Company:HITRUST
| Type | Private |
|---|---|
| Industry | Health information technology |
| Founded | 2007 in Frisco, Texas, U.S. |
| Founder | Daniel Nutkis |
| Headquarters | Frisco, Texas , U.S. |
Key people | |
| Parent | Brighton Park Capital |
| Website | hitrustalliance |
HITRUST (formerly known as Health Information Trust Alliance) is an organization headquartered in Frisco, Texas, that provides information risk management and compliance assessments and certifications.[1]
History
HITRUST was formed in 2007 in response to heightened concerns about healthcare data breaches, expanding federal and state compliance mandates, and the need for a standardized approach to information protection in healthcare.[2] Initially focused on HIPAA and other U.S. healthcare privacy and security laws, HITRUST later adapted its framework for broader use in different industries, including financial services and defense contracting.[3][4]
In response to emerging AI concerns, the organization developed AI-specific control requirements and certifications to address related risks in 2024.[5]
In December 2024, the organization announced a cyber insurance consortium in partnership with Lloyd’s of London.[6] This partnership benefitted customers of both HITRUST and Lloyd's of London by offering discounted insurance rates through Lloyd's of London if users pass a HITRUST assessment and achieve a certification.[7] Organizations that use both services also experience a more streamlined process due to Lloyd's of London using HITRUST's framework to assess coverage and costs.[8]
In 2025, the organization announced the general availability of its HITRUST Assessment XChange App for ServiceNow.[9]
HITRUST Framework
HITRUST's assessments are based on its cybersecurity framework, the HITRUST CSF (originally the HITRUST Common Security Framework), which integrates requirements from multiple regulations and standards.[3]
The HITRUST Framework incorporates control requirements from more than 60[10] regulations and standards for assessing security and compliance.[11] It is divided into 19 control domains,[3] such as endpoint protection, access control, business continuity, and incident management.[2] The certification model built on the framework adjusts security requirements based on an organization’s size, risk profile, and regulatory obligations.[2]
According to the HITRUST’s 2025 Trust Report, certified environments reported an incident rate under 1%. However, independent validation of the finding is unclear.[12]
Critics argue that HITRUST certification can be expensive and time-consuming, especially for smaller entities with limited budgets and staffing.[2] Some also caution that while the framework covers many cybersecurity controls, it does not guarantee full compliance with every niche regulation (e.g., certain OSHA requirements and CMS’s conditions of Medicare and Medicaid participation).[3]
Certifications
HITRUST offers multiple kinds of certifications depending on organization's data security needs and regulations that need to be met. These certifications are achieved through assessments to help build organization's security through HITRUST's framework.[13] Organizations are able to work their way up through certifications to further strengthen security.[14]
| Certification | Target User | Purpose | # of Controls | Level of Assurance | Time of Validity | Complexity of Assessment | Ref. |
|---|---|---|---|---|---|---|---|
| e1 | Small, low-risk organizations new to HITRUST | Set up organizations with an entry-level cybersecurity system and strengthen security | 44 | Foundational | 1 Year | Low | [13][14] |
| i1 | Moderate-risk organizations with needs higher than e1 | Focus on new and rising threats to data security (used to help obtain r2 certification) | 182 | Intermediate | 1 Years | Medium | [13][14] |
| r2 | High-risk and large-scale organizations with lots of regulations | Managing and securing large amounts of sensitive data | 2,000+
(chosen based on risk) |
Risk-Based | 2 Years | High | [13][14] |
Board of Directors
HITRUST is led by a management team and governed by a Board of Directors made up of leaders from across a variety of industries. These leaders represent the governance of the organization, but other founders also comprise the leadership.[15] The Board Members are:
- Daniel S. Nutkis - Chief Executive Officer, HITRUST
- Robert Booker - Chief Strategy Officer, HITRUST
- Pamela Arora - President and Chief Executive Officer, AAMI
- Caroline Budde - Associate General Counsel, Digital & Data Assets, McKesson
- Dr. Kevin Charest - Chief Information Security Officer, Accumulus Synergy
- George DeCesare, JD - Senior Vice President, Chief Technology Risk Officer, Kaiser Permanente
- Kimberly Gray, Esq - CIPP Chief Privacy Officer, Global, IQVIA
- Omar Khawaja - Vice President, Security, and Field Chief Information Security Officer, Databricks
- Stirling Martin - Senior Vice President, Epic and President, Epic Hosting
- Roy R. Mellinger - Senior Vice President, Security, Privacy, IT Risk and Compliance and Global Chief Information Security Officer, Aimbridge Hospitality
- Aman Raheja - Chief Information Security Officer, HP Enterprise
References
- ↑ "Our Vision for Cybersecurity and Risk Management | HITRUST" (in en). https://hitrustalliance.net/about-us.
- ↑ 2.0 2.1 2.2 2.3 Alder, Steve (2024-08-01). "HIPAA vs HITRUST". The HIPAA Journal.
- ↑ 3.0 3.1 3.2 3.3 "HITRUST explained: One framework to rule them all" (in en). https://www.csoonline.com/article/570765/hitrust-explained-one-framework-to-rule-them-all.html.
- ↑ "Everything You Need to Know About HITRUST | CSA". 4 January 2023. https://www.a-lign.com/articles/everything-you-need-to-know-about-hitrust-certification.
- ↑ Wallace, Elizabeth (2024-12-26). "HITRUST Launches AI Security Certification" (in en-US). https://www.rtinsights.com/hitrust-launches-ai-security-certification-to-address-emerging-risks/.
- ↑ "Lloyd's of London launches cyber insurance consortium with HITRUST certification - ADS Advance". https://www.adsadvance.co.uk/lloyd-s-of-london-launches-cyber-insurance-consortium-with-hitrust-certification.html.
- ↑ vidhyamunnangi (2024-12-13). "HITRUST joins hands with Lloyd's to introduce cyber insurance consortium" (in en-US). https://www.lifeinsuranceinternational.com/news/hitrust-lloyds-cyber-insurance/.
- ↑ Corp, HITRUST Services. "Lloyd's of London Launches First-of-its-kind Consortium Built on HITRUST Certification to Shape the Future of Cyber Insurance" (in en). https://www.prnewswire.com/news-releases/lloyds-of-london-launches-first-of-its-kind-consortium-built-on-hitrust-certification-to-shape-the-future-of-cyber-insurance-302329703.html.
- ↑ "HITRUST launches Assessment XChange App for ServiceNow to enhance risk management". SDx Central. 2025-01-23. https://www.sdxcentral.com/articles/stringerai-announcements/hitrust-launches-assessment-xchange-app-for-servicenow-to-enhance-risk-management/2025/01/.
- ↑ "Cybersecurity Frameworks and Compliance Solutions | HITRUST" (in en). https://hitrustalliance.net/at-a-glance.
- ↑ Calder, Alan; Watkins, Steve (2024). IT Governance ? An international guide to data security and ISO 27001/ISO 27002, Eighth edition. IT Governance Publishing. ISBN 978-1-78778-408-6. https://www.jstor.org/stable/j.ctv336p2z9.
- ↑ Kaleah, Salmon (2025-02-24). "HITRUST report shows improved outcomes for 2025 with AI". SecurityBrief. https://securitybrief.co.nz/story/hitrust-report-shows-improved-outcomes-for-2025-with-ai.
- ↑ 13.0 13.1 13.2 13.3 "HITRUST Certification Services | Accorian - Risk-Based Compliance & Security" (in en-US). https://www.accorian.com/hiturst-certification/.
- ↑ 14.0 14.1 14.2 14.3 "HITRUST CSF certification" (in en). https://rsmus.com/services/risk-fraud-cybersecurity/cybersecurity-business-vulnerability/cybersecurity-risk-compliance/hitrust-compliance.html.
- ↑ "Meet the Board of Directors | HITRUST" (in en). https://hitrustalliance.net/board-of-directors.
