HITRUST e1 vs i1 vs r2: which assessment do you actually need?
HITRUST offers three assessment options — e1, i1, and r2 — aimed at different risk profiles. Picking wrong means either overpaying or answering customer questionnaires all over again.
e1: foundational hygiene
The e1 is the entry point: a smaller set of foundational cybersecurity requirements, 1-year certification. Sensible for smaller organizations or as a stepping stone toward i1/r2. It's the fastest and least expensive validated option.
i1: leading practice
The i1 covers leading-practice requirements — broader than e1 — with a 1-year certification. A common middle path for mid-market companies whose customers ask for HITRUST but don't require the full r2.
r2: comprehensive, 2-year
The r2 is the flagship: the full requirement set, risk-based tailoring, and a 2-year certification. It's what large healthcare enterprises and their regulators expect. It also requires a HITRUST-authorized external assessor — no exceptions for validated assessments.
How to choose
- Ask your customers which they require — many accept i1 where you assumed r2.
- Start with readiness regardless: a readiness assessment against your target option exposes gaps cheaply.
- Budget honestly: our cost guide puts r2 validated assessments at $75,000–$200,000+ — i1 and e1 cost materially less.
Get quotes from verified firms
One brief, matched firms, competing quotes — free.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.