Overview
HITRUST is a US organization that maintains the HITRUST CSF, a certifiable security and privacy framework that harmonizes requirements from more than 70 standards and regulations, including HIPAA, NIST publications, ISO/IEC standards, PCI DSS, and GDPR. It began in US health care and is now used in other sectors too. The latest is CSF v11.9.0. Released on September 24, 2026, it refreshed mappings to NIST SP 800-53, added content on agentic AI, public key infrastructure, and post-quantum cryptography, and set the e1 baseline at 44 requirement statements.
HITRUST offers 3 main validated assessments. The e1 covers foundational cyber hygiene for lower-risk organizations and is valid for 1 year. The i1 covers 182 leading-practice requirements and is also valid for 1 year, with a lighter rapid recertification in year 2. The r2 is risk-based, tailored to the organization's scope and risk factors, and is valid for 2 years with an interim assessment after the first year. A HITRUST Authorized External Assessor performs each one, and HITRUST reviews every assessment for quality before it issues a certification. HITRUST also offers AI security and AI risk management assessments.
Canadian software, analytics, and services companies meet HITRUST when they sell to US hospitals, health insurers, and their business associates, who often name it in vendor contracts as a way to show HIPAA-aligned safeguards. No Canadian regulator recognizes HITRUST, and Canadian health privacy laws such as Ontario's PHIPA set their own rules. External assessors work internationally. Many Canadian vendors pair HITRUST with ISO 27001 or SOC 2 for customers outside the US. HITRUST has set December 31, 2026 as the last day to create new e1 and i1 assessments on v11.8.0.
Who it applies to in Canada
Organizations that handle sensitive data, especially vendors and service providers to US hospitals, health insurers, and other health care organizations, as well as companies in other regulated sectors.
Canadian health technology, analytics, and services companies are asked for HITRUST certification when they sell to US health care customers. It is not required by any Canadian regulator.
Controls at a glance
HITRUST assessments are organized into 19 assessment domains, grouped here by theme, and the requirement statements in scope depend on the assessment type.
Information protection program and risk management (2 domains)
- Documented security program with assigned responsibility
- Formal risk assessment and treatment
- Policies reviewed and approved by management
Endpoint, portable media, mobile, and wireless security (4 domains)
- Endpoint protection and anti-malware
- Encryption and control of portable media
- Mobile device security and management
- Secure wireless configuration
Configuration and vulnerability management (2 domains)
- Baseline configurations and change control
- Vulnerability scanning and patching
- Penetration testing where required
Network and transmission protection (2 domains)
- Network segmentation and boundary protection
- Encryption of data in transit
- Secure remote access
Password management and access control (2 domains)
- Password and authenticator rules
- User provisioning and periodic access reviews
- Least privilege and multi-factor authentication
Audit logging, incident management, and continuity (3 domains)
- Audit logging and monitoring
- Incident management and reporting
- Business continuity and disaster recovery testing
Training, third parties, physical security, and privacy (4 domains)
- Education, training, and awareness
- Third-party assurance and contract terms
- Physical and environmental security
- Data protection and privacy
Certification and assessment
The organization scopes the assessment in HITRUST's MyCSF platform and works with an External Assessor, who tests the requirement statements in scope. HITRUST then performs its own quality assurance review and issues the certification report. The r2 adds maturity scoring of policy, procedure, and implementation.
Dates to know
- 2026-05-08
- HITRUST CSF v11.8.0 available in MyCSF
- 2026-09-24
- HITRUST CSF v11.9.0 released, with an e1 baseline of 44 requirement statements
- 2026-12-31
- Last day to create new e1 and i1 assessments on CSF v11.8.0
- 2027-03-31
- Last day to submit e1 and i1 assessments on CSF v11.8.0 or earlier
Resources
Official texts and free tools for HITRUST. Links open the publisher’s site.
- HITRUST framework (CSF), HITRUST
- Assessments and certifications, HITRUST
- e1 assessment, HITRUST
- i1 assessment, HITRUST
- r2 assessment, HITRUST
- HAA 2026-005: CSF version 11.9.0 release, HITRUSTguidance
Need help? Browse the directory or read the guides.
References
- HITRUST framework (CSF), HITRUST
- Assessments and certifications, HITRUST
- HAA 2026-005: CSF version 11.9.0 release, HITRUST
- HAA 2026-006: CSF v11.8 creation deadline for e1 and i1 assessments, HITRUST
- r2 assessment, HITRUST
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.