In this case study, we follow the journey of a company seeking a HITRUST i1 certification to close a lucrative healthcare-related client. They faced numerous remediation tasks to satisfy the HITRUST i1 requirements. We assisted them in prioritizing the remediation tasks. This suggested they obtain a HITRUST e1 certification first, which they could do within the period promised to their client. The lead time to complete all the required statements for the HITRUST i1 validated assessment placed the certification at risk within the allotted time. The company was already PCI-DSS compliant but needed to know what else was necessary for a HITRUST certification. HITRUST protects one or more systems and measures additional security controls, such as risk analysis, incident response, data backup and recovery, and a more in-depth examination of policies and processes. The company had implemented many of the required HITRUST i1 controls but needed the policy to enforce the reason or efficacy of the control. In addition, there were no documented processes delineating the responsibilities, frequency, and documentation for managing the controls. Other controls were not implemented and would require assistance from a third party for configuration and operation.
Proposed Solutions: We conducted a gap analysis in Phalanx, our GRC (governance, risk, and compliance) platform, measuring both the current level of compliance and the amount of work required to close the current gap. This provided the client with a list of items to begin with due to the greater effort required for remediation. Since the requirement statements for the new e1 validated assessment are also included in the i1, we also tracked gaps for it. While some domains began with a lower score in the e1, we observed that fewer requirement statements needed improvement to pass an e1-validated assessment. The company chose to move forward with the e1 certification that fit their client's requirements, timeframe, and cost and provided the client with their roadmap to obtain HITRUST i1 certification.
Implementation: We collaborated with the client to implement the proposed solutions, which included prioritizing remediation items, documentation of policies and processes, and support from a third party for control implementation. The e1 certification demonstrated the organization's dedication to HITRUST and indicated substantial progress toward a validated i1 assessment. The contract was no longer in jeopardy by focusing on the first and second priority requirement statements for completing an e1 in the time required.
Gary Holverson
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)