Scrutineer · By framework
HITRUST i1 certification software and i1 assessment
A health system's vendor risk team wants a HITRUST i1, and your team has to turn that into a plan. The i1 is HITRUST's one-year, moderate-assurance certification: 182 requirement statements in CSF v11.9, scored on implementation only, tested by an Authorized External Assessor, with an average of 83 or more needed in every domain.
Scrutineer runs the controls the i1 tests on one library already mapped to HIPAA and SOC 2, shows coverage per domain before the assessor does, and keeps the evidence current through year two. Compliance software for readiness, not a certification.
Control-mapped findings · linked evidence · you decide what to remediate
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with HITRUST i1
The i1 is scored on implementation, and every domain has to reach 83
HITRUST scores i1 requirement statements on the implemented maturity level only, so a written policy earns little on its own and the assessor looks at whether the control actually runs across your scope. The core statements in each domain have to average at least 83. One weak domain produces a validated report without a certificate, however strong the others are. Scrutineer tracks coverage per control and per system, which is the number the assessor computes.
Controls have to run for 90 days before the assessor tests them
HITRUST's assessment handbook sets an incubation period for the i1: a control must have operated for 90 days before it is tested, and policies and procedures for 60 days. A control you deploy the month before fieldwork does not count yet. HITRUST says most companies complete the i1 process in 6 to 12 months, and the incubation clock is usually what sets the date.
Year two is decided by what you leave open in year one
An i1 lasts 12 months, and the cheaper second year runs through rapid recertification. HITRUST then tests every statement added in the newer CSF version, a sample of 60 previously scored statements, every statement that needed a corrective action plan and every statement marked not applicable. Closing CAPs and keeping N/A honest in year one shrinks year two.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Runs the controls the i1 tests (access control, MFA, endpoint protection, vulnerability and patch management, logging, encryption, third-party assurance, incident response, backup and recovery) on one library already mapped to HIPAA and SOC 2
- Shows implementation coverage per control and per system, so a domain heading below 83 is visible before the External Assessor scores it
- Timestamps when each control started producing evidence, so you can see which ones have cleared the 90-day incubation period
- Keeps the evidence an assessor samples current through read-only connections to your cloud, identity and device tools, which is what a 60-statement rapid recertification sample draws on
- Lists every service provider in scope with the evidence you rely on, because third-party assurance is its own i1 domain
- Answers health system security questionnaires from the same record while the i1 is in progress
- Loads the i1 baseline as its own framework mapped onto your controls on the Enterprise plan, and carries the same controls forward if a customer later asks for an r2
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Why year one sets the cost of year two
HITRUST i1 rapid recertification, statement by statement
Most guides describe the i1 as a one-year certificate. In practice it is a two-year plan, because the year-two rapid recertification does not resample everything at random. Some statements are always retested, and you decide which ones in year one.
| Statement in your i1 | Year one full assessment | Year two rapid recertification | What to do in year one |
|---|---|---|---|
| Scored fully compliant, no CAP | Tested by the External Assessor | Rolls forward unless it is drawn into the sample of 60 | Keep the evidence current, since any of these can be sampled |
| Needed a corrective action plan | Tested, CAP recorded in the report | Always retested, outside the sample | Close the CAP with evidence before the year-two representation letter |
| Logged as a gap (control reference averaged 80 or more) | Tested, gap recorded, no CAP required | Eligible for the sample of 60 | Fix it anyway while it is cheap, before it is drawn |
| Marked not applicable | Justified to the assessor | Always retested | Mark N/A only what is truly outside scope |
| New in the newer CSF version | Not part of your year-one baseline | Always tested | Watch the CSF release advisories and add the new statements early |
| Scope change or significant change | Not applicable | Rapid recertification not available, a full assessment again | Hold the assessed scope stable through the year |
| Readiness in Scrutineer | Your controls scored against real evidence before you engage an assessor | Evidence kept current between assessments | Not a certification and never presented as one |
Sources: HITRUST advisory HAA 2026-005 (CSF v11.9.0 released September 24, 2026; i1 baseline remains 182 requirement statements; every e1 statement is in the i1 and every i1 statement is in the r2), the HITRUST Assessment Handbook v1.1 (83 per domain, implemented level scored, 90-day control and 60-day policy incubation, 90-day fieldwork, rapid recertification sample of 60 plus CAP, N/A and new statements, same scope required) and the HITRUST i1 data sheet. Scrutineer prepares and maintains evidence and does not perform or issue a HITRUST assessment.
Good questions
Questions about HITRUST i1
Keep reading
Guides for the HIPAA and SOC 2 work around a HITRUST i1
HITRUST vs SOC 2
What each one proves, who issues it, and which one a health system is really asking you for.
Read the guideBest HIPAA risk assessment software
The HIPAA risk analysis an i1 certificate does not replace, and the tools that produce it.
Read the guideHIPAA compliance checklist
The Security Rule duties a hospital still asks about after it has your i1.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification