HITRUST anchors

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Primary documents

  • HITRUST CSF — current v11+ (paid access).
  • MyCSF platform — HITRUST-hosted assessment platform.
  • HITRUST Assurance Program documentation.

Operating body

  • HITRUST Alliance — Frisco, Texas. Founded 2007.

Assessment ecosystem

  • HITRUST Authorized External Assessor firms — Schellman, Coalfire, A-LIGN, Big Four, and many others.
  • HITRUST quality control review of assessor work.

Adjacent US healthcare regulation

  • HIPAA Security Rule — primary healthcare security regulation.
  • HITECH Act — breach notification.
  • State privacy laws (CA CCPA / CPRA, others).
  • 45 CFR Parts 160, 162, 164 — HHS HIPAA regulations.

Adjacent frameworks (mapped in HITRUST CSF)

  • NIST 800-53
  • NIST CSF
  • ISO 27001 / 27002
  • PCI DSS
  • COBIT
  • CIS Controls
  • Multiple others

Reference resources

  • hitrustalliance.net
  • MyCSF portal

See also