Some hospital procurement teams accept SOC 2 Type II. The big ones - large IDNs, AMCs, and national health systems - increasingly require HITRUST CSF certification. We get MedTech and digital health companies HITRUST-ready at the right level (e1, i1, or r2) - aligned with your FDA cybersecurity program and one shared evidence vault.
The short answer
They are three levels of HITRUST assurance. e1 covers a small set of essential controls and suits early-stage companies. i1 adds a broader, fixed set of leading-practice controls. r2 is risk-based, tailored to your environment and the most demanding, and it's the one large health systems most often ask for. We help you pick the right level and prepare for certification.
Right level. Right scope. No wasted year.
Picking i1 or r2 when e1 would close the deal wastes 6-12 months. Picking e1 when an IDN required r2 loses the deal.
An r2 effort runs 200-500+ controls. If your buyers only need e1 or i1, you've burned a year and six figures of effort for no commercial gain.
Factors set incorrectly add hundreds of controls you don't actually need to certify. We scope MyCSF correctly the first time.
MedTech HITRUST has to span the device, its update pipeline, and the cloud back-end - and the risk analysis has to acknowledge that loss of availability or integrity can become a clinical event.
We size the depth of each control family to e1, i1, or r2 - never deeper than the buyers in your pipeline actually require.
Level decided in week 1. Controls operating by month 3. Validated assessment in months 9-12.
Weeks 1-2: pick e1, i1, or r2 based on your customer pipeline. Tune MyCSF factors so you certify the controls you need - and not 400 you don't.
Weeks 3-12: gap-assess against the chosen level, implement missing controls, write policies, set up evidence pipelines. Crosswalk to FDA SPDF, SOC 2, HIPAA, and GDPR.
Months 3-9: collect the evidence the External Assessor will sample. Quarterly internal reviews catch drift before the assessment.
Coordinate the authorized HITRUST External Assessor, handle walkthroughs, evidence Q&A, finding remediation, and CAP management. Ship the report to your buyer.
Every hitrust readiness (e1 / i1 / r2) engagement ships with the artifacts FDA reviewers expect to see - traceable, complete, and aligned with current guidance.
Some hospital procurement teams accept SOC 2 Type II. The big ones - large IDNs, AMCs, and national health systems - increasingly require HITRUST CSF certification. We get MedTech and digital health companies HITRUST-ready at the right level (e1, i1, or r2) - aligned with your FDA cybersecurity program and one shared evidence vault.