Skip to content

Webinar Transcript: HITRUST Assessments

Understanding the Differences Between the e1, i1, and r2 Assessments

Webinar Transcript | McKonly & Asbury

Dave Hammarberg
Thanks for joining us for today’s webinar, HITRUST Assessments: Understanding the Differences Between the e1, i1, and r2 Assessments. I’m Dave Hammarberg, Partner at McKonly & Asbury, and joining me today is Director Josh Bantz.

Josh Bantz
Good afternoon, everybody.

Dave Hammarberg
If you’re not familiar with us, McKonly & Asbury is an accounting and business advisory firm with offices in Camp Hill, Lancaster, Bloomsburg, and Philadelphia, Pennsylvania. We offer a wide range of services to organizations across various industries. For more information, please visit our website.
If you’ve joined us for past webinars, welcome back. If you haven’t, our monthly webinars feature various business topics to keep you updated on what’s going on around us.

Be sure to check out our website to catch past presentations as well as current information through our blog. Our thought leadership subscription, M&A Insights, has been revised to give our subscribers the opportunity to select the topics most relevant to them. Subscribe today to stay
informed.

I think today we have a good agenda for you. I can stop reading now, which I’m thankful for, but again, the agenda includes an Introduction to HITRUST Assessments, as well as the differences and similarities between the e1, i1, and r2. Josh, just for a little bit of background, this is relatively new—HITRUST being broken out like this.

Josh Bantz
That is correct, Dave. I believe it was 2021 or 2022 when they broke these out into three categories. Prior to that, it was just deemed the HITRUST CSF Validated Assessment. Then in 2021 and 2022, they established these three types of assessments that we’re going to go over today.

Dave Hammarberg
Yeah, so if they hadn’t done that, I guess we’d be speaking about nothing today. But the i1 came out fairly quickly after the r2, and then the e1 came out after that, probably a year later. So it’s interesting, but it does help small and medium-sized organizations get into HITRUST. I think that’s really why they put it out there, because the r2 is quite a feat.

We’ll get into that, and again, we’ll go through the differences and similarities. Next is evaluating the level of effort and requirements, which are extremely different between the e1, i1, and r2. It almost sounds like we’re talking about Star Wars here, but we’re not. We’ll also cover differences in scoping documentation and the external assessment process for each type of assessment.

Again, it’s very different. The nice thing is that it’s sort of a ladder: you go up 10 steps on the e1, then go to the i1 for another 40 steps, and then maybe another 300 steps to the r2. So, it’s at least a progression.

Anyway, moving into that—next slide, where you were just at—polling questions. If you have any questions… can we go back to that polling question? Yeah, I think we’re already on the polling question. Okay. If you have any questions for us during today’s presentation, please submit them through the built-in question function in the webinar control panel.

We will do our best to answer them during or after the webinar. For those looking to obtain CPE credit for today’s webinar, please keep in mind there will be five polling questions throughout today’s presentation, and you must answer all of them to get your certificate via email within a month after the webinar. In order for attendees to be eligible, you must answer via the polling submission. We will not accept late responses, and we’ll leave this open for another 45 seconds.

Josh Bantz
Absolutely. Looks like we have about 79% submitted, so for those who have not answered the CPE polling question yet, please do so now so you can receive your CPE.

Dave Hammarberg
All right. We’ll go ahead and close that.

Josh Bantz
I was just going to say that. Yeah. All right, moving on. The first aspect of this webinar is to give an initial introduction and background to what HITRUST is. I think it’s wise to go through and provide a background on HITRUST, and I think Dave would probably agree with me on that, given that HITRUST is a unique framework and assessment. So, I think we would probably not be doing any justice here if we were not giving at least an initial background to what we’re going to be talking about, because there is a lot of verbiage and language that we’ll be talking about throughout that needs to be sort of talked through over the next several slides.

Dave Hammarberg
Yeah, because I think people just don’t get what it is. Someone asks, “Hey, do you have HITRUST?” and then they call us up and say, “Hey, I need HITRUST.” They think, “Hey, it’s going to take a week and we’ll have your HITRUST.” So it is good for the audience—whether you’re just here for CPE or here to actually learn what the different versions of HITRUST are. But just from an educational standpoint, it’s good to know.

Josh Bantz
Absolutely. So the official definition of HITRUST is that it’s a comprehensive, flexible, and efficient approach to compliance and risk management that has been adopted on a global scale. What is the plain-English definition of HITRUST? Because that official definition is a lot of words. HITRUST is a framework of frameworks that organizations who create, access, store, or exchange sensitive information can use as a roadmap for security, privacy, and compliance. HITRUST was formed in 2007 as the Health Information Alliance, and the goal in 2007 was to create a framework of frameworks that would allow organizations to demonstrate compliance with HIPAA PHI regulations regarding security and data privacy.

It has since evolved from that into being more than just a healthcare framework. The HITRUST framework itself is actually based on ISO 27001 and ISO 27002. In addition to that, specifically with the r2, the r2 framework allows you to layer in over 40 other security and privacy regulation frameworks.

So really, the HITRUST framework is built off of other frameworks—not just one. It is a combination of ISO, NIST, CIS, and other frameworks that they’ve pulled together to take the best control requirements and build out a framework that provides security.

Dave Hammarberg
So Josh, are you saying… I know HITRUST is expensive. Are you saying that now if I get HITRUST, I get certified in ISO and NIST, and now I have a SOC 2? Can I say I have all of those different certifications or audits?

Josh Bantz
Yes and no, Dave. That’s a great question because what you can do in a HITRUST assessment is layer in those frameworks so that you do a HITRUST r2 plus ISO 27001, and those requirements will be part of your assessment. Now, in order to get the certification for a SOC 2, there is a mapping that HITRUST provides between the SOC 2 Trust Services Criteria and the HITRUST framework.

Ultimately, before you can get a SOC 2—which is actually an attestation report provided by a CPA—you would still have to show your evidence and compliance with those specific controls from the HITRUST requirements and how you’ve met your SOC 2 requirements. One of the interesting things, Dave, is that the HITRUST validated assessment certification is sort of a forward-looking assessment. When you complete your assessment, the r2 is good for two years. The i1 and e1 are good for one year.

Whereas the SOC 2 is somewhat of a retrospective audit opinion attestation report looking backwards. So you certainly can leverage the work that you’ve done—same with ISO, same with NIST. But if you require an attestation report, you can get a report from the HITRUST MyCSF web application. When you complete your HITRUST assessment, it will actually map your requirements and scores to those various frameworks to provide to any of your vendors if they’re asking for your
compliance within NIST 800-171 or NIST 800-53. So you do have the option to get an actual SOC 2 or an ISO certification, though it will take additional steps. But to be honest, the heavy lifting will be done in getting through the HITRUST certification in most cases.

Dave Hammarberg
It’s almost an educational situation in regards to third-party compliance for your customers or whoever is requiring HITRUST instead of a SOC 2. We have a lot of clients where we’ll do HITRUST, SOC 2, and another framework. But if third-party compliance reviewers knew how much HITRUST covered, it might cover all those frameworks without having to do a separate SOC 2 attestation, HITRUST, ISO 27001, etc. Most of the time, the third-party compliance team requiring
the HITRUST assessment simply doesn’t know HITRUST, SOC 2, or ISO 27001 well enough.

It seems like they’re more comfortable with one framework over another, and then all these clients have to do multiple frameworks. But again, HITRUST covers a lot of that.

Josh Bantz
Absolutely. And the other thing that really does a great job with the HITRUST CSF—specifically with the r2—is that you can layer in regulatory requirements as well. I know Massachusetts has a data privacy requirement, and California has them. They’re also part of the HITRUST CSF and can be added into an r2 assessment. So beyond getting a separate report that shows ISO compliance or SOC 2, you have the ability to present to your customers, vendor management, or regulators how you have complied with their specific requirements in Massachusetts or California. In the event that happens where it doesn’t take a separate report, the HITRUST MyCSF application actually allows you to run additional framework reports to show your scoring and compliance with the requirements for those data frameworks. When it comes to regulatory requirements, it’s really, really helpful because even if there isn’t a specific separate report, Dave, there is the ability to say, “Well, here’s how we have complied with this regulatory framework.” So beyond just other standards, regulatory frameworks add a lot of value to that HITRUST assessment.

Dave Hammarberg
Makes a lot of sense. I mean, the big thing with HITRUST is MyCSF—that’s the big difference. With ISO 27001, no one has a single mandatory software package that you have to use to get validation. But I’m sure we’ll get more into that.

Josh Bantz
Yeah. As we talk about what HITRUST is, I’m going to delve into the HITRUST CSF. CSF stands for Common Security Framework. So when we talk about the HITRUST Common Security Framework, that is the framework of frameworks we refer to. It merges existing controls, standards, regulatory resources, business, and third-party requirements into one framework. The baseline i1 (182 requirements) is based upon various frameworks—a lot of it is based on ISO, but there are also
some NIST requirements and other elements in there. So it’s not built off of just one framework; it’s compliance and risk-management driven.

One thing that is very different here is that the requirements and controls in the Common Security Framework for HITRUST are quantitatively evaluated to determine your scoring. There’s certainly judgment involved in assessing an organization’s ability to meet those requirements and how your external assessor determines whether you’ve met them. But effectively, HITRUST has defined a quantitative scoring rubric for each maturity level that is part of each requirement statement. So you can compare any organization’s score.

It’s very defined: this is the score you get based upon how you’ve implemented the requirement or documented your policies and procedures. It’s much more comparable. I won’t say there’s no subjectivity to it, but it’s definitely more objective because it requires a score and has defined scoring thresholds.

As Dave mentioned, HITRUST has various tools to assist in the assessment process—specifically MyCSF. MyCSF is a SaaS-based application that you are required to purchase from the HITRUST Alliance to complete any HITRUST certification or validated assessment, whether it’s e1, i1, or r2.

What that application does is allow you to view your requirement statements, score them, access scoring details, and work through what your assessment will look like based on your environment. It sort of does a lot of the work for you. You and your external assessor still have to understand the scoring, but there isn’t a complex mathematical burden on your end to calculate the score for each domain; MyCSF really handles that on your behalf.

MyCSF contains substantial information, including regulatory frameworks and mappings to various frameworks from the HITRUST CSF. It has the ability to show in an i1 how you have mapped to the SOC 2 Trust Services Criteria, and it’s the same with NIST 800-53 or 800-171. So it is very beneficial from that perspective.

Dave Hammarberg
So MyCSF is basically a GRC platform?

Josh Bantz
I wouldn’t call it a full GRC platform—it’s more of an evidence collection tool. For an organization seeking a HITRUST assessment, it generates the specific requirements you need to meet (whether e1, i1, or r2). If it’s an r2, which is risk-based, it guides you through the risk-based assessment to
determine which requirements are in scope.

It provides those requirements, and then for each requirement, there is a place where you can document your scope, as well as the evidence and artifacts defining how you’ve met the requirement and what your score should be. It aggregates your evidence for you and then allows the external assessor—like McKonly & Asbury—to log in, evaluate the evidence, and rescore or revalidate it within MyCSF.

However, when I say it’s not a full GRC package, I want to clarify that there aren’t automated settings pulling data directly from your systems—like quarterly password policy downloads—to validate compliance. It’s not at that level of automated GRC package. What it really is, is documentation retention and scoring software. As you go through future HITRUST assessments, that information is retained.

Dave Hammarberg
Yeah, it’s interesting because some people might define that as a GRC package. With the evolution of GRC tools in the IT assessment world, we see systems that pull settings directly rather than just letting you upload evidence.

Josh, there are a lot of accountants on the call today looking for CPE, and we’re all thinking: there’s a huge price difference between an e1, i1, and r2. Is there any difference in buying MyCSF, and how does that work?

Josh Bantz
You have to purchase MyCSF from HITRUST directly. As external assessors, we are not authorized resellers. There are really two different levels of packages, and pricing generally depends on the number of users you need and the functionality required. A good example is that one subscription package has limited users and doesn’t allow for features

like inheritance or multiple assessment objects. For those on the call, inheritance in HITRUST is the ability to inherit control scores from third-party providers. If the organization seeking assessment uses Microsoft Azure or AWS as cloud infrastructure for their in-scope applications, they can inherit the HITRUST scores from AWS or Azure, as those providers already hold HITRUST certifications.

Where the assessed organization is not responsible on a responsibility matrix for specific requirements, they can inherit those scores through MyCSF. That feature requires a higher package tier. If your organization is entirely on-premises with local data centers and servers, and you don’t use third-party cloud providers or MSPs operating controls, you can get a lower package tier that is much cheaper than the inheritance package.

Dave Hammarberg
We had a couple of questions come in. Do you want to answer them right now?

Josh Bantz
Sure.

Dave Hammarberg
Here’s one, and I think we’ve touched on this, but I’ll throw it out there: Is the HITRUST framework open-source and free like NIST, or do you have to purchase it like ISO?

Josh Bantz
The HITRUST framework actually needs to be purchased; it is not open-source and sits behind a paywall. You have to buy MyCSF. Once you get your MyCSF subscription, you can see the specific requirements.

You can go out to the HITRUST Alliance website and download the high-level control references of the HITRUST CSF for free. However, you are scored and assessed for a HITRUST assessment based upon specific requirement statements. Those requirement statements are proprietary, so you wouldn’t be able to fully assess whether you’ve met all aspects to score yourself accurately without having those requirement statements available in MyCSF during an e1, i1, or r2 assessment.

Dave Hammarberg
Okay. Next question, and this is probably a tricky one: Should an internal audit group be auditing using the HITRUST framework?

Josh Bantz
I would say yes. In my opinion, HITRUST is one of the upper-echelon assessment frameworks you can use because of its comprehensive requirements and how it’s built off of multiple standards.

From an internal audit perspective, over the last two years, HITRUST-certified environments have experienced very few breaches—I believe around 0.63% of recorded breaches occurred in HITRUST-certified environments. It’s a framework that works. There’s no way around that. To the extent that an internal audit group can align with HITRUST and its underlying frameworks, it certainly elevates that organization’s cybersecurity compliance posture.

Dave Hammarberg
I would agree.

Josh Bantz
Regarding the HITRUST Common Security Framework design: the framework is built on control references, requirement statements, and evaluative elements. As mentioned, control references are publicly available. Each control reference contains a set of requirement statements. For example, password policies might be a control reference, which then defines four or five requirement statements detailing specific password rules.

Within each requirement statement are evaluative elements. If you have password policies in place, evaluative elements specify that you must have account lockout enabled and technical settings enforcing it. One requirement statement might have 17 evaluative elements, while others have only one. You are scored based on whether you have the requirement in place and whether you meet those evaluative elements.

For example, if a requirement statement has five evaluative elements and you have implemented four of them, your raw score would be roughly 80%. So there are layers: Control references contain requirement statements, and requirement statements contain evaluative elements that determine your score.

Your scoring occurs at the requirement statement level. The evaluative elements serve as explicit, prescriptive procedures that specify exactly what you need to do to satisfy the HITRUST framework.

Dave Hammarberg
Yeah, scoring is very complex in HITRUST. We could probably do an entire session just on scoring.

Josh Bantz
As you go through HITRUST, you want to aim for a 100% score. Nobody gets a perfect 100, but you want to try to follow it as closely as possible. You also have to perform controls consistently for at least 90 days prior to the validated assessment.

If you miss doing a background check on one employee, you don’t automatically fail the whole assessment—your score is simply adjusted based on that sample exception. So you don’t want to cut corners by skipping evaluative elements; you want to establish processes that meet all of them.

Dave Hammarberg
The HITRUST Common Security Framework is broken into 19 domains, covering areas like Education, Training and Awareness, and Audit Logging and Monitoring. Within each domain is a set of requirements, and your score is assessed at the domain level. If there are ten requirement statements in Network Protection, you get a score for each, and the domain average must meet a specific threshold for certification. For an e1 and i1, you need an 83% average score in each domain to get certified. For an r2, the threshold is 62%. Every single domain must meet or exceed the required threshold.

Josh Bantz
Regarding assessment types: HITRUST offers readiness assessments as well as validated/certified assessments. A readiness assessment can be completed self-guided by your organization and submitted to HITRUST to evaluate whether you are ready for a validated assessment.

A validated assessment requires an external assessor. Whether it’s an e1, i1, or r2, every validated assessment must be conducted by an authorized external assessor like McKonly & Asbury. Your organization collects evidence and performs initial self-scoring, and then the external assessor comes in to test and validate those scores. If the validated scores meet the required thresholds (83% per domain for e1/i1, 62% for r2), HITRUST issues a certification.

Now we come to polling question number two.

Dave Hammarberg
Polling Question #2: What is your current understanding of HITRUST and the types of HITRUST assessments?

We’ll give it another 20 seconds for everyone to respond.

Josh Bantz
Looks like we have most responses in.

Dave Hammarberg
All right, looking at the results: 53% have heard of HITRUST with some understanding, 27% have a solid understanding, and 20% have never heard of it. That aligns with my point earlier—third-party vendor management requirements depend on which frameworks people are familiar with. That’s why organizations end up getting both a SOC 2 and a HITRUST, even though maintaining multiple certifications gets expensive.

Josh Bantz
Correct. Moving on to the specific differences and similarities between the three validated assessments: e1, i1, and r2. All validated assessments are performed against the CSF by an external assessor in accordance with the HITRUST Assurance Program, and scoring thresholds must be met for certification. If
scores fall below certain thresholds, Corrective Action Plans (CAPs) may be required.

CAPs are assigned at the control reference level. If your score for a control reference falls below the required threshold, a CAP is issued. To maintain certification, you must demonstrate annual progress toward remediating CAPs in subsequent assessments. So yes, you can achieve HITRUST certification while still having Corrective Action Plans.

Additionally, there are “gaps.” A gap occurs when a requirement statement receives a score below 100% (for example, 75%, which represents “mostly compliant”). Gaps are noted in the report but do not necessarily prevent certification, provided the overall domain score stays above the required threshold (83% for e1/i1, 62% for r2). However, every single domain must pass—you cannot have 100% in 18 domains and 50% in one domain and still achieve certification.

Josh Bantz
Let’s detail the three types:

  1. HITRUST e1: A foundational-level assessment. It is the lightest and least invasive tier, comprising 43 requirement statements, and focuses solely on the Implementation maturity level.
  2. HITRUST i1: A moderate-level assessment with 182 requirement statements. It also focuses on the Implementation maturity level, but represents a much larger effort than the e1.
  3. HITRUST r2: A risk-based assessment. (Note: The numbers 1, 1, and 2 in e1, i1, and r2 indicate how many years the assessment certification is valid for—e1 and i1 last 1 year, while r2 lasts 2 years.) The r2 is risk-driven and can range from 200 up to 1,900 requirement statements depending on the risk profile and regulatory frameworks selected. Additionally, the r2 evaluates all 5 maturity levels: Policy, Procedure, Implementation, Measured, and Managed. Organizations can opt out of Measured and Managed, which caps their maximum score at 75% per requirement—which is why the r2 certification threshold is set at 62%.

To explain the maturity levels:
– Policy: Documented policy in place.
– Procedure: Documented procedure in place.
– Implementation: Controls actively functioning in the environment.
– Measured: Mechanisms in place to track and measure control performance (e.g., internal audit
monitoring).
– Managed: Processes to handle control failures, gaps, and CAPs.

Josh Bantz
Regarding similarities: The 43 requirement statements in the e1 are a subset of the 182 in the i1, and the 182 in the i1 are a subset of the base r2 requirement statements. So as you complete the e1, you are 43 steps toward the i1, and so on.

Furthermore, scoping components are identical across all three assessments. You must clearly define the scope: systems, platforms, applications, databases, operating systems, facilities, etc. Scoring rules and sampling methodologies are also consistent.

Josh Bantz
Key differences:

  • Number of Requirements: Fixed for e1 (43) and i1 (182), but variable for r2 (200 to 1,900+ based on risk factors and regulatory add-ons).
  • Maturity Levels: e1 and i1 evaluate Implementation only. r2 evaluates up to 5 maturity levels, requiring formal policy and procedure documentation for every requirement.
  • Scoring Thresholds: e1 and i1 require an 83% domain average. r2 requires a 62% domain average.

Dave Hammarberg
Josh, for comparison, how does the effort required for HITRUST compare to a standard SOC 2?

Josh Bantz
In terms of effort:

  • e1 is very comparable to a standard SOC 2 report (which typically evaluates 70 to 90 controls).
  • i1 is a significantly larger lift—182 requirement statements containing over 600 evaluative
    elements.
  • r2 is a major undertaking because documenting formal policies and procedures for hundreds of
    requirements requires immense effort.

Dave Hammarberg
Is MyCSF pricing published or negotiable?

Josh Bantz
MyCSF pricing is not publicly published and generally not negotiable. Standard annual pricing typically ranges from ~$18,000 for a basic subscription up to ~$35,000 annually for subscriptions including inheritance functionality. It is a noticeable investment for organizations.

Dave Hammarberg
Polling Question #3: What HITRUST assessment are you most interested in learning more information about? We’ll give everyone a moment to respond.

Josh Bantz
Moving into timeline and resource expectations:

  • e1 Level of Effort: Light to moderate. Typical completion timeline is 4 to 6 months.
  • i1 Level of Effort: Moderate to substantial. Typical completion timeline is 6 to 12 months.
  • r2 Level of Effort: Substantial. Typical completion timeline is 12 to 24 months.

Note that for all HITRUST validated assessments, controls must be implemented and operating consistently for at least 90 days before testing can occur.

Dave Hammarberg
Polling Question #4: Does your organization currently have any IT audits or assessments? Thank you for submitting your responses.

Josh Bantz
Now regarding scoping: Scoping is critical. You want to scope for success by narrowing the focus to the specific customer-facing platform or system that processes, stores, or transmits sensitive data. HITRUST does not certify companies—it certifies specific information systems and platforms. Avoid unnecessarily including auxiliary tools or enterprise-wide infrastructure if they can be excluded from scope.

Dave Hammarberg
Documentation is the key takeaway. If it isn’t documented, it can’t be validated.

Dave Hammarberg
Polling Question #5: Does your organization currently get a HITRUST assessment or plan on becoming a certified organization in the future?

Josh Bantz
We had a final question: Do you have to abandon your current IT controls and policies to adopt exact HITRUST wording? No, you do not. As long as your existing policies and controls meet the specific evaluative elements required by HITRUST, you can keep your existing structure.

Dave Hammarberg
Thank you for joining us for today’s webinar. A recording will be posted on our website in a few days, and CPE certificates will be emailed within a month. Join us on July 30th for our next webinar on Year 15 LIHTC transitions. Have a great rest of your day!