HITRUST CSF recently released version 11, which includes important updates to the framework that will help streamline the process to greater healthcare assurance and protect against new and emerging threats.
As a single framework, HITRUST CSF v11 provides broad assurance for different risk levels and compliance requirements with greater reliability than other assessment options. HITRUST CSF v11 enables the entire HITRUST assessment portfolio to leverage threat-adaptive controls that are appropriate for each level of assurance.
Let’s take a closer look at the exciting enhancements to HITRUST CSF v11 and how your organization can prepare for and adjust to the new changes.
Overall, HITRUST CSF v11 includes improved control mappings and precision of specifications, which reduces the level of effort for a HITRUST certification. For example, the level of effort to achieve and maintain HITRUST Implemented 1-year (i1) Certification can be reduced up to 45% over the course of two years.
Here’s a few more important updates in the HITRUST CSF v11 that your organization can expect.
HITRUST CSF v11 added a new assessment to its services, and past assessments are now subsets or supersets of each other. This allows organizations to reuse work from lower-level HITRUST assessments to progressively achieve higher assurance by sharing common control requirements in inheritance.
These updates include:
With v11, HITRUST CSF has two new authoritative sources: NIST SP 800-53, Rev 5 and the Health in Industry Cybersecurity Practices Standards.
HITRUST developed AI-based standards development capabilities to aid their assurance experts in mapping and maintaining authoritative sources.
HITRUST CSF v11 is the first version with this enhanced function, which will reduce mapping and maintenance efforts by 70% while improving the quality of mappings to authoritative sources and allowing more authoritative sources in future releases.
Past versions of HITRUST CSF will transition to an end-of-life process. For r2 Assessments, HITRUST CSF v9.1 and v9.4 will transition to an end-of-life, and i1 Assessments will transition from 9.6.2 to v11.
Take a look at a few important dates regarding both the r2 and i1 Assessments’ end-of-life cycles.
r2 Assessments
i1 Assessments
Organizations that previously downloaded past versions of HITRUST CSF will be notified of the new version. In the meantime, BARR’s HITRUST team of experts is here to help. We’re excited about these new enhancements to HITRUST CSF v11 and how they can improve the process toward healthcare compliance, and we’re available to answer any of your questions as we go through these changes.
You can also join us for our weekly HITRUST Open House every Wednesday at 11 a.m. CST to learn more.
If you’re interested in more information about HITRUST CSF v11 or HITRUST certification, reach out to BARR for a free consultation.