Scrutineer.ai

Scrutineer · By framework

HITRUST e1 certification software and e1 cost

A hospital sent a vendor security review and the answer it wants is a HITRUST e1. The e1 is HITRUST's smallest certification: 44 requirement statements in CSF v11.9, tested by an Authorized External Assessor, with a straight average of 83 or more needed in every domain and a certificate that lasts one year.

Scrutineer runs the controls the e1 tests on one library already mapped to HIPAA and SOC 2, shows coverage per domain before the assessor does, and keeps the evidence current. Compliance software for readiness, not a certification.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with HITRUST e1

e1 is scored per domain, and one weak domain fails the whole thing

HITRUST certifies an e1 only when the straight average score in every assessment domain is at least 83. A strong overall average does not help if endpoint protection or incident management sits at 70. Each requirement is scored from 0 to 100 on how much of it is implemented across your scope, so a control that runs on 80 percent of laptops is a partial score, not a pass. Scrutineer tracks coverage per control and per system, which is exactly the number the assessor will compute.

The baseline just changed from 43 to 44 statements

HITRUST released CSF v11.9.0 on September 24, 2026 and grew the e1 baseline to 44 requirement statements, up from 43 in v11.8. You can still create an e1 on v11.8 until December 31, 2026, and you must submit any v11.8 e1 by March 31, 2027. Pick the version before you scope evidence, because the requirement list your assessor tests depends on it.

Most of e1 is controls you should already be running

HITRUST says the e1 overlaps with CISA Cyber Essentials, the HICP practices for small healthcare organizations, the basic requirements of NIST SP 800-171 and NIST IR 7621. In practice that is MFA, endpoint protection, patching, backups, logging, removable media, wireless and incident response. If you already run SOC 2 or HIPAA controls, the e1 is mostly an evidence and coverage exercise, not new security work.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Runs the controls the e1 tests (access, MFA, endpoint protection, patching, backups, logging, incident response) on one library already mapped to HIPAA and SOC 2
  • Shows implementation coverage per control and per system, so you see a domain heading below 83 before the External Assessor does
  • Keeps the evidence an assessor samples current through read-only connections to your cloud, identity and device tools
  • Lists every service provider in scope with the evidence you will rely on, because outsourced controls still have to be addressed
  • Answers hospital security questionnaires from the same record while the e1 is in progress
  • Loads the e1 baseline as its own framework mapped onto your controls on the Enterprise plan
  • Carries the same controls forward when a customer later asks for an i1 or r2, since every e1 statement sits inside the i1 baseline
HITRUST e1 readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

What a hospital is actually asking for

HITRUST e1 compared with the other proofs a hospital accepts

A health system that asks a vendor for HITRUST is asking for a level of assurance, not a logo. HITRUST itself describes the e1 as built for lower assurance scenarios, more than a questionnaire and less than its heavier assessments. This is how the options line up for a vendor deciding what to put in front of a hospital.

Proof you hand over Who issues it How it is tested How long it lasts What the hospital reads into it
Completed security questionnaire You Not tested by anyone independent Until the next request Your own claims, often the first gate before anything else
SOC 2 Type 2 report A licensed CPA firm Auditor tests controls over an observation period against the Trust Services Criteria Covers a past period, usually refreshed every 12 months Strong general assurance, but not healthcare specific and not scored
HITRUST e1 certification HITRUST, after an Authorized External Assessor validates and HITRUST runs quality assurance 44 requirement statements in v11.9 (43 in v11.8), scored on implementation, 83 or more in every domain One year, and HITRUST can investigate or revoke after a reportable breach or significant change Foundational cybersecurity hygiene, validated. Common for lower-risk vendors and as a first step
HITRUST i1 certification HITRUST, same assessor and QA process 182 requirement statements, scored on implementation One year Moderate-risk vendors. Every e1 statement is included, so the e1 work carries over
HITRUST r2 certification HITRUST, same assessor and QA process Risk-tailored, commonly several hundred statements, scored on policy, procedure and implementation Two years with an interim assessment High-risk relationships and contracts that name r2
Readiness in Scrutineer Nobody, it is your internal preparation Your controls scored against real evidence before you engage an assessor Continuous Not a certification and never presented as one

Sources: HITRUST advisory HAA 2026-006 (v11.9.0 released September 24, 2026; e1 baseline 44 statements; v11.8 e1 creation closes December 31, 2026 and submission March 31, 2027) and HITRUST's sample e1 certification report (83 per domain, one-year validity, revocation criteria, corrective action plan rule). Scrutineer prepares and maintains evidence and does not perform or issue a HITRUST assessment.

Good questions

Questions about HITRUST e1

HITRUST e1 (Essentials, 1-year) is a validated assessment and certification of foundational cybersecurity controls. An Authorized External Assessor tests a fixed set of HITRUST CSF requirement statements, 44 in CSF v11.9, HITRUST runs a quality review, and HITRUST issues a certificate valid for one year. It is the smallest of the three HITRUST certifications.
HITRUST publishes no e1 list price, and third-party estimates disagree. All-in first-year budgets quoted online run from roughly $20,000 to $90,000, combining MyCSF access, the External Assessor fee, HITRUST report credits and remediation. The assessor fee and your own remediation labor move the number most, so a team that already runs mapped, evidenced controls lands near the low end.
The e1 has 44 requirement statements in HITRUST CSF v11.9.0, released September 24, 2026, and 43 in v11.8.0. Between September 24 and December 31, 2026 you can create an e1 on either version. After that, new e1 assessments must use v11.9, and unsubmitted v11.8 assessments cannot be submitted after March 31, 2027.
You need a straight average score of at least 83 in each assessment domain. It is not an overall average, so one weak domain blocks certification. Requirements scoring below 100 whose control reference averages below 80 also need a corrective action plan, while smaller shortfalls are recorded as gaps that HITRUST recommends fixing.
HITRUST says an e1 can be completed in as little as a few weeks and averages around 30 days for the assessment itself. Readiness is the variable. A company that already runs MFA, endpoint protection, patching, backups and logging across every in-scope system can move quickly; one that has to deploy those controls first should plan in months, not weeks.
Often, for lower-risk vendors, but it depends on the contract. HITRUST positions the e1 for lower assurance scenarios, so a health system handing you large volumes of PHI may ask for an i1 or r2 instead. Ask the customer which level its vendor risk team accepts before you scope, since every e1 statement is reused if you move up to the i1.
No. HITRUST's own e1 report states that the e1 is not a compliance assessment. It validates foundational security controls, many of which overlap with the HIPAA Security Rule, but it does not cover your risk analysis, business associate agreements or privacy obligations. Hospitals that need HIPAA assurance usually still ask for a signed BAA and your risk analysis alongside the certificate.
Yes. The certificate stays valid for one year only if no breach reportable to a federal or state agency occurs in the assessed environment and no significant change affects your ability to meet the e1 criteria. If either happens, HITRUST investigates and can revoke the certification, so incident and change records matter during the year, not only before the assessment.
Get the one your first large customer names. Enterprise buyers outside healthcare almost always ask for SOC 2, while some health systems ask specifically for HITRUST. Because the controls overlap heavily, many vendors run both from one control library: SOC 2 for the general market and an e1 or i1 for the healthcare accounts that require it.
No. Only HITRUST issues the certification, after an Authorized External Assessor validates your assessment. Scrutineer is the readiness and evidence layer: it runs your controls on one library mapped to HIPAA and SOC 2, shows coverage per domain, and keeps evidence current. Most e1 work fits on Growth at $1,200 a month; loading the e1 baseline as its own framework needs Enterprise.

Keep reading

Guides for the HIPAA and SOC 2 work around a HITRUST e1

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification