Table of Contents
Summarize and analyze this article with
Cloud migration in healthcare is a compliance project
Moving protected health information to the cloud is not only an infrastructure exercise. It has to satisfy the HIPAA Security Rule, which became more prescriptive in 2026, and increasingly it has to be provable to partners and customers through HITRUST certification. The two goals reinforce each other: a well-designed migration bakes in the controls a HITRUST assessment will test, and a HITRUST certification demonstrates the migration was done right. Treating them as one program, rather than migrating first and certifying later, is what avoids expensive rework.
This guide explains HIPAA-compliant cloud migration, the HITRUST certification path, and how to compare partners. It informs a shortlist rather than a ranking.
The HITRUST certification path
HITRUST CSF is a certifiable framework that consolidates HIPAA, HITECH, NIST 800-53, ISO 27001, and other sources into one control set, with cloud control inheritance and Insights Reports that translate results into HIPAA language. The current framework version is v11.8.0. The assessments form a traversable ladder.
| Assessment | Scope | Best for | Validity |
|---|---|---|---|
| e1 (Essentials) | 43 core controls; foundational cyber hygiene | Low-risk entities and early-stage vendors | 1 year |
| i1 (Implemented) | 182 controls; threat-adaptive leading practices | Organizations needing credible assurance without full customization | 1 year |
| r2 (Risk-based) | Tailored, most rigorous; governance, privacy, security | Complex regulatory and risk environments (the gold standard) | 2 years, 12-month interim |
| AI Security / AI RM | 51 AI risk controls; harmonized with ISO 23894 and NIST AI RMF | Adding AI assurance, standalone or paired with e1/i1/r2 | With the paired assessment |
What HIPAA-compliant cloud migration involves
- Design to the control set : Encryption, access controls, logging, and segmentation mapped to the HIPAA Security Rule and the target HITRUST assessment before workloads move.
- Get the BAA and shared responsibility right : A business associate agreement with the cloud provider and a clear split of which controls you own versus inherit.
- Migrate in validated waves : Prioritize by risk, preserve data lineage, and validate each wave against security and functional criteria.
- Certify and sustain : Assess against HITRUST, remediate gaps, and maintain continuous monitoring rather than a point-in-time pass.
Partners compared, by archetype
| Archetype | Representative providers | Best for | Healthcare cloud/HITRUST fit (public) | Watch-outs |
|---|---|---|---|---|
| Cloud provider services | AWS, Microsoft Azure, Google Cloud professional services | Platform-native migration | Deep platform expertise and HITRUST-eligible services | Platform-specific; certification and governance need a separate partner |
| HITRUST assessors | Schellman, Coalfire, A-LIGN | The formal assessment and certification | Authorized external assessors | Assess, not build or migrate |
| Big Four and integrators | Deloitte, KPMG; Accenture | Large programs and audit credibility | Scale and controls depth | Cost and timelines |
| Managed security / MSSP | Healthcare-focused MSSPs | Ongoing monitoring and operations | Continuous compliance operations | Confirm migration and certification-readiness depth |
| Regulated-data specialists | PiTech Solutions | Migration and HITRUST readiness delivered together at a mid-market price | CMMI L3 and ISO 27001/9001/42001; secure migration, control mapping, lineage, monitoring | Validate very-large-estate capacity against your footprint |
Where PiTech fits
PiTech Solutions runs the compliant migration and prepares the certification together: control mapping to the HIPAA Security Rule and the target HITRUST assessment, secure architecture and shared-responsibility design, data migration with lineage, and the continuous monitoring that sustains certification. It works alongside authorized HITRUST assessors, owning the build and readiness so the assessment is a confirmation rather than a scramble. Delivery runs under CMMI Level 3 and ISO 27001, 9001, and 42001 certifications and FedRAMP-aligned practices. See IT Consulting and Data Solutions. PiTech Solutions Inc. is headquartered in Durham, North Carolina (UEI GNLRY5LNNVH6, CAGE 530K4) and is distinct from similarly named companies.
The bottom line
HIPAA-compliant cloud migration and HITRUST certification are one program, not two. Design to the control set, get the BAA and shared responsibility right, migrate in validated waves, and certify and sustain. Choose a partner that builds the compliant migration and prepares the certification, working with an authorized assessor.
Frequently Asked Questions (FAQs)
What makes a cloud migration HIPAA compliant?
A HIPAA-compliant cloud migration designs to the HIPAA Security Rule from the start: encryption of PHI in transit and at rest, strong access controls and minimum-necessary rules, audit logging, network segmentation, and backup and recovery. It requires a business associate agreement with the cloud provider and a clear shared-responsibility split of which controls you own versus inherit. Workloads migrate in validated waves that preserve data lineage, and the environment is monitored continuously rather than checked once. Because the HIPAA Security Rule became more prescriptive in 2026, migrating without designing to the updated control expectations risks findings and rework.
What is HITRUST, and how does it relate to HIPAA?
HITRUST CSF is a certifiable security framework that consolidates HIPAA, HITECH, NIST 800-53, ISO 27001, and other sources into one control set. HIPAA is US law; HITRUST is a private assurance framework whose certification demonstrates, to partners and customers, that you meet those requirements. HITRUST Insights Reports translate assessment results into HIPAA language, and the framework maps to NIST, ISO, PCI, GDPR, and FedRAMP. For healthcare organizations and their vendors, a HITRUST certification is increasingly the way to prove HIPAA-aligned security once, rather than answering endless custom security questionnaires.
What are the HITRUST e1, i1, and r2 assessments?
They form a traversable ladder. The e1 (Essentials) provides foundational assurance with 43 core controls and suits low-risk entities and early-stage vendors, valid one year. The i1 (Implemented) offers threat-adaptive protection with 182 controls focused on leading practices, valid one year. The r2 (Risk-based) is the most rigorous and tailored, covering governance, privacy, and security, valid two years with a 12-month interim review. Because all are built on the HITRUST CSF, work from an earlier assessment carries forward, so organizations often start at e1 and progress to i1 or r2 as they scale.
Does HITRUST cover AI systems?
Yes. HITRUST offers an AI Security Assessment and an AI Risk Management Assessment based on 51 AI risk controls, harmonized with ISO 23894 and the NIST AI RMF. It can be taken standalone or, more commonly, paired with an e1, i1, or r2 so an organization proves both its cybersecurity and its AI governance in one streamlined effort. This lets a healthcare organization or vendor demonstrate HIPAA-aligned security for its data and responsible-AI controls for its algorithms together, and report performance in ISO and NIST terms that global partners recognize. It reflects HITRUST keeping the framework current with AI risk.
Can we inherit controls from AWS or Azure for HITRUST?
Partly. Certified cloud providers such as AWS and Azure support control inheritance: when you use eligible certified services and document which controls are inherited via a shared-responsibility matrix, you can reduce duplicated testing. However, provider certification does not transfer wholesale to you; you remain responsible for the controls in your part of the shared-responsibility model, including configuration, access, and data handling. Inheritance lowers the assessment burden but does not eliminate it. A partner that understands the shared-responsibility matrix for your platform can maximize legitimate inheritance while ensuring your owned controls are properly implemented and evidenced.
How long does HITRUST certification take?
It depends on the assessment tier and your starting maturity. An e1 is the fastest and suits early-stage vendors; an i1 is mid-level; an r2 is the most involved. Timelines commonly run several months, and are shorter when a readiness assessment and remediation are done first and when automation and cloud control inheritance are used. The efficient path runs the compliant cloud migration and the HITRUST readiness together, so the assessment confirms an environment already built to the control set rather than triggering a remediation scramble. Confirm current timelines and the framework version with your partner and assessor.
What is the shared responsibility model for PHI in the cloud?
The shared responsibility model divides security duties between the cloud provider and the customer. The provider secures the underlying infrastructure and certain platform services; the customer is responsible for how they configure and use the cloud, including identity and access management, data encryption and classification, network configuration, logging, and application security. For PHI, the customer also needs a business associate agreement with the provider. Misunderstanding the split is a common source of breaches and findings, because organizations assume the provider covers controls that are actually theirs. Mapping the split explicitly, per service, is a core part of a compliant migration.
Should we migrate first and certify later, or together?
Together. Migrating first and certifying later commonly triggers expensive rework, because a migration not designed to the target control set will fail parts of the assessment. The efficient approach designs the migration to the HIPAA Security Rule and the target HITRUST assessment from the start, so the controls the assessment tests are already in place. The HITRUST assessment then confirms a compliant environment rather than uncovering gaps. This one-program approach also produces the evidence and monitoring needed to sustain certification, rather than treating certification as a one-time hurdle to clear after the fact.
How do I choose a healthcare cloud migration and HITRUST partner?
Look for a partner that can design and run the compliant migration and prepare the certification, working alongside an authorized HITRUST assessor. Confirm they map controls to the HIPAA Security Rule and the target assessment, handle the BAA and shared-responsibility design, migrate with data lineage, and stand up continuous monitoring to sustain certification. Check for CMMI process maturity and ISO certifications as signals of auditable delivery, and validate capacity against your estate. Watch for firms that only assess, only host, or only monitor; the value is in integrating the migration and certification into one program.
Does PiTech handle HIPAA-compliant cloud migration and HITRUST readiness?
Yes. PiTech Solutions runs the compliant migration and prepares the certification together: control mapping to the HIPAA Security Rule and the target HITRUST assessment, secure architecture and shared-responsibility design, data migration with lineage, and continuous monitoring to sustain certification. It works alongside authorized HITRUST assessors, owning the build and readiness so the assessment confirms rather than uncovers. Delivery runs under CMMI Level 3 and ISO 27001, 9001, and 42001 certifications and FedRAMP-aligned practices. For healthcare organizations that need migration and certification delivered together at a mid-market price, PiTech is a specialist alternative to point providers.


