There is NO single complete public list of HITRUST certified companies — certifications are issued to organizations for specifically scoped systems, and HITRUST shares validated results only with parties the certified company authorizes. So stop searching and start verifying: ask the vendor for their certification letter, check the assessment type (e1 / i1 / r2), confirm the scope names the product you're actually buying, and check the validity dates. AWS, Microsoft Azure, and Google Cloud all publicly document HITRUST certification for in-scope services — but that never automatically certifies an app built on top of them.
Everyone selling into healthcare says “HITRUST certified.” The letter, the type, the scope, and the dates are what make it true.
HITRUST certifications are issued to an organization for a defined scope — specific platforms, systems, and facilities — not to a company as a whole. Results distribution is controlled by the certified organization: they choose who sees the letter and the full assessment report. That design decision is why no complete public directory exists, and why third-party “lists of HITRUST certified companies” you find in blog posts are assembled from press releases — perpetually incomplete, often stale, and blind to scope.
The good news: verification is easy and vendors with a real certification are HAPPY to prove it, because it cost them real money. A vendor who stalls on producing the letter is telling you something.
| Step | What you're checking |
|---|---|
| 1 · Request the certification letter | Real HITRUST letters name the organization, the in-scope systems, the assessment type, and validity dates. “We're HITRUST compliant” without a letter = marketing, not certification |
| 2 · Check the assessment type | e1 (44 controls, essentials) · i1 (~182 controls, 1-year) · r2 (risk-tailored 300-2,000+, 2-year gold standard). Match the tier to your risk |
| 3 · Check the scope | The letter must name the product/platform YOU are buying. A certified billing platform doesn't certify the same company's new analytics product |
| 4 · Check the dates | e1/i1 = 1-year validity, full annual re-assessment. r2 = 2 years with a required interim. Old press release ≠ current certification |
Some categories where HITRUST status is publicly documented or routinely announced — treat every entry as a lead to verify against a current letter, not as proof:
| Category | What you'll find |
|---|---|
| Major clouds (AWS, Azure, Google Cloud) | All three document HITRUST CSF certification for defined in-scope services on their public compliance/trust pages — the strongest public documentation you'll find anywhere |
| EHR / clearinghouse / health-data platforms | Frequently announce certifications via press release; scope and currency vary — verify |
| Telehealth & digital-health SaaS | Growing cohort, usually i1 first then r2 when payer contracts demand it |
| Healthcare BPO / RCM vendors | r2 is common here because payers and health systems contractually require it |
If you're a BUYER: the list you're searching for doesn't exist, and that's fine — one email requesting the certification letter, plus a 60-second check of type, scope, and dates, beats any directory. The trap to avoid is inheritance conflation: “we run on HITRUST-certified AWS” means the vendor can inherit some control requirements — it does NOT mean the vendor is certified. If you're a SELLER being asked for this proof: the e1 → i1 → r2 ladder exists so you can start credible and cheap, and every tier reuses prior work when you climb.
We run vendor due-diligence checks (letter, type, scope, dates, inheritance reality) for buyers, and we help SaaS and digital-health teams climb the e1 → i1 → r2 ladder without the bloated consultant retainer.