Blog

HIPAA vs HITRUST: Which Do You Need?

HIPAA is a federal law that requires covered entities and business associates to protect health information, while HITRUST is a private, certifiable security framework th...

Arinder Singh SuriArinder Singh Suri|October 8, 2026·16 min read

HIPAA is a federal law that requires covered entities and business associates to protect health information, while HITRUST is a private, certifiable security framework that organizations use to demonstrate how well they protect it. HIPAA compliance is mandatory for regulated organizations. HITRUST certification is voluntary, but many hospitals and payers require it from vendors.

The confusion between HIPAA and HITRUST costs health technology companies months of sales time. Founders discover mid-deal that a hospital wants HITRUST, while others spend heavily on certification no customer asked for. The right answer depends on who your customers are and what evidence they demand. Taction Software builds compliant healthcare software across 200+ projects since 2013, using ISO 27001 certified processes, and this guide explains exactly when each one applies and how to plan for both.

The Core Difference Between HIPAA and HITRUST

HIPAA and HITRUST answer different questions. HIPAA asks whether your organization meets legal obligations to protect health information. HITRUST asks whether an independent assessor has verified that your security controls meet a defined, measurable standard. One is law, enforced by regulators. The other is a framework, validated by assessors and valued by customers. Understanding this distinction prevents expensive mistakes in both directions. The six differences below explain how the two compare in practice, and our glossary entries on HIPAA compliance and HITRUST define each term in more detail. Both matter.

Law vs Framework

HIPAA is federal law, with the Privacy, Security and Breach Notification Rules defining obligations. HITRUST is a private framework, the HITRUST CSF, that maps many standards, including HIPAA, into a single set of controls organizations can be assessed against. They complement each other.

Mandatory vs Voluntary

HIPAA applies automatically to covered entities and their business associates, with no option to opt out. HITRUST is voluntary. Organizations pursue it because customers, partners or boards want independent assurance, not because any federal law requires certification. Markets drive adoption.

No Certification vs Certification

There is no official government HIPAA certification, and claims of being HIPAA certified mean little. HITRUST offers formal certification after an assessment by an authorized external assessor and quality review by HITRUST, producing a report customers can rely on. Reports carry real weight.

Flexible vs Prescriptive

The HIPAA Security Rule is intentionally flexible, letting organizations choose reasonable safeguards based on risk. HITRUST is more prescriptive, defining specific control requirements and maturity levels, which makes results comparable across vendors but requires more documentation effort. Each approach has tradeoffs.

Regulator Enforcement vs Customer Demand

HIPAA is enforced by the HHS Office for Civil Rights, with civil penalties and corrective action plans. HITRUST is driven by customer demand, where the consequence of not having it is losing deals rather than regulatory penalties. Both consequences are serious.

Self-Assessed vs Independently Validated

HIPAA compliance is typically demonstrated through internal risk analyses, policies and documentation. HITRUST requires independent validation of controls, which gives customers stronger assurance but costs significantly more time and money to achieve and maintain over time. Budget accordingly. Assurance costs more.

When You Need HIPAA Compliance

HIPAA compliance is not optional for organizations that create, receive, maintain or transmit protected health information on behalf of covered entities. Every health technology company handling PHI for providers, health plans or clearinghouses becomes a business associate, with direct legal obligations under the Security Rule. Compliance is the baseline, regardless of whether customers ask for additional certifications. The six situations below are where HIPAA applies, and our HIPAA compliant app development work builds these safeguards into software from the first sprint. Every situation requires documented safeguards and signed agreements. Plan early.

You Are a Covered Entity

Healthcare providers that bill electronically, health plans and healthcare clearinghouses are covered entities. They must comply with the Privacy, Security and Breach Notification Rules directly, including risk analysis, safeguards, workforce training and patient rights obligations. Obligations are comprehensive and ongoing.

You Handle PHI for Covered Entities

Software vendors, cloud providers, billing companies and AI vendors handling PHI on behalf of covered entities are business associates. They must sign Business Associate Agreements and meet Security Rule requirements directly, with their own liability for violations. Agreements define responsibilities.

You Use Subcontractors With PHI

Business associates that share PHI with subcontractors, such as hosting providers or AI model vendors, must sign agreements with them too. Our guide to business associate agreements for developers explains this chain of obligations. Every link in the chain matters.

You Build Apps for Providers

Apps that store or transmit patient data for clinics, hospitals or health plans fall under HIPAA. Encryption, access control, audit logging, backups and incident response must be built in, documented and maintained throughout the life of the application. Security starts at design.

You Process Claims or Billing Data

Billing, revenue cycle and claims processing companies handle large volumes of PHI. They face HIPAA obligations as business associates, and their scale makes strong safeguards especially important because a single breach can affect many covered entity customers at once. Scale raises stakes.

You Are Not Sure

Consumer health apps that do not work on behalf of covered entities may fall outside HIPAA but still face FTC and state privacy laws. If you are uncertain, get legal advice early, because misclassification creates significant regulatory and contractual risk.

When You Need HITRUST Certification

HITRUST becomes necessary when customers demand it, which usually happens as health technology companies move into larger hospitals, health systems and payers. Enterprise security teams use HITRUST to reduce vendor review effort, because a certified report answers many questionnaire items at once. Some organizations make HITRUST a contractual requirement for vendors handling large volumes of PHI. The six signals below indicate when HITRUST certification is worth pursuing, and our page on HITRUST CSF for healthcare AI covers certification for AI-specific products. Demand should guide timing, not assumptions. Track demand carefully.

Enterprise Customers Require It

When hospital, health system or payer security teams list HITRUST as a requirement in RFPs or contracts, certification becomes a sales necessity. Track how often prospects ask, because repeated requests are the clearest signal that certification will pay back. Data beats guesses.

Security Reviews Are Slowing Deals

If lengthy security questionnaires delay deals for months, HITRUST can shorten them. Many enterprise customers accept a HITRUST report in place of much of their custom review, freeing sales and engineering teams from repetitive questionnaire work. Faster deals improve cash flow.

You Handle Large PHI Volumes

Organizations processing PHI for many customers or millions of patients face greater scrutiny. HITRUST demonstrates mature controls at scale, reassuring customers who worry about concentration risk when many organizations rely on one vendor for sensitive data. Assurance builds trust. Scale invites scrutiny.

You Sell to Payers

Health plans frequently require HITRUST from vendors handling member data, claims or care management information. Payer-focused health technology companies often need certification earlier than provider-focused companies selling to smaller clinics and medical groups. Plan certification early for payer sales. Ask early.

Investors or Acquirers Ask

Private equity investors and acquirers increasingly examine security maturity during due diligence. HITRUST certification provides credible evidence, which can support valuation and reduce diligence friction during fundraising or acquisition conversations with sophisticated buyers. Maturity signals discipline to buyers. Diligence moves faster.

You Want One Framework for Many Standards

HITRUST maps HIPAA, NIST, ISO and other frameworks into one control set. Organizations facing multiple compliance demands can use it to consolidate effort, rather than managing separate programs for every customer or regulation independently. Consolidation saves effort. Teams stay focused.

HITRUST Assessment Types

HITRUST offers assessment types at different levels of rigor, letting organizations start with a smaller assessment and progress as customer demands grow. Choosing the right level avoids overspending early while still meeting customer expectations. The details of each assessment, including control counts and validity periods, are defined by HITRUST and can change between framework versions, so always confirm current requirements directly with HITRUST or an authorized assessor. The six points below explain the assessment options and how health technology companies typically progress through them as they grow and move upmarket.

e1: Essentials Assessment

The e1 assessment covers foundational cybersecurity practices and suits early-stage companies or lower-risk products. It offers a practical starting point for organizations whose customers want independent assurance but do not require the most rigorous certification level yet. It builds momentum.

i1: Implemented Assessment

The i1 assessment covers a broader set of leading security practices and suits organizations facing moderate customer demands. It validates that controls are implemented, offering stronger assurance than e1 while requiring less effort than the most comprehensive assessment. Many vendors start here.

r2: Risk-Based Assessment

The r2 assessment is HITRUST’s most comprehensive option, tailored to an organization’s risk factors and evaluating control maturity in depth. Large hospitals and payers often expect r2 from vendors handling significant volumes of sensitive health information. Preparation takes longer. Plan ahead.

Readiness Before Assessment

Organizations usually complete a readiness assessment before the validated assessment, identifying control gaps and remediation needs. Readiness work prevents expensive failed assessments and gives leadership a realistic timeline and budget before engaging an external assessor. Readiness reduces surprises significantly. Do it first.

Authorized External Assessors

Validated assessments must be performed by HITRUST authorized external assessor firms, then quality reviewed by HITRUST. Assessor fees and HITRUST platform fees are separate from internal remediation costs, so budget for all three when planning certification. Fees vary by firm.

Progressing Over Time

Many companies start with e1 or i1 to satisfy early customers, then move to r2 as they sell to larger organizations. Planning this progression avoids rework, because controls built for earlier assessments can support later, more rigorous ones. Plan the path early.

HIPAA, HITRUST and SOC 2 Together

HIPAA and HITRUST are rarely the only compliance conversations health technology companies face. SOC 2 is widely requested by technology buyers, and many healthcare customers accept it as security evidence, especially from smaller vendors. Understanding how the three relate helps companies choose the right evidence at each growth stage without duplicating effort. The six points below explain how they fit together in practice, and our SOC 2 and HITRUST healthcare comparison explores the relationship between those two frameworks in more depth. Shared controls reduce cost. Plan them together. Sequence matters.

HIPAA Is Always the Baseline

Whatever certifications you pursue, HIPAA obligations remain if you handle PHI as a covered entity or business associate. Certifications provide evidence of security practices, but they do not replace risk analysis, policies, agreements and breach notification obligations. Never skip it.

SOC 2 Suits Many Early Sales

SOC 2 is familiar to technology buyers and often satisfies smaller healthcare customers. Many health technology startups pursue SOC 2 first, then add HITRUST when enterprise healthcare customers specifically require it during later growth stages. It is often faster. Buyers know it.

HITRUST Suits Healthcare Enterprises

HITRUST is designed around healthcare risk and maps directly to HIPAA, making it especially valued by hospitals and payers. Companies selling primarily into large healthcare enterprises often prioritize HITRUST over SOC 2 for that reason. Healthcare buyers recognize it. Fit matters.

Controls Overlap Significantly

Much of the work for HIPAA, SOC 2 and HITRUST overlaps, including access control, encryption, logging, vendor management and incident response. Building controls once and mapping them to each framework saves substantial effort compared with separate programs. Map once. Reuse helps.

Evidence Collection Can Be Shared

Automated evidence collection, policy management and control monitoring can support multiple frameworks simultaneously. Investing in shared tooling and processes early reduces the marginal cost of each additional certification as customer demands expand over time. Automation pays back quickly. Tools help.

Choose Based on Customers

The right sequence depends on who you sell to. Ask prospects which evidence they accept, track their answers and let real demand guide certification investments rather than assumptions about what healthcare customers generally prefer. Demand should drive decisions. Ask them.

Cost and Timeline Planning

Compliance costs fall into three buckets: internal engineering and policy work, assessor or auditor fees, and ongoing maintenance. Our engineering and readiness work is billed at a blended rate of $50 per hour, and the ranges below are planning figures, not quotes. Assessor, auditor and HITRUST fees are separate and paid directly to those organizations. Timelines depend on current control maturity, so organizations starting from scratch should plan for longer timelines. The six options below describe how organizations engage us, and our HIPAA compliance consulting services page explains the advisory side.

HIPAA Gap Assessment: $3,000 to $10,000

A HIPAA gap assessment covering safeguards, policies, agreements and risk analysis typically takes 60 to 200 hours. It produces a prioritized remediation plan, giving leadership a clear picture of obligations and gaps before investing in larger compliance programs. Findings are prioritized.

HIPAA Remediation: $10,000 to $50,000

Remediating technical and administrative gaps, such as encryption, access control, logging, backups and policies, typically takes 200 to 1,000 hours, depending on how many systems and how much existing documentation need updating to meet requirements. Work is prioritized by risk.

HITRUST Readiness: $10,000 to $40,000

Readiness work for a HITRUST assessment, including gap analysis, control implementation planning and evidence preparation, typically takes 200 to 800 hours of internal support. Assessor and HITRUST fees are separate from this preparation effort. Gaps become clear early. Timelines become realistic.

HITRUST Remediation: $20,000 to $80,000

Implementing missing controls identified during readiness, such as logging, vulnerability management and configuration hardening, typically takes 400 to 1,600 hours. Organizations with mature security programs usually need less remediation before validated assessment. Work is prioritized by assessment impact. Scope varies.

Ongoing Compliance Support: $1,000 to $4,000 Per Month

After certification, retainers covering 20 to 80 hours per month maintain controls, evidence and documentation between assessments, so organizations stay ready for renewals, customer reviews and audits without scrambling before each deadline. Scope is reviewed quarterly. Renewals become routine. Teams stay ready.

Compliance Engineers

Organizations needing dedicated help can hire HITRUST consultants or compliance engineers at about $8,000 per engineer per month to implement controls, automate evidence collection and support assessments continuously. Engineers bring healthcare security, cloud and audit preparation experience, and engagements can start within weeks.

Why Choose Taction for HIPAA and HITRUST Readiness

Compliance consultants can write policies, but health technology companies also need engineers who can implement the technical controls auditors test. Our team combines both: we build healthcare software and the security controls around it, using ISO 27001 certified processes developed across 200+ healthcare projects since 2013. That means remediation happens in your code, cloud and pipelines, not just in documents. We sign Business Associate Agreements before accessing PHI. The six points below explain what working with us on HIPAA and HITRUST readiness looks like and why engineering-led compliance tends to move faster.

Engineers Who Implement Controls

Our engineers implement encryption, access control, logging, vulnerability management and backup controls directly in your systems. Engineering-led remediation closes gaps faster than handing recommendations to busy internal teams who must then interpret and build everything themselves. Progress stays visible. Momentum holds.

Cloud Security Experience

We configure HIPAA-eligible services and security controls across major cloud platforms. Our guide to HIPAA compliant cloud architecture on AWS, Azure and GCP explains the architecture patterns we use for compliant workloads. Configurations are documented for auditors and reused across environments.

Evidence Built Into Pipelines

We automate evidence collection through infrastructure as code, CI/CD checks and monitoring, so audit evidence is generated continuously. Automated evidence makes renewals and customer reviews far easier than reconstructing proof manually before every assessment deadline. Audits become routine. Reviews go faster.

Behavioral Health Compliance Experience

For Procentive, we supported a behavioral health platform handling highly sensitive records. The Procentive case study shows how we approach privacy and security where data sensitivity is especially high. The same discipline applies to every compliance engagement we take on.

Honest Scoping

We tell you when HITRUST is premature and when SOC 2 or HIPAA remediation alone will satisfy customers. Honest scoping prevents spending on certifications that do not yet pay back, protecting budget for product development and growth. Spend wisely. Trust follows.

Not a Law Firm or Assessor

We are engineers, not attorneys or HITRUST assessors. We work alongside your legal counsel and chosen assessor, handling the technical and documentation work that prepares you for successful assessments and confident answers in customer security reviews. Roles stay clear. Collaboration works.

Frequently Asked Questions

These are the questions founders, CTOs, compliance officers and security leaders ask most often when comparing HIPAA and HITRUST, whether they are preparing for enterprise sales, responding to a customer requirement or planning their compliance roadmap. The answers are short on purpose and are not legal advice, so confirm obligations with qualified counsel and HITRUST requirements with authorized assessors. If your question depends on your customers or product, a short call with our team will help. For the latest rule changes, see our HIPAA Security Rule update resource. Answers reflect our experience.

Is HITRUST Required by Law?

No. HITRUST is a voluntary private framework. HIPAA is the legal requirement for covered entities and business associates. HITRUST becomes necessary when customers, partners or contracts require it as evidence of security, which is common with large hospitals and payers.

Does HITRUST Certification Mean HIPAA Compliance?

Not automatically. HITRUST maps to HIPAA Security Rule requirements and provides strong evidence of security controls, but HIPAA also includes privacy, breach notification and administrative obligations that organizations must still meet and document separately. Both need attention. Plan for both.

Is There a HIPAA Certification?

There is no official government HIPAA certification. Organizations demonstrate compliance through risk analyses, policies, safeguards and documentation. Third-party attestations exist, but they do not carry official government recognition, so be cautious about vendors claiming formal HIPAA certification. Evidence matters most.

Should a Startup Pursue HITRUST or SOC 2 First?

It depends on customers. Many startups begin with SOC 2 because it satisfies a broad range of buyers, then add HITRUST when enterprise healthcare customers require it. Ask prospects which evidence they accept before investing. Customer demand decides. Ask prospects.

How Long Does HITRUST Certification Take?

Timelines depend on assessment type and current control maturity. Organizations with mature controls can move faster, while those starting from scratch need significantly longer for readiness and remediation before the validated assessment and HITRUST quality review. Readiness clarifies timing. Start early.

Do You Perform HITRUST Assessments?

No. Validated assessments must be performed by HITRUST authorized external assessors. We help with readiness, remediation, engineering controls and evidence preparation, so your organization enters the assessment prepared and avoids costly delays or failed assessment attempts. Assessors stay independent. We prepare you.

Tell Us About Your Compliance Requirements

Share your product, customers, PHI volumes and the security evidence prospects are requesting. In a 30-minute call we will recommend whether to focus on HIPAA, SOC 2 or HITRUST and outline the work involved. Book a free consultation. No commitment.

Ready to Discuss Your Project With Us?

Your email address will not be published. Required fields are marked *

What's Next?

Our expert reaches out shortly after receiving your request and analyzing your requirements.

If needed, we sign an NDA to protect your privacy.

We request additional information to better understand and analyze your project.

We schedule a call to discuss your project, goals. and priorities, and provide preliminary feedback.

If you're satisfied, we finalize the agreement and start your project.