Skip to main content
All answers

What is HITRUST CSF?

HITRUST CSF (Common Security Framework, current version v11) is the dominant US healthcare cybersecurity certification, used as a contractual baseline by US healthcare payers (UnitedHealth, Anthem, Aetna, Humana, Centene, Cigna), hospital systems, pharma, and the HIPAA business-associate ecosystem. It maps 14 control categories across 40+ authoritative sources. Three certification tiers: e1 (~44 controls), i1 (~182 controls), r2 (200-2,000 controls).

The longer answer.

HITRUST CSF v11 offers three assessment types: e1, a one-year essentials assessment; i1, a one-year implemented assessment; and r2, a two-year risk-based assessment whose scope depends on the organization. All are performed by an approved HITRUST external assessor.

Because the CSF harmonizes more than 40 authoritative sources, including HIPAA, NIST 800-53, ISO 27001 and PCI-DSS, configuration evidence from CIS benchmark scans supports many of its technical requirements. CISGuard does not map HITRUST CSF directly; its NIST 800-53 and ISO 27001 reports provide the supporting evidence.

More questions on Frameworks?

Our compliance engineers can show you exactly how CISGuard handles Frameworks in a briefing scoped to your environment.