HITRUST introduced the i1 Assurance Program in 2024 as a replacement for its e1 and r2 certification pathways. The change fundamentally alters how organizations demonstrate compliance with healthcare security requirements, particularly regarding controls inherited from service providers. Healthcare organizations holding existing HITRUST certifications must decide whether and when to transition, with implications for regulatory positioning, vendor relationships, and governance accountability.
This article explains what changed in the i1 model, when transition decisions must be made, and which executive roles carry accountability for regulatory strategy and risk acceptance.
What i1 Changes in Practice
The i1 Assurance Program separates inherited controls from organization-specific implementation in a way that earlier HITRUST certification models did not. Under e1 and r2, organizations could claim partial credit for security controls performed by underlying infrastructure or service providers—such as cloud platforms, data centres, or SaaS applications—without always demonstrating direct oversight or independent validation of those inherited controls.
i1 requires explicit documentation of which controls are inherited, from which providers, and under what evidence standard. This means organizations must identify each service provider contributing to their control environment, confirm that the provider holds current, scope-appropriate HITRUST certification or equivalent third-party assurance, and map inherited controls to their own assessment scope. Where a provider does not hold acceptable certification, the organization must either implement the control itself or formally accept the gap as residual risk.
The practical effect is greater transparency and accountability. Organizations can no longer implicitly rely on vendor claims; they must validate and govern inherited risk as part of their own compliance posture.
Why This Matters to Healthcare Organizations Now
Healthcare organizations operate under overlapping regulatory obligations—HIPAA, state breach notification laws, and in some cases contractual requirements from payers or partners. HITRUST certification has become a de facto standard for demonstrating security maturity in many business relationships, particularly with large health systems, payers, and business associates.
The shift to i1 creates a decision point. Organizations holding e1 or r2 certifications have a defined transition window during which they must choose to migrate to i1, re-certify under the older pathway if still available, or allow certification to lapse. Each choice has regulatory and commercial consequences.
Allowing certification to lapse may not be viable if business relationships require it. Re-certifying under e1 or r2 defers the decision but does not resolve it, as HITRUST has indicated these pathways will be retired. Migrating to i1 requires upfront work to document inherited controls, validate vendor assurances, and potentially fill gaps where providers lack acceptable certification.
The timeline is not indefinite. HITRUST has published transition schedules tied to existing certification expiry dates. Organizations approaching renewal must decide now whether to commit resources to i1 transition or manage the implications of not holding current certification.
Transition Timeline and Key Deadlines
The i1 transition timeline depends on when an organization's current certification expires. HITRUST has not mandated an immediate cutoff for e1 or r2, but has indicated that i1 is the only pathway that will remain fully supported beyond a defined horizon.
Organizations renewing certification in 2025 or later should confirm with their assessor whether e1 or r2 remains available for their renewal cycle, and if so, for how long. Some organizations may have one final renewal opportunity under the older model before i1 becomes mandatory.
For organizations currently holding certification, the practical deadline is the earlier of: the published end-of-life date for their current pathway, or the expiry of their existing certificate plus any grace period. Waiting until expiry to begin i1 preparation creates execution risk, as the inherited control documentation and vendor validation work is not trivial.
Organizations pursuing HITRUST certification for the first time will likely be directed to i1 immediately, as it is now the primary pathway.
What the Inheritance Model Requires of Leadership
i1 makes explicit a governance responsibility that was often ambiguous under earlier models: the organization's executive leadership must know which security controls they own, which they inherit, and from whom. This is not solely a technical question—it is a risk acceptance and vendor governance question.
Three areas require executive-level decisions:
- **Vendor assurance validation.** For each service provider whose controls are inherited, leadership must confirm that the provider's certification scope covers the controls being claimed, that the certification is current, and that the provider's obligations are documented in contract terms.
- **Gap treatment.** Where a provider does not hold acceptable certification, leadership must decide whether to implement the control internally, accept the residual risk, or replace the provider. This is a strategic and financial decision, not solely an IT decision.
- **Ongoing governance.** Inherited controls must be monitored as part of the organization's compliance program. If a provider's certification lapses or its scope changes, the organization's own compliance posture is affected. Leadership must define who monitors this and how quickly gaps are escalated.
These responsibilities do not naturally belong to IT, compliance, or procurement alone. They require a single accountable executive who can make risk decisions, direct resources across functions, and report to the board or senior leadership on regulatory positioning.
Who Owns This and What Adequate Ownership Looks Like
HITRUST i1 transition is not a project that can be delegated to a consultant or technical team without executive ownership. The work requires strategic decisions about vendor relationships, risk appetite, resource allocation, and regulatory positioning—all of which are governance responsibilities.
In organizations with a Chief Information Security Officer (CISO) or equivalent, this role is the natural owner. The CISO can coordinate across compliance, IT, procurement, and legal to validate inherited controls, document vendor assurances, and present risk decisions to executive leadership or the board.
Many healthcare organizations—particularly those below enterprise scale—do not have a full-time CISO. In these cases, the work is often fragmented across IT directors, compliance officers, or external consultants, none of whom have the authority or mandate to make strategic risk decisions. This fragmentation creates execution risk and accountability gaps.
Adequate ownership requires a single point of accountability with three capabilities: the authority to make risk decisions, the ability to direct cross-functional work, and a reporting line to executive leadership or the board. This is a governance function, not solely an operational one. For organizations without internal CISO capacity, the [virtual CISO (vCISO) model](/vciso/) provides this executive ownership on a fractional basis, with the strategy, governance, and reporting functions performed by an experienced security executive who acts as a member of the leadership team.
How This Relates to Regulatory and Framework Readiness
HITRUST i1 transition is a subset of a broader governance discipline: maintaining regulatory and framework readiness across an evolving set of obligations. Healthcare organizations operate under HIPAA, state breach laws, and often contractual security requirements imposed by partners. HITRUST certification is one way to demonstrate readiness, but it is not the only requirement.
Organizations that treat i1 transition as a one-time compliance exercise will find themselves in the same position at the next framework change or regulatory update. Sustainable readiness requires ongoing governance: a defined process for monitoring regulatory changes, assessing applicability, making risk decisions, and allocating resources to maintain compliance.
This governance function is distinct from technical security operations. It requires someone who can interpret regulatory requirements, translate them into organizational risk, present options to executive leadership, and ensure that decisions are implemented and monitored. This is the role of a CISO or vCISO: strategic leadership, not technical implementation.
Practical Next Steps for Healthcare Leadership
Healthcare executives facing HITRUST i1 transition decisions should take the following steps:
- **Confirm certification status and timeline.** Determine when your current HITRUST certification expires, whether e1 or r2 renewal is available, and when i1 becomes mandatory for your organization.
- **Inventory inherited controls.** Identify all service providers whose security controls you currently claim as part of your compliance posture—cloud platforms, SaaS applications, data centres, business associates. Document which controls are inherited from each provider.
- **Validate vendor assurances.** For each provider, confirm whether they hold current HITRUST certification or equivalent third-party assurance, whether the certification scope covers the controls you are claiming, and whether your contract documents the inherited control responsibilities.
- **Identify gaps and decide on treatment.** Where providers lack acceptable certification, decide whether to implement controls internally, accept residual risk, or change providers. Document these decisions as part of your risk register.
- **Assign executive ownership.** Designate a single accountable executive—CISO, vCISO, or equivalent—to coordinate the transition, make risk decisions, and report progress to senior leadership or the board.
- **Build ongoing governance.** Establish a process for monitoring vendor certifications, tracking certification expiry dates, and escalating gaps. This should be part of your regular compliance and risk reporting, not a one-time exercise.
For organizations without internal CISO capacity, or where existing leadership lacks bandwidth for strategic governance work, Heights provides [virtual CISO services](/vciso/) that include regulatory strategy, framework readiness, vendor risk governance, and executive reporting. This is not consulting advice; it is accountable leadership as a service, with a single point of contact who acts as a member of your executive team.
If you are approaching a HITRUST renewal decision and need to clarify accountability, validate your transition plan, or establish governance over inherited controls, a confidential consultation can help you determine the right path forward. This is offered once, at the point where strategic clarity has the most value: before resources are committed and timelines compressed.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Regulatory and Framework Readiness
Readiness for the frameworks and regulations that genuinely apply to you, NIST CSF, ISO 27001, SOC 2, CMMC, HIPAA, PCI DSS and SOX-related IT controls, with the evidence maintained between assessments.