HITRUST Compliance Readiness Checklist cover image

The HITRUST Compliance Readiness Checklist

Written by
Travis Good
Founder and CEO at Workstreet
Reviewed by
No items found.

Accelerating security solutions for small businesses 

Tagore offers strategic services to small businesses. 

A partnership that can scale 

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Getting HITRUST certified is a big investment. Compared to other security frameworks, HITRUST is significantly more expensive, time-consuming, and resource-intensive. The process can take anywhere from 6 to 18 months to complete, requiring deep documentation, detailed security assessments, and ongoing coordination across teams.

But with that extra rigor comes serious credibility.

HITRUST holds more weight in the market than many other certifications because it’s so thorough. For organizations in highly regulated industries—particularly in healthcare, where handling sensitive patient data is core to the business—HITRUST isn’t simply a report you share as a part of procurement. It’s a competitive differentiator and a signal of security maturity.

At Workstreet, a Vanta partner, we bring over a decade of experience navigating the complexities of HITRUST certification. As former founders of one of the first startups to achieve HITRUST certification, our experience has shaped our approach to guiding companies through this rigorous process. Our founders have spoken at the HITRUST conference five times, and we are founding members of the HITRUST Third-Party Assurance Council. We also wrote and open-sourced HITRUST-aligned policies and procedures used by 100s of companies. Currently supporting over 20 customers with their HITRUST certifications, we understand the nuances that make the difference between success and frustration.

This readiness checklist is designed to help you lay the groundwork before diving into the certification process. By getting your controls, documentation, and stakeholders aligned early, you’ll be in a much stronger position when it’s time to work with a HITRUST assessor or submit to the HITRUST MyCSF.

Choosing the right HITRUST assessment type

HITRUST offers three types of assessments to meet organizations at different maturity and assurance needs. We recommend building a high-level HITRUST roadmap to target and progress through the different maturity levels.

e1 (Essential 1)

The e1 assessment is HITRUST's entry-level offering, providing a streamlined path to demonstrate basic security controls. This is ideal for companies just beginning their compliance journey, startups looking to establish baseline security credibility, or companies that need to show foundational security measures without the full rigor of more advanced assessments. We recommend starting here unless contractual obligations require a higher level.

i1 (Implemented 1)

The i1 assessment offers a middle ground, with more thorough requirements than e1 but less complexity than r2. This level is suitable for companies that need to demonstrate stronger assurance to customers and partners but aren't yet ready for the comprehensive r2 assessment. While some organizations benefit from this intermediate step, we often recommend progressing directly from e1 to r2 when possible, depending on your scope and business needs.

r2 (Risk-based 2)

The r2 assessment is HITRUST's most comprehensive option, delivering the highest level of assurance. The r2 is fully scoped to your company, meaning the number of controls, level of effort, and cost depends on your company, data, and risk. This rigorous assessment is necessary for organizations handling sensitive data, serving enterprise clients with strict security requirements, or operating in heavily regulated industries like healthcare. While r2 requires significant resources and preparation, it offers the strongest market differentiation and compliance coverage.

HITRUST compliance-readiness checklist:

{{hitrust-readiness="/checklists"}}

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.