What is HITRUST Compliance? | Perimeter 81

What is HITRUST Compliance?

HITRUST is a healthcare-driven industry organization that created and maintains the certifiable Common Security Framework (CSF).

What is HITRUST and What Does it Mean?

The HITRUST CSF enables healthcare organizations and providers to demonstrate security and compliance in a consistent and streamlined manner.

The HITRUST CSF builds on HIPAA and the HITECH Act US healthcare laws that have established requirements for the use, disclosure, and safeguarding of electronic personal health information (ePHI).

HITRUST provides an integrated approach to ensure that security frameworks and controls are aligned, maintained, and comprehensive to support an organization’s information risk management and compliance program.

Looking for a HITRUST Compliant Cybersecurity Solution ?

Book a Demo

Start Now

HITRUST Requirements

HITRUST requirements include complying with 19 control domains, 75 control objectives, and 156 specific controls. The HITRUST CSF 19 control domains cover the following information security and privacy areas:

The 156 HITRUST CSF controls are separated into three implementation levels, each of which builds on the previous level. Thus, HITRUST level 2 includes all level 1 controls plus additional control requirements.

Level 3 controls include level 2 controls and additional requirements making Level 3 the most secure implementation of the HITRUST CSF.

Organizations using the CSF must determine their level of applicable risk based on attributes such as organization size, number of health records, and ePHI that must be secured.

How Often is HITRUST CSF Updated?

New versions of HITRUST CSF are published periodically to stay ahead of the latest technology and cyber security threats. The average update is once per year. The last time that HITRUST CSF was updated was in June 2020.

It is currently operating with HITRUST CSF version 9.4, which builds on its mission of “ One Framework, One Assessment, Globally”.

As technology continues to develop, we can expect that version 10 is just around the corner. The HITRUST Threat Catalogue is also updated annually and may also be released at another time if there is a significant change to warrant a new release in the interim.

HITRUST CSF Version 9.4 – New Requirements You Should Know About

The HITRUST CSF version 9.4 delivered several updates to meet the evolving regulations, risk-management landscape, and the need for control requirements.

The latest update included significant development to the HITRUST NIST mapping. The most noteworthy updates made available with this version include:

As part of these updates, HITRUST has flagged that organizations may have requirements imposed on them as a result of being part of a smaller niche.

Such organizations include those who are a State Agency or a subset of an industry group.

In some scenarios, there will not be any new privacy or security controls, but organizations will have more specific implementation requirements with version 9.4.

HITRUST has established a mechanism that is enabled by MyCSF for these requirements to become incorporated, harmonized, and included during the assessment process. They are also included in the HITRUST CSF Assessment Report.

The HITRUST CSF maps to CMMC requirements, with HITRUST developing guides to help organizations understand and become confident in the HITRUST framework.

HITRUST CSF Version 10 – What to Expect Next

HITRUST CSF Version 10 is expected to be one of the most innovative releases. It’s predicted to be a significant update from the existing versions. Although HITRUST CSF has focused on health care organizations, the upcoming version 10 is expected to create a more general security framework with a view of attracting specific industries.

The new framework is expected to help facilitate the adoption of CSF outside the healthcare industry by giving organizations a certification option to provide assurances to clients through third-party validated assessments.

The impending version 10 is expected to require certification of all 135 control references. By comparison, version 9.2 only required 75 of the 135 control references to allow for certification. This is expected to result in a larger number of individual requirement statements, similar to what we saw when HITRUST moved from 66 control references to 75 as their requirement for certification after the initial version 9 release.

It was widely held that Version 10 would be released in mid-2020, but it’s no surprise that the global pandemic appears to have delayed this release. As of summer 2021, version 10 is yet to be released. As long as version 9.4 remains up to date and current in its technology, there appears to be no rush to release version 10.

What is the HITRUST Common Security Framework?

The HITRUST Common Security Framework (CSF) is divided into 19 different domains that include endpoint protection and access control. The CSF helps organizations address security challenges through a comprehensive framework of prescriptive and scalable security and privacy controls. HITRUST certified IT offerings against these controls by adapting requirements for certification based on organizational, system, and regulatory factors.

HITRUST provides a standardized compliance framework, assessment methodology, and certification process so that cloud service providers and covered health entities can measure their compliance posture.

The HITRUST CSF is a highly tailored, industry-level overlay of NIST SP 800-53 moderate impact baseline controls, structured on ISO 27001:2005 Appendix A.

The CSF also incorporates healthcare-specific security, privacy, and other regulatory requirements from frameworks such as the Payment Card Industry Data Security Standard (PCI-DSS), ISO/IEC 27001 information security management standards, and Minimum Acceptable Risk Standards for Exchanges (MARS-E).

What are HITRUST Controls?

HITRUST CSF operates by providing organizations with the controls and framework for security compliances and to support data protection. HITRUST controls form the Common Security Framework (CSF) which brings together guidelines – or controls – from industry-specific documents and gather them in one inclusive form of guidance.

HITRUST Controls are designed to streamline and simplify cybersecurity for organizations. These controls help organizations to meet the requirements and be compliant with regulations like GDPR and HIPAA.

The HITRUST framework is made up of three elements. The ‘ Control Categories’ are the general cybersecurity domains from HITRUST. The ‘ Objective Names’ form the control groups which are found within these categories. Finally, ‘ Control References’ are the HITRUST controls themselves.

HITRUST CSF Controls are mapped across various standards – 13 in total – that achieve and ensure regulatory compliance. These controls and the HITRUST CSF framework enable data protection and security compliance for companies.

For example, Control Category 02.0 ‘ Human Resources’ has four Objective Names, with nine Control References. These categories, objective names, and control references operate as follows:

o Control Reference 02.a – Define roles and responsibilities

o Control Reference 02.b – Implement personnel screening.

How Many HITRUST Controls Are There?

There are over 150 individual requirements within HITRUST Controls. The number of controls that a business needs to implement for their security and compliance will depend on the control specifications and other requirements.

The 150+ HITRUST Controls requirements are placed into tiers, otherwise known as control categories or objectives. The most basic control category has 49 objectives, which then break down into 156 references. It is these references that are often thought of as controls.

Technically, every reference can be broken down into specific instruments. There are 156 HITRUST controls that every company must implement. For some businesses, it’s easier to think of them as 14 objectives.

HITRUST Control Categories

The HITRUST Control categories are made up of the objectives and their corresponding reference. These categories are as follows:

These HITRUST CSF security controls require verification of implementation’s assessments including self-assessment, CSF validation or certification, along with HITRUST CSF Bridge Assessment.

Why Businesses Should Get HITRUST CSF Certified

Every business should get HITRUST CSF certification as it helps control and reduce your risk. It reduces risk through increased information security, enabling companies to establish security frameworks.

Most healthcare providers are HITRUST CSF as it ensures that patient information and other personal data are kept protected from any potential breach that could lead to significant financial and reputational consequences for the business.

Companies that are HITRUST CSF Certified have a lower security risk. They are better informed about changes in the security sphere and are able to improve their coverage when necessary, allowing for a reduction in the premiums on their cyber premiums. For any modern company, being HITRUST CSF Certified is a win-win.

Being fully certified also helps to reduce time spent on audits and saves companies money. When you have a HITRUST CSF certificate, it allows you to qualify for other certifications, including NIST, PCI, and HIPAA.

HITRUST Policies

The average cost of a data breach is $4.24 million. HITRUST Policies are always evolving, alongside the updates to the framework in order to help prevent potential leaks and costly data breaches from hitting organizations.

The documentation that you provide during audits and assessments must meet HITRUST’s policies and criteria.

The documentation must be approved formally by management, communicated to the workforce and stakeholders of the company. The following are criteria that should be met in order to achieve perfect HITRUST policy compliance:

How to Conduct a HITRUST Audit and Assessment

When a company meets its HITRUST compliance, it means that they’ve taken proactive steps to interrogate technological infrastructure to protect their data and systems.

A HITRUST audit and assessment can be carried out either through a self-assessment or validated assessment. You can carry out your own self-assessment with the myCSF tool, giving you an idea of where you would stand during an audit.

Self-assessments are usually chosen by companies who want to save money while showing their compliance. The individual within your business carrying out the self-assessment will need to have the appropriate expertise and skills. The results they produce will need to be verified.

By comparison, a validated assessment is carried out by a HITRUST CSF Assessor, who is an independent auditor. They carry out an audit and assess whether the business is compliant with their applicable HITRUST CSF requirements. If they are, the business can be certified as being HITRUST certified.

The average cost of a HITRUST audit ranges between $60,000 – $120,000 depending on the requirements of the organization.

HITRUST Cyber Threat Xchange (CTX) – The Future of Healthcare Threat Analysis

In 2014, HITRUST announced the launch of their HITRUST Cyber Threat Xchange (CTX) that is designed to significantly speed up the detection of and response to cyber threat indicators targeted at companies within the healthcare industry.

CTX is designed to automate the process of analyzing and collecting cyber threats, distributing actionable indicators in electronically consumable formats. It’s tailored to be utilized by companies of all sizes and with various cyber security HITRUST maturity levels to improve their cyber defenses.

The CTX assessment is designed to function as an advanced early warning system to alert organizations to potential cyber threats.

The HITRUST Cyber Threat Xchange has undergone several updates since its release. It’s currently used to provide companies with various cybersecurity maturity levels a way to defend against the increasing volume of cyber threats that are becoming increasingly sophisticated.

HIPAA Requirements

Data security has grown into a significant problem for healthcare organizations as the proliferation of electronic patient data grows. To meet Health Insurance Portability and Accountability Act (HIPAA) compliance regulations, organizations must comply with the HIPAA Security Rule to protect ePHI through integrity control, access control, audit control, and network security.

This Security Rule sets national standards for protecting the confidentiality, integrity, and availability of electronically protected health information.

For HIPAA compliance, Technical Safeguards should be in place so that only authorized entities can access electronic protected health data. Additionally, these policies cover integrity control and network security.

Hitrust vs HIPAA : What Are The Differences?

HIPAA Compliance Requirements HITRUST Certification Requirements
Organizations are focused on complying with legal regulations. HITRUST focuses on managing risk for comprehensive positive impacts on healthcare organizations.
No HIPAA certification process to demonstrate or ensure HIPAA compliance. The certification process for HITRUST compliance.
HIPAA compliance does not ensure compliance with regulations such as NIST, SOC2, and PCI DSS. HITRUST covers HIPAA, NIST, SOX, and PCI DSS.
No framework for risk assessment. A comprehensive framework for risk assessment.
HIPAA compliance requires selecting security multiple controls. HITRUST maps to the HIPAA Security Rule.
No annual certification process. Annual HITRUST certification audit.
No frequent HIPAA updates. HITRUST continuously re-evaluates risk management processes to protect against the latest threats.
Penalties for non-compliance. No penalties for non-HITRUST certification.
HIPAA regulations can be complex. HITRUST certification is achieved through third-party auditors.
No single report for regulatory compliance requirements. Run a single report for all regulatory compliance requirements.

How to Become HITRUST Compliant with Cloud Vendors? Amazon AWS GDPR Compliance

Cloud Service Providers (CSPs) that have achieved CSF certification meet all the certification requirements for HITRUST. The following cloud vendors all offer HITRUST-certified solutions and services.

AWS HITRUST Quickstart

The Amazon Web Services (AWS) HITRUST Quick Start deploys a model environment within the AWS Cloud that deploys workloads that fall within the scope of the HITRUST CSF.

The solution architecture maps to technical requirements imposed by HITRUST controls using AWS CloudFormation templates. The AWS Quick Start templates automate the building of compliant, baseline architectures.

Microsoft Azure HITRUST

Both Microsoft Azure and Office 365 were the first hyper-scale cloud services to receive certification for the HITRUST CSF based on how Azure and Office 365 implement security, privacy, and regulatory requirements to protect customer data and sensitive information. Microsoft also supports the HITRUST Shared Responsibility Program.

Google and HITRUST

Google Workspace and Google Cloud Platform have both achieved HITRUST CSF certification. Google Cloud offers built-in default data protection that meets HITRUST requirements to secure organizations against intrusions, data theft, and cyber-attacks.

Customer data stored in Google Cloud is encrypted at rest by default. Google also applies default protections to customer data in transit.

Salesforce and HITRUST

Salesforce has obtained HITRUST CSF Certification and the company is committed to achieving and maintaining customer trust across its cloud solutions and services.

Salesforce provides a comprehensive cyber-security and privacy program encompassing its data protection across all of its suite of services, including the protection of customer data as defined in its Salesforce’s Master Subscription Agreement.

What is the Cost of HITRUST CSF Certification in 2021?

The cost of becoming HITRUST certified in 2021 is determined by the fees charged by a HITRUST CSF Assessor. At the beginning of the certification process, the appointed assessor will carry out a thorough analysis of your risk profile by asking 50 questions. It is your risk profile that will determine the cost of becoming HITRUST certified in 2021.

Small companies that have a lower risk profile can expect to see a fee from HITRUST of between $6,000 and $15,000. In this scenario, the HITRUST CSF assessor may also charge around $30,000. Larger organizations that are determined as having a higher risk profile can expect their costs to range anywhere from $40,000 to over $150,000.

AWS HITRUST Certification Cost

In 2020, 120 Amazon Web Services (AWS) services were certified for HITRUST CSF. An AWS HITRUST certification allows companies that are AWS customers to tailor their security control baselines to factors such as regulatory requirements and organization type.

Microsoft Azure HITRUST Certification Cost

In February 2021, Microsoft Azure announced that they had increased the scope of its HITRUST CSF certification to include 172 Azure offerings across 49 Azure regions. Businesses can access the Azure HITRUST certification letter through Microsoft’s Service Trust Portal.

The HITRUST Shared Responsibility Matrix for Microsoft Azure is the result of a partnership between Azure and HITRUST Alliance. It allows Azure customers to leverage their HITRUST CSF certifications to inherit controls and apply them to carry out their own assessments.

Microsoft Azure customers can accelerate the deployment of HITRUST CSF by using Azure’s HITRUST Blueprint. It provides customers with a core set of policies to deploy, defining them as a repeatable set of standards, requirements, and patterns that can be enforced across Azure resources.

HITRUST Collaborate 2021 – The HITRUST Annual Conference

The HITRUST Summit happened virtually on 5-6th October 2021, with pre-conference workshops being offered the day before. The HITRUST Collaborate 2021 conference had the tagline of “ Learn. Collaborate. Deliver.” It pitches itself as the most comprehensive and definitive information risk management conference for privacy, security, and compliance professionals.

The purpose of the HITRUST summit is to enable the attendees to collaborate, learn, and deliver more effective methods of risk management, information protection, and compliance. Attendees of the HITRUST Collaborate summit were able to listen and participate in discussions focused on the best practices within the industry and the latest trends in cyber security.

HITRUST Compliance FAQs

What is HITRUST?

HITRUST or the Health Information Trust Alliance is a healthcare-driven industry organization that created and maintains the certifiable Common Security Framework (CSF). The HITRUST CSF enables healthcare organizations and providers to demonstrate security and compliance in a consistent and streamlined manner.

How does HITRUST differ from HIPAA?

With HIPAA, organizations must comply with legal regulations. HITRUST focuses on managing risk for comprehensive positive impacts on healthcare organizations.

How is HITRUST related to GDPR?

HITRUST integrates the European Union’s General Data Protection Regulation (GDPR) into the HITRUST CSF to help organizations identify and mitigate gaps, and meet compliance requirements.

How does HITRUST relate to ISO27001?

The HITRUST CSF’s security safeguards are derived from industry and government frameworks, and cybersecurity requirements including ISO/IEC 27001, HIPAA, security standards, and best practices.

How does HITRUST differ from SOC2?

SOC 2 is a reporting format and not a security framework. The AICPA’s Trust Services Criteria is aligned to the HITRUST CSF that provides standard and equivalent requirements for SOC 2 reporting. Organizations can issue a SOC 2 report on HITRUST CSF control requirements and them as the basis of their cybersecurity program.

How long does it take to get HITRUST certified?

The HITRUST certification process can take up to twelve months, depending on the size and scope of the organization.

How much does HITRUST certification cost?

The cost for a HITRUST certification ranges from $40,000 – $60,000.