◦ Reference · Framework

HITRUST

HITRUST CSF, the US certifiable framework that maps HIPAA, NIST SP 800-53, NIST CSF, and PCI-DSS into a single control set. Healthcare entities and their business associates pursue HITRUST r2 certification as the cross-walk attestation weight in third-party-risk reviews. Attention is triggered by a control that is marked "Partially Compliant" rather than "Fully Compliant" during the validated assessment, by a corrective action plan (CAP) that is open past the HITRUST SLA window, by a maturity score drop on PRISMA-based scoring, and by a HITRUST inheritance chain that breaks because a sub-provider’s certification was withdrawn.

/hitrust