Listing Thumbnail

    HITRUST Certification Roadmap on AWS — i1, r2, AI Security Readiness

     Info
    Sold by: Kriv AI 
    4-week virtual HITRUST readiness engagement for healthcare on AWS. Kriv AI scopes your CSF boundary, performs control-by-control gap analysis, remediates AWS configurations (HealthLake, CloudTrail, KMS, GuardDuty, Config, Security Hub), and prepares MyCSF-ready evidence packages so your Authorized External Assessor can validate i1, r2, or the new AI Security Assessment under HITRUST CSF (current release). Three fixed-fee tiers (i1 / r2 / r2 + AI Security) plus optional MyCSF Workspace Setup add-on. Delivered by Kriv AI — AWS Select Tier Services Partner, Databricks Partner, and Anthropic Claude Partner Network member (April 9, 2026). Kriv prepares organizations for HITRUST certification but does not issue HITRUST certificates; only Authorized External Assessor firms perform validated assessments under HITRUST Alliance trademark.

    Overview

    HITRUST certification has become the de facto trust signal for healthcare. 81% of U.S. hospitals and 83% of U.S. health plans use HITRUST for third-party risk assurance (HITRUST Alliance 2024 Trust Report). Enterprise procurement, payer risk teams, and hospital CISOs increasingly require i1 or r2 validated status before onboarding vendors that touch PHI. The challenge: most organizations underestimate the readiness work, fail their first assessment, and burn 6–9 months reworking controls.

    Kriv AI's HITRUST Certification Roadmap compresses the readiness phase into four structured virtual weeks.

    4-week schedule:

    Week 1 — Scoping & control selection. Define CSF boundary, inventory in-scope AWS + hybrid systems, map AWS shared-responsibility inheritance, identify PHI data flows + AI/ML workloads. Select tier (e1 / i1 / r2 / r2 + AI Security) based on risk profile, customer requirements, and scope. Week 2 — Gap analysis. Control-by-control assessment vs HITRUST CSF (e1: 44 controls · i1: 182 · r2: 300–500+ tailored). Maturity scoring across PRISMA levels (Policy, Process, Implemented, Measured, Managed). Evidence review across AWS services. Week 3 — Remediation + CAP drafting. Prescriptive AWS configuration guidance (CloudTrail logging depth, KMS key policies, GuardDuty finding response, HealthLake access patterns); policy + procedure drafting; Corrective Action Plan (CAP) with owners + target dates; AI Security Assessment overlay if applicable. Week 4 — Evidence package + handoff. MyCSF workspace prep, evidence collection templates, readout, Authorized External Assessor referral with warm introductions (LBMC, Digital Edge, BDO, Schellman, Coalfire, A-LIGN).

    Tier selection guide.

    e1 (Basic) — 44 controls, 30-day turnaround. Entry point for small orgs / early posture. i1 (Intermediate) — 182 controls, implementation-level rigor, 1-year validity. Most common tier; suitable for mid-market healthcare. r2 (Rigorous) — 300–500+ tailored controls, risk-based, 2-year validity. Required for large health systems, payers, and regulated AI deployments. AI Security Assessment (HITRUST CSF v11.2+ overlay) — AI-specific controls overlaid on r2 for orgs running LLMs, agents, or ML on PHI. Maps NIST AI RMF + ISO/IEC 42001 + MITRE ATLAS.

    Deliverables: 35-page HITRUST Readiness Report · Control gap matrix against selected tier · Corrective Action Plan with owners + target dates · AI Security Assessment overlay (Tier 3) · AWS-native evidence mapping (HealthLake, CloudTrail, KMS, GuardDuty, Config, Security Hub) · Authorized External Assessor referral list with warm intros.

    Important disclaimers. Kriv AI prepares organizations for HITRUST certification but does NOT issue HITRUST certification. Only HITRUST Authorized External Assessor firms can perform validated assessments and submit them to HITRUST for certification. Kriv AI is not currently an Authorized External Assessor; we work alongside your chosen assessor firm. AWS infrastructure costs (HealthLake, CloudTrail, KMS, GuardDuty, compute, storage) are billed directly by AWS. Trademarks: HITRUST, MyCSF, and CSF are marks of HITRUST Alliance; AWS service names are marks of Amazon Web Services; Anthropic and Claude are marks of Anthropic, PBC.

    About Kriv AI. AWS Select Tier Services Partner, Databricks Partner, Anthropic CPN member (April 9, 2026; no endorsement implied). Healthcare-specific control mapping experience across HealthLake, CloudTrail, KMS, GuardDuty, Config, and Security Hub.

    Highlights

    • 4-week virtual readiness for HITRUST i1 or r2 on AWS — evidence package ready for your Authorized External Assessor. Define CSF boundary, inventory in-scope AWS + hybrid systems, map AWS shared-responsibility inheritance, identify PHI data flows and AI/ML workloads. Control-by-control gap analysis vs HITRUST CSF (e1: 44 / i1: 182 / r2: 300–500+ tailored) with PRISMA maturity scoring. Prescriptive AWS configuration guidance for CloudTrail, KMS, HealthLake, GuardDuty, Config, Security Hub.
    • Tier 3 covers HITRUST CSF AI Security Assessment — the 2026 requirement for PHI-processing AI systems. AI-specific control overlay maps NIST AI RMF, ISO/IEC 42001 Annex A, and MITRE ATLAS to your Bedrock, SageMaker, and third-party model deployments. Deliverables: 35-page HITRUST Readiness Report, Control gap matrix, Corrective Action Plan with owners and target dates, AI Security overlay (Tier 3), MyCSF workspace prep, Authorized External Assessor referral list with warm introductions.
    • Three fixed-fee tiers $20K–$35K + $3,500 MyCSF setup add-on — transparent pricing where competitors require "Contact for Quote". i1 ($20K) is the most common entry; r2 ($27.5K) required for large systems + payers; r2 + AI Security ($35K) is the 2026 standard for PHI-processing AI. AWS Select Tier Partner + Databricks Partner + Anthropic CPN member (April 2026, no endorsement implied) with healthcare-specific control mapping experience.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. To get a custom quote for your needs, request a private offer.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Support

    Vendor support

    Primary support contact. info@kriv.ai  · +1-732-433-5564 · https://kriv.ai/support 

    Response SLA. First response within 1 US business day (Mon–Fri 9 am – 6 pm ET, excluding US federal holidays). For active engagements, named Engagement Lead responds within 4 business hours during weekdays.

    Engagement onboarding SLA. First customer contact within 2 US business days of (a) buyer inquiry via Marketplace and (b) private offer acceptance. Kickoff scheduled within 2 weeks of countersigned SOW.

    Escalation path.

    Engagement Lead (named in SOW) Practice Director (info@kriv.ai ) CEO Abhinav Dangri (info@kriv.ai )

    Communication. Dedicated Microsoft Teams channel, weekly 60-minute video checkpoint, written status note every Friday. Customer SMEs requested 8–10 hours/week during 4-week window (CISO, CPO, GRC, Security Engineering, HIPAA Privacy Officer).

    Documentation handoff. Deliverables provided as editable Word/Excel + PDF in your secure file share. AWS evidence mapping delivered as Excel cross-referenced to HealthLake, CloudTrail, KMS, GuardDuty, Config, and Security Hub. MyCSF workspace prep includes assessment object configuration and user provisioning.

    What support does NOT cover. Kriv is NOT a HITRUST Authorized External Assessor. We do not perform validated assessments, submit assessments to HITRUST Alliance, or issue HITRUST certificates. Your chosen Authorized External Assessor firm performs the validated assessment.

    AWS-side billing. AWS infrastructure costs (HealthLake, CloudTrail, KMS, GuardDuty, Config, Security Hub, compute, storage) are billed directly by AWS and not included in Kriv AI fees.

    Holiday coverage. Closed on US federal holidays. Engagement schedule adjusted at SOW execution if holidays fall in the 4-week window.

    Software associated with this service