HITRUST reports a security breach rate of 99.62% breach-free. The number is real work — HITRUST is the only assurance body that collects breach data centrally at all. But the count it is divided by is printed nowhere: not in the Trust Report, not on the web page, not in the assessment handbook. Three parties state the rate over three different populations, each larger than the next, and none of the three is counted. Everything below runs in your browser, on your own copy of the files.
Here are the three sentences, verbatim, in the order the number travels.
What HITRUST divides by — the method sentence, printed once in the 2025 Trust Report:
“We calculate our security breach rate based on the rate of reported breaches to HITRUST-issued certifications.”2025 Trust Report, p. 9 — sha256 77e32e7c…2b7b7c2, 1,575,731 bytes
What HITRUST headlines — the next sentence but one, and every chart label, and the front page of the web site:
“We noted 99.41% of HITRUST-certified environments did not report a security breach in 2024.”2025 Trust Report, same paragraph
What the insurer relies on — Trium Cyber, a Lloyd’s cyber underwriter, on the page describing its HITRUST Shared Risk Facility:
“HITRUST’s framework has demonstrated relevancy and reliability: less than 1% of organizations with HITRUST certifications reported breaches in 2022 and 2023.”triumcyber.com/consortia-and-hitrust.html, re-fetched 21 Aug 2026
Certifications, environments, organizations. One organization can run several certified environments; one environment can carry several certifications, and HITRUST sells three certification types that an organization can hold at once. So
certifications ≥ certified environments ≥ organizations
and a breach count divided by the largest of the three gives the smallest rate — the most flattering one. That is not an accusation of arithmetic error. It is the observation that the reader cannot tell, because not one of the three counts is printed. Step 1 below searches your copy of the Trust Report for any of them and lists every large integer in the file so you can see the whole set is borrowed from other people’s surveys.
The claim on this page, stated so it can be checked. Not “the rate is false” — I have no way to know that and neither do you. The claim is: no reader outside HITRUST can reproduce, bound, or audit this percentage, and the party pricing insurance against it restates it over a population that is not the one it was computed on. Every step below is a test of that sentence, run on your own bytes.
HITRUST’s server sends no Access-Control-Allow-Origin header, so this page
cannot fetch the report for you — which is the better arrangement anyway. You
fetch it; your browser does the arithmetic; nothing leaves your machine.
Download the 2025 Trust Report (HITRUST asks for a form on some routes; this is the direct file), then drop it here.
What that step does, in order: hashes your file; inflates every compressed stream; rebuilds the text from the PDF’s own drawing operators; documents the ligature glyphs this file uses instead of letters; checks five sentences word for word; and then searches for a population count — first by pattern, then by listing every integer of three digits or more with its context.
A rate printed to two decimals is not nothing. “99.41%” means the breach share sits in a band one hundredth of a percentage point wide, and that band excludes most small denominators outright. What it cannot do is name one.
Step 2. For each published rate, every pair (breaches, certifications) that prints it — exact integer arithmetic, no floating point in any verdict.
Read the output with the caveat it prints for itself: this file implies no floor. Because the report never says how many certifications exist, the smallest denominator consistent with “99.41%” is 169, and that bounds nothing but the arithmetic. If HITRUST published “we issued N certifications”, the search would start at N and the answer would change. That sentence is exactly what is missing.
This is the part that matters to an underwriter, and it needs no bad faith to happen. If the denominator grows faster than the numerator, the percentage improves while the absolute number of breached customers rises. The published decimals let you compute exactly how much growth that takes.
Step 3. Enter how much the certification count grew, in percent, and see what the published rates then force.
Two thresholds come out of the arithmetic, and both are modest. From 99.36% to 99.41%, more breaches become possible once the denominator grows by 6.7227%, and become unavoidable at 10.2564%. From 99.41% to 99.62%, possible at 51.9481%, unavoidable at 58.6667%. Step 3 prints a worked witness: 1 breach in 156, then 2 in 337, then 3 in 780 — the rate improves at every step, and the number of breached customers triples.
The report describes the only channel through which a breach is required to be disclosed:
“External Assessors must examine with each organization whether they experienced a security breach upon the one-year anniversary of an r2 assessment (during the interim assessment).”2025 Trust Report, “How HITRUST Collects Breach Data”
The r2 is the two-year certification. The e1 and i1 are one-year certifications, and the report is explicit that they carry no interim assessment:
“…since interim assessments are not performed on one-year assessments.”2025 Trust Report, section on Corrective Action Plans
And the report dates the arrival of the newest one-year type:
“In January 2023, the HITRUST assessment portfolio was expanded with the introduction of the e1 assessment.”2025 Trust Report, p. 16
So between the 2022 figure Trium cites and the 2025 figure on HITRUST’s front page, a certification type that did not exist before January 2023 entered the population — a type on which no assessor is required to ask the breach question. Alongside it, the report prints the mix of validated assessment types chosen by 2024 customers: r2 62.1%, i1 21.9%, e1 16%.
Two honest caveats, both of which cut against my own case and both of which I would rather state than have pointed out to me. First, HITRUST also monitors public breach disclosures, so the interim assessment is not the only channel — it is only the mandatory one. Second, that 62.1 / 21.9 / 16 mix is labelled “Validated Assessment Types Chosen by All 2024 Customers”: it is a flow of assessments chosen in one year, not the stock of certifications in force, and an r2 spans two years, so the two differ. Which means even the composition of the denominator is unpublished — a reader cannot say how much of the rate is r2 and how much is e1. That is the same gap again, one level down.
Trium’s underwriting page states the rate over organizations. HITRUST computes it over certifications. Moving between the two multiplies the rate by the average number of certifications per organization — a number nobody has published either.
Step 4. Assume an average of c HITRUST certifications per certified organization, and see what survives of “less than 1% of organizations”.
The break points are exact and they move with the rate you type. For 99.36% — the figure HITRUST’s own trust-report page serves for both of the years Trium names — they are 1.5504 and 1.5748. For 99.41% they are 1.6807 and 1.7094. Below the first, “less than 1% of organizations” holds no matter what. Above the second, it fails no matter what. HITRUST sells three certification types, certifies environments rather than companies, and markets holding more than one; whether the average sits below 1.55 is unknown to Trium, to me, and to Trium’s insureds. The right word for the sentence is therefore unsupported, not false — and unsupported is the harder problem, because there is no correction that fixes it.
Trium’s claim is specifically about “2022 and 2023”. HITRUST’s trust report page carries four year toggles above the headline rate. Here is what its own markup says, and you should not take my word for it — view the source of hitrustalliance.net/trust-report, copy it, and paste it in.
Step 5. Paste the page source. This step reads only the
four toggle buttons and prints label, data-year and data-value side by side.
The button labelled 2022 carries data-year="2023" and
data-value="99.36" — byte for byte the same attributes as the button labelled 2023.
Click 2022 and you are shown the 2023 figure. Of the two years Trium’s underwriting page names,
one has no distinct number on the source it points to. This is small, and it is
concrete, and it is fixable in an afternoon — which is why it belongs on the same page as the
part that is not.
A page that only ever prints red is worth nothing. The last row of this block deliberately sabotages the instrument: if the verdicts above were hardcoded, that row would still come out green.
Nothing on this page asks HITRUST to change a number. The rate may be exactly right. What is missing is the arithmetic that lets anyone else check it. Three integers, printed beside the percentage, close every gap above:
Three numbers HITRUST already holds. Publishing them would make it the only assurance body whose headline figure a customer, a competitor, or an underwriter can reproduce from the page it is printed on — which is a stronger claim than the percentage itself.