The HITRUST Common Security Framework (HITRUST CSF) is a certifiable framework that provides organizations with a comprehensive, flexible, and efficient approach to regulatory compliance and risk management. The HITRUST Alliance is a not-for-profit organization, founded in 2007, âborn out of the belief that information protection should be a core pillar of, rather than an obstacle to, the broad adoption of health information systems and exchanges.â HITRUST also leads many efforts in awareness, education, and advocacy related to information protection. In addition, HITRUST's framework has since been developed to be non-industry specific.
The HITRUST CSF consists of 14 Control Categories (see below), 19 Domains, 49 Control Objectives, 156 Control References, and 3 Implementation Levels. The HITRUST CSF was built on the primary principles of ISO 27001/27002 and has evolved to align with a wide range of regulations, standards, and business requirements. These include HIPAA, PCI-DSS, NIST 800-53, NIST Cybersecurity Framework, COBIT, GDPR, and more.
One PPG Place, Suite 1700
Pittsburgh, PA 15222
p: 412.261.3644 f: 412.261.4876
65 East State Street, Suite 2000
Columbus, OH 43215
p: 614.621.4060 f: 614.621.4062
1660 International Drive
McLean, VA 22102