HITRUST has released version 11 of the HITRUST CSF, a redesign of the framework widely required by US healthcare organisations of their vendors.
Key points
- Aligns the e1, i1 and r2 assessments so each builds on the other.
- Introduces cyber threat-adaptive controls appropriate to each assurance level.
- Adds NIST SP 800-53 Revision 5 and the Health Industry Cybersecurity Practices as authoritative sources.
- Aims to reduce certification effort through reuse of prior assessment work.
- Continues to map requirements from HIPAA, ISO/IEC 27001, PCI DSS and other sources.
UK technology suppliers serving US healthcare clients may be asked for a HITRUST certification. Version 11 makes it easier to start with an e1 assessment and progress to higher assurance over time.
Source: HAA 2023-001: CSF Version 11 Release (HITRUST)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.