
HITRUST certification is not one-size-fits-all.
Depending on your organisation’s risk profile, customer requirements and compliance maturity, you may need e1, i1 or r2.
The challenge is choosing the right level without over-investing — or choosing a level that your customers will not accept
HITRUST e1, i1 and r2 at a glance
One important advantage is that the HITRUST framework is traversable.
Requirements completed for e1 are incorporated into i1, while i1 requirements form part of r2. This allows organisations to increase their assurance level as customer expectations and risk exposure grow.
What is HITRUST e1?
The e1 assessment focuses on essential cybersecurity practices such as:
MFA, access controls, patching, malware protection, backups, security awareness and incident response.
It is best suited for organisations that:
- Are early in their HITRUST journey
- Have relatively limited data risk
- Need a recognised cybersecurity assurance baseline
- Want to build towards i1 or r2 later
Think of e1 as answering:
“Are the cybersecurity fundamentals in place?”
What is HITRUST i1?
The i1 assessment provides a stronger level of assurance through a broader set of cybersecurity controls.
It can be a good fit for organisations that:
- Handle meaningful volumes of PHI
- Serve healthcare customers
- Sell into mid-market or enterprise environments
- Need stronger assurance without the full complexity of r2
For many healthcare technology vendors, i1 can provide the balance between meaningful assurance and manageable implementation effort.
What is HITRUST r2?
The r2 assessment is HITRUST’s most comprehensive risk-based assessment.
Unlike e1 and i1, its requirements are tailored according to factors such as:
- Data volumes
- Number of users
- Internet exposure
- Third-party access
- Technology environment
- Applicable regulatory requirements
It also evaluates controls across multiple maturity dimensions including policy, procedures, implementation, measurement and management.
r2 is generally appropriate when:
- A customer or contract specifically requires it
- Your organisation handles significant PHI volumes
- You operate a complex or higher-risk environment
- You need multiple regulatory requirements incorporated into one assessment
So which HITRUST level should you choose?
Start with five questions:
1. What does the contract require? If a customer specifically requests i1 or r2, that requirement should drive the decision.
2. What will your customers accept? If they simply ask for “HITRUST certification,” confirm the required level with their security or TPRM team.
3. What is your actual data risk? Consider PHI volume, sensitivity, third-party access and business criticality.
4. How mature are your controls today? If fundamental areas such as MFA, logging, access management or patching still need improvement, starting with e1 may be more practical.
5. What will you need in the next two or three years? A staged roadmap such as:
e1 → i1 → r2
can allow your assurance programme to grow alongside the business.
Avoid these common mistakes
One of the biggest mistakes is choosing r2 simply because it appears to be the highest level, even when customers would accept i1.
The opposite mistake is choosing e1 to reduce cost when an upcoming customer contract actually requires i1 or r2.
The right HITRUST level should be based on customer requirements, risk exposure and business objectives — not prestige.
The key takeaway
There is no universally “best” HITRUST certification.
e1 provides foundational assurance. i1 provides stronger implemented assurance. r2 provides comprehensive, risk-based assurance.
The best choice is the level that meets your customer expectations today while supporting where your organisation needs to go tomorrow.
Need help choosing?
Finstein is a HITRUST Authorized External Assessor.
Our team supports organisations with:
- HITRUST readiness assessments
- e1, i1 and r2 validated assessments
- Interim assessments
- Recertification
- HITRUST roadmap and level selection
We support organisations serving the US healthcare ecosystem across the US, India, UK and Middle East through an efficient remote delivery model.
Not sure whether you need e1, i1 or r2? Talk to Finstein and get a level recommendation based on your customer requirements and risk profile.
#HITRUST #HITRUSTCSF #HIPAACompliance #HealthcareCybersecurity #Cybersecurity #HealthcareIT #GRC #Compliance #DataSecurity #RiskManagement #Finstein #FinsteinCyber
