i1 · Implemented, 1-Year

Security Operations Accelerator for HITRUST (i1)

$799.99

Assessment-ready governance documentation for organizations pursuing the HITRUST i1 Implemented, 1-Year assessment — demonstrating operational maturity beyond basic hygiene.

Buy Now — Secure Checkout

Who it's for

Mid-market healthcare SaaS and services companies whose customers or partners require a more rigorous control set than e1 provides — commonly the entry point enterprise buyers expect before signing a BAA.

What it does

The i1 Security Operations Accelerator covers 17 of the 19 HITRUST CSF domains (01–15, 17, 19) — the six governance domains shared with e1, plus 11 technical domains covering endpoints, portable media, mobile device management, access control, and audit logging & monitoring. Each domain includes a policy plus a much deeper set of supporting procedures, standards, checklists, and evidence guides than e1. Domains 16 (Business Continuity) and 18 are not included at this tier. Every control requirement is tagged with a [BUID Reference] marker for traceability to your assessment — confirm the specific control citation with your assessor via MyCSF.

Deliverables (73 files)

  • START_HERE Guide (PDF)
  • Implementation Guide (PDF)
  • 17 domain policies (Domains 01–15, 17, 19) + 50+ supporting procedures, standards, checklists & evidence guides (.docx)
  • Control documentation tagged with [BUID Reference] markers
  • Readiness Assessment Workbook
  • Gap Assessment Tool
  • Evidence Tracker & Security Evidence Tracker
  • Internal Audit Workbook
  • Executive Dashboard & Governance Readiness Scorecard
  • Vulnerability Tracker & Security Operations Readiness Scorecard
  • Technical Control Matrix, Vendor Security Tracker & Access Review Tracker
  • RACI Matrix
  • Framework Crosswalk (HITRUST ↔ HIPAA ↔ NIST ↔ ISO 27001)
  • License Agreement (PDF)

Frequently Asked Questions

How is i1 different from e1?

i1 covers a broader set of HITRUST requirements and expects more mature, consistently operated controls — not just documented policy, but evidence the controls are actually running. The i1 Accelerator's evidence tracker and internal audit workbook are scoped accordingly.

Which HITRUST domains does i1 cover?

17 of the 19 domains: 01–15, 17, and 19. That's the same six governance domains included in e1, plus 11 technical domains (endpoints, portable media, mobile device management, access control, audit logging & monitoring). Domains 16 (Business Continuity) and 18 are not included in this toolkit.

Can I upgrade from e1 later?

Yes. i1 includes the same six governance domain policies as e1 plus the 11 technical domains, so moving from e1 to i1 documentation is an extension, not a rebuild.

Does this replace an external assessor?

No — a HITRUST-authorized external assessor is still required for certification. This toolkit dramatically reduces the prep work before that engagement.

What's covered by the license?

Each purchase includes a signed License Agreement (PDF) granting your organization a non-exclusive, non-transferable license to use, customize, and internally distribute the toolkit — including its policies, procedures, standards, checklists, and evidence guides — for your own HITRUST program. See the full License Agreement for details.

Ready to accelerate your i1 readiness?

$799.99

Checkout is handled securely through Lemon Squeezy — instant digital download after purchase.

Buy Now — Secure Checkout

Questions first? Contact us or try the free resources.