Frameworks

HIPAA vs HITRUST: what is the difference?

25 August 2026 · 8 min read · CertAssist

HIPAA is a legal obligation. HITRUST is a certificate you can earn. Here is how they relate, and when to pursue each.

HIPAA is a United States law that requires organisations handling protected health information to safeguard it, and you cannot be certified to it, you simply must comply. HITRUST is a private security framework, the HITRUST CSF, that you can be formally certified against, and it incorporates HIPAA's requirements along with many other standards. So they are not alternatives: HIPAA is the legal obligation, and a HITRUST certification is one way to demonstrate that you meet HIPAA and more, with an independent certificate customers recognise. Here is how they differ and when you need each.

Comparison matrix of HIPAA and HITRUST across what they are, certifiability and enforcement

What is HIPAA?

HIPAA, the Health Insurance Portability and Accountability Act, is a US federal law whose Privacy and Security Rules govern how protected health information, or PHI, is used and safeguarded. It applies to covered entities such as healthcare providers and health plans, and to business associates that handle PHI on their behalf. HIPAA sets requirements but does not offer a certificate; compliance is a legal state, enforced by the Department of Health and Human Services Office for Civil Rights, which can investigate and impose penalties.

What is HITRUST?

HITRUST is an organisation that maintains the HITRUST CSF, a certifiable security framework widely used in healthcare. The CSF harmonises requirements from many sources, including HIPAA, ISO 27001, NIST and others, into a single control set, and it offers assessment types of increasing rigour, commonly the e1, i1 and r2 assessments. Achieving a HITRUST certification means an approved assessor has verified your controls, giving you an independent certificate that many healthcare customers specifically request.

What is the difference between HIPAA and HITRUST?

The difference between HIPAA and HITRUST is that HIPAA is a law you must obey and HITRUST is a framework you can be certified against. HIPAA tells you what is legally required for PHI but offers no certificate and no single checklist blessed by the regulator. HITRUST gives you a concrete control set and an independent certification that demonstrates strong security, including HIPAA-relevant controls. You can be HIPAA compliant without HITRUST, but you cannot be HITRUST certified without addressing HIPAA-style protections.

Do you need HITRUST to be HIPAA compliant?

No, you do not need HITRUST to be HIPAA compliant. HIPAA compliance is achieved by meeting the Privacy and Security Rules, and many organisations demonstrate it through their own documented controls, risk analysis and policies. HITRUST is one way to prove a strong, independently assessed security posture that covers HIPAA, and some healthcare customers prefer or require it because a certificate is easier to trust than a self-attestation. Whether to pursue HITRUST is a commercial and risk decision, not a legal one.

When should you choose HITRUST certification?

Choose HITRUST certification when your customers, often large health systems or payers, ask for it specifically, or when you want a recognised, independently verified way to prove your security in the healthcare market. HITRUST is more involved and more costly than a self-attested HIPAA programme, so it makes sense when the commercial upside, winning or keeping healthcare contracts, justifies the effort. If no customer requires it and you are early, a solid HIPAA programme may be enough until demand appears.

How do HIPAA, HITRUST and SOC 2 relate?

HIPAA is the legal baseline, and both HITRUST and SOC 2 are ways to demonstrate security to customers, with overlap. Some healthcare buyers accept a SOC 2 report that includes HIPAA-mapped controls; others specifically want a HITRUST certification. Because the underlying safeguards, access control, encryption, logging, risk management, are shared, work done for one supports the others. Deciding among them comes down to what your customers ask for, so confirm the exact requirement before committing to the most demanding path.

How CertAssist helps with HIPAA

CertAssist lays out HIPAA's safeguards as clear controls with editable policy and evidence templates, so a covered entity or business associate can build and document a defensible HIPAA programme without starting from scratch. You keep your risk analysis, policies and evidence organised in one place, ready to show a customer or an investigator. CertAssist does not connect to your systems, which is reassuring when the data in question is health information, and the price is a published US$225 per month during its launch.

How much does HITRUST cost compared to HIPAA?

HIPAA compliance has no certification fee, because there is no certificate; your costs are the internal work of building and documenting the programme, plus any advisory help. HITRUST certification, by contrast, carries real cost: the HITRUST subscription, an external assessor's fee, and the effort to reach the control maturity the assessment demands. The exact figure depends on which HITRUST assessment you pursue, the e1, i1 or r2, and the size of your environment, with the r2 being the most rigorous and expensive. This cost difference is the practical reason many smaller healthcare vendors run a documented HIPAA programme first and pursue HITRUST only when a major customer requires it, since the certificate is a commercial investment rather than a legal necessity.

Frequently asked questions

What is the difference between HIPAA and HITRUST?

HIPAA is a US law that requires safeguarding protected health information, and you cannot be certified to it, you must comply. HITRUST is a certifiable security framework, the HITRUST CSF, that incorporates HIPAA and other standards and gives you an independent certificate. HIPAA is the legal obligation; HITRUST is one way to demonstrate you meet it and more.

Do you need HITRUST to be HIPAA compliant?

No. HIPAA compliance is achieved by meeting the Privacy and Security Rules through documented controls, risk analysis and policies. HITRUST is one way to prove a strong, independently assessed posture that covers HIPAA, and some customers require it, but it is a commercial and risk choice, not a legal requirement for HIPAA compliance.

Can you be certified in HIPAA?

No, there is no official HIPAA certification. HIPAA is a legal requirement enforced by the HHS Office for Civil Rights, not a certification scheme. Organisations demonstrate HIPAA compliance through their own documentation and controls, or by earning a related certificate such as HITRUST or a SOC 2 with HIPAA-mapped controls, which customers accept as evidence.

Is HITRUST based on HIPAA?

HITRUST incorporates HIPAA. The HITRUST CSF harmonises requirements from many sources, including HIPAA, ISO 27001 and NIST, into one control set. So a HITRUST certification demonstrates HIPAA-relevant safeguards along with broader security controls, which is why healthcare customers often accept it as strong evidence of HIPAA alignment.

Is HITRUST worth it for a small company?

HITRUST is worth it for a small company when customers require it or when a recognised healthcare-security certificate wins meaningful business. It is more involved and costly than a self-attested HIPAA programme, so if no customer asks for it and you are early, a solid documented HIPAA programme may be enough until the demand appears.

Related guides

Build a defensible HIPAA programme without the blank page

CertAssist lays out HIPAA safeguards with editable policy and evidence templates, for a published $225 a month during the launch.

See pricing Frameworks

← Back to the blog

Powerful in its simplicity.

Flat $225 a month during the launch, normally $375, or $3,999 a year (12 months for the price of 11). All prices in USD.