HITRUST Expert
Deep expertise in HITRUST Common Security Framework (CSF) for healthcare and business-associate organizations.
Important — normative text. HITRUST CSF is proprietary and subscription-required. This skill provides implementation guidance, assessment workflow, and evidence patterns — phrased in the author's own words. All normative control statements, scoring rubrics, and MyCSF-specific requirement language must be read from your licensed CSF. When a command in this plugin quotes a control description, it is a paraphrased summary; consult the CSF for authoritative text.
Expertise Areas
HITRUST Alliance Overview
Mission: Create security and privacy programs that can be certified
Founded: 2007
Purpose: Address security/privacy challenges in healthcare industry
Key Value: Single framework harmonizing 40+ regulations and standards
HITRUST CSF (Common Security Framework)
Current Version: CSF v11 (as of 2024)
Control Objectives: 156 across 19 domains
Customization: MyCSF tailored assessment
Certifications: i1, r2, e1
Assessment Types
| Type |
Full Name |
Duration |
Assessor |
Validity |
Use Case |
| i1 |
Implemented, 1-year |
3-6 months |
Self or validated |
1 year |
Initial cert, vendors |
| r2 |
Reportable, 2-year |
6-12 months |
External required |
2 years |
Providers, high assurance |
| e1 |
e1 Assessment |
3-6 months |
Can be self |
Bridge |
Upgrade i1 to r2 |
i1 Assessment:
- Demonstrates control implementation
- Self-assessment or externally validated
- Less rigorous than r2
- Lower cost ($30K-$80K validated)
- Good for: Vendors, BAs, initial certification
r2 Assessment:
- Full external validation required
- Independent HITRUST assessor
- Comprehensive testing
- Higher cost ($100K-$300K+)
- Required for: Healthcare providers, payers, high-risk BAs
e1 Assessment:
- Bridges i1 to r2 in year 2
- Validates changes since i1
- Extends certification to 2-year cycle
- Cost-effective staged approach
MyCSF Customization
HITRUST CSF requirements tailored based on:
Organization Factors:
- Type: Provider, payer, clearinghouse, BA, vendor, other
- Size:
- Small: <$20M revenue or <20 employees
- Medium: Mid-sized
- Large: >$1B revenue or >1000 employees
- System Type: SaaS, on-premise, hybrid, mobile
- Regulatory Factors: HIPAA, state laws, international regs
Customization Result:
- Not Applicable: Requirements excluded
- Implementation Levels:
- Baseline: Minimum requirements
- Middle: Moderate requirements
- Enhanced: Advanced requirements
19 Control Domains
Information Security Management Program (01) - 12 controls
- Security governance
- Risk management program
- Compliance management
Access Control (02) - 14 controls
- User access management
- Privileged access
- Access reviews
- Remote access
Human Resources Security (03) - 8 controls
- Background screening
- Terms of employment
- Termination procedures
Risk Management (04) - 5 controls
- Risk assessment methodology
- Risk treatment
- Acceptance criteria
Security Policy (05) - 3 controls
- Information security policy
- Review and updates
Organization of Information Security (06) - 8 controls
- Management commitment
- Security roles
- Contact with authorities
Compliance (07) - 6 controls
- Legal requirements
- Privacy obligations
- Intellectual property
Asset Management (08) - 7 controls
- Asset inventory
- Information classification
- Media handling
Physical and Environmental Security (09) - 11 controls
- Secure areas
- Physical entry controls
- Equipment security
- Disposal
Communications and Operations Management (10) - 23 controls
- Change management
- Capacity management
- Malware protection
- Backup
- Network security
Information Systems Acquisition, Development and Maintenance (11) - 15 controls
- Security requirements
- Secure development
- Cryptographic controls
Information Security Incident Management (12) - 6 controls
- Incident response plan
- Reporting procedures
- Collection of evidence
Business Continuity Management (13) - 5 controls
- BCM process
- Continuity planning
- Testing
Network Protection (14) - 7 controls
- Network architecture
- Segmentation
- Firewall management
Password Management (15) - 6 controls
- Password policies
- Storage and transmission
- Multi-factor authentication
Education, Training and Awareness (16) - 4 controls
- Security awareness
- Role-based training
Third Party Assurance (17) - 6 controls
- Business associate agreements
- Vendor risk management
- Cloud service provider oversight
Mobile Device Security (18) - 5 controls
- Mobile device policy
- BYOD management
- Mobile application security
Incident Detection and Response (19) - 5 controls
- Monitoring and detection
- Security information and event management (SIEM)
- Threat intelligence
Framework Harmonization
HITRUST CSF maps to 40+ frameworks including:
Primary Frameworks:
- HIPAA Security and Privacy Rules
- NIST 800-53, Cybersecurity Framework
- ISO/IEC 27001:2013, 27002
- PCI DSS v3.2.1
- FedRAMP Moderate Baseline
Additional Frameworks:
- AICPA Trust Services Criteria (SOC 2)
- COBIT 5
- GDPR
- FISMA
- FDA Medical Device Guidance
- CMS MARS-E
- State breach notification laws
- Canadian PIPEDA
- UK Data Protection Act
Benefits of Harmonization:
- Single assessment covers multiple requirements
- Reduced audit fatigue
- Streamlined compliance
- Consistent control language
Certification Process
Phase 1: Preparation (2-4 months)
- Gap assessment
- Remediation planning
- Control implementation
- Documentation
- Self-assessment
Phase 2: Assessment (1-3 months)
- Assessor selection (for validated/r2)
- Scoping and kickoff
- Evidence collection
- Interviews and testing
- Assessor review
Phase 3: Certification (1-2 months)
- Corrective action (if needed)
- Final review
- Certification decision
- Certificate issuance
Ongoing: Surveillance
- Continuous monitoring
- Interim assessments
- Change notifications
- Annual recertification (i1) or biennial (r2)
Common Implementation Challenges
Scope Definition:
- System boundaries unclear
- Data flows not documented
- Inherited controls from cloud providers
Resource Constraints:
- Limited security staff
- Budget limitations
- Competing priorities
Documentation Gaps:
- Policies outdated or missing
- Procedures not formalized
- Evidence not collected systematically
Technical Deficiencies:
- MFA not fully deployed
- Encryption gaps
- Logging/monitoring insufficient
- Vulnerability management immature
Organizational:
- Lack of executive support
- Unclear roles and responsibilities
- Change management resistance
Critical Controls (High Failure Rate)
- 09.ab - Encryption of ePHI at Rest
- 10.k - Encryption in Transit
- 15.d - Multi-Factor Authentication
- 10.j - Audit Logging
- 12.a - Incident Response Plan
- 13.a - Business Continuity Plan
- 17.a - Business Associate Agreements
- 04.a - Risk Assessment
Evidence Requirements
Common Artifacts Needed:
- Information security policies
- Risk assessment reports
- Business impact analysis
- System security plans
- Network diagrams
- Data flow diagrams
- Asset inventories
- Access control matrices
- Audit logs
- Vulnerability scan reports
- Penetration test reports
- Security awareness training records
- Incident response plans and tests
- Business continuity/disaster recovery plans
- Business associate agreements
- Vendor risk assessments
- Change management records
Cost Considerations
i1 Validated Assessment:
- Assessor fees: $30K-$80K
- Remediation: $50K-$150K
- Tools/tech: $20K-$50K
- Internal effort: 500-1000 hours
- Total: $100K-$280K
r2 Assessment:
- Assessor fees: $100K-$300K
- Remediation: $150K-$500K
- Tools/tech: $50K-$150K
- Internal effort: 1000-2000 hours
- Total: $300K-$950K+
Costs vary by scope, readiness, and organization size
Certification Benefits
Regulatory:
- Demonstrates HIPAA compliance
- Satisfies breach safe harbor (some states)
- Shows due diligence
Business:
- Competitive differentiator
- Customer confidence
- BAA credibility
- Reduced audit burden
- Streamlined vendor assessments
Operational:
- Improved security posture
- Standardized processes
- Better risk visibility
- Incident readiness
Capabilities
- HITRUST CSF assessment planning (i1, r2, e1)
- MyCSF scoping and customization
- Gap analysis and remediation roadmaps
- Control implementation guidance (156 controls)
- Evidence collection and documentation
- Assessor selection and management
- Framework mapping (HIPAA, NIST, ISO, PCI-DSS)
- Business associate agreement review
- Vendor risk assessment (HITRUST CSF perspective)
- Continuous monitoring and surveillance
- Certification maintenance
1---2name: hitrust-expert3description: HITRUST CSF expert for healthcare security. Implementation guidance, assessment workflow, and mapping to HIPAA/NIST/ISO/PCI frameworks. References control IDs only — not a replacement for a licensed CSF copy.4---5
6# HITRUST Expert
7
8Deep expertise in HITRUST Common Security Framework (CSF) for healthcare and business-associate organizations.
9
10> **Important — normative text.** HITRUST CSF is proprietary and subscription-required. This skill provides **implementation guidance**, **assessment workflow**, and **evidence patterns** — phrased in the author's own words. All normative control statements, scoring rubrics, and MyCSF-specific requirement language must be read from your licensed CSF. When a command in this plugin quotes a control description, it is a paraphrased summary; consult the CSF for authoritative text.
11
12## Expertise Areas
13
14### HITRUST Alliance Overview
15
16**Mission**: Create security and privacy programs that can be certified
17**Founded**: 2007
18**Purpose**: Address security/privacy challenges in healthcare industry
19**Key Value**: Single framework harmonizing 40+ regulations and standards
20
21### HITRUST CSF (Common Security Framework)
22
23**Current Version**: CSF v11 (as of 2024)
24**Control Objectives**: 156 across 19 domains
25**Customization**: MyCSF tailored assessment
26**Certifications**: i1, r2, e1
27
28### Assessment Types
29
30| Type | Full Name | Duration | Assessor | Validity | Use Case |
31|------|-----------|----------|----------|----------|----------|
32| **i1** | Implemented, 1-year | 3-6 months | Self or validated | 1 year | Initial cert, vendors |
33| **r2** | Reportable, 2-year | 6-12 months | External required | 2 years | Providers, high assurance |
34| **e1** | e1 Assessment | 3-6 months | Can be self | Bridge | Upgrade i1 to r2 |
35
36**i1 Assessment**:
37
38- Demonstrates control implementation
39- Self-assessment or externally validated
40- Less rigorous than r2
41- Lower cost ($30K-$80K validated)
42- Good for: Vendors, BAs, initial certification
43
44**r2 Assessment**:
45
46- Full external validation required
47- Independent HITRUST assessor
48- Comprehensive testing
49- Higher cost ($100K-$300K+)
50- Required for: Healthcare providers, payers, high-risk BAs
51
52**e1 Assessment**:
53
54- Bridges i1 to r2 in year 2
55- Validates changes since i1
56- Extends certification to 2-year cycle
57- Cost-effective staged approach
58
59### MyCSF Customization
60
61HITRUST CSF requirements tailored based on:
62
63**Organization Factors**:
64
651. **Type**: Provider, payer, clearinghouse, BA, vendor, other
662. **Size**:
67 - Small: <$20M revenue or <20 employees
68 - Medium: Mid-sized
69 - Large: >$1B revenue or >1000 employees
703. **System Type**: SaaS, on-premise, hybrid, mobile
714. **Regulatory Factors**: HIPAA, state laws, international regs
72
73**Customization Result**:
74
75- **Not Applicable**: Requirements excluded
76- **Implementation Levels**:
77 - Baseline: Minimum requirements
78 - Middle: Moderate requirements
79 - Enhanced: Advanced requirements
80
81### 19 Control Domains
82
831. **Information Security Management Program (01)** - 12 controls
84 - Security governance
85 - Risk management program
86 - Compliance management
87
882. **Access Control (02)** - 14 controls
89 - User access management
90 - Privileged access
91 - Access reviews
92 - Remote access
93
943. **Human Resources Security (03)** - 8 controls
95 - Background screening
96 - Terms of employment
97 - Termination procedures
98
994. **Risk Management (04)** - 5 controls
100 - Risk assessment methodology
101 - Risk treatment
102 - Acceptance criteria
103
1045. **Security Policy (05)** - 3 controls
105 - Information security policy
106 - Review and updates
107
1086. **Organization of Information Security (06)** - 8 controls
109 - Management commitment
110 - Security roles
111 - Contact with authorities
112
1137. **Compliance (07)** - 6 controls
114 - Legal requirements
115 - Privacy obligations
116 - Intellectual property
117
1188. **Asset Management (08)** - 7 controls
119 - Asset inventory
120 - Information classification
121 - Media handling
122
1239. **Physical and Environmental Security (09)** - 11 controls
124 - Secure areas
125 - Physical entry controls
126 - Equipment security
127 - Disposal
128
12910. **Communications and Operations Management (10)** - 23 controls
130 - Change management
131 - Capacity management
132 - Malware protection
133 - Backup
134 - Network security
135
13611. **Information Systems Acquisition, Development and Maintenance (11)** - 15 controls
137 - Security requirements
138 - Secure development
139 - Cryptographic controls
140
14112. **Information Security Incident Management (12)** - 6 controls
142 - Incident response plan
143 - Reporting procedures
144 - Collection of evidence
145
14613. **Business Continuity Management (13)** - 5 controls
147 - BCM process
148 - Continuity planning
149 - Testing
150
15114. **Network Protection (14)** - 7 controls
152 - Network architecture
153 - Segmentation
154 - Firewall management
155
15615. **Password Management (15)** - 6 controls
157 - Password policies
158 - Storage and transmission
159 - Multi-factor authentication
160
16116. **Education, Training and Awareness (16)** - 4 controls
162 - Security awareness
163 - Role-based training
164
16517. **Third Party Assurance (17)** - 6 controls
166 - Business associate agreements
167 - Vendor risk management
168 - Cloud service provider oversight
169
17018. **Mobile Device Security (18)** - 5 controls
171 - Mobile device policy
172 - BYOD management
173 - Mobile application security
174
17519. **Incident Detection and Response (19)** - 5 controls
176 - Monitoring and detection
177 - Security information and event management (SIEM)
178 - Threat intelligence
179
180### Framework Harmonization
181
182HITRUST CSF maps to 40+ frameworks including:
183
184**Primary Frameworks**:
185
186- **HIPAA** Security and Privacy Rules
187- **NIST** 800-53, Cybersecurity Framework
188- **ISO/IEC** 27001:2013, 27002
189- **PCI DSS** v3.2.1
190- **FedRAMP** Moderate Baseline
191
192**Additional Frameworks**:
193
194- AICPA Trust Services Criteria (SOC 2)
195- COBIT 5
196- GDPR
197- FISMA
198- FDA Medical Device Guidance
199- CMS MARS-E
200- State breach notification laws
201- Canadian PIPEDA
202- UK Data Protection Act
203
204**Benefits of Harmonization**:
205
206- Single assessment covers multiple requirements
207- Reduced audit fatigue
208- Streamlined compliance
209- Consistent control language
210
211### Certification Process
212
213**Phase 1: Preparation (2-4 months)**
214
2151. Gap assessment
2162. Remediation planning
2173. Control implementation
2184. Documentation
2195. Self-assessment
220
221**Phase 2: Assessment (1-3 months)**
222
2231. Assessor selection (for validated/r2)
2242. Scoping and kickoff
2253. Evidence collection
2264. Interviews and testing
2275. Assessor review
228
229**Phase 3: Certification (1-2 months)**
230
2311. Corrective action (if needed)
2322. Final review
2333. Certification decision
2344. Certificate issuance
235
236**Ongoing: Surveillance**
237
238- Continuous monitoring
239- Interim assessments
240- Change notifications
241- Annual recertification (i1) or biennial (r2)
242
243### Common Implementation Challenges
244
2451. **Scope Definition**:
246 - System boundaries unclear
247 - Data flows not documented
248 - Inherited controls from cloud providers
249
2502. **Resource Constraints**:
251 - Limited security staff
252 - Budget limitations
253 - Competing priorities
254
2553. **Documentation Gaps**:
256 - Policies outdated or missing
257 - Procedures not formalized
258 - Evidence not collected systematically
259
2604. **Technical Deficiencies**:
261 - MFA not fully deployed
262 - Encryption gaps
263 - Logging/monitoring insufficient
264 - Vulnerability management immature
265
2665. **Organizational**:
267 - Lack of executive support
268 - Unclear roles and responsibilities
269 - Change management resistance
270
271### Critical Controls (High Failure Rate)
272
2731. **09.ab** - Encryption of ePHI at Rest
2742. **10.k** - Encryption in Transit
2753. **15.d** - Multi-Factor Authentication
2764. **10.j** - Audit Logging
2775. **12.a** - Incident Response Plan
2786. **13.a** - Business Continuity Plan
2797. **17.a** - Business Associate Agreements
2808. **04.a** - Risk Assessment
281
282### Evidence Requirements
283
284**Common Artifacts Needed**:
285
286- Information security policies
287- Risk assessment reports
288- Business impact analysis
289- System security plans
290- Network diagrams
291- Data flow diagrams
292- Asset inventories
293- Access control matrices
294- Audit logs
295- Vulnerability scan reports
296- Penetration test reports
297- Security awareness training records
298- Incident response plans and tests
299- Business continuity/disaster recovery plans
300- Business associate agreements
301- Vendor risk assessments
302- Change management records
303
304### Cost Considerations
305
306**i1 Validated Assessment**:
307
308- Assessor fees: $30K-$80K
309- Remediation: $50K-$150K
310- Tools/tech: $20K-$50K
311- Internal effort: 500-1000 hours
312- **Total**: $100K-$280K
313
314**r2 Assessment**:
315
316- Assessor fees: $100K-$300K
317- Remediation: $150K-$500K
318- Tools/tech: $50K-$150K
319- Internal effort: 1000-2000 hours
320- **Total**: $300K-$950K+
321
322*Costs vary by scope, readiness, and organization size*
323
324### Certification Benefits
325
326**Regulatory**:
327
328- Demonstrates HIPAA compliance
329- Satisfies breach safe harbor (some states)
330- Shows due diligence
331
332**Business**:
333
334- Competitive differentiator
335- Customer confidence
336- BAA credibility
337- Reduced audit burden
338- Streamlined vendor assessments
339
340**Operational**:
341
342- Improved security posture
343- Standardized processes
344- Better risk visibility
345- Incident readiness
346
347## Capabilities
348
349- HITRUST CSF assessment planning (i1, r2, e1)
350- MyCSF scoping and customization
351- Gap analysis and remediation roadmaps
352- Control implementation guidance (156 controls)
353- Evidence collection and documentation
354- Assessor selection and management
355- Framework mapping (HIPAA, NIST, ISO, PCI-DSS)
356- Business associate agreement review
357- Vendor risk assessment (HITRUST CSF perspective)
358- Continuous monitoring and surveillance
359- Certification maintenance