HIPAA is a law, NIST CSF is a voluntary framework, and HITRUST is a certification a vendor pays to earn. EMR marketing pages tend to display all three as interchangeable trust badges, which leaves buyers comparing things that answer different questions. HIPAA tells you what a vendor handling patient records is legally obligated to do. NIST tells you how a security program can be organized to meet obligations like HIPAA's. HITRUST tells you a third party examined the vendor's controls against a framework that incorporates both. None of the three substitutes for the others, and only one of them is mandatory.
Three different kinds of thing
Confusion here has a real cost in EMR selection. A buyer who treats "HIPAA compliant" as a certification may accept a self-declared claim no authority has examined. A buyer who demands HITRUST from a small niche vendor may be imposing a six-figure certification burden the vendor's actual risk posture does not require. Sorting the three into their categories, legal obligation, organizing framework, third-party attestation, makes the requests you put in an RFP both fair and useful.
HIPAA: the legal floor
An EMR vendor holding electronic protected health information for a covered practice is a business associate under HIPAA, directly subject to the Security Rule and to breach notification obligations, and required to sign a business associate agreement. This is not optional and not graded: there is no HIPAA certificate, no official registry, and no government audit that pre-clears a vendor. HHS states plainly that it neither endorses nor certifies any product's compliance. When a vendor says "HIPAA compliant," it is making a self-assessment. The BAA is where the claim becomes contractual, which is why the BAA, not the badge, is the document to read.
NIST CSF and SP 800-66: the playbook
The NIST Cybersecurity Framework is a voluntary structure for organizing security work into functions such as identify, protect, detect, respond, and recover. It certifies nothing. Its healthcare relevance runs through NIST SP 800-66 Revision 2, the publication HHS points to for implementing the HIPAA Security Rule, which maps the rule's standards onto NIST's risk-management approach. A vendor that says "we align to NIST CSF" is describing how its program is organized. That is a meaningful signal of maturity, and it is also unverified until someone independent examines it, which is where attestations come in.
HITRUST: the paid attestation
The HITRUST CSF is a proprietary framework that consolidates requirements from many sources, HIPAA and NIST among them, into one certifiable control set. Certification involves an assessor and validation by HITRUST, comes in tiers (the lightweight e1 and i1, and the full r2), and costs real money, which is why it is common among large EMR and cloud vendors and rare among small ones. For a buyer, a current HITRUST certification is strong third-party evidence about the vendor's environment. Two cautions: check which tier and scope the certificate covers, and remember it says nothing about your side of the shared arrangement. Your practice's own Security Rule obligations, including its own risk analysis, do not transfer to a certified vendor.
The mapping, in one table
| HIPAA Security Rule | NIST CSF / SP 800-66 | HITRUST CSF | |
|---|---|---|---|
| What it is | Federal regulation | Voluntary framework and implementation guidance | Proprietary framework with paid certification |
| Who must have it | Every covered entity and business associate | Nobody; adopted by choice | Nobody; demanded by markets, not law |
| Who checks it | OCR, after complaints or breaches | Self-assessed unless separately audited | External assessor plus HITRUST validation |
| What it proves about an EMR vendor | Legal duty exists; BAA makes it contractual | The program has a recognized structure | A third party examined the controls at a point in time |
| Expiry | Ongoing obligation | Not applicable | Certificate has a validity window; check the date |
What to ask an EMR vendor for
Every vendor, regardless of size: a signed BAA, and specific written answers on encryption at rest and in transit, access controls and audit logging, subcontractors who touch ePHI, and breach notification timelines. Cloud vendors at scale: a current third-party attestation, HITRUST at an appropriate tier or a SOC 2 Type II, with the scope statement, not just the logo. Small vendors without certifications: their most recent risk analysis summary or security questionnaire responses in writing. A vendor unwilling to put security answers in writing is answering a different question than the one you asked.