— TITAN CERTIFY · HITRUST module

HITRUST readiness, run by agents — not spreadsheets.

CERTIFY scopes your assessment, auto-collects Azure evidence per requirement, chases the human-owned controls, and exports a MyCSF-ready workbook. e1, i1, and r2 — with every requirement cross-mapped to HIPAA, SOC 2, and NIST so one scan feeds four audits.

Today, HITRUST preparation lives in a 500-row spreadsheet: one row per requirement, an evidence column that says “Needs evidence” 400 times, an owner column full of names, and one compliance lead chasing fifteen people by email for months. CERTIFY replaces that spreadsheet with an agent that already has most of the evidence — because it is scanning the environment the evidence comes from.

e1, i1, r2 — one module covers all three.

AssessmentRequirementsCycleWho it fits
HITRUST e144 essential requirements1-yearStartups and vendors proving foundational cyber hygiene to their first health-system customer.
HITRUST i1182 leading-practice requirements1-yearGrowing digital-health and health-IT companies with an established security program.
HITRUST r2250–2,000+ requirements, tailored by risk scoping2-year (interim at year one)Payers, providers, and any vendor a hospital procurement team calls “high risk.” The gold standard.

Certification itself is issued by HITRUST through an Authorized External Assessor firm — no software can sell you the certificate, and anyone who implies otherwise is misleading you. CERTIFY does everything before that: scoping, control tracking, evidence collection, gap remediation, and the export your assessor works from. Customers typically cut assessor prep time by months.

Every requirement: status, evidence, owner. Live, not quarterly.

The same table your compliance lead keeps in Excel — except the evidence column fills itself. Every HITRUST requirement is tracked by domain with its evidence state, its owner, and the Azure artifacts that prove it.

HITRUST r2 · requirement tracker refreshed on every scan
01.q · Access Control — user registrationAC · 11220.01b · mapped: HIPAA 164.312(a)(1) · SOC 2 CC6.1 owner: security team Evidence auto-collected
09.ab · Audit logging — monitoring of system useALM · 1215.09ab · mapped: HIPAA 164.312(b) · NIST AU-6 owner: security team Evidence auto-collected
02.e · Human resources — security awareness trainingDPP · 1903.06d1 · human-process control owner: HR lead Owner reminded · due in 6 days
10.f · Cryptography — encryption of data at restTP · 0903.10f1 · gap found by SCOUT · fix queued in FORGE owner: cloud team Gap · fix proposed
12.c · BCDR — business continuity planningBCDR · 1602.12c1 · policy doc on file · last reviewed 34 days ago owner: ops lead OK · verified

Illustrative rows. Domains follow the HITRUST CSF structure: AC, ALM, BCDR, CM, DPP, ETA, IM, MDS, NP, PES, PM, PMS, RM, TP, TPA, VM, WS.

Four steps from spreadsheet chaos to assessor-ready.

One control surface, four audits fed.

HITRUST CSF already harmonizes HIPAA, NIST, and ISO. CERTIFY keeps that mapping live: the encryption evidence that satisfies HITRUST 10.f also files itself under HIPAA 164.312(a)(2)(iv), SOC 2 CC6.7, and NIST SC-28. Collect once, satisfy everywhere.

For healthcare vendors

The procurement unblock

Hospital and payer procurement teams increasingly require HITRUST before contract signature. CERTIFY turns “we are working on it” into a live readiness score you can show a prospect mid-deal.

Included in the Healthcare tier
For compliance leads

Evidence that stays current

HITRUST evidence expires: a screenshot from January does not prove March. Because CERTIFY re-collects on every scan, every artifact carries a fresh Last-Verified timestamp when the assessor asks.

Continuous · not point-in-time
For the CISO

Gaps become fixes, not findings

Other platforms stop at “requirement not met.” CERTIFY hands the gap to FORGE, which proposes the exact Azure change, shows the blast radius, and applies it only with your approval — then re-collects the evidence to prove closure.

Find → recommend → fix → re-verify
For the assessor

MyCSF-ready export

Per-requirement workbook in the structure external assessors work from: requirement ID, implementation statement, evidence artifacts, owner, and verification date. Your assessor starts validating on day one instead of organizing on week six.

Workbook · PDF · DOCX · JSON
Bring your own workbook

Import your assessment. We fill the evidence column.

Already mid-assessment? Import the workbook your assessor gave you — domain, control ID, requirement, owner — and CERTIFY fills the evidence column from your live Azure tenant on every scan. Your owners stay your owners; the 400 rows of “Needs evidence” start closing themselves. No platform migration, no starting over.

CSV in → evidence-filled workbook out · works with any assessor’s format
No HITRUST yet? Start free of it.

TITAN-HSF: the public-law baseline

Not every health company needs HITRUST on day one — but every one of them must meet the HIPAA Security Rule, because it is federal law. TITAN-HSF is our healthcare security framework built entirely on public-domain sources (45 CFR 164 + NIST SP 800-66), organized in the same 17 domains. Start there with zero third-party licensing; when a payer contract later demands HITRUST, your evidence cross-walks straight into the workbook.

HIPAA Security Rule · NIST 800-66 · no external license required

See your HITRUST readiness score in ten minutes.

Read-only scan. No credit card. Requirement tracker populated on the first pass.