The HITRUST CSF is a comprehensive security framework that incorporates information protection standards from multiple industries, including healthcare. For example, the framework incorporates control requirements to demonstrate compliance with HIPAA based on a review of the HHS Office for Civil Rights’ audit protocol.
The ninth version of the framework also includes objectives from the National Institute of Standards and Technology’s Cybersecurity Framework, which provides organizations with guidance related to cybersecurity risks.
“Organizations now have [an] effective and efficient approach for reporting an organization’s cybersecurity posture leveraging the NIST Cybersecurity categorization,” said Jason Newman, vice president and chief information security officer of Blue Cross and Blue Shield of Minnesota. “This is another benefit in leveraging a common and comprehensive framework in the HITRUST CSF.”
HITRUST plans to release the ninth version of its framework in August.
More articles on health IT:
CHIME to conduct ‘Health Care’s Most Wired’ survey
House 2018 budget proposal would ask HHS to consider patient matching
Parkland Center for Clinical Innovation taps former Epic lead for VP of data science
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.