HITRUST Brings Rely-Ability™ and Efficiency to All Levels of Information Assurance
All HITRUST assessments leverage a single methodology, framework, assessment platform, and the HITRUST Results Distribution System (RDS) to deliver the best information protection assurances needed for full Rely-Ability and efficiency. This proven approach ensures transparency, accuracy, consistency, and integrity across the HITRUST assessment portfolio and makes it easier for assessed entities to transition to higher levels of assurance as their program matures. Each HITRUST assessment helps organizations evaluate and understand the effectiveness of their cyber preparedness and resilience.
HITRUST assessments provide organizations with a means to assess and communicate their current state of information security and compliance with internal and external stakeholders along with Corrective Action Plans (CAPs) to address any identified deficiencies. Now, the HITRUST Assessment Portfolio meets market needs with higher reliability by offering assurances at all levels – including low, moderate, and high.
HITRUST Approach to Information Risk Management and Compliance
Best-in-class, integrated solutions that align to provide world-class information protection assurances.
HITRUST CSF Framework. All assessments are scoped and built using our risk-based security and privacy controls framework, which maps to 46 authoritative sources and is regularly updated. Learn more.
HITRUST MyCSF SaaS Platform. Interfaces with the CSF information risk management framework to scope and perform comprehensive and accurate information risk assessments, streamline remediation activities, and report and track compliance. Learn more.
HITRUST Assurance Program. Providing prescriptive methodologies and granular oversight, the HITRUST Assurance Program ensures the consistency and quality of all HITRUST Assessments. Learn more.
New Results Distribution System (RDS) for All HITRUST Assessments. The RDS allows for assessed entities to share assessment results through a highly secure web portal or API so that relying parties can more easily find and view the information they need to make better-informed decisions faster. (Initial Release Planned for Q2 2022) Learn more.
Authorized External Assessor Program. HITRUST trains and certifies a broad network of Authorized External Assessor organizations, ensuring that your organization can be confident partnering with any of our trusted assessment professionals, who offer everything from consulting services to third-party validation. Learn more.
Assessment Options to Meet Every Level of Assurance
There are many situations where a moderate or low level of assurance is warranted. That’s why organizations are seeking a broader range of assessment options that require less effort and time to perform while still providing a level of reliability that is commensurate with moderate and lower risk scenarios. To meet market needs for varying levels of assurance, HITRUST is adding two new assessment offerings. While the HITRUST Risk-Based, 2-Year (r2) Validated Assessment – formerly named the HITRUST CSF Validated Assessment – will continue to provide the highest level of information protection assurance, with two new additions, the HITRUST assessment portfolio now includes:
- NEW! HITRUST Basic, Current-State (bC) Assessment. The bC is a “good hygiene” self assessment that offers higher reliability than other self-assessments and questionnaires by utilizing the HITRUST Assurance Intelligence Engine (AI Engine) to identify errors, omissions, and deceit.
- NEW! HITRUST Implemented, 1-Year (i1) Validated Assessment. The i1 is a “best practices” assessment recommended for situations that present moderate risk. The i1 is a new-class of information security assessment that is threat-adaptive with a control set that evolves over time to deliver continuous cyber relevance. The i1 is designed to provide higher levels of transparency, integrity, and reliability over existing moderate assurance reports, with comparable levels of time, effort, and cost. HITRUST i1 Readiness Assessment available.
Learn more about the HITRUST i1 Assessment.
- HITRUST Risk-Based, 2-Year (r2) Validated Assessment. Formerly named the HITRUST CSF Validated Assessment, the r2 remains the industry gold standard as a risk-based and tailorable assessment that continues to provide the highest level of assurance for situations with greater risk exposure due to data volumes, regulatory compliance, or other risk factors. HITRUST r2 Readiness, Interim, and Bridge Assessments available.
Which Assessment is Right for Me?
Current-State Assessment (bC)
1-year (i1) Validated Assessment
2-year (r2) Validated Assessment
(Former Name: HITRUST CSF Validated Assessment)
|Description||Verified Self-Assessment||Validated Assessment + Certification||Validated Assessment +
|Purpose (Use Case)||Focus on good security hygiene controls in virtually any size organization with a simple approach to evaluation, which is suitable for rapid and/or low assurance requirements||A threat-adaptive assessment focused on best security practices with a more rigorous approach to evaluation, which is suitable for moderate assurance requirements||Focus on a comprehensive risk-based specification of controls suitable for most organizations with a very rigorous approach to evaluation, which is suitable for high assurance requirements|
|Number of Control Requirement Statements||71 Static||219 Pre-Set (Static) Controls that leverage security best practices and threat intelligence||2000+ based on Tailoring
(360 average in scope of assessments)
|Flexibility of Control Selection||No Tailoring||No Tailoring||Tailoring|
|Evaluation Approach||1×3: Control Implementation||1×5: Control Implementation||3×5 or 5×5: Control Maturity assessment against either 3 or 5 maturity levels|
|Targeted Coverage*||NISTIR 7621: Small Business Information Security Fundamentals||NIST SP 800-171, HIPAA Security Rule, GLBA Safeguards Rule, U.S. Department of Labor EBSA Cybersecurity Program Best Practices, Health Industry Cybersecurity Practices (HICP)||NIST SP 800-53, HIPAA, FedRAMP, NIST CSF, AICPA TSC, PCI DSS, GDPR, and 37 others|
|Level of Assurance**||Low||Moderate||High|
|Relative Level of Effort||0.5||1.0||5.0|
|Certifiable Assessment||No||Yes, 1 Year||Yes, 2 Year|
|Complementary Assessments||None||Readiness||Readiness, Interim, Bridge|
(Control Requirements Performed by Subservice Providers)
|Allows Carve-Outs or Inclusion||Allows Carve-Outs or Inclusion||Included|
|Leverages HITRUST Results Distribution System (RDS) to Share Results||Yes||Yes||Yes|
|Leverages HITRUST AI Engine to Prevent Omissions, Errors, or Fraud||Yes||Yes||Yes|
FOR CURRENT PRICING OR MORE INFORMATION: Contact your HITRUST Product Specialist
Call: 855-448-7878 or Email: email@example.com
*Targeted Coverage means substantial coverage is intended
** A particular level of assurance (e.g., low, medium/moderate, or high) is generally characterized by the relative level of suitability, impartiality, and rigor in the approach used to specify, assess, and report on the effectiveness of information security and privacy controls and the risks they are intended to manage.