Skip to content

Highlights from our
2025 Trust Report

At HITRUST, we believe that we are building an assurance mechanism that organizations and their stakeholders can Trust. In a constantly shifting threat landscape and regulatory environment, our objective is to continue providing the assurances that organizations need to support their information compliance and security programs.

Trust Report Key Takeaways

  • Only HITRUST is proven to mitigate cyber risks. Organizations with HITRUST certifications reported a 0.59% incident rate in 2024 — meaning 99.41% remained breach-free. Only HITRUST delivers quantifiable proof that its certifications work.
  • The HITRUST framework addresses 100% of the known Tactics, Techniques, and Procedures (TTPs) that can be mitigated. Our cyber threat-adaptive framework leverages top threat intelligence, ensuring organizations remain protected against the latest risks. HITRUST is built to counter modern cyber challenges and assessments. 
  • Regular, repeated HITRUST certification processes drive material, continuous improvement. Repeat customers see up to 54% fewer corrective actions needed in subsequent certification, year-over-year.
  • HITRUST’s two, new AI assurances empower organizations to embrace AI with confidence. HITRUST launched the industry leading AI Security Assessment and Certification to seamlessly add AI assurance to any core certification, and the AI Risk Management Assessment, so organizations can evaluate and continuously improve their AI risk management programs.
CREATING AN ECOSYSTEM OF TRUST WITH POWERFUL NETWORK EFFECTS

Assessed Entity: Organizations seeking to certify their security and risk management posture

Assessors: Organizations authorized by HITRUST to help companies assess, achieve, and maintain compliance with the HITRUST framework

Relying Party: Organizations leveraging HITRUST to secure supply chains and manage third-party risk

arrows

Key Findings in Numbers

Security Incident Types Reported to HITRUST

 
 
 
 Phishing
 Credentials
 Vulnerability Exploit

Security Incidents in 2024

Repeat HITRUST customers required

% LESS

corrective actions in their 2024 i1 assessments

%

of Actionable MITRE ATT&CK threats mitigated by CSF version 11.4

On average, External Assessors spent:

14% FEWER HOURS

on r2 assessments which used inheritance

23.4% FEWER HOURS

on i1 assessments which used inheritance

9.1% FEWER HOURS

on e1 assessments which used inheritance

Assessment types chosen by all customers in 2024

Get the HITRUST 2025 Trust Report.

Chat

Chat Now

This is where you can start a live chat with a member of our team