Providers, Payors, PBMs, etc.

Healthcare organizations benefit from the HITRUST CSF – a scalable, prescriptive and certifiable framework specific to healthcare organizations. The MyCSF tool provides organizations of all types and sizes with a secure, web-based solution for accessing the CSF, performing assessments and managing compliance. HITRUST Academy educates individuals about information protection in the healthcare industry and utilization of the CSF to manage risk. The HITRUST Cyber Threat Intelligence and Incident Coordination Center provides cyber threat warning and intelligence services by informing them of general and sector-specific threats impacting the industry.

Texas Covered Entity Privacy and Security Certification

The Texas Health Services Authority (THSA) and HITRUST have partnered to develop and manage this program in accordance with Texas House Bill (HB) 300 passed in 2011. HITRUST has developed resources and tools to aid organization in understanding the requirements and preparing for and undergoing an assessment.

Read More


Business associates can streamline the compliance process and reduce costs with a standardized approach to performing assessments and reporting security controls by utilizing the MyCSF tool to perform a CSF assessment and report once against a multiple sets of requirements and to multiple entities. HITRUST Academy provides individuals with the knowledge and skills to utilize the CSF and perform assessments as well as general knowledge and skills for protecting health information.

Get started on an assessment

You can begin reporting your information security posture to multiple healthcare industry partners using a standardized and user-friendly set of tools and methodologies in 5 easy steps.

Learn More


Organizations can partner with HITRUST to provide trained resources to healthcare organizations of varying size and complexity to assess compliance with security control requirements, develop corrective action plans that align with the CSF, and provide remediation for organizations looking to be fully compliant with the myriad of authoritative sources incorporated into the HITRUST CSF. These organizations are called CSF Assessors and have met certain criteria as well as completed courses to become Certified CSF Practitioners.

Read more about becoming an assessor.


HITRUST Academy offers the only training courses designed to educate healthcare security professionals about information protection in the healthcare industry and the utilization of the HITRUST Common Security Framework (CSF) to manage risk.

Read More

HITRUST recognized as one of SC Magazine’s top industry influencers for 2014; shares cybersecurity forecasts for 2015

Published on: December 10, 2014 HITRUST is excited to share that the organization has been recognized as an industry influencer in the Reboot 25 edition of SC Magazine. This year’s annual edition offers a special feature of individuals and organizations who’ve paved the way over the years and presented the industry with “innovative technology, thought-provoking…

Read More

Acting Out: Cyber Simulation Exercises

From the November 2014 Issue of SCMagazine Published on: November 03, 2014 By: Teri Robinson “Simulation exercises show how companies should respond under a cyberattack,” says HHS’s Sara Hall. Teri Robinson reports. In the common parlance of child psychologists, role-playing—particularly acting out scenarios—is good practice for real life, helping kids develop the skills and tools…

Read More

HITRUST Common Security Framework: Tips for Healthcare Facilities

Published on: October 28, 2014 By: Elizabeth Snell The HITRUST Common Security Framework (CSF) is an important tool that healthcare organizations of all sizes can use in their approach to regulatory compliance and risk management. But what exactly are the basics of the CSF program, and what can facilities to do ensure that they are…

Read More

Go To News Archive

HITRUST Announces Cyber Threat XChange (CTX)

Published on: October 8, 2014 HITRUST announced today the HITRUST Cyber Threat XChange (CTX) to significantly accelerate the detection of and response to cyber threat indicators targeted at the healthcare industry. HITRUST CTX will automate the process of collecting and analyzing cyber threats and distributing actionable indicators in electronically consumable formats that organization’s of almost…

Read More

HITRUST Announces CyberRX 2.0 Program

Published on: September 3, 2014 HITRUST announced today that over 750 healthcare organizations have signed-up to participate in the healthcare industry’s cyber attack simulation exercise, CyberRX 2.0, to begin in October 2014. This overwhelming response is the result of the success and important lessons learned from the inaugural CyberRX exercise held in April 2014. It…

Read More

HITRUST HHS Monthly Briefing Press Release

Published on: March 13, 2014 HITRUST HHS Monthly Briefing Press Release

Read More

Go To Archive

Join NIST and HITRUST in a discussion about Cyber Security Frameworks

Published on: November 12, 2014 On February 12, 2014, NIST issued the Framework for Improving Critical Infrastructure Cybersecurity in response to Executive Order 13636. The Framework, created through collaboration between industry and government, consists of standards, guidelines, and practices to help critical infrastructure, including the Healthcare and Public Health Sector, manage cybersecurity risk. To learn…

Read More

CyberRX 2.0 Playbook and Webinar Now Available

The CyberRX 2.0 Level I Playbook is now available for download, and a webinar has been scheduled to provide insights and expectations for those considering participation and guidance for those wanting to get started. Discussion topics will include program overview, value of participation, what to expect, getting started, how to get help and rules and…

Read More

Educational Webinar Series: MyCSF – A Customer’s Perspective

Published on: October 21, 2014 HITRUST is announcing a new webinar series that will provide participants with the opportunity to hear and interact with organizations using the HITRUST MyCSF to manage their information security programs and implement secure measures to comply with HIPAA, HITECH and other compliance requirements. To learn more about this webinar series,…

Read More

View Current Events View Past Events