SideGuy North County San Diego
SideGuy Compliance Field Guide · Updated 2026

HITRUST Certified Companies (2026): How to Find & Verify the Real List

⚡ The Honest Answer First

There is NO single complete public list of HITRUST certified companies — certifications are issued to organizations for specifically scoped systems, and HITRUST shares validated results only with parties the certified company authorizes. So stop searching and start verifying: ask the vendor for their certification letter, check the assessment type (e1 / i1 / r2), confirm the scope names the product you're actually buying, and check the validity dates. AWS, Microsoft Azure, and Google Cloud all publicly document HITRUST certification for in-scope services — but that never automatically certifies an app built on top of them.

Everyone selling into healthcare says “HITRUST certified.” The letter, the type, the scope, and the dates are what make it true.

PJ Magalong — SideGuy
PJ explains this page
Tap my face for the 30-second verification path
I'll walk you through why the public list doesn't exist, the 4-step verification any vendor should pass in one email, and the inheritance trap — why “we run on a HITRUST-certified cloud” is not the same claim as “we are HITRUST certified.”
Text PJ for help

Why There's No Public List

HITRUST certifications are issued to an organization for a defined scope — specific platforms, systems, and facilities — not to a company as a whole. Results distribution is controlled by the certified organization: they choose who sees the letter and the full assessment report. That design decision is why no complete public directory exists, and why third-party “lists of HITRUST certified companies” you find in blog posts are assembled from press releases — perpetually incomplete, often stale, and blind to scope.

The good news: verification is easy and vendors with a real certification are HAPPY to prove it, because it cost them real money. A vendor who stalls on producing the letter is telling you something.

The 4-Step Verification (One Email)

StepWhat you're checking
1 · Request the certification letterReal HITRUST letters name the organization, the in-scope systems, the assessment type, and validity dates. “We're HITRUST compliant” without a letter = marketing, not certification
2 · Check the assessment typee1 (44 controls, essentials) · i1 (~182 controls, 1-year) · r2 (risk-tailored 300-2,000+, 2-year gold standard). Match the tier to your risk
3 · Check the scopeThe letter must name the product/platform YOU are buying. A certified billing platform doesn't certify the same company's new analytics product
4 · Check the datese1/i1 = 1-year validity, full annual re-assessment. r2 = 2 years with a required interim. Old press release ≠ current certification

Who Publicly Documents HITRUST Certification

Some categories where HITRUST status is publicly documented or routinely announced — treat every entry as a lead to verify against a current letter, not as proof:

CategoryWhat you'll find
Major clouds (AWS, Azure, Google Cloud)All three document HITRUST CSF certification for defined in-scope services on their public compliance/trust pages — the strongest public documentation you'll find anywhere
EHR / clearinghouse / health-data platformsFrequently announce certifications via press release; scope and currency vary — verify
Telehealth & digital-health SaaSGrowing cohort, usually i1 first then r2 when payer contracts demand it
Healthcare BPO / RCM vendorsr2 is common here because payers and health systems contractually require it

Honest Verdict

If you're a BUYER: the list you're searching for doesn't exist, and that's fine — one email requesting the certification letter, plus a 60-second check of type, scope, and dates, beats any directory. The trap to avoid is inheritance conflation: “we run on HITRUST-certified AWS” means the vendor can inherit some control requirements — it does NOT mean the vendor is certified. If you're a SELLER being asked for this proof: the e1 → i1 → r2 ladder exists so you can start credible and cheap, and every tier reuses prior work when you climb.

Buying from a vendor
Letter → type → scope → dates. No letter, no certification.
Need to BE on the list
Start at e1 or i1, climb to r2 when a contract forces it — see the ladder guides below.

FAQ

Is there an official public list of HITRUST certified companies?
No single complete public registry exists. HITRUST issues certification letters to organizations for specifically scoped systems, and shares validated results with the parties the certified company authorizes. Many companies announce certifications via press release, and the major cloud providers document theirs on public compliance pages — but announcements are leads to verify, not a registry.
How do I verify a company is actually HITRUST certified?
Ask the vendor for their HITRUST certification letter. A real one names the certified organization, the exact systems/platforms in scope, the assessment type (e1, i1, or r2), and the validity window. Then check three things: the scope covers the product YOU are buying, the certification is currently valid, and the assessment tier matches your risk requirement.
Are AWS, Microsoft Azure, and Google Cloud HITRUST certified?
All three publicly document HITRUST CSF certification for defined in-scope services on their compliance pages. But cloud-provider certification covers THEIR infrastructure services — it does not make an application built on top of them certified. Vendors can inherit a portion of control requirements from a certified cloud, which reduces their own assessment effort, but they still need their own certification.
Which HITRUST assessment type matters when checking a vendor?
The letter states e1 (44 foundational controls, essentials tier), i1 (~182 controls, implemented 1-year), or r2 (risk-tailored 300-2,000+ requirement statements, the 2-year gold standard). For vendors handling large volumes of PHI for payers or health systems, r2 is what contracts typically name. For most SaaS vendor relationships an i1 is a strong, current signal.
How long is a HITRUST certification valid?
e1 and i1 certifications are valid one year and re-assessed annually. An r2 is valid two years with a required interim assessment at the one-year mark. Always check the dates on the letter — a certification announced in a years-old press release may have lapsed.
Related Resources
Text PJ · 858-461-8054
Done-for-you with SideGuy

Need to verify vendors — or become the certified vendor?

We run vendor due-diligence checks (letter, type, scope, dates, inheritance reality) for buyers, and we help SaaS and digital-health teams climb the e1 → i1 → r2 ladder without the bloated consultant retainer.

Text PJ to verify or get certified →
⭐ Leave SideGuy a Google Review
Serving North County
Solana Beach Encinitas Leucadia Cardiff Del Mar
Trying to confirm a vendor's HITRUST claim?
Text PJ — real human, honest answer, fast. No consultant pitch.
💬 Text PJ — 858-461-8054
Text PJ
Text PJ
858-461-8054

Related Decisions — Compliance

📊 Compliance comparisons · explore the full cluster