Scrutineer · By framework
HITRUST e1 certification software and e1 cost
A hospital sent a vendor security review and the answer it wants is a HITRUST e1. The e1 is HITRUST's smallest certification: 44 requirement statements in CSF v11.9, tested by an Authorized External Assessor, with a straight average of 83 or more needed in every domain and a certificate that lasts one year.
Scrutineer runs the controls the e1 tests on one library already mapped to HIPAA and SOC 2, shows coverage per domain before the assessor does, and keeps the evidence current. Compliance software for readiness, not a certification.
Control-mapped findings · linked evidence · you decide what to remediate
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with HITRUST e1
e1 is scored per domain, and one weak domain fails the whole thing
HITRUST certifies an e1 only when the straight average score in every assessment domain is at least 83. A strong overall average does not help if endpoint protection or incident management sits at 70. Each requirement is scored from 0 to 100 on how much of it is implemented across your scope, so a control that runs on 80 percent of laptops is a partial score, not a pass. Scrutineer tracks coverage per control and per system, which is exactly the number the assessor will compute.
The baseline just changed from 43 to 44 statements
HITRUST released CSF v11.9.0 on September 24, 2026 and grew the e1 baseline to 44 requirement statements, up from 43 in v11.8. You can still create an e1 on v11.8 until December 31, 2026, and you must submit any v11.8 e1 by March 31, 2027. Pick the version before you scope evidence, because the requirement list your assessor tests depends on it.
Most of e1 is controls you should already be running
HITRUST says the e1 overlaps with CISA Cyber Essentials, the HICP practices for small healthcare organizations, the basic requirements of NIST SP 800-171 and NIST IR 7621. In practice that is MFA, endpoint protection, patching, backups, logging, removable media, wireless and incident response. If you already run SOC 2 or HIPAA controls, the e1 is mostly an evidence and coverage exercise, not new security work.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Runs the controls the e1 tests (access, MFA, endpoint protection, patching, backups, logging, incident response) on one library already mapped to HIPAA and SOC 2
- Shows implementation coverage per control and per system, so you see a domain heading below 83 before the External Assessor does
- Keeps the evidence an assessor samples current through read-only connections to your cloud, identity and device tools
- Lists every service provider in scope with the evidence you will rely on, because outsourced controls still have to be addressed
- Answers hospital security questionnaires from the same record while the e1 is in progress
- Loads the e1 baseline as its own framework mapped onto your controls on the Enterprise plan
- Carries the same controls forward when a customer later asks for an i1 or r2, since every e1 statement sits inside the i1 baseline
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
What a hospital is actually asking for
HITRUST e1 compared with the other proofs a hospital accepts
A health system that asks a vendor for HITRUST is asking for a level of assurance, not a logo. HITRUST itself describes the e1 as built for lower assurance scenarios, more than a questionnaire and less than its heavier assessments. This is how the options line up for a vendor deciding what to put in front of a hospital.
| Proof you hand over | Who issues it | How it is tested | How long it lasts | What the hospital reads into it |
|---|---|---|---|---|
| Completed security questionnaire | You | Not tested by anyone independent | Until the next request | Your own claims, often the first gate before anything else |
| SOC 2 Type 2 report | A licensed CPA firm | Auditor tests controls over an observation period against the Trust Services Criteria | Covers a past period, usually refreshed every 12 months | Strong general assurance, but not healthcare specific and not scored |
| HITRUST e1 certification | HITRUST, after an Authorized External Assessor validates and HITRUST runs quality assurance | 44 requirement statements in v11.9 (43 in v11.8), scored on implementation, 83 or more in every domain | One year, and HITRUST can investigate or revoke after a reportable breach or significant change | Foundational cybersecurity hygiene, validated. Common for lower-risk vendors and as a first step |
| HITRUST i1 certification | HITRUST, same assessor and QA process | 182 requirement statements, scored on implementation | One year | Moderate-risk vendors. Every e1 statement is included, so the e1 work carries over |
| HITRUST r2 certification | HITRUST, same assessor and QA process | Risk-tailored, commonly several hundred statements, scored on policy, procedure and implementation | Two years with an interim assessment | High-risk relationships and contracts that name r2 |
| Readiness in Scrutineer | Nobody, it is your internal preparation | Your controls scored against real evidence before you engage an assessor | Continuous | Not a certification and never presented as one |
Sources: HITRUST advisory HAA 2026-006 (v11.9.0 released September 24, 2026; e1 baseline 44 statements; v11.8 e1 creation closes December 31, 2026 and submission March 31, 2027) and HITRUST's sample e1 certification report (83 per domain, one-year validity, revocation criteria, corrective action plan rule). Scrutineer prepares and maintains evidence and does not perform or issue a HITRUST assessment.
Good questions
Questions about HITRUST e1
Keep reading
Guides for the HIPAA and SOC 2 work around a HITRUST e1
HITRUST vs SOC 2
What each one proves, who issues it, what each costs, and which one your customers are asking for.
Read the guideHIPAA compliance checklist
The Security Rule safeguards a hospital still asks about after it has your e1 certificate.
Read the guideBest HIPAA risk assessment software
The risk analysis an e1 does not cover, and the tools that produce it.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification