You are here:

Why U.S. Health Plans Stopped Accepting Self-Attestation – and How a Health IT Vendor Answered with HITRUST r2 

Glass shield with ECG waveform representing a Health IT vendor achieving HITRUST r2 assurance to meet U.S. health plan security requirements.

When a health plan hands a vendor its claims and clinical data, it takes on that vendor’s risk. For years, a completed questionnaire and a set of policies were enough to get through procurement. Not anymore. Health plans now want independent proof, and increasingly that proof has a name: HITRUST r2. 

This case study follows a U.S. healthcare technology company through that shift, and how ValueMentor helped it achieve HITRUST r2 certification alongside a SOC 2 Type 2 report from one shared evidence base. 

The client in brief 

  • What they do: power value-based care, risk adjustment, quality reporting and care coordination for health plans and provider organizations 
  • What they handle: claims, clinical and quality data from multiple health plans, moving through many integrations 
  • What they achieved: HITRUST r2 certification, the highest level of HITRUST assurance, plus SOC 2 Type 2 

Five questions every health plan asked, and how the client answered them 

The client’s customers didn’t ask for “a certification.” They asked specific questions in vendor reviews and contract renewals. We built the HITRUST r2 assessment around answering them. 

1. “Is your HIPAA compliance independently verified?” 

What they were really asking: can we rely on your controls without auditing you ourselves? 

How we answered it: the r2 was scoped with HIPAA requirements mapped in, so each control was tested by an authorized External Assessor and then reviewed through HITRUST’s centralized quality assurance. Health plans get a single report that speaks directly to HIPAA, instead of a self-assessment they have to take on trust. 

2. “How mature is your security program, beyond the documents?” 

What they were really asking: will these controls still work when we’re not looking? 

How we answered it: the r2 scores every requirement across five maturity levels: policy, procedure, implemented, measured and managed. First-time r2 candidates often score well on the first three and lose points on the last two. We helped the client define the metrics, review cycles and follow-up actions that show a control is monitored and managed over time, not just switched on. 

3. “You connect to many of our peers. How do you contain that risk?” 

What they were really asking: if another customer or integration is compromised, are we exposed? 

How we answered it: instead of scoping around the org chart, we scoped around the data. We mapped where PHI enters the platform, how it moves between services and customers, and where it leaves. The assessment then focused on the controls that matter most along those paths: customer data segregation, access control, interface security and oversight of third parties. 

4. “We also need SOC 2. Can you give us both?” 

What they were really asking: can you meet our requirements without slowing everything down? 

How we answered it: one control set, one evidence library. Evidence was organized so the same artifacts supported both the HITRUST r2 and the SOC 2 Type 2 examination. The client’s engineering and operations teams answered each request once, not twice. 

5. “Will this still hold next year?” 

What they were really asking: is this a one-time project, or a program? 

How we answered it: an r2 certification is valid for two years, with an interim assessment at the one-year mark. We set the client up with clear control owners, an evidence calendar and a scoped plan for the interim review, so assurance doesn’t lapse between cycles. 

Where first-time r2 candidates usually lose time 

The HITRUST r2 assessment is demanding, and most delays are avoidable. These were the traps we steered the client around. 

Common pitfall What happens What we did instead 
Scoping the whole company The assessment grows, costs rise and timelines slip Scoped around PHI data flows and the systems that support them 
Underestimating “measured” and “managed” Controls exist but score low on maturity Built metrics and review cycles into remediation, not after it 
Running SOC 2 and HITRUST separately Duplicate evidence requests and team fatigue One mapped control set supporting both reports 
Leaving QA prep to the end Late questions from HITRUST QA delay certification Reviewed evidence and scoring before submission 

The outcome 

The client now holds HITRUST r2 certification and a SOC 2 Type 2 report, the strongest combination of independent assurance available to a health data vendor in the U.S. market. 

  • Faster procurement: meets health plans that list HITRUST as a condition of doing business 
  • Less compliance overhead: HIPAA, NIST and other requirements consolidated into one certifiable HITRUST assessment 
  • A clear edge in RFPs: independent validation where many competitors still rely on self-attestation 

Is HITRUST r2 right for your organization? 

You’re likely a strong r2 candidate if: 

  • You store or process PHI on behalf of multiple health plans or providers 
  • Customers are writing HITRUST into RFPs or contract renewals 
  • You already have, or need, SOC 2 and want one program instead of two 
  • Security questionnaires are slowing down your sales cycle 

Our HITRUST compliance services cover the full journey, from scoping and readiness through remediation, assessor coordination and interim reviews. Talk to a ValueMentor HITRUST advisor or read more about HITRUST r2. 

Author

David Joseph blog headshot

David Joseph

David is a cybersecurity and Digital Trust leader with over a decade of experience helping organizations strengthen their security, risk, and compliance capabilities. As a Vice President, he partners with business and technology leaders to translate complex security and regulatory requirements into practical, scalable, and business-aligned solutions. His expertise spans governance, risk management, privacy, and cloud security, with a strong focus on building resilient, audit-ready environments that enhance trust and support sustainable growth.

Table of Contents

Protect Your Business from Cyber Threats Today!

Safeguard your business with tailored cybersecurity solutions. Contact us now for a free consultation and ensure a secure digital future!

Ready to Secure Your Future?

We partner with ambitious leaders who shape the future, not just react to it. Let’s achieve extraordinary outcomes together.

I want to talk to your experts in:

Related Blogs

Telephone on a doctor’s desk, illustrating healthcare contact center and customer experience services.
Cloud security illustration with a globe and connected nodes for a private cloud provider’s HITRUST i1 certification case study
Gaming equipment representing cybersecurity and compliance for regulated lottery and gaming operations in the UAE.