Compliance & frameworks
HITRUST
HITRUST CSF
The HITRUST CSF is a certifiable security framework that harmonizes HIPAA, ISO 27001, NIST SP 800-53, PCI-DSS, and other authoritative sources into one prescriptive control set. Unlike a self-attested policy, a HITRUST certification is issued after an authorized external assessor validates your controls and HITRUST itself performs quality review — which is why healthcare buyers treat it as strong, portable assurance. Certification comes in scaled assessment types (e1, i1, and the risk-based r2), so the same framework covers a small vendor and a large health system with different levels of rigor.
Who it applies to
HITRUST is not a law — it is driven by contracts and vendor-risk requirements, and it is dominant in US healthcare. Health plans, hospital systems, and digital-health companies increasingly require their business associates and technology vendors to hold a HITRUST certification before handling ePHI or connecting to their systems, so the pressure usually arrives through a customer's security questionnaire or master services agreement. Adoption has also spread beyond healthcare into financial services and other regulated sectors that want a single certifiable standard mapped to many frameworks at once.
Cloud control themes
What HITRUST asks of your cloud
- Access control and password management (control domains 10 and 11) — least privilege, MFA, session control, and deprovisioning
- Configuration and vulnerability management (domains 06 and 07) — hardened baselines and remediation of exposed weaknesses
- Network and transmission protection (domains 08 and 09) — segmentation, boundary controls, and encryption in transit
- Audit logging and monitoring (domain 12) — log coverage, integrity, and the ability to detect and reconstruct an incident
- Data protection and privacy (domain 19) — encryption at rest, data handling, and safeguarding of ePHI across accounts and tenants
Domain × framework
Which assessment domains produce HITRUST evidence
| Assessment domain | How it maps |
|---|---|
| Identity & access | IAM findings map to the Access Control and Password Management domains — least privilege, MFA, and deprovisioning evidence that HITRUST requirements probe directly. |
| Data security | Encryption-at-rest and storage-exposure findings support the Data Protection & Privacy domain, where ePHI safeguards carry the most weight for healthcare assessors. |
| Network exposure | Segmentation and boundary findings evidence the Network Protection and Transmission Protection domains, including how workloads are isolated and traffic is encrypted. |
| Logging & monitoring | Log coverage, retention, and integrity findings map to the Audit Logging & Monitoring domain — the basis for detection and incident reconstruction requirements. |
| Configuration & posture | Baseline-drift and vulnerability findings support the Configuration Management and Vulnerability Management domains across every account, subscription, and project. |
| Framework mapping | Because HITRUST harmonizes HIPAA, ISO 27001, NIST, and PCI, each cloud finding is tied back to the specific HITRUST control reference — and, through it, to the underlying frameworks the same control satisfies. |
What you get
A findings report organized so it feeds your HITRUST readiness: each cloud gap tied to the relevant HITRUST control domain and the underlying authoritative source it inherits from, ranked by real risk, with a remediation order your assessor and your engineers can both follow. It shortens the gap-assessment phase by showing where your cloud controls already stand before an external assessor walks in.
Most relevant to: Healthcare, FinTech
Questions
Do you issue HITRUST certification?
No. HITRUST certification is issued after an authorized external assessor validates your controls and HITRUST performs its own quality review. The health check is readiness work — it finds and prioritizes the cloud-technical gaps that would otherwise surface during that assessment, so you go in prepared.
Which assessment do you help with — e1, i1, or r2?
All three. The cloud-technical control areas we assess — access, configuration, network, logging, and data protection — appear across every HITRUST assessment type; the r2 simply tailors and expands the requirement set. We frame findings so they apply whichever path you are pursuing.
How is this different from a HIPAA readiness check?
The HIPAA Security Rule is the regulatory floor and is largely outcome-based. HITRUST is prescriptive and certifiable — it specifies concrete control requirements and maps them to multiple frameworks at once. Our findings serve both, but HITRUST readiness is held to a more detailed, testable bar.
Framework work in practice
Evidence rooms and compliance tables
Mapping is for auditors and operators — shown in the spaces where evidence is reviewed.





