge to organizations looking to protect sensitive information and achieve certification with confidence.

LBMC’s relationship with HITRUST continues to evolve. As an authorized reseller of the HITRUST MyCSF® platform, LBMC can now coordinate subscription and renewal services directly within client engagements. Combined with 15 years of HITRUST assessment experience, this gives organizations a more connected path from planning and subscription through assessment and ongoing certification needs.

For many organizations, HITRUST is just one component of a broader cybersecurity and compliance strategy. Depending on your industry and business objectives, you may also need to demonstrate compliance through SOC 2 audits, implement security controls aligned with the NIST Cybersecurity Framework or ISO 27001, validate PCI DSS compliance for payment card environments, meet CMMC compliance requirements for Department of Defense contracts, conduct HIPAA risk assessments to address regulatory obligations, or support international privacy initiatives such as GDPR compliance. Because our team works across these frameworks, we help identify overlapping controls that reduce duplicate effort while strengthening your overall security program.

As external assessor council members, we assist the industry with education and outreach and feel compelled and obligated to offer encouragement and advice to those embarking on this journey. 

CLIENT TESTIMONIALS

Reducing Audit Fatigue, Improving Efficiency

See how a leading healthcare organization streamlined compliance and simplified audits with a unified HITRUST® strategy.

Which HITRUST Assessment Is Right for Your Organization?

HITRUST offers multiple assessment options designed for different levels of cybersecurity assurance, organizational risk, and customer requirements. Choosing the appropriate assessment is an important first step because the scope, control requirements, level of effort, and certification objectives can differ significantly.

HITRUST e1 Assessment

The HITRUST e1 Assessment provides foundational cybersecurity assurance focused on essential cybersecurity controls. It can be appropriate for organizations that need a lower-effort starting point for demonstrating security practices or are beginning their HITRUST journey.

Learn more about the HITRUST e1 Assessment and its role in cybersecurity assurance.

HITRUST i1 Assessment

The HITRUST i1 Implemented Assessment provides a broader level of assurance by evaluating the implementation of a defined set of controls. It can be appropriate for organizations that need a standardized, certifiable assessment with greater assurance than a foundational assessment.

Organizations already using i1 should also plan for ongoing certification requirements. See how the HITRUST i1 Rapid Recertification process can affect renewal planning.

HITRUST r2 Assessment

The HITRUST r2 Risk-Based Assessment provides the highest level of HITRUST assurance and uses a risk-based, tailored scope based on factors such as organizational characteristics, systems, regulatory requirements, and risk exposure. It is generally suited to organizations facing more complex assurance requirements or significant customer and regulatory expectations.

Not sure which assessment fits your requirements? Talk with an LBMC HITRUST advisor before determining your certification scope.

Webinar: HITRUST i1 Assessment

In December 2021, HITRUST announced the newest service offering – the new i1 Implemented Certification.
 
In this video, you will learn:
  • What is the HITRUST i1 Implemented Verified Assessment and Certification?
  • Why was this new option was created?
  • Key differences between i1 vs r2.
  • How to choose which option is right for you.

On-Demand Webinar Duration: 7:36

The HITRUST Assessment and Certification Process

While the exact process varies based on the assessment selected and your organization’s environment, a HITRUST engagement typically includes:

1. Determine assessment type and scope.

Identify the appropriate HITRUST assessment, systems, business units, locations, regulatory requirements, and other factors that affect scope.

2. Assess readiness.

Evaluate existing controls and documentation to identify gaps that could affect assessment results.

3. Remediate identified gaps.

Prioritize control improvements, documentation, evidence, and other corrective actions needed before validation.

4. Complete the validated assessment.

LBMC’s HITRUST assessment professionals evaluate applicable controls and supporting evidence as part of the formal assessment process.

5. Submit for HITRUST review and certification.

Assessment results are submitted through the HITRUST process for quality assurance and certification determination.

6. Maintain certification readiness.

Continue monitoring controls and prepare for interim, recertification, or other ongoing requirements as applicable.

Industries We Serve

Organizations pursuing HITRUST certification often operate in highly regulated environments where customers, partners, and regulators expect mature security programs. LBMC helps healthcare organizations, healthcare technology companies, business associates, financial services organizations, and other regulated businesses prepare for and achieve HITRUST certification.

Featured Industries 

Explore Additional Industries We Serve

Local Expertise, Wherever You Are

With offices in Chattanooga, Memphis, Louisville, Nashville, Knoxville, Philadelphia, and Charlotte, plus remote offices, LBMC partners with businesses across the region and beyond.

HITRUST® FAQs

How do I know if my organization is ready for a HITRUST® assessment?

Readiness depends on the type of HITRUST assessment you are pursuing, the scope of the assessment, the maturity of your existing security controls, available documentation and evidence, and any gaps that need to be remediated before validation.

A HITRUST readiness assessment can help identify control and documentation gaps early, establish remediation priorities, and reduce surprises during the validated assessment.

Organizations beginning the process can use LBMC’s HITRUST readiness checklist to identify areas that may require attention. For additional preparation guidance, read HITRUST: Are You Ready for It?.

HITRUST offers multiple assessment options based on the level of assurance an organization needs. The e1 Assessment focuses on essential cybersecurity controls, the i1 Assessment provides broader assurance over the implementation of a defined set of controls, and the r2 Assessment provides a more comprehensive, risk-based assessment tailored to an organization’s environment and requirements.

The right assessment depends on factors such as customer and contractual requirements, organizational risk, regulatory obligations, and the level of assurance stakeholders expect.

Organizations considering foundational assurance can learn more about the HITRUST e1 Assessment.

The timeline for HITRUST certification varies based on the assessment selected, scope, complexity of the environment, maturity of existing controls, availability of documentation and evidence, and the amount of remediation required.

Organizations that identify gaps before beginning validation are generally better positioned to manage the process efficiently. A readiness or gap assessment can help establish a realistic timeline based on your organization’s current state and certification objectives.

SOC 2 and HITRUST both provide assurance about an organization’s controls, but they use different approaches and may address different customer, contractual, industry, and compliance requirements. The right approach depends on your organization’s customers, industry, existing compliance program, and assurance objectives. Some organizations may benefit from both.

LBMC’s SOC 2 vs. HITRUST comparison explains the key differences. Organizations that have already completed a SOC 2 audit can also explore why HITRUST e1 may be a logical next step after SOC 2.

HIPAA does not provide an official certification. However, the HITRUST CSF® incorporates and maps to requirements from the HIPAA Security, Privacy, and Breach Notification Rules, giving organizations a structured way to assess relevant controls and demonstrate their security and compliance efforts.

Organizations subject to HIPAA should evaluate HITRUST as part of their broader compliance program rather than treating certification as a replacement for their HIPAA obligations.

No. Although HITRUST has strong roots in healthcare and is widely used by healthcare organizations and their business associates, the framework is used by organizations across industries that need to protect sensitive information and demonstrate mature cybersecurity practices.

Technology companies, financial services organizations, service providers, and other businesses may pursue HITRUST because of customer requirements, contractual obligations, risk management objectives, or the need for independent assurance.

Maintaining HITRUST certification requires organizations to continue operating and monitoring their controls and complete applicable ongoing assessment or recertification requirements. The specific requirements depend on the assessment and certification held.

For eligible organizations using the i1 Assessment, HITRUST’s Rapid Recertification option may provide a more streamlined path for maintaining certification. Learn more about the HITRUST i1 Rapid Recertification process.

The HITRUST CSF incorporates requirements and authoritative sources from multiple security, privacy, and regulatory frameworks, helping organizations address overlapping requirements through a unified control framework.

Organizations working with frameworks such as NIST or ISO 27001 may be able to identify common controls, reduce duplicated compliance effort, and build a more coordinated security and assurance program.

HITRUST can provide a structured approach for evaluating security, privacy, and risk controls that may apply to AI systems and the sensitive information those systems process. As organizations adopt AI, existing cybersecurity, privacy, data governance, and third-party risks can take on new dimensions that should be evaluated within the broader security program.

Learn more about assessing AI security and risk through HITRUST.

Yes. LBMC is an authorized reseller of the HITRUST MyCSF® platform. Organizations pursuing certification or approaching renewal can purchase or renew their HITRUST subscription through LBMC and coordinate their subscription, assessment, and related advisory needs through one established relationship.

There is no additional cost for purchasing the HITRUST subscription through LBMC; HITRUST subscription pricing remains the same. HITRUST continues to serve as the certification body and MyCSF platform provider, while LBMC serves as your authorized reseller and HITRUST assessor.

Meet LBMC’s HITRUST & Cybersecurity Leaders

HITRUST certification requires more than technical knowledge of a framework. It requires experienced professionals who understand how security, compliance, risk, and business requirements come together throughout the assessment process.

LBMC’s HITRUST and cybersecurity leaders bring deep assessment and advisory experience to organizations pursuing and maintaining certification, including leadership from Robyn Barton, LBMC’s HITRUST and CMMC Practice Leader.

Let’s Simplify Your HITRUST Journey

The right path to HITRUST certification depends on your organization’s requirements, current security environment, assessment type, and certification goals. LBMC can help you understand what comes next and develop a clear path forward.

With 15 years of HITRUST assessment experience and the ability to coordinate MyCSF® subscription and renewal services, LBMC provides experienced support throughout the HITRUST journey.

Scroll to Top
LBMC
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.