HITRUST Common Security Framework. Healthcare-origin US framework, broadened to cross-sector. Certifiable. Combines HIPAA + NIST + ISO 27001 + PCI DSS + multiple frameworks. Primarily US healthcare and adjacent sectors.
Anchors
Provenance
- HITRUST Alliance — founded 2007. Healthcare-origin.
- HITRUST CSF evolved through multiple versions. Current ~v11+ (2024-2025).
- Multi-framework integration: HIPAA + HITECH + NIST + ISO 27001 + PCI DSS + COBIT + state laws + others.
What HITRUST is
Cross-mapped control framework. Tailored to multiple authorities. Three assessment levels:
- HITRUST e1 (Essentials) — entry-level. ~44 controls. 1-year cycle.
- HITRUST i1 (Implemented) — intermediate. ~182 controls. 1-year cycle. Designed for ongoing security.
- HITRUST r2 (Risk-based, 2-year) — comprehensive. Tailored set. 2-year cycle with interim assessment.
HITRUST CSF v11+
- Multi-authority mappings updated.
- AI risk content (HITRUST AI Security Certification — 2024+).
- Sustainability considerations.
Assessment process
Performed by HITRUST-authorized External Assessor firms. Quality-controlled by HITRUST. Results in:
- HITRUST e1, i1, r2 Certification — public-facing.
- HITRUST Assessment Report — detailed.
Why this matters
- US healthcare procurement — many providers, payers, vendors require HITRUST.
- Cross-mapping reduces multi-framework audit overhead.
- AI Security Certification emerging signal.
Related clusters
See also
HITRUST Cluster (pillars MOC) · position · anchors · ISO 27001 Cluster · SOC 2 Cluster