HITRUST Certification Roadmap on AWS — i1, r2, AI Security Readiness
Kriv AI · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
HITRUST certification has become the de facto trust signal for healthcare. 81% of U.S. hospitals and 83% of U.S. health plans use HITRUST for third-party risk assurance (HITRUST Alliance 2024 Trust Report). Enterprise procurement, payer risk teams, and hospital CISOs increasingly require i1 or r2 validated status before onboarding vendors that touch PHI. The challenge: most organizations underestimate the readiness work, fail their first assessment, and burn 6–9 months reworking controls.
Kriv AI's HITRUST Certification Roadmap compresses the readiness phase into four structured virtual weeks.
Show the rest of the publisher’s description (13 more lines)
4-week schedule:
Week 1 — Scoping & control selection. Define CSF boundary, inventory in-scope AWS + hybrid systems, map AWS shared-responsibility inheritance, identify PHI data flows + AI/ML workloads. Select tier (e1 / i1 / r2 / r2 + AI Security) based on risk profile, customer requirements, and scope.
Week 2 — Gap analysis. Control-by-control assessment vs HITRUST CSF (e1: 44 controls · i1: 182 · r2: 300–500+ tailored). Maturity scoring across PRISMA levels (Policy, Process, Implemented, Measured, Managed). Evidence review across AWS services.
Week 3 — Remediation + CAP drafting. Prescriptive AWS configuration guidance (CloudTrail logging depth, KMS key policies, GuardDuty finding response, HealthLake access patterns); policy + procedure drafting; Corrective Action Plan (CAP) with owners + target dates; AI Security Assessment overlay if applicable.
Week 4 — Evidence package + handoff. MyCSF workspace prep, evidence collection templates, readout, Authorized External Assessor referral with warm introductions (LBMC, Digital Edge, BDO, Schellman, Coalfire, A-LIGN).
Tier selection guide.
e1 (Basic) — 44 controls, 30-day turnaround. Entry point for small orgs / early posture.
i1 (Intermediate) — 182 controls, implementation-level rigor, 1-year validity. Most common tier; suitable for mid-market healthcare.
r2 (Rigorous) — 300–500+ tailored controls, risk-based, 2-year validity. Required for large health systems, payers, and regulated AI deployments.
AI Security Assessment (HITRUST CSF v11.2+ overlay) — AI-specific controls overlaid on r2 for orgs running LLMs, agents, or ML on PHI. Maps NIST AI RMF + ISO/IEC 42001 + MITRE ATLAS.
Deliverables: 35-page HITRUST Readiness Report · Control gap matrix against selected tier · Corrective Action Plan with owners + target dates · AI Security Assessment overlay (Tier 3) · AWS-native evidence mapping (HealthLake, CloudTrail, KMS, GuardDuty, Config, Security Hub) · Authorized External Assessor referral list with warm intros.
Important disclaimers. Kriv AI prepares organizations for HITRUST certification but does NOT issue HITRUST certification. Only HITRUST Authorized External Assessor firms can perform validated assessments and submit them to HITRUST for certification. Kriv AI is not currently an Authorized External Assessor; we work alongside your chosen assessor firm. AWS infrastructure costs (HealthLake, CloudTrail, KMS, GuardDuty, compute, storage) are billed directly by AWS. Trademarks: HITRUST, MyCSF, and CSF are marks of HITRUST Alliance; AWS service names are marks of Amazon Web Services; Anthropic and Claude are marks of Anthropic, PBC.
About Kriv AI. AWS Select Tier Services Partner, Databricks Partner, Anthropic CPN member (April 9, 2026; no endorsement implied). Healthcare-specific control mapping experience across HealthLake, CloudTrail, KMS, GuardDuty, Config, and Security Hub. EDP-eligible. Structured as a Marketplace private offer - PHI never leaves your AWS account.
Highlights
Highlighted by the publisher on AWS Marketplace.
4-week virtual readiness for HITRUST i1 or r2 on AWS — evidence package ready for your Authorized External Assessor. Define CSF boundary, inventory in-scope AWS + hybrid systems, map AWS shared-responsibility inheritance, identify PHI data flows and AI/ML workloads. Control-by-control gap analysis vs HITRUST CSF (e1: 44 / i1: 182 / r2: 300–500+ tailored) with PRISMA maturity scoring. Prescriptive AWS configuration guidance for CloudTrail, KMS, HealthLake, GuardDuty, Config, Security Hub.
Tier 3 covers HITRUST CSF AI Security Assessment — the 2026 requirement for PHI-processing AI systems. AI-specific control overlay maps NIST AI RMF, ISO/IEC 42001 Annex A, and MITRE ATLAS to your Bedrock, SageMaker, and third-party model deployments. Deliverables: 35-page HITRUST Readiness Report, Control gap matrix, Corrective Action Plan with owners and target dates, AI Security overlay (Tier 3), MyCSF workspace prep, Authorized External Assessor referral list with warm introductions.
Three fixed-fee tiers $20K–$35K + $3,500 MyCSF setup add-on — transparent pricing where competitors require "Contact for Quote". i1 ($20K) is the most common entry; r2 ($27.5K) required for large systems + payers; r2 + AI Security ($35K) is the 2026 standard for PHI-processing AI. AWS Select Tier Partner + Databricks Partner + Anthropic CPN member (April 2026, no endorsement implied) with healthcare-specific control mapping experience.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Sources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

