Attestation, assessment and label schemes
HITRUST CSF:v11
A prescriptive control framework that harmonises HIPAA, NIST and ISO requirements with scored maturity. The assessor validates evidence; HITRUST performs quality assurance and issues the result.
What you receive
Validated assessment; certification issued by HITRUST
Performed by an Authorised External Assessor organisation. The certification decision and the certificate itself come from HITRUST, not from the assessor.
This scheme does not produce a certificate. If a body has offered you one for HITRUST CSF, that alone tells you what their audit work is worth.
Who needs it
Healthcare payers, providers and their vendors, particularly where a US health system demands HITRUST specifically.
Prerequisites
A scoped assessment tier — e1, i1 or r2 — selected against risk factors, not preference.
How this engagement is delivered
Programme managed by Securo Cert LLC. Audit and certification decision by the appointed partner body.
Securo Cert document not accreditedThe partner body is named in the proposal before any work begins, and printed on the resulting document alongside the delivery mode.
Frequent questions
What do we actually receive?
Validated assessment; certification issued by HITRUST. Performed by an Authorised External Assessor organisation. The certification decision and the certificate itself come from HITRUST, not from the assessor.
How long is it valid?
Two-year validity for e1 and r2 with an interim assessment; i1 is annual.
What has to be in place first?
A scoped assessment tier — e1, i1 or r2 — selected against risk factors, not preference.