Highlights from our
2025 Trust Report
At HITRUST, we believe that we are building an assurance mechanism that organizations and their stakeholders can Trust. In a constantly shifting threat landscape and regulatory environment, our objective is to continue providing the assurances that organizations need to support their information compliance and security programs.

Trust Report Key Takeaways
- Only HITRUST is proven to mitigate cyber risks. Organizations with HITRUST certifications reported a 0.59% incident rate in 2024 — meaning 99.41% remained breach-free. Only HITRUST delivers quantifiable proof that its certifications work.
- The HITRUST framework addresses 100% of the known Tactics, Techniques, and Procedures (TTPs) that can be mitigated. Our cyber threat-adaptive framework leverages top threat intelligence, ensuring organizations remain protected against the latest risks. HITRUST is built to counter modern cyber challenges and assessments.
- Regular, repeated HITRUST certification processes drive material, continuous improvement. Repeat customers see up to 54% fewer corrective actions needed in subsequent certification, year-over-year.
- HITRUST’s two, new AI assurances empower organizations to embrace AI with confidence. HITRUST launched the industry leading AI Security Assessment and Certification to seamlessly add AI assurance to any core certification, and the AI Risk Management Assessment, so organizations can evaluate and continuously improve their AI risk management programs.
CREATING AN ECOSYSTEM OF TRUST WITH POWERFUL NETWORK EFFECTS
Assessed Entity: Organizations seeking to certify their security and risk management posture

Assessors: Organizations authorized by HITRUST to help companies assess, achieve, and maintain compliance with the HITRUST framework

Relying Party: Organizations leveraging HITRUST to secure supply chains and manage third-party risk


Key Findings in Numbers
Security Incidents in 2024



Repeat HITRUST customers required
% LESS
corrective actions in their 2024 i1 assessments
%
of Actionable MITRE ATT&CK threats mitigated by CSF version 11.4
On average, External Assessors spent:
14% FEWER HOURS
on r2 assessments which used inheritance
23.4% FEWER HOURS
on i1 assessments which used inheritance
9.1% FEWER HOURS
on e1 assessments which used inheritance
Assessment types chosen by all customers in 2024


