For healthcare technology companies, security is more than a technical requirement. It is a condition of trust.
That challenge becomes even more complex for organizations using artificial intelligence. As AI introduces emerging risks related to model integrity, training data security, and incident monitoring, companies must do more than say their technology is secure. They need a credible way to demonstrate it.
For Notable, pursuing both HITRUST r2 Certification and HITRUST AI Security Certification provided that assurance.
Notable automates more than 1.4 million tasks each day for major health systems, medical groups, and payers and has served more than 32 million patients. Its platform handles work that healthcare organizations have traditionally managed manually.
Because the platform operates in healthcare and uses AI, security has always been a priority. The challenge was demonstrating that commitment in a way customers could trust.
“Before we had our HITRUST certification, it was difficult to reassure our customers about our security posture,” said Vivian Lee, Security Analyst at Notable. “We needed some way to show them that we take security seriously.”
Notable selected HITRUST r2 Certification because of its reputation, rigor, and broad adoption across healthcare. The HITRUST CSF brings together more than 70 authoritative sources, including NIST, FedRAMP, ISO, and HIPAA, within a single framework.
When HITRUST introduced its AI Security Certification, Notable moved quickly to extend that assurance to the risks associated with its AI systems.
The two certifications serve complementary purposes.
HITRUST r2 Certification validates Notable’s broader security and compliance posture. HITRUST AI Security Certification provides additional assurance that its AI systems are hardened against risks unique to AI environments, including model integrity, training data security, and incident monitoring.
“HITRUST r2 certification proves our overall security and compliance posture, while the HITRUST AI Security Certification proves we’ve hardened our AI systems against unique threats,” Lee said. “Both show that our platform and AI usage are validated to a high bar.”
Together, the certifications give customers stronger assurance that Notable’s platform, data practices, and use of AI have been independently assessed against a rigorous standard.
Rather than relying on internal claims or self-scoped assessments, Notable’s controls were reviewed through a structured process involving a HITRUST Authorized External Assessor and multiple layers of expert validation.
For Notable, the value of certification extends beyond the security organization.
The company has experienced several business benefits:
Lower procurement barriers with healthcare organizations that require HITRUST certification
Stronger competitive differentiation in the healthcare AI market
Greater customer confidence that patient data is protected
Faster movement through RFPs and sales conversations
“Sometimes, informing a prospective customer that we have a HITRUST certification helps accelerate sales conversation,” Lee explained.
This is where assurance becomes more than a compliance exercise. It becomes a practical business asset that helps establish credibility, satisfy customer requirements, and keep opportunities moving forward.
The certifications have also changed how security is viewed within Notable.
“Our experience with HITRUST r2 certification and HITRUST AI Security Certification has been very rewarding,” Lee said. “It has changed security from a cost center to a partnership enabler.”
By pursuing both certifications, Notable strengthened its security posture while creating a meaningful trust advantage in the healthcare AI market. The certifications provide customers with added confidence that Notable’s platform and AI systems have been validated to a high standard.
Read the full Notable customer story to learn how HITRUST r2 and AI Security Certifications helped the company strengthen customer trust, reduce procurement barriers, and support growth.