In 2022, HITRUST will change its Assurance Assessments and Results Distribution to include three levels bC, i1, and r2. These changes will help start-ups and high-growth organizations obtain assurance assessments through HITRUST.
Introduction
HITRUST was founded in 2007 to provide healthcare IT organizations with assessments of their security controls. It has since broadened the scope to offer risk-based security assessments and assurances to third party associates and stakeholders regardless of industry. The HITRUST CSF, previously known as the Common Security Framework, is a collection of security controls. A scoping exercise done in the MyCSF portal is leveraged to select the controls that are applicable to an organization based on an evaluation of risk factors. An external assessment of the use of the controls could lead to a HITRUST certification. HITRUST currently offers only one certification at a high level of assurance. If you would like to learn more about the current requirements, please read our HITRUST CSF Certification whitepaper. This article will explain the changes coming to HITRUST Assurance Assessments and Results Distribution in 2022, including bC, i1, r2, and RDS.Currently, HITRUST offers three levels of assessments:
- HITRUST CSF Rapid Assessment: Self-assessed, security-only questionnaire facilitated through the HITRUST Assessment Exchange. (A low level of effort resulting in a low level of assurance.)
- HITRUST CSF Readiness Assessment: Performed in preparation for a validated assessment. (A high level of effort resulting in a low level of assurance.)
- HITRUST CSF Validated Assessment: Assessment leads to the HITRUST Certification. (A high level of effort resulting in a high level of assurance.)The chart below represents the "level of effort" required for the HITRUST CSF legacy certification. For comparison, the chart uses 360 controls as an average, and three mandatory maturity test categories.

2022 Changes to the HITRUST MyCSF
Although anecdotal evidence states that a HITRUST Certification has prevented federal audits, small organizations often have difficulty documenting evidence and managing the HITRUST MyCSF portal. Start-ups and high-growth organizations asked for a HITRUST "Lite" assessment leading to certification, and HITRUST responded to this request with a new portfolio of assessments.Beginning in Q1 of 2022, HITRUST will offer three new assessments
Basic, Current-state Assessment ( bC)- Focus on good security hygiene controls for almost any size organization
- Suitable for rapid and/or low assurance requirements
- 71 HITRUST CSF requirements
- Considers control implementation only
- No supporting evidence required
- Self-assessment only (no External Assessor required)
- No certification can result
- Readiness and Validated Assessments
- Focus on leading security practices; designed to provide moderate assurance
- Considers control implementation only; Policy and Process maturity levels are not considered
- Approximately 200 HITRUST CSF requirements
- QA is completed by HITRUST
- Can lead to a 1-year HITRUST certification
- Same level of assurance and effort as the legacy HITRUST CSF Validated Assessment
- Considers all five control maturity Levels; Measured and Managed are still optional
- Varies from 198 to 2,000 requirements; an average threshold is considered 360 controls
- Can lead to a 2-year HITRUST certification
- Requires an assessor's examination of evidence
Also new for 2022, certification attestation hosted by the governing body.
The HITRUST Results Distribution System (RDS) Assessed entities grant access to reliant parties in HITRUST's RDS system. RDS replaces sending PDF reports.Conclusion
In 2022, HITRUST will change its Assurance Assessments and Results Distribution to include three levels bC, i1, and r2. Basic, Current-state Assessment (bC) will focus on good security hygiene controls for almost any size organization. Implemented, 1-year Assessment (i1) will focus on leading security practices and is designed to provide moderate assurance. Risk-based, 2-year Assessment (r2) will have the same level of assurance and effort as the legacy HITRUST CSF Validated Assessment. These changes will help start-ups and high-growth organizations obtain assurance assessments through HITRUST.
Gary Holverson
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)