PLANTE MORAN 1
Want to be HIPAA
compliant?
GET HITRUST CERTIFIED
By Alexis Kennedy | alexis.kennedy@plantemoran.com
Did you know that it’s impossible to assert that your organization is
“HIPAA compliant” due to the fact that there’s no formal certifying
body to substantiate that claim?
Enter the Health Information Trust Alliance’s Common Security
Framework (HITRUST CSF), which provides an avenue for a
third-party assessment to verify the controls in place to meet all of
the CSF Certification requirements. In addition, organizations can
market compliance with the HITRUST CSF, as each certification
comes complete with a validated report and letter of certification.
The CSF also provides an avenue to reduce audit costs, as it can
easily be mapped to other compliance frameworks in order to help
organizations audit once and report many times over.
It’s impossible to
assert that your
organization is
“HIPAA Certified”
WANT TO BE HIPAA COMPLIANT? GET HITRUST CERTIFIED2
Here are a few frequently asked questions about the CSF and the
certification process.
1
2
3
What is the HITRUST CSF?
What are the reporting options?
The HITRUST CSF was developed to address the security, privacy,
and regulatory challenges facing the healthcare industry. It provides
a comprehensive framework of prescriptive security controls and was
developed with ISO/IEC 27001 as a primary reference. Its primary
goal is to give prescriptive guidance help organizations comply with
HIPAA and HITECH.
HITRUST offers a multitude of reporting options to help organizations
achieve the correct level of assurance necessary for their operations.
There are three options of reports that build upon each other:
Self-assessment.
Organizations complete an internal assessment that results in a report
issued from HITRUST.
Validated assessment.
Once the internal assessment is complete, a certified HITRUST assessor
validates and scores the response on site. The assessment is issued to
the HITRUST Alliance for quality assurance, and then a validated report
is issued.
Validated assessment with certification.
During the validated assessment, the HITRUST assessor will also be
looking at the scoring achieved by the organization. If the score meets
the threshold for certification, a validated report plus certification will
be issued.
Its primary goal is to give
prescriptive guidance
help organizations
comply with HIPAA
and HITECH.
PLANTE MORAN 3
How do I achieve certification?
There are 66 controls required for certification dispersed among
19 different domains. An aggregate score of at least three must be
achieved within each domain in order to become HITRUST certified.
Can I achieve certification with control gaps?
Yes. As long as organizations achieve an average score of three in
each of the 19 domains, they can achieve certification. If control
gaps are identified, however, a corrective action plan (CAP) will
need to be developed and submitted.
How long does my certification last?
Certification lasts for 2 years reliant on an interim assessment being
performed and submitted within 60 days of the one year anniversary
on the initial report date. This assessment will encompass a sample
of testing in each of the 19 domains as well as a review of any CAPs
that were identified after the initial assessment.
Organizations
can pay an
annual fee to
have 24/7 access
to document
controls and
improvements on
an ongoing basis
in the tool.
What is a CSF subscription?
The HITRUST Alliance offers the CSF to organizations on a
subscription basis. This means organizations can pay an annual fee
to have 24/7 access to document controls and improvements on an
ongoing basis in the tool. However, a subscription is not necessary to
become HITRUST certified. All of the assessments are available for
purchase outside of a subscription. Without a subscription, however,
organizations only have 90 days to complete their assessments and
submit them to HITRUST for review, or they’ll be deleted.
WANT TO BE HIPAA COMPLIANT? GET HITRUST CERTIFIED4
A SOC 2 report
mapped to the
HITRUST CSF
will ensure an
organization is
able to meet all
of the reporting
requests received.
SOC 2 and HITRUST: Can we do both?
Yes, a SOC 2 report mapped to the HITRUST CSF will ensure an
organization is able to meet all of the reporting requests received.
By mapping the HITRUST CSF to the SOC 2 report, organizations
have a comprehensive and detailed control report to submit to
their customers. In addition, while performing testing for the
SOC and HITRUST CSF, we can gain efficiencies between the two
reporting frameworks and assist in obtaining a validated report
with certification from HITRUST. We can use the “audit once, report
many” mentality to help organizations issue a HITRUST certified
report from a registered HITRUST assessor as well as issue a SOC 2
report with and opinion from a registered AICPA CPA firm.
plantemoran.com

More Related Content

PDF
UoF - HITRUST & Risk Analysis v1
PDF
HITRUST 101: All the basics you need to know
PPTX
HITRUST CSF in the Cloud
PDF
Hitrust csf-assurance-program-requirements-v1 3-final
PDF
Hitrust: Navigating to 2017, Your Map to HITRUST Certification
PPTX
HealthCare Compliance - HIPAA and HITRUST
DOCX
Common Security Framework Summary
PDF
HITRUST CSF Meaningful use risk assessment
UoF - HITRUST & Risk Analysis v1
HITRUST 101: All the basics you need to know
HITRUST CSF in the Cloud
Hitrust csf-assurance-program-requirements-v1 3-final
Hitrust: Navigating to 2017, Your Map to HITRUST Certification
HealthCare Compliance - HIPAA and HITRUST
Common Security Framework Summary
HITRUST CSF Meaningful use risk assessment

What's hot (19)

PDF
Get Ready Now for HITRUST 2017
PPT
It Audit Expectations High Detail
PDF
HealthCare Compliance - HIPAA & HITRUST
PPTX
HITRUST Certification
PDF
EHR meaningful use security risk assessment sample document
PPT
PCI DSS Compliance and Security: Harmony or Discord?
PPTX
Logging, monitoring and auditing
PPTX
Meaningful Use and Security Risk Analysis
PDF
Ecfirstbiz
PPTX
Its time to rethink everything a governance risk compliance primer
PPTX
Integrated Compliance
PPTX
MindLeaf - HIPAA privacy and cybersecurity insurance
PDF
Hipaa Gap Assessment.Sanitized Report
PPTX
HIPAA omnibus rule update
PPTX
Risk Presentation
PDF
How to Prepare for a PCI DSS Audit
DOCX
Risk Assessment Famework
PPSX
Mbm Hipaa Hitech Ss Compliance Risk Assessment
PDF
Cybersecurity Program Assessments
Get Ready Now for HITRUST 2017
It Audit Expectations High Detail
HealthCare Compliance - HIPAA & HITRUST
HITRUST Certification
EHR meaningful use security risk assessment sample document
PCI DSS Compliance and Security: Harmony or Discord?
Logging, monitoring and auditing
Meaningful Use and Security Risk Analysis
Ecfirstbiz
Its time to rethink everything a governance risk compliance primer
Integrated Compliance
MindLeaf - HIPAA privacy and cybersecurity insurance
Hipaa Gap Assessment.Sanitized Report
HIPAA omnibus rule update
Risk Presentation
How to Prepare for a PCI DSS Audit
Risk Assessment Famework
Mbm Hipaa Hitech Ss Compliance Risk Assessment
Cybersecurity Program Assessments
Ad

Similar to HITRUST Article (7)

PDF
Compliance 101 HITRUST Update.pdf
DOCX
Annotated Bibliography for Health Information Trust Alliance (.docx
PDF
CHIME LEAD Fourm Houston - "Case Studies from the Field: Putting Cyber Securi...
PPTX
HITRUST Overview and AI Assessments Webinar.pptx
PDF
HIPAA and HITRUST on AWS
PPTX
Certification and Accreditation for Health IT Systems
PPTX
Confidentiality power point
Compliance 101 HITRUST Update.pdf
Annotated Bibliography for Health Information Trust Alliance (.docx
CHIME LEAD Fourm Houston - "Case Studies from the Field: Putting Cyber Securi...
HITRUST Overview and AI Assessments Webinar.pptx
HIPAA and HITRUST on AWS
Certification and Accreditation for Health IT Systems
Confidentiality power point
Ad

HITRUST Article

  • 1. PLANTE MORAN 1 Want to be HIPAA compliant? GET HITRUST CERTIFIED By Alexis Kennedy | alexis.kennedy@plantemoran.com Did you know that it’s impossible to assert that your organization is “HIPAA compliant” due to the fact that there’s no formal certifying body to substantiate that claim? Enter the Health Information Trust Alliance’s Common Security Framework (HITRUST CSF), which provides an avenue for a third-party assessment to verify the controls in place to meet all of the CSF Certification requirements. In addition, organizations can market compliance with the HITRUST CSF, as each certification comes complete with a validated report and letter of certification. The CSF also provides an avenue to reduce audit costs, as it can easily be mapped to other compliance frameworks in order to help organizations audit once and report many times over. It’s impossible to assert that your organization is “HIPAA Certified”
  • 2. WANT TO BE HIPAA COMPLIANT? GET HITRUST CERTIFIED2 Here are a few frequently asked questions about the CSF and the certification process. 1 2 3 What is the HITRUST CSF? What are the reporting options? The HITRUST CSF was developed to address the security, privacy, and regulatory challenges facing the healthcare industry. It provides a comprehensive framework of prescriptive security controls and was developed with ISO/IEC 27001 as a primary reference. Its primary goal is to give prescriptive guidance help organizations comply with HIPAA and HITECH. HITRUST offers a multitude of reporting options to help organizations achieve the correct level of assurance necessary for their operations. There are three options of reports that build upon each other: Self-assessment. Organizations complete an internal assessment that results in a report issued from HITRUST. Validated assessment. Once the internal assessment is complete, a certified HITRUST assessor validates and scores the response on site. The assessment is issued to the HITRUST Alliance for quality assurance, and then a validated report is issued. Validated assessment with certification. During the validated assessment, the HITRUST assessor will also be looking at the scoring achieved by the organization. If the score meets the threshold for certification, a validated report plus certification will be issued. Its primary goal is to give prescriptive guidance help organizations comply with HIPAA and HITECH.
  • 3. PLANTE MORAN 3 How do I achieve certification? There are 66 controls required for certification dispersed among 19 different domains. An aggregate score of at least three must be achieved within each domain in order to become HITRUST certified. Can I achieve certification with control gaps? Yes. As long as organizations achieve an average score of three in each of the 19 domains, they can achieve certification. If control gaps are identified, however, a corrective action plan (CAP) will need to be developed and submitted. How long does my certification last? Certification lasts for 2 years reliant on an interim assessment being performed and submitted within 60 days of the one year anniversary on the initial report date. This assessment will encompass a sample of testing in each of the 19 domains as well as a review of any CAPs that were identified after the initial assessment. Organizations can pay an annual fee to have 24/7 access to document controls and improvements on an ongoing basis in the tool. What is a CSF subscription? The HITRUST Alliance offers the CSF to organizations on a subscription basis. This means organizations can pay an annual fee to have 24/7 access to document controls and improvements on an ongoing basis in the tool. However, a subscription is not necessary to become HITRUST certified. All of the assessments are available for purchase outside of a subscription. Without a subscription, however, organizations only have 90 days to complete their assessments and submit them to HITRUST for review, or they’ll be deleted.
  • 4. WANT TO BE HIPAA COMPLIANT? GET HITRUST CERTIFIED4 A SOC 2 report mapped to the HITRUST CSF will ensure an organization is able to meet all of the reporting requests received. SOC 2 and HITRUST: Can we do both? Yes, a SOC 2 report mapped to the HITRUST CSF will ensure an organization is able to meet all of the reporting requests received. By mapping the HITRUST CSF to the SOC 2 report, organizations have a comprehensive and detailed control report to submit to their customers. In addition, while performing testing for the SOC and HITRUST CSF, we can gain efficiencies between the two reporting frameworks and assist in obtaining a validated report with certification from HITRUST. We can use the “audit once, report many” mentality to help organizations issue a HITRUST certified report from a registered HITRUST assessor as well as issue a SOC 2 report with and opinion from a registered AICPA CPA firm. plantemoran.com