Quick answer
OptiTech supports HITRUST at all three levels: activate e1, i1, or r2 and the corresponding requirement catalog loads, cross-mapped against your existing controls, so HIPAA, ISO 27001, and SOC 2 work you've already done counts immediately. Evidence collects continuously with the timestamps and history HITRUST assessors sample, and the readiness view shows per-requirement maturity before you engage the external assessor.
Level-aware from the start
You pick the target level and the platform scopes accordingly: e1's essentials list, i1's broader implemented set, or r2's risk-tailored requirements driven by your scoping factors (data volumes, system exposure, regulatory context). Upgrading levels later is a delta, not a restart: the i1 evidence base carries into r2, with the gap list showing only what r2 adds for your risk profile.
Maturity, not just pass-fail
HITRUST scores policy, process, and implementation maturity per control. OptiTech tracks all three dimensions: policies live in the versioned document machinery, process evidence accumulates from workflows (reviews completed, incidents handled, training done), and implementation verifies through integration checks against your identity provider, cloud, and MDM. The readiness dashboard shows where maturity is thin before the assessor bills you for the same discovery.
Working with your external assessor
HITRUST requires an approved external assessor, and the engagement runs better when evidence is self-serve: grant scoped, read-only access to the in-scope controls and their history. PHI-bearing system scoping from your HIPAA setup carries over directly, since HITRUST's boundary questions are the same ones.
Keeping certification current
e1 and i1 renew annually, r2 has an interim assessment: all of it lands in the recurring calendar with owners and deadlines, and because evidence never stopped collecting, renewal is review work, not archaeology.

Get a personalized walkthrough of automated compliance for your team. No commitment required.