Skip to main content
Category: HITRUST Assessment Types

i1 Assessment

Also known as: i1, HITRUST Implemented, 1-Year (i1) Assessment, HITRUST i1 Validated Assessment, Implemented 1-Year Assessment
Simply put

The i1 Assessment is one of the validated assessment options offered under the HITRUST CSF Assurance Program, providing a moderate, one-year level of assurance about an organization's security controls. It is generally positioned between the lighter e1 assessment and the more rigorous r2 assessment, offering a faster and less complex path than the r2 while still supporting third-party assurance. It is a private-sector certification framework product and, on its own, does not establish or guarantee compliance with HIPAA or any other legal requirement.

Formal definition

The HITRUST Implemented, 1-Year (i1) Assessment is a validated assessment within the HITRUST CSF Assurance Program that evaluates an assessed entity's scoped control environment against a curated set of controls (reported by HITRUST as 182 controls) selected as threat-adaptive and mapped to evolving cyber risks. Introduced by HITRUST (per HITRUST Advisory HAA 2021-012, dated December 2021), the i1 conveys moderate-level, one-year assurance and is designed to be faster, less costly, and less complex than the r2 assessment while providing more rigor than the e1. As a HITRUST product, i1 results speak only to the assessed, scoped control environment and to conformance with HITRUST CSF requirements; they do not by themselves demonstrate HIPAA compliance, and applicable HIPAA obligations, the HITECH Act, and state law may impose additional requirements. Specific control counts, assurance levels, and program details should be verified against the current HITRUST CSF version and HITRUST guidance.

Why it matters

The i1 Assessment gives organizations a middle option within the HITRUST CSF Assurance Program, sitting between the lighter e1 assessment and the more rigorous r2 assessment. For healthcare organizations and their vendors that need to demonstrate a moderate level of assurance to customers or partners, the i1 offers a faster, less costly, and less complex path than the r2 while still conveying validated, third-party assurance about a scoped control environment. This can be attractive when a business relationship calls for more than a self-attestation but does not demand the depth of the r2.

Because the i1 relies on a curated set of controls (reported by HITRUST as 182) selected to be threat-adaptive and mapped to evolving cyber risks, it is positioned as a way to keep pace with changing threat conditions rather than a fixed baseline. Organizations weighing assurance options often use the i1 as an intermediate step, either as a destination in itself or as a stepping stone toward the more comprehensive r2. The one-year term of assurance also shapes how organizations plan their assessment cadence and budget.

Critically, an i1 is a private-sector certification product and does not, on its own, establish or guarantee compliance with HIPAA or any other legal requirement. HIPAA obligations are enforced by HHS OCR, and the HITECH Act and applicable state laws may impose additional requirements beyond what any HITRUST assessment covers. i1 results speak only to the assessed, scoped control environment and to conformance with HITRUST CSF requirements, so organizations should not treat an i1 as a substitute for a HIPAA compliance program.

Who it's relevant to

Healthcare vendors and business associates
Organizations that handle data on behalf of covered entities may pursue an i1 to provide moderate, validated third-party assurance to their customers without undertaking the more demanding r2. An i1 can support vendor-risk conversations, but it does not by itself demonstrate HIPAA compliance or satisfy obligations that attach through business associate agreements.
Compliance and security officers
Those responsible for selecting an assurance strategy can use the i1 as an intermediate option, either as a destination or as a stepping stone toward the r2. They should confirm current control counts, assurance levels, and program requirements against the latest HITRUST CSF version and treat the i1 as separate from, not a replacement for, a HIPAA compliance program.
Organizations evaluating assessment options
Entities comparing the e1, i1, and r2 will find the i1 positioned between the lighter e1 and the more rigorous r2, offering a faster, less costly, and less complex path than the r2 while providing more rigor than the e1. The one-year assurance term is a factor in planning assessment cadence and budget.
Auditors and third-party assessors
HITRUST-authorized assessors perform the validated evaluation of the scoped control environment against the i1's curated control set. They must scope engagements carefully, since the resulting assurance speaks only to the assessed, in-scope controls and conformance with HITRUST CSF requirements.

Inside i1

Threat-Adaptive Control Set
The i1 Assessment (HITRUST Implemented, 1-year certification) is built around a curated, static set of controls that HITRUST selects based on prevailing threats. This distinguishes it from the more tailored r2 Assessment, which scales controls based on organizational risk factors. Practitioners should confirm the current control count and composition against the applicable HITRUST CSF version, as these are periodically updated.
Implemented Maturity Evaluation
The i1 evaluates controls primarily on whether they are implemented, rather than assessing the full maturity model (policy, process, implemented, measured, managed) applied in the r2 Assessment. Scoring approach and requirements should be verified against current HITRUST guidance.
One-Year Certification Validity
An i1 certification is generally issued with a shorter validity period than the r2, and HITRUST has offered mechanisms intended to support continued assurance between full assessments. Confirm the exact validity term and any interim requirements against the current HITRUST CSF version.
Relationship to HIPAA
The i1 is a product of HITRUST, a private organization, and results in a certification against the HITRUST CSF control framework. It is not a legal requirement, and by itself it does not establish HIPAA compliance. HIPAA compliance is a matter of federal regulation enforced by HHS OCR, spanning the Privacy Rule, Security Rule, Breach Notification Rule, and Enforcement Rule across obligations that HITRUST certification does not automatically satisfy.
Scope of Applicability
The i1 can be pursued by organizations acting as covered entities, business associates, or subcontractors seeking to demonstrate assurance about their control environment, often to satisfy third-party or contractual expectations. The assessment itself does not create or replace obligations that attach through business associate agreements or through regulation.

Common questions

Answers to the questions practitioners most commonly ask about i1.

Does earning an i1 Assessment result mean my organization is HIPAA compliant?
No. The i1 Assessment is a validated assessment offering from HITRUST, a private organization, and its results do not by themselves establish HIPAA compliance. HIPAA is a US federal regulatory framework enforced by HHS OCR, and neither HITRUST certification nor any i1 result is a legal requirement under HIPAA. An i1 outcome may support and provide evidence toward a compliance program, but organizations should assess HIPAA obligations separately against the current regulatory text and applicable state law.
Is the i1 Assessment the same level of rigor as HITRUST's other assessment types?
No. The i1 is a distinct assessment offering within the HITRUST portfolio and is generally positioned differently from HITRUST's more comprehensive assessment options in terms of scope, control set, and depth of evaluation. Organizations should not treat an i1 result as interchangeable with other HITRUST assessment types. Because HITRUST periodically updates its offerings and the underlying HITRUST CSF, readers should confirm the current characteristics, control requirements, and applicable CSF version directly with HITRUST.
How do we determine whether the i1 Assessment is the right choice for our organization?
Selection generally depends on factors such as your risk profile, the maturity of your security program, contractual or customer expectations, and the scope of systems in question. Because the i1 is one of several HITRUST offerings with differing scope and effort, organizations typically evaluate it against their objectives and any third-party assurance requirements. Confirm the current selection criteria and offering details against the current HITRUST CSF and HITRUST guidance, as these are subject to change.
What should we do to prepare for an i1 Assessment?
Preparation typically involves scoping the environment to be assessed, identifying the applicable control requirements under the current HITRUST CSF version, gathering evidence, and remediating gaps before validation. Because control requirements and evidence expectations are defined by HITRUST and change across CSF versions, organizations should base preparation on the current HITRUST CSF and HITRUST's published requirements rather than prior versions.
How does an i1 Assessment relate to our HIPAA Security Rule obligations?
An i1 Assessment may help evaluate controls that overlap with HIPAA Security Rule safeguards, which cover electronic protected health information (ePHI) across administrative, physical, and technical categories. However, the i1 control set and the Security Rule are distinct, and an i1 result does not automatically demonstrate that required or addressable implementation specifications have been satisfied. Note that addressable does not mean optional under the Security Rule. Organizations should map any assessment results back to their specific Security Rule obligations and verify against current guidance.
Can business associates use an i1 Assessment to satisfy obligations under a business associate agreement?
It depends on what the business associate agreement (BAA) requires and what the covered entity or upstream party expects. HIPAA obligations flow to business associates and subcontractors through defined relationships and contractual terms rather than through any HITRUST offering. An i1 result may serve as supporting assurance evidence if the BAA or customer accepts it, but it is not a substitute for the specific safeguards and obligations set out in the applicable regulation and agreement. Confirm acceptance criteria with the relevant party and the current regulatory requirements.

Common misconceptions

Achieving an i1 certification means an organization is HIPAA compliant.
HITRUST certification, including the i1, is issued by a private organization against the HITRUST CSF and is not a legal requirement. It does not by itself establish HIPAA compliance, which is enforced by HHS OCR and covers Privacy, Security, Breach Notification, and Enforcement Rule obligations that may extend beyond the controls assessed in an i1. Overlap does not equal equivalence.
The i1 is simply a lighter version of the r2 that measures the same things less rigorously.
The i1 uses a static, threat-adaptive control set evaluated principally on implementation, whereas the r2 uses a tailored, risk-based control selection and a broader maturity model. They are designed for different assurance needs rather than being the same assessment at different depths. Confirm current scope and scoring differences against the applicable HITRUST CSF version.
An i1 certification guarantees that an organization will not experience a breach.
No certification or set of controls guarantees compliance or prevents all breaches. An i1 provides point-in-time and period-limited assurance about implemented controls; it does not eliminate residual risk, and organizations remain subject to breach notification and other regulatory obligations.

Best practices

Verify the current control count, scoring methodology, and certification validity period against the applicable HITRUST CSF version rather than relying on figures from prior cycles, as these are periodically updated.
Treat the i1 as one input to an assurance strategy, not as evidence of HIPAA compliance; separately map and validate your obligations under the Privacy Rule, Security Rule, Breach Notification Rule, and Enforcement Rule.
Assess whether the i1's implementation-focused, static control set meets the assurance expectations of your customers and contracts, or whether the risk-tailored r2 is a better fit for your organization's needs.
Confirm that Security Rule safeguards relevant to your ePHI, across administrative, physical, and technical categories, are addressed, recognizing that addressable specifications are not optional and must be documented as implemented or reasonably justified.
For business associates and subcontractors, ensure that obligations flowing through business associate agreements are satisfied independently, since an i1 certification does not automatically discharge contractual or regulatory duties.
Account for additional requirements that may arise from state law or the HITECH Act beyond HIPAA and beyond the i1 control set, and document how those are addressed.