CERTIFY scopes your assessment, auto-collects Azure evidence per requirement, chases the human-owned controls, and exports a MyCSF-ready workbook. e1, i1, and r2 — with every requirement cross-mapped to HIPAA, SOC 2, and NIST so one scan feeds four audits.
Today, HITRUST preparation lives in a 500-row spreadsheet: one row per requirement, an evidence column that says “Needs evidence” 400 times, an owner column full of names, and one compliance lead chasing fifteen people by email for months. CERTIFY replaces that spreadsheet with an agent that already has most of the evidence — because it is scanning the environment the evidence comes from.
| Assessment | Requirements | Cycle | Who it fits |
|---|---|---|---|
| HITRUST e1 | 44 essential requirements | 1-year | Startups and vendors proving foundational cyber hygiene to their first health-system customer. |
| HITRUST i1 | 182 leading-practice requirements | 1-year | Growing digital-health and health-IT companies with an established security program. |
| HITRUST r2 | 250–2,000+ requirements, tailored by risk scoping | 2-year (interim at year one) | Payers, providers, and any vendor a hospital procurement team calls “high risk.” The gold standard. |
Certification itself is issued by HITRUST through an Authorized External Assessor firm — no software can sell you the certificate, and anyone who implies otherwise is misleading you. CERTIFY does everything before that: scoping, control tracking, evidence collection, gap remediation, and the export your assessor works from. Customers typically cut assessor prep time by months.
The same table your compliance lead keeps in Excel — except the evidence column fills itself. Every HITRUST requirement is tracked by domain with its evidence state, its owner, and the Azure artifacts that prove it.
Illustrative rows. Domains follow the HITRUST CSF structure: AC, ALM, BCDR, CM, DPP, ETA, IM, MDS, NP, PES, PM, PMS, RM, TP, TPA, VM, WS.
HITRUST CSF already harmonizes HIPAA, NIST, and ISO. CERTIFY keeps that mapping live: the encryption evidence that satisfies HITRUST 10.f also files itself under HIPAA 164.312(a)(2)(iv), SOC 2 CC6.7, and NIST SC-28. Collect once, satisfy everywhere.
Hospital and payer procurement teams increasingly require HITRUST before contract signature. CERTIFY turns “we are working on it” into a live readiness score you can show a prospect mid-deal.
HITRUST evidence expires: a screenshot from January does not prove March. Because CERTIFY re-collects on every scan, every artifact carries a fresh Last-Verified timestamp when the assessor asks.
Other platforms stop at “requirement not met.” CERTIFY hands the gap to FORGE, which proposes the exact Azure change, shows the blast radius, and applies it only with your approval — then re-collects the evidence to prove closure.
Per-requirement workbook in the structure external assessors work from: requirement ID, implementation statement, evidence artifacts, owner, and verification date. Your assessor starts validating on day one instead of organizing on week six.
Already mid-assessment? Import the workbook your assessor gave you — domain, control ID, requirement, owner — and CERTIFY fills the evidence column from your live Azure tenant on every scan. Your owners stay your owners; the 400 rows of “Needs evidence” start closing themselves. No platform migration, no starting over.
Not every health company needs HITRUST on day one — but every one of them must meet the HIPAA Security Rule, because it is federal law. TITAN-HSF is our healthcare security framework built entirely on public-domain sources (45 CFR 164 + NIST SP 800-66), organized in the same 17 domains. Start there with zero third-party licensing; when a payer contract later demands HITRUST, your evidence cross-walks straight into the workbook.
Read-only scan. No credit card. Requirement tracker populated on the first pass.