One Framework, One Assessment, Globally.
The foundation of all HITRUST programs and services is the HITRUST CSF, a certifiable framework that provides organizations a comprehensive, flexible, and efficient approach to regulatory/standards compliance and risk management.
The HITRUST CSF provides the structure, transparency, guidance, and cross-references to authoritative sources that organizations globally need to be certain of their data protection compliance. The initial development of the HITRUST CSF leveraged nationally and internationally accepted security and privacy-related regulations, standards, and frameworks – including ISO, NIST, PCI, HIPAA, and GDPR – to ensure a comprehensive set of security and privacy controls. HITRUST continually incorporates additional authoritative sources as they are released and accepted in industry and global sectors. The HITRUST CSF standardizes these requirements across authoritative sources to provide clarity and consistency and reduce the burden of compliance.
The commitment and expertise demonstrated by HITRUST ensures that organizations leveraging the framework are prepared when new security and privacy regulations and risks are introduced.
For more on understanding and leveraging the HITRUST CSF, click here.
Download the HITRUST CSF v11.2.0 free of charge.
The HITRUST CSF provides the structure, transparency, guidance, and cross-references to authoritative sources that organizations globally need to be certain of their data protection compliance. The initial development of the HITRUST CSF leveraged nationally and internationally accepted security and privacy-related regulations, standards, and frameworks–including ISO, NIST, PCI, HIPAA, and GDPR–to ensure a comprehensive set of security and privacy controls, and continually incorporates additional authoritative sources. The HITRUST CSF standardizes these requirements, providing clarity and consistency and reducing the burden of compliance.
The commitment and expertise demonstrated by HITRUST ensures that organizations leveraging the framework are prepared when new security and privacy regulations and risks are introduced.
For more on understanding and leveraging the HITRUST CSF, click here.
To keep the CSF relevant and up to date, v11.2.0 leverages the speed, accuracy, and efficiency of the AI-supported toolkit in the v11 framework to refresh three authoritative sources and add six new ones, most notably the addition of mappings to NIST AI RMF v1.0 and ISO/IEC 23894 and ISO 31000.
- Added NIST AI RMF v1.0, ISO/IEC 23894, and ISO 31000 mapping and selectable Compliance factor “Artificial Intelligence Risk Management”
- Added Ontario Personal Health Information Protection Act mapping and selectable Compliance factor “Ontario Personal Health Information Protection Act”
- Added Veteran Affairs Directive 6500 mapping and selectable Compliance factor, “Veteran Affairs Directive 6500”
- Added ISO 27001:2022 mapping and added a selectable Compliance factor, “ISO 27001:2022”
- Added ISO 27002:2022 mapping and added a selectable Compliance factor, “ISO 27002:2022”
- Added NY OHIP Moderate-Plus v5 mapping and selectable Compliance factor, “NY OHIP Moderate-plus Security Baselines v5”
- The existing NY OHIP Moderate-Plus Compliance factor, “NY OHIP Moderate-plus Security Baselines v3.1” will not be selectable as of v11.2.
- Refreshed 23 NYCRR 500 mapping and selectable Compliance factor, “23 NYCRR 500”
- Refreshed FTC Red Flags Rule mapping and selectable Compliance factor, “FTC Red Flags Rule”
- Refreshed NV Title 52 603A mapping and selectable Compliance factor, “NV Title 52 603A”
