HITRUST, alongside the HIPAA program you already run.
84 CSF controls across 14 domains — and the HIPAA, NIST, ISO 27001 and PCI DSS work it harmonises, in the same platform.
Why payers keep asking for it
HIPAA tells you what to achieve but not how, and it has no certificate. That gap is why health plans, payers and large providers increasingly ask their vendors for HITRUST CSF certification instead — it is assessable, it is issued by a third party, and it means something specific.
The CSF harmonises requirements from HIPAA, NIST, ISO 27001, PCI DSS and others into a single assessable standard. In practice that means the work you have already done for those frameworks is most of the work for this one — provided you can show it.
OpenGRC includes the HITRUST CSF bundle on every plan, alongside HIPAA Security, Privacy and Breach Notification, ISO 27001, PCI DSS and NIST CSF.
The overlap works in your favour.
Do the harmonised work once
The CSF exists because HIPAA, NIST, ISO and PCI overlap heavily. OpenGRC aggregates control coverage across every framework you import, so a control satisfying ISO 27001 and HITRUST is evidenced once rather than assessed twice.
Evidence at control level
HITRUST assessment is evidence-driven and specific. Each control carries its implementation, maturity, test procedures and attached evidence, so a requirement and its proof sit together rather than in a shared drive.
A portal for your assessor
External assessors get an MFA-protected panel with time-bounded, revocable access, IP allow-listing, immutable versioned submissions and workpaper bundles — plus a record of everything opened.
The 14 CSF control domains
| Domain | Controls |
|---|---|
| 00 Information security management program | 1 |
| 01 Access control | 23 |
| 02 Human resources security | 9 |
| 03 Risk management | 3 |
| 04 Security policy | 2 |
| 05 Organization of information security | 8 |
| 06 Compliance | 6 |
| 07 Asset management | 5 |
| 08 Physical and environmental security | 4 |
| 09 Communications and operations management | 6 |
| 10 Information systems acquisition, development and maintenance | 5 |
| 11 Information security incident management | 5 |
| 12 Business continuity management | 4 |
| 13 Privacy practices | 3 |
Controls are also classified by type — 63 preventive, 11 detective, 5 recovery, 4 corrective and 1 deterrent — which maps directly onto how OpenGRC records control type and effectiveness.
HITRUST questions
Does OpenGRC certify us against HITRUST?
No. Certification is issued by the HITRUST Alliance following an assessment performed by an authorised external assessor. OpenGRC is where the program lives: the controls, implementations, evidence, gaps and the assessor's access.
™