Terminology Index

Glossary

2953 terms

Open concept maps
G
25
H
7

HITRUST CSF

A comprehensive, certifiable security framework widely used in healthcare that harmonizes many standards and regulations (including HIPAA) into one set of prescriptive, assessable controls, so one certification can demonstrate broad compliance.

The HITRUST CSF integrates requirements from numerous frameworks and regulations, HIPAA, ISO 27001, NIST, and more, into a single certifiable control set, with assessment levels and a formal certification. It is especially prevalent in healthcare, where it lets organizations satisfy many obligations and prove it through one rigorous, recognized certification rather than many separate assessments. In framework work it exemplifies a harmonizing, certifiable standard.

Introduced in: Security Frameworks and Control Mapping

Examples

  • Pursuing HITRUST certification to demonstrate broad healthcare compliance.
  • Using HITRUST to satisfy HIPAA and other standards through one control set.
  • Choosing a HITRUST assessment level appropriate to the organization's risk.