Security and compliance
10 HITRUST certification experts
These ten professionals have worked on HITRUST certification as external assessors, internal assessors, GRC leaders and security executives who led their companies through it. A reader can learn how practitioners approach HITRUST certification from people who have done the work.
Professionals to explore
01—10Benjamin Davis
LinkedInExperience: Senior Consultant · Baker Tilly US
Former Senior Consultant at Baker Tilly US (2020–2025) and Manager Risk Management there since 2025. The profile says he managed HITRUST validated e1, i1 and r2 assessments, along with NIST and HIPAA assessments, for clients, leading walkthroughs, testing controls and assigning maturity scores. Earlier he was a Senior Associate in Controls Advisory at Grant Thornton (2016–2020).
Brianna Plush
LinkedInExperience: HITRUST Field Manager · BARR Advisory, P.A.
HITRUST Field Manager at BARR Advisory, P.A. since 2025, after serving there as Senior Consultant - Cyber Risk Advisory (2022–2025). Earlier she worked in technology risk at EY (2019–2022). The profile says she serves mainly healthcare clients, planning and executing risk assessments and technology audits against HITRUST, ISO 27001, SOC 1 and SOC 2.
Bryan Cline
LinkedInExperience: VP of Standards and Analysis · HITRUST
Former VP of Standards and Analysis at HITRUST (2011–2019) and Chief Research Officer there since 2019. Before joining HITRUST he was CISO and Director, Information Security at Catholic Health East (2009–2011). The profile describes a background in security and compliance risk management, information assurance and security engineering.
Chris Morrison
LinkedInExperience: Manager of Security, GRC, and IT · Springbuk
Former Manager of Security, GRC, and IT at Springbuk (2019–2026), and Director of Governance and Compliance at Harmony Healthcare IT since 2026. The profile describes him as a first security hire who built security, compliance and risk functions from the ground up in HIPAA-regulated SaaS companies, owning SOC 2 Type II and HITRUST r2 CSF.
Cyrus Makalinaw
LinkedInExperience: Sr. GRC Analyst · Health Catalyst
Sr. GRC Analyst at Health Catalyst since 2022 and GRC Manager there since 2026. The profile describes facilitating multiple HITRUST validated assessments, implementing HITRUST 11.6 controls on a new business unit with no gaps, and leading the transition from HITRUST 9.5 to version 11. Earlier he was Security and Privacy Officer at ARMUS Corporation (2007–2022).
David Conrad
LinkedInExperience: Fractional Chief Information Security Officer (CISO) · Socially Determined
Fractional Chief Information Security Officer at Socially Determined since 2022, after serving as its Chief Technology Officer and CISO (2018–2021). He has also been a fractional CISO in secure health care analytics for multiple health care organizations since 2024. The profile says he led a team through HITRUST certification for a scalable, secure data analytics platform.
Dennis Kabelac
LinkedInExperience: HITRUST Internal Assessor & Senior IT Auditor · MEDHOK, INC
Former HITRUST Internal Assessor & Senior IT Auditor at MEDHOK, INC (2023–2026), after holding the same title at Trinisys, a Harmony Healthcare IT Company (2020–2022). The profile describes 10+ years as an IT compliance analyst and auditor across healthcare and financial services, working with HITRUST CSF, NIST SP 800-53, ISO 27001, SOC 2 and HIPAA.
Joseph Essling
LinkedInExperience: Information Security Compliance Analyst II · Eight Eleven Group
Former Information Security Compliance Analyst II at Eight Eleven Group (2023–2026) and Senior Governance Risk Compliance Analyst there since 2026, after earlier security and systems administration roles at the company. The profile says he led the organization's effort to achieve HITRUST certification and assesses and monitors compliance with its security policies.
Kevin Thompson
LinkedInExperience: GRC HITRUST Manager · Cognizant
Former GRC HITRUST Manager at Cognizant (2021–2022), and HITRUST GRC Consultant at Privaxi since 2023. He was also vCISO Support Manager at SunStone Secure (2022–2024), and earlier Healthcare Regulatory Compliance Program Director at InComm Payments (2014–2020). His headline lists HITRUST, HIPAA, SOC 2 and ISO 27001 work and says he has had zero failed validated assessments.
Shreesh Bhattarai
LinkedInExperience: Director of HITRUST · A-LIGN
Director of HITRUST at A-LIGN since 2024, after serving as Associate Director of HITRUST (2022–2024) and in earlier A-LIGN roles from 2019. The profile describes performing HITRUST, SSAE 18 and SOC 2 examinations, including planning audits, overseeing fieldwork for HITRUST and SOC reviews, and preparing final reports.
Choose the right perspective
Match the person's seat to your question: external assessors for how validated assessments are scoped, tested and scored, in-house GRC leads and security executives for running readiness and remediation inside a company, and people who have worked at HITRUST itself for how the framework is built. Also consider your company's size, since a first security hire at a startup and a large health system face different work.
Questions to take into the conversation
- 01How should a company choose between the HITRUST e1, i1 and r2 assessments?
- 02What does a realistic readiness and remediation plan look like before a HITRUST validated assessment?
- 03How do you keep HITRUST controls and evidence current after certification so renewal is not a scramble?
Reaching HITRUST certification experts
How can I contact one of these HITRUST certification experts?
Pick one of the 10 people on this page and choose "Book a paid call", or describe your project to find others. You offer a fee for a 15-minute call or a written answer, Instant Expert finds the person's work email and sends the invitation, and they decide whether to accept. The list covers 10 companies, including Baker Tilly US; BARR Advisory, P.A. and HITRUST, based on profile data retrieved on October 9, 2026. Being listed here doesn't mean someone has agreed to take calls.
How much does it cost to reach HITRUST certification experts?
You choose the offer, starting at $5 per person. It includes Instant Expert's 20% fee, so an offer that pays the person $100 costs you $125. You're charged only when the person books the call or sends the answer.
What if they don't reply?
You pay nothing. Instant Expert sends follow-up reminders, and if the person hasn't booked or answered within 7 days, the request expires and any hold on your card is released. You can invite several of the 10 people on this list at once and cap your total spend, so you pay only for the ones who accept.
Can an AI agent ask one of these HITRUST certification experts a question?
Yes. An agent with a USDC wallet on Base can ask one question without an Instant Expert account. It names the person, for example by the LinkedIn URL on this page, and pays per ask over x402 (HTTP 402). The person answers in writing or by voice note, and if nobody answers within 7 days, the payment goes back to the wallet automatically. x402 docs
About this directory
This is a professional research starting point based on business profile data retrieved on . Titles and companies reflect that source snapshot and may describe past or present roles. Check the linked profiles for current details. Inclusion does not imply Instant Expert membership or availability.
Request a correction or removal