
HIPAA is a US federal law that requires covered entities and business associates to protect health information. HITRUST is a private organisation whose framework, the HITRUST CSF, turns HIPAA and other standards into prescriptive, testable controls with an independent certification. HIPAA tells you what to achieve. HITRUST shows how, and proves it.
What is HIPAA?
The Health Insurance Portability and Accountability Act of 1996 is federal legislation. Its security and privacy obligations sit in three rules:
1. Privacy Rule. Governs permitted uses and disclosures of protected health information (PHI) and patient rights.
2. Security Rule. Requires administrative, physical and technical safeguards for electronic PHI (ePHI), built on risk analysis and risk management.
3. Breach Notification Rule. Requires notification to individuals, HHS and sometimes the media after a breach of unsecured PHI.
HIPAA applies to covered entities (providers, health plans, clearinghouses) and, since the HITECH Act, directly to business associates. It is enforced by the HHS Office for Civil Rights (OCR) through investigations, audits, corrective action plans and civil monetary penalties.
Two design features of HIPAA create the gap that HITRUST fills:
- The Security Rule is deliberately flexible. Many specifications are “addressable” and the standard is “reasonable and appropriate”. This scales across organisations but leaves real ambiguity.
- There is no official HIPAA certification. HHS does not certify anyone and does not endorse third-party certificates. A vendor claiming to be “HIPAA certified” is using a marketing term, not a regulatory status.
Note that HHS proposed a significant update to the Security Rule in January 2025, with more prescriptive expectations such as mandatory MFA, encryption and asset inventories. Check the current regulatory status before relying on this point, but the direction of travel is towards the type of specificity HITRUST already requires.
What is HITRUST?
HITRUST is a private standards and certification body. Its HITRUST CSF harmonises HIPAA with NIST, ISO/IEC 27001, PCI DSS and dozens of other sources into one control library across 19 domains. An Authorized External Assessor tests the controls, HITRUST performs quality assurance, and HITRUST issues an e1, i1 or r2 certification.
HIPAA vs HITRUST at a glance
| Dimension | HIPAA | HITRUST |
| Nature | Federal law and regulations | Private framework and certification |
| Issued by | US Congress and HHS | HITRUST Alliance |
| Enforced by | HHS OCR and state attorneys general | Contract and market expectation |
| Mandatory? | Yes, for covered entities and business associates | No, unless required by contract |
| Level of detail | Principle-based, flexible | Prescriptive requirement statements |
| Certification available? | No | Yes: e1, i1, r2 |
| Scope | PHI only | Any sensitive data, multiple regulations |
| Penalty for failure | Fines, corrective action plans, reputational damage | Loss of certification, contracts and deals |
| Update cycle | Infrequent rulemaking | Regular CSF releases, threat-adaptive |
Does HITRUST certification make you HIPAA compliant?
Not automatically, and any provider who says otherwise is overstating. Here is the accurate position:
- HITRUST maps HIPAA Security Rule requirements into the CSF. A certified organisation has independently validated evidence that security safeguards aligned to HIPAA are implemented.
- HIPAA also includes Privacy Rule obligations, patient rights processes, BAAs and breach notification procedures. HITRUST covers privacy in Domain 19 and organisations can add HIPAA as a compliance factor in an r2, but operational privacy compliance still depends on your processes.
- OCR makes compliance determinations, not HITRUST. Certification is strong evidence, not a legal shield.
The practical benefit: MyCSF can generate HIPAA-oriented reporting from your assessment, and under the 2021 HITECH amendment (Public Law 116-321), OCR must consider recognized security practices in place for the prior 12 months when assessing penalties.
Does HIPAA compliance mean you are ready for HITRUST?
No. Organisations that consider themselves HIPAA compliant typically find these gaps during a HITRUST readiness assessment:
1. Risk analysis exists but is outdated or not tied to a risk treatment plan.
2. Policies exist but procedures are informal.
3. Technical controls (hardening standards, vulnerability management cadence, log review) are inconsistent.
4. Third-party assurance is limited to signed BAAs with no ongoing due diligence.
5. Evidence of operation is not retained.
HIPAA compliance is often self-asserted. HITRUST requires proof.
How do HIPAA and HITRUST work together?
Think of it as a three-layer model:
| Layer | Role | Example |
| Law | Sets the obligation | HIPAA Security Rule requires access controls |
| Framework | Defines the control | HITRUST requirement statements on unique IDs, MFA, access reviews |
| Assurance | Proves operation | Validated assessment, HITRUST QA, certification letter |
Customers cannot audit every vendor against HIPAA themselves. HITRUST certification gives them a standard, comparable assurance artefact.
Which one should you focus on first?
HIPAA first, always. It is the legal obligation. Complete a Security Rule risk analysis, sign BAAs, implement breach response. Then use HITRUST to mature, structure and prove the programme, starting with an e1 or i1 as customer demand dictates.
Key takeaways
- HIPAA is law. HITRUST is a voluntary, certifiable framework.
- There is no official HIPAA certification.
- HITRUST is the most widely accepted way to demonstrate HIPAA-aligned security to customers.
- Certification supports, but does not guarantee, HIPAA compliance.
- HIPAA compliant organisations still face gaps when first assessed against HITRUST.
Frequently asked questions
Is HITRUST the same as HIPAA?
No. HIPAA is a US federal law. HITRUST is a private framework and certification that incorporates HIPAA requirements alongside other standards.
Is there an official HIPAA certification?
No. HHS does not issue or recognise any HIPAA certification. HITRUST is commonly used as independent evidence of HIPAA-aligned security.
Does HITRUST certification guarantee HIPAA compliance?
No. It provides validated evidence of security safeguards mapped to HIPAA, but HHS OCR determines compliance and privacy processes must also be maintained.
Do I need HITRUST if I am already HIPAA compliant?
Only if customers require independent proof. Many payers and health systems do.
Who enforces HIPAA and who enforces HITRUST?
HHS OCR enforces HIPAA. HITRUST is enforced through customer contracts and the conditions of maintaining certification.
About Finstein
Finstein is a HITRUST Authorized External Assessor. Our team includes CCSFP and CHQP qualified HITRUST professionals, CISA certified auditors and ISO 27001 lead auditors, led by Chartered Accountants. We support readiness assessments, validated e1, i1 and r2 assessments, interim assessments and recertification for organisations in the US, India, the UK and the Middle East that serve US healthcare, using an efficient remote delivery model. Request a HIPAA to HITRUST mapping review.
