
The Security Standard You Should Be Asking Every Vendor About
When a vendor asks you to trust them with protected health information (PHI), "we're HIPAA compliant" is the bare minimum required by law. Here is what a genuinely rigorous security posture looks like, and why the difference matters for every vendor relationship in your portfolio.

What HiTrust Actually Is
HiTrust CSF (Common Security Framework) was built specifically for healthcare. Unlike HIPAA, which sets legal minimums, the HiTrust framework consolidates multiple global standards, including HIPAA, NIST, ISO 27001, PCI-DSS, and GDPR, into a single unified framework.
The result is one of the most comprehensive security certifications available to any healthcare software vendor. Achieving it requires rigorous third-party validation. Organizations cannot self-certify. An independent assessor audits the controls, tests the evidence, and determines whether certification is warranted. That distinction matters more than most people realize.
Why HIPAA Compliance Alone Falls Short
HIPAA is required by law. Every covered entity and business associate has to comply. That means HIPAA status tells you almost nothing about how seriously a vendor actually treats security, because the bar for "compliance" can be met through self-attestation and internal audits.
Vendors without HiTrust certification are essentially self-reporting their own security posture. There is no independent body looking over their shoulder. No external validation that their controls hold up under scrutiny.
For executives responsible for choosing software partners who will touch PHI, that gap is significant. A vendor can claim strong security practices. HiTrust certification means a third party verified it.
Why HiTrust r2 Is the Tier Worth Asking About
HiTrust has multiple certification levels. The most rigorous is HiTrust r2, a risk-based certification that takes approximately 12 to 18 months to complete and must be renewed on a two-year cycle. Vendors must continuously maintain and improve their security program to retain it. The certification expires and must be re-earned.
The numbers behind this standard are compelling. Across organizations that have achieved HiTrust certification, 99.62% reported no breach in the measured period. That figure reflects what a high-security bar, applied consistently and validated externally, actually produces in the real world.
When you are evaluating healthcare software vendors for your SNF, health system, or payer organization, asking "are you HiTrust r2 certified?" is one of the fastest ways to separate vendors with mature security programs from those still running on self-assessment.
What Happens When You Choose the Wrong Vendor
A data breach involving PHI carries consequences across every dimension: regulatory, financial, operational, and reputational. Many of the organizations most exposed got there by choosing vendors without asking the right questions before signing the contract.
Scrutinizing a vendor's security certifications during procurement is a core part of the job for executives at director level and above. The wrong vendor relationship can result in OCR (Office for Civil Rights) investigations, breach notification obligations, civil liability, and the kind of coverage that ends careers.
Vendors without independent certification ask you to take their word for it. That is a risk you are accepting on behalf of your organization, your patients, and your members.
Olio Is HiTrust r2 Certified
Olio holds HiTrust r2 certification and recently renewed it, advancing from version 9.3 to 11.4 of the framework. That progression reflects ongoing investment in security infrastructure and a commitment to continuous improvement.
Patrick Glover, Olio's VP of Security and Compliance, described the renewal this way: "A strong reaffirmation of the robust, continuously improving security and compliance foundation our customers rely on every day."
For SNF operators, payer organizations, and health systems evaluating post-acute care coordination software, that certification is one less risk to carry.
Want to learn more about how Olio approaches security and compliance? Visit olio.health to see how we support your organization.



