HIPAA plus HITRUST plus ISO 42001: the healthcare AI matrix.
Three frameworks, heavy overlap, and a sequencing decision worth several months.
A healthcare AI company selling into health systems and payers ends up carrying three frameworks. Not because anyone planned it, but because each one answers a question the others do not, and the buyers ask all three questions.
HIPAA is the regulatory floor. From the first business associate agreement, the Security Rule applies: a documented risk analysis, administrative, physical, and technical safeguards, workforce training, and breach determination procedures. There is no certificate, which is precisely the problem — a buyer who wants assurance has to assess you directly.
HITRUST answers that. It is a certifiable assessment against a prescriptive control catalogue, performed by an authorized external assessor and validated by HITRUST, with scoring across policy, procedure, implementation, measurement, and management maturity. Payers and large health systems increasingly name it because it replaces bespoke diligence with a single assessed result. The assessment type matters enormously: e1, i1, and r2 differ substantially in control count, rigour, and cost, and choosing r2 when the customer would accept i1 is the most expensive early mistake in this framework.
ISO 42001 answers the newest question. Buyers evaluating clinical or administrative AI have moved past data protection to model governance — intended use, data provenance, evaluation records, human oversight, and what happens when the model behaves unexpectedly. Neither HIPAA nor HITRUST covers that lifecycle, and the security controls that satisfy both say nothing about it.
Sequencing is where the months are won or lost. HIPAA first, because the risk analysis and safeguard set underpin everything above it and because the regulation applies whether or not anyone has asked. HITRUST second, scoped to the assessment type your actual customers require, reusing the HIPAA work rather than restarting. ISO 42001 third, built as an extension of the management system rather than as a parallel program.
Run in that order under one program, the overlap works for you: one control implementation, one evidence library, three answers. Run as three procurements with three firms, and you will build the same access control three times and reconcile the results yourself.