HITRUST, alongside the HIPAA program you already run.

84 CSF controls across 14 domains — and the HIPAA, NIST, ISO 27001 and PCI DSS work it harmonises, in the same platform.

Why payers keep asking for it

HIPAA tells you what to achieve but not how, and it has no certificate. That gap is why health plans, payers and large providers increasingly ask their vendors for HITRUST CSF certification instead — it is assessable, it is issued by a third party, and it means something specific.

The CSF harmonises requirements from HIPAA, NIST, ISO 27001, PCI DSS and others into a single assessable standard. In practice that means the work you have already done for those frameworks is most of the work for this one — provided you can show it.

OpenGRC includes the HITRUST CSF bundle on every plan, alongside HIPAA Security, Privacy and Breach Notification, ISO 27001, PCI DSS and NIST CSF.

Built for the assessment

The overlap works in your favour.

Do the harmonised work once

Do the harmonised work once

The CSF exists because HIPAA, NIST, ISO and PCI overlap heavily. OpenGRC aggregates control coverage across every framework you import, so a control satisfying ISO 27001 and HITRUST is evidenced once rather than assessed twice.

Evidence at control level

Evidence at control level

HITRUST assessment is evidence-driven and specific. Each control carries its implementation, maturity, test procedures and attached evidence, so a requirement and its proof sit together rather than in a shared drive.

A portal for your assessor

A portal for your assessor

External assessors get an MFA-protected panel with time-bounded, revocable access, IP allow-listing, immutable versioned submissions and workpaper bundles — plus a record of everything opened.

The 14 CSF control domains

DomainControls
00 Information security management program1
01 Access control23
02 Human resources security9
03 Risk management3
04 Security policy2
05 Organization of information security8
06 Compliance6
07 Asset management5
08 Physical and environmental security4
09 Communications and operations management6
10 Information systems acquisition, development and maintenance5
11 Information security incident management5
12 Business continuity management4
13 Privacy practices3

Controls are also classified by type — 63 preventive, 11 detective, 5 recovery, 4 corrective and 1 deterrent — which maps directly onto how OpenGRC records control type and effectiveness.

HITRUST questions

Does OpenGRC certify us against HITRUST?

No. Certification is issued by the HITRUST Alliance following an assessment performed by an authorised external assessor. OpenGRC is where the program lives: the controls, implementations, evidence, gaps and the assessor's access.

We already run HIPAA in OpenGRC. Does that carry over?

Is HITRUST an add-on?

Why would we do HITRUST rather than just HIPAA?