HITRUST CSF readiness

We help your team choose the right HITRUST assessment, close control gaps and organize evidence before an authorized external assessor begins fieldwork.

On this page

What HITRUST CSF is

The HITRUST CSF is a security and privacy control framework maintained by HITRUST. It draws requirements from many authoritative sources, such as HIPAA, NIST publications and ISO standards, into one control set. HITRUST also runs an assurance program in which an authorized external assessor validates controls and HITRUST reviews the work before issuing a certification.

Organizations that handle sensitive data, especially health information, often pursue HITRUST certification because customers ask for it. Health systems and payers use it to review vendors, and one certification can answer several customer questionnaires. The framework itself is not a law, and adopting it does not on its own establish compliance with every source it draws from.

Key facts

Three assessment types

e1, i1 and r2 offer increasing levels of assurance. The right one depends on what your customers ask for and on your risk profile.

MyCSF

HITRUST's platform for scoping assessments, recording control results, attaching evidence and submitting work for review.

Authorized external assessor

A validated assessment is performed by an External Assessor organization authorized by HITRUST. HITRUST then performs quality assurance and issues the result.

Readiness assessment

Organizations can run a readiness or self-assessment in MyCSF before the validated assessment to find gaps early.

Inheritance

Where a service provider holds a HITRUST certification, some control results can be inherited through HITRUST's inheritance program. Your own configuration still needs evidence.

Corrective action plans

Gaps found during a validated assessment may need corrective action plans, which HITRUST expects to be tracked to completion.

How the work runs with us

We help define the systems, facilities, data and teams in scope and confirm which assessment type your customers expect. We identify service providers whose controls may be inherited. You receive a scope statement and a plan with dates.

What you receive

Each engagement has a fixed scope agreed in writing. The deliverables below are typical. The exact set depends on your scope.

Scope and approach

  • Scope statement for systems, sites and data
  • Recommended assessment type with reasoning
  • Inheritance candidates listed

Gap assessment

  • Status for each requirement in scope
  • Gaps ranked by risk and effort
  • Owner suggested for each item

Remediation

  • Prioritized remediation plan
  • Controls implemented by our engineers
  • Policies and procedures written or updated

Evidence

  • Evidence organized by requirement
  • Control test results before fieldwork
  • Support during assessor requests

Control areas we help implement

These areas appear across HITRUST assessment types. We work inside your existing systems where possible.

Access control and identity

Single sign-on, multi-factor authentication, least privilege and access reviews. We can deploy Keycloak privately where it fits.

Logging and monitoring

Central logging, alerting and log review records. We can deploy Wazuh privately where it fits.

Vulnerability management

Scanning, patch timelines and exception tracking. Penetration testing supports requirements for technical testing.

Encryption

Encryption at rest and in transit, with key management recorded.

Incident response

Incident plan, roles and exercises. We also offer incident response training.

Backup and recovery

Backup coverage, restore tests and business continuity plans.

Vendor risk

Third-party inventory, security reviews and contract requirements.

Policies and procedures

Written policies and procedures that match how controls operate, which matter most for r2 scoring.

HITRUST e1, i1 and r2 compared

A summary based on HITRUST's published descriptions. Requirements change between CSF versions, so confirm current details with HITRUST and your assessor.

Topice1i1r2
PurposeEssential cybersecurity hygieneLeading security practicesRisk-based, expanded assurance
Control setSmallest fixed setLarger fixed setTailored to your risk factors and selected regulatory sources
What is evaluatedImplementation of controlsImplementation of controlsMaturity of policy, procedure and implementation, with optional measured and managed levels
Certification validityOne yearOne yearTwo years, with an interim assessment in the first year
Typical fitStartups and lower-risk vendorsOrganizations needing moderate assuranceOrganizations handling higher-risk data or with customers who require r2

Who does what

We scope the work, assess gaps, implement agreed controls, write or update policies, organize evidence and test controls before fieldwork. Your team owns the controls, runs them day to day and approves what goes into MyCSF.

We do not issue HITRUST certifications and do not perform the validated assessment. An External Assessor organization authorized by HITRUST performs the assessment, and HITRUST reviews it and issues the certification. We work alongside your assessor and your compliance platform, and we do not promise any assessment outcome.

Common questions

How long does it take?

It depends on the assessment type, the size of the scope and how much remediation is needed. We agree a plan with dates during scoping. HITRUST also sets its own steps for review after the assessor submits.

Which assessment should we choose?

Start with what your customers ask for. We compare that with your risk profile and current controls and recommend an assessment type during scoping. Your team makes the final choice.

Can you be our external assessor?

No. We provide readiness and implementation support. The validated assessment must be performed by an External Assessor organization authorized by HITRUST, which you engage directly.

Can we inherit controls from our cloud provider?

Often, if the provider participates in HITRUST's inheritance program for the services you use. We help identify inheritable controls and the evidence your own configuration still needs.

Can you sign an NDA?

Yes. We sign an NDA on request before reviewing documents or systems.

Do you help after certification?

Yes. Engagements have a fixed scope, and we offer retainers for corrective action plans, interim assessments and evidence upkeep.

How to prepare

Gather current policies and procedures, a list of systems and sites in scope, network and data flow diagrams, a list of key vendors and any certifications they hold, and recent audit, risk assessment or penetration test reports.

Note which customers asked for HITRUST and which assessment type they named. Tell us whether you already have a MyCSF subscription or an assessor selected, and name owners for identity, infrastructure, security operations and vendor management.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.