HITRUST
HITRUST is a private framework that harmonizes HIPAA, NIST, ISO, and other requirements into one certifiable control set (the CSF), with assessments ranging from the lightweight e1 through i1 to the full r2 certification. Unlike HIPAA itself — which has no certificate — HITRUST produces one, which is exactly why large health systems ask for it.
Who actually requires it
A subset of large health systems, payers, and their vendors — often as a BAA condition or procurement gate. If your buyers are hospitals and national payers, HITRUST requests are a matter of time. If you sell to digital-health startups and clinics, the HIPAA + SOC 2 pairing typically clears review without it.
What it costs, honestly
The r2 certification is among the heaviest lifts in commercial compliance — hundreds of requirement statements, external assessment, and pricing that commonly runs multiples of a SOC 2 engagement. The newer e1/i1 tiers exist precisely because the market balked; they’re credible intermediate answers when a customer’s security team will accept them.
The sequencing advice
Don’t pursue HITRUST speculatively. Build the HIPAA + SOC 2 program first (most of HITRUST’s substance, a fraction of its ceremony), keep the control mapping clean, and let a signed-revenue requirement — not a sales hypothesis — trigger the upgrade. When it does, your existing evidence discipline carries much of the load.
Attestation vs Certification — SOC 2 is an attestation — a CPA's opinion in a report. ISO 27001 is a certification — a pass/fail certificate. The difference changes how you sell each.
Business Associate Agreement — A BAA is the HIPAA-required contract between covered entities and vendors handling PHI — what it must contain and why missing BAAs trigger enforcement.
SOC 2 Type I vs Type II — Type I attests your controls are designed properly at a point in time. Type II attests they operated over a period. Here's which one customers accept.