HITRUST Controls: Requirements, Maturity Levels and Evidence

A healthcare organization can have a HIPAA program, follow NIST guidance, and maintain hundreds of security policies and still struggle to answer one question: Are our security controls actually working? Recent U.S. enforcement shows why this matters. In March 2026, HHS settled a HIPAA investigation involving MMG Fusion following a breach affecting approximately 15 million individuals, highlighting gaps around risk analysis, access controls, audit logging, authentication, and ongoing security management. These are familiar controls. The challenge is proving they are consistently implemented, effective, and supported by evidence.
This is where HITRUST controls become relevant. Instead of managing overlapping HIPAA, NIST, privacy, and contractual requirements as separate checklists, the HITRUST control framework brings them into a common, risk-based structure. The question shifts from “Do we have the control?” to “Does it work, and can we prove it?” That is the real value of understanding HITRUST CSF controls.
What Are HITRUST Controls?
HITRUST controls are structured security and privacy requirements within the HITRUST CSF that organizations use to manage information risk and demonstrate control effectiveness. The HITRUST control framework harmonizes requirements from numerous standards, regulations, and authoritative sources. This allows organizations to address overlapping security and compliance obligations through a more integrated control structure rather than maintaining separate control programs for every requirement. At a high level, HITRUST CSF controls follow a hierarchy from Control Category to Control Objective, Control Specification, Control Requirement, and finally the Evidence needed to demonstrate compliance.
For example, an organization may have an access control objective requiring appropriate authentication. That objective is translated into more specific requirements that define what needs to be implemented and what evidence can demonstrate that the requirement is being met. The presence of a policy requiring multi-factor authentication is not sufficient evidence of compliance; organizations must also demonstrate that MFA is effectively implemented and enforced across all applicable systems. That is why HITRUST security controls place importance on implementation, measurement, and management.
How Is the HITRUST Control Framework Organized?
The HITRUST CSF is not simply a static HITRUST controls list that every organization implements identically. Its structure organizes security and privacy requirements into control categories and objectives, which are then tailored to the characteristics and risk profile of an organization. Areas addressed through HITRUST CSF controls include topics such as:
- Information security management
- Access control
- Risk management
- Asset management
- Human resources security
- Physical and environmental security
- Communications and operations
- Incident management
- Business continuity
- Secure system development
- Privacy
- Compliance
This structure allows organizations to look at security holistically. For example, protecting sensitive information may require more than technical safeguards. It can also depend on employee responsibilities, access governance, incident response, physical security, vendor management, and business continuity. For U.S. organizations, this integrated approach can be particularly valuable when multiple regulatory and contractual requirements overlap.
Strengthen your security and privacy assurance with INTERCERT’s HITRUST Certification services. Demonstrate effective controls, meet applicable requirements, and build stakeholder confidence.
How Does HITRUST Determine Which Controls Apply?
One of the most important characteristics of HITRUST is its risk-based approach. Organizations do not necessarily face identical HITRUST control requirements. The applicable requirements and level of rigor can depend on factors related to the organization, systems, information, technology environment, and risk. This means two organizations operating in the same industry may not necessarily have identical control requirements. For example, a healthcare organization processing large volumes of sensitive patient information and operating internet-facing systems may have a different risk profile from a smaller organization with a more limited technology environment. The practical takeaway is important: HITRUST is not simply a checklist. It is a risk-tailored control framework. This approach helps organizations focus their resources on controls that are relevant to their risk exposure instead of applying identical security measures everywhere.
Understanding HITRUST Control Maturity
Another important part of the HITRUST methodology is control maturity. Organizations sometimes make the mistake of viewing a control as either “implemented” or “not implemented.” In practice, control effectiveness is more nuanced. HITRUST evaluates maturity across five levels:
- Policy – Management's expectations and intent are formally established.
- Procedure – The organization defines how the control will be performed.
- Implemented – The control is actually operating.
- Measured – The organization evaluates control performance.
- Managed – Results are reviewed and used to improve the control.
Consider an organization's MFA control. A policy may state that MFA is mandatory. A procedure may explain how users enroll. Implementation means MFA is technically enforced. Measurement could involve tracking MFA coverage and exceptions. At the managed level, management reviews performance trends and takes corrective action when weaknesses appear. This demonstrates why HITRUST controls and requirements should not be treated as documentation exercises.
What Evidence Is Needed for HITRUST Controls?
Having a control documented is only the starting point. HITRUST assessments require organizations to demonstrate that controls are implemented, operating consistently, and producing the intended results. Depending on the requirement, evidence may include:
- Security policies and procedures
- Access review records
- Vulnerability assessment results
- System configurations
- Security logs
- Training records
- Incident response records
- Risk assessments
- Monitoring reports
- Control testing results
- Management review records
The key is traceability. Evidence should connect the requirement to what actually happens in the organization and show when, how, and by whom the control was performed. For example, an access control policy may require periodic user access reviews. The completed review demonstrates that the process occurred, while records of revoked privileges, exceptions, and corrective actions show that identified issues were actually addressed. This is what makes HITRUST compliance controls different from a documentation exercise. The objective is not simply to produce documents for an assessment, but to demonstrate that controls are operating effectively and being managed over time.
HITRUST e1, i1, and r2: Different Levels of Assurance
Not every organization needs the same depth of cybersecurity assurance. HITRUST offers three assessment paths, e1, i1, and r2, designed to address different levels of risk, control maturity, and assurance needs.
HITRUST e1: Essential Cybersecurity
The e1 assessment focuses on foundational cybersecurity practices. It is designed to establish a baseline of essential controls for organizations looking to demonstrate that core security practices are in place.
HITRUST i1: Current Cybersecurity Practices
The i1 assessment builds on that foundation with a broader set of controls aligned with current and emerging cybersecurity threats. It provides stronger assurance that an organization has implemented practices appropriate for a changing threat environment.
HITRUST r2: Risk-Based Assurance
The r2 assessment takes a deeper, more tailored approach. Its requirements are adjusted to the organization's specific risk factors, resulting in greater control depth and a more comprehensive assessment of security and privacy practices.
The key takeaway is that HITRUST CSF requirements are not a one-size-fits-all checklist. The appropriate assessment depends on an organization's risk profile, regulatory obligations, customer expectations, and desired level of assurance. For businesses operating in the USA, choosing between e1, i1, and r2 should therefore be based on the level of assurance the business needs.
HITRUST Controls vs. HIPAA, NIST, and ISO 27001
If an organization already follows HIPAA, NIST, or ISO 27001, it may ask: Why add HITRUST? The answer lies in the different purposes each serves and how HITRUST brings multiple requirements into a common control and assurance structure.
HIPAA — Regulatory Requirements
HIPAA establishes legal requirements for protecting certain health information in the USA, covering areas such as privacy, security, and breach notification. However, HIPAA itself is not a comprehensive, certification-oriented cybersecurity control framework.
NIST — Cybersecurity Guidance
NIST provides cybersecurity frameworks and control guidance that organizations can use to identify, manage, and reduce cybersecurity risk. Its frameworks and controls can serve as a strong foundation for building and strengthening an organization's security program.
ISO/IEC 27001 — Information Security Management
ISO/IEC 27001 defines requirements for establishing and continually improving an Information Security Management System (ISMS). It focuses on systematic information security management through governance, risk management, documented information, internal audits, and continual improvement.
HITRUST — Integrated Control and Assurance Framework
HITRUST brings requirements from multiple authoritative sources into a common, risk-based control framework. It provides organizations with a structured approach to determine applicable requirements, implement controls, and demonstrate their effectiveness through formal assessments.
Why This Matters?
Organizations do not necessarily need separate control environments for every framework. Existing policies, processes, HITRUST security controls, and evidence can often be mapped across overlapping requirements. such as those addressed through HIPAA and ISO 27001 mapping. The objective is to move from multiple disconnected compliance checklists to a unified control environment that reduces duplication and provides a more consistent way to manage and demonstrate security risk.
Common Challenges With HITRUST Security Controls
Adopting HITRUST security controls is not simply about checking requirements off a list. Organizations often encounter challenges when translating documented requirements into controls that are consistently implemented, measured, and maintained.
Treating Controls as a Documentation Exercise
Policies and procedures establish expectations, but they do not demonstrate that a control works. Organizations may create documentation to meet an assessment requirement without ensuring that the underlying process is consistently performed and reviewed.
Fragmented Evidence Management
Evidence can sit across security tools, ticketing systems, HR platforms, cloud environments, and individual teams. When evidence is fragmented or poorly maintained, demonstrating that a control operated consistently can become difficult, even when the underlying process is effective.
Unclear Control Ownership
HITRUST requirements can span multiple functions, including IT, security, HR, compliance, and business operations. Without clearly defined ownership, responsibilities can overlap or fall through the gaps, resulting in inconsistent control execution.
Measuring the Control, Not Just Performing It
A control can be performed regularly without anyone evaluating whether it remains effective. Organizations need meaningful metrics, reviews, and testing to identify recurring exceptions, performance gaps, and changes in risk.
Preparing Only for the Assessment
A control environment should not be optimized for a single assessment date. Threats, systems, risks, and business processes change continuously. Controls that are effective during an assessment can become outdated if they are not monitored and improved afterward.
These challenges highlight why HITRUST compliance controls should be managed as part of an ongoing risk and control program. The objective is not simply to demonstrate compliance once, but to maintain controls that remain relevant, effective, measurable, and defensible over time.
Build confidence in your security and privacy controls with INTERCERT’s HITRUST Certification services. Demonstrate control effectiveness and strengthen assurance for customers and business partners.
How to Build a Strong HITRUST Control Program?
A strong HITRUST control program should do more than prepare an organization for an assessment. It should create a repeatable process for understanding risk, managing controls, maintaining evidence, and demonstrating effectiveness over time.
Define the Assessment Scope
Start by establishing exactly what is being assessed. Identify the relevant systems, applications, data, business processes, locations, and third parties. A clearly defined scope prevents unnecessary effort and ensures that applicable HITRUST CSF requirements are evaluated against the right environment.
Determine Applicable Requirements
Once the scope is established, identify the HITRUST control requirements that apply to the organization. Consider factors such as the assessment type, organizational characteristics, technology environment, regulatory obligations, and risk profile.
Map Existing Controls
Do not start from scratch. Map existing policies, procedures, technologies, and security practices to applicable HITRUST requirements. This can reveal where existing controls already satisfy requirements and where additional measures may be needed.
Evaluate Control Maturity
Assess each control beyond a simple “implemented” or “not implemented” status. Determine whether the control is documented, operational, measured, and actively managed. This provides a clearer picture of where control maturity needs to improve.
Establish Evidence Ownership
Assign clear ownership for each control and its supporting evidence. Define who is responsible for collecting, reviewing, updating, and retaining evidence so that documentation does not become fragmented across teams.
Prioritize Control Gaps
Not every gap carries the same level of risk. Prioritize deficiencies based on their impact, likelihood, affected systems or data, and relevance to applicable HITRUST controls and requirements. This helps direct resources toward the areas that matter most.
Validate Operating Effectiveness
Verify that controls are actually working as intended. Review samples, test processes, examine system configurations, and evaluate records rather than relying solely on policies or management statements.
Monitor and Improve Continuously
Control effectiveness can change as systems, threats, regulations, and business processes evolve. Use metrics, control testing, reviews, exceptions, and corrective actions to identify weaknesses and keep controls effective between assessment cycles.
The goal is not simply to prepare for a HITRUST assessment. A well-designed program turns HITRUST CSF controls into an ongoing part of governance and risk management, giving organizations greater visibility into what controls exist, who owns them, how well they perform, and where improvement is needed.
Why HITRUST Controls Matter Beyond Certification?
The value of HITRUST controls extends well beyond achieving an assessment result. A mature control environment gives organizations a clearer view of how security requirements are implemented, who owns them, how performance is measured, and where weaknesses or recurring gaps exist. For organizations in the USA, this also creates a stronger basis for demonstrating security assurance to customers, business partners, regulators, and other stakeholders.
More importantly, HITRUST shifts the focus away from simply asking, “Do we have this control?” and toward more meaningful questions: “Is the control implemented? Is it operating effectively? How do we know? And what happens when it fails?” This emphasis on demonstrable effectiveness makes HITRUST compliance controls more than documentation requirements. It turns them into an ongoing mechanism for managing risk, measuring performance, and improving the organization's security posture.
Moreover, certification should be viewed as an outcome of a mature control environment. The real value lies in maintaining controls that remain relevant, effective, measurable, and aligned with changing risks long after the assessment is complete.
HITRUST Certification as a Foundation for Ongoing Security
HITRUST controls are most valuable when they are treated as part of a continuously managed security program rather than a checklist for achieving certification. From risk-based control selection and maturity evaluation to evidence management and ongoing monitoring, the focus is on demonstrating that security controls are not only defined, but consistently operating and producing measurable outcomes. For businesses in the U.S, this approach can provide greater confidence that security and privacy requirements are being addressed through a structured and defensible control environment. It also creates a stronger foundation for demonstrating assurance to customers, business partners, and other stakeholders.
As an independent third-party certification body, INTERCERT provides HITRUST certification services with an emphasis on impartiality, competent assessment, and internationally recognized certification practices. Its experienced auditors evaluate organizations against applicable HITRUST requirements, providing an objective view of control effectiveness and assessment outcomes.