Compliance audit review

Compare voice AI

HITRUST i1 is the current voice AI procurement gate. HITRUST CSF is the legacy framework.

The voice platform for regulated industries. Built for calls that have to be right.

SOC 2 Type II · HITRUST i1 · PCI DSS L1 · BAA available

99.62%

i1 environments with no 2025 breach (HITRUST Trust Report)

182 controls

In i1 scope (vs. 44 in e1)

1 year

i1 threat-adaptive assurance window

14 days

Kickoff to live call

In production with

  • Memorial Hermann
  • CHRISTUS Health
  • Raya Health
  • Posterity Health
  • Texas Tech University Health Sciences Center

The direct answer

What HITRUST i1 actually means

HITRUST i1 is the implemented, 1-year certification that healthcare procurement teams ask for by name. It evaluates 182 curated controls — up from the entry-level e1's 44 — and provides threat-adaptive assurance that the legacy HITRUST CSF baseline doesn't. Versions 11.5.0 (April 2025) and 11.6.0 (August 2025) added AI-related guideline mappings, making i1 the most current framework for AI-enabled health infrastructure. Guava is HITRUST i1 certified.

Why this matters now

99.62% of HITRUST-certified environments reported no breach in 2025, with an incident rate of 0.38% (HITRUST 2025 Trust Report, based on FY25 data). Independent surveys of uncertified organizations show breach rates above 40%. The gap isn't marketing — it's that HITRUST-certified environments are the ones whose controls actually hold under audit. For voice AI handling patient calls, that 99.62% number is the difference between a procurement approval and a 12-month sales cycle.

Security framework review

Multi-vendor voice stack vs. Guava

Multi-vendor stack
4 seams
Telephony+handoff blockedASR+latency blockedLLM+drift blockedTTS+blame blockedOrchestration

Every seam is a place to lose a call — and when one drops, each vendor points at the next.

Guava fastest path
<200ms · one throat to choke
TelephonyASRLLMTTSOrchestration

One platform, one attestation, one SLA.

What the procurement team checks
Multi-vendor voice stack
Guava
HITRUST i1 — not CSF, not “aligned”
Often HITRUST CSF or “HIPAA-aligned”
HITRUST i1 certified
182-control coverage
Vendor-dependent
All 182 controls in scope
Aligned to the current AI guideline mappings (11.5.0+)
Not yet
Current
Single attestation, single platform
3–5 stitched vendors, 3–5 attestations
One platform, one cert
1-year threat-adaptive assurance
Snapshot certification
i1's threat-adaptive design
14 days from kickoff to live call
Typical: 6–9 months
14 days
Security framework review

Where Guava ships

The voice platform for regulated industries. Built for calls that have to be right.

What makes HITRUST i1 the procurement gate

HITRUST i1 is what hospital procurement teams now ask for by name. It evaluates 182 curated controls, refreshes annually, and was extended in 2025 (versions 11.5.0 and 11.6.0) to include AI-related guideline mappings. Most voice AI vendors still cite legacy HITRUST CSF or “HIPAA-aligned” — neither passes a current i1 procurement review.

Four reasons hospital procurement teams ask for HITRUST i1 specifically:

It's stricter than CSF.

Legacy HITRUST CSF is a baseline. i1 is a current, threat-adaptive framework — designed for the threat landscape your hospital actually faces.

It's mapped to AI.

Versions 11.5.0 and 11.6.0 (2025) added AI-related guideline mappings — making i1 the only HITRUST tier current with the AI deployment patterns hospitals are evaluating.

It's annual.

1-year threat-adaptive assurance, not a 2-year snapshot.

It's audited.

99.62% of i1 environments reported no breach in 2025. The cert is doing the work.

Where HITRUST i1 fits in a voice AI procurement

  • Procurement intake

    i1 is the certification that lets your voice vendor skip the 12-month custom security review.

    ↓Review time↑Pass rate
  • Audit and assurance

    i1's threat-adaptive design means your annual review surfaces real changes, not paperwork churn.

    ↓Findings↑Coverage
  • AI governance

    i1's 11.5.0+ AI guideline mappings align to NIST AI RMF and emerging state AI laws.

    ↑Controls↓Risk
  • Vendor consolidation

    One i1 attestation replaces 3–5 stitched-vendor SOC 2 reports.

    ↓Vendors↑Single attestation

Frequently asked questions

What's the difference between HITRUST i1 and HITRUST CSF?

HITRUST i1 is the current, 1-year, threat-adaptive certification with 182 curated controls. HITRUST CSF is the legacy baseline. Healthcare procurement teams have largely moved to i1 because it reflects current threat patterns and AI deployment risks.

Why isn't “HIPAA certified” enough?

HIPAA is a regulation, not a certification. Saying a vendor is “HIPAA certified” is technically meaningless. What procurement is asking for is evidence of HIPAA's safeguards — and HITRUST i1 is the framework that provides it.

Is HITRUST i1 mapped to AI risk frameworks?

Yes. HITRUST 11.5.0 (April 2025) and 11.6.0 (August 2025) added AI-related guideline mappings aligned to NIST AI RMF and emerging state requirements.

How long does HITRUST i1 certification last?

1 year. Annual reassessment is part of the threat-adaptive design.

Does Guava hold any other certifications?

Yes. SOC 2 Type II, PCI DSS Level 1, and BAA available for healthcare deployments.

Get a working agent in 10 minutes