Covenant Advisory Group / HITRUST e1, i1, and r2

HITRUST e1, i1, or r2: which one do you need?

A plain-language guide to the three HITRUST certifications, who asks for each one, how long they take, and how to avoid certifying more than your customers actually require.

Reviewed September 2026. Requirement counts reflect the current HITRUST CSF version 11.

The short answer

Let your customer decide. Most organizations pursue HITRUST because a health system, payer, or partner asked for it. The right level is the one their contract accepts. If they just say "HITRUST," ask which one before you start. It can mean the difference between a few months of work and more than a year.

The three levels

e1: Essentials

About 44 foundational requirements covering basic cyber hygiene: access, patching, malware protection, incident response. Valid for one year. It's the fastest way to earn a HITRUST credential and a sensible first step for smaller organizations with limited patient data.

i1: Implemented

182 fixed requirements covering leading security practices. Valid for one year. It's often the middle ground when a customer asks for "HITRUST" in a vendor questionnaire without naming a level. Like e1, it checks that controls are implemented.

r2: Risk-based

The most rigorous level, and what most large health systems and payers mean by "HITRUST certified." The requirements are tailored to your size, systems, and data, often running to several hundred. Controls are scored on maturity, meaning they have to be documented in policy and procedure, not just implemented. Valid for two years, with an interim assessment at year one.

e1i1r2
RequirementsAbout 44182Tailored, often several hundred
Scored onImplementationImplementationPolicy, procedure, implementation, and more
Valid for1 year1 year2 years with interim
Typical timeline3 to 6 months6 to 9 months9 to 18 months

Timelines are typical ranges from the start of readiness work. Controls also have to be operating for about 90 days before they can be tested, so remediation done the week before an assessment doesn't count yet.

How to choose

  1. Read the contract language. If it names r2, that's your answer. If it names HITRUST generically, ask which assessments they accept.
  2. Match the deadline to the level. If you need something within six months, an r2 is rarely realistic. An i1 now with r2 later is a common path, if your customer accepts it.
  3. Scope carefully. Certify the systems that handle your customers' data, not your whole company. Scope is the biggest driver of effort and cost.
  4. Start with your risk analysis. A current HIPAA risk analysis tells you where you stand and makes every HITRUST level easier.

Find your likely path

Check what's true for you. We'll point you to the likely fit.

What's true for your organization?
  1. ReadinessScope and gap assessment

    Confirm the level you need and where you stand.

    Covenant
  2. RemediationClose gaps, then let them run

    Controls operate about 90 days before testing.

    Covenant + your team
  3. AssessmentValidated assessment

    BEYOND HC, our authorized assessor partner.

    BEYOND HC
  4. CertificationHITRUST review

    Quality review and certificate issued.

    HITRUST

Questions

Is HITRUST required by law?

No. HIPAA is the law. HITRUST is a certification customers use as proof that your security program is real. It usually shows up in a contract, RFP, or vendor questionnaire.

Does HITRUST certification make us HIPAA compliant?

Not by itself. HITRUST covers most of what the HIPAA Security Rule expects and is strong evidence, but you still need your own current risk analysis and HIPAA program.

Can we start with e1 and move up later?

Yes. The levels build on each other: e1 requirements are part of i1, and i1 requirements are part of the r2 baseline. Moving up means a new assessment, but the work you've done carries forward.

How long is a certification good for?

e1 and i1 are valid for one year. r2 is valid for two years, with an interim assessment at the one-year mark to show the program is still operating.

Who performs the assessment?

An authorized HITRUST external assessor tests your controls and submits the assessment, then HITRUST performs its own quality review before issuing the certification. We prepare you, and our assessor partner BEYOND HC performs the validated assessment.

Sources
HITRUST Alliance assessment and certification materials. Requirement counts reflect HITRUST CSF version 11 as of September 2026 and change between versions.

Tell us what you're working on

No pitch, no pressure. We reply within one business day, and everything you share stays confidential.

We reply within one business day.