Business Wire

HITRUST® to Address Market Gaps in Reliability and Challenges in the Exchange of Security and Privacy Assessments

6.10.2021 16:00:00 EEST | Business Wire | Press release

Share

HITRUST® announced today a major expansion of its assessment portfolio to raise the quality and efficiency of assurances across the spectrum of information assurance needs. HITRUST also is unveiling a new evolutionary approach to streamline the exchange and consumption of assessment results across the ecosystem of relying parties.

HITRUST CSF Certification is the most reliable information assurance report on the market and made possible by the transparency and consistency in the selection of controls, and in the scoring, and validation of controls by both qualified third-party assessors and the HITRUST Assurance and Quality teams. The assurance process is rigorous by design to ensure a high level of assurance in the results provided. However, there are many situations where a moderate or low level of assurance is warranted. Organizations are seeking a broader range of assessment options that require less effort and time to perform while still providing a commensurate level of reliability for moderate- to lower-risk scenarios.

To meet the market needs for varying levels of assurance with higher reliability, HITRUST is adding two new assessment offerings. Like the HITRUST CSF Validated Assessment, these new offerings will aid in understanding control effectiveness as well as cyber preparedness and resilience. With the two new additions, the HITRUST assessment portfolio will include:

  • The Basic Current State (bC) Assessment is a “good hygiene” assessment and offers higher reliability than self-assessments and questionnaires by utilizing the HITRUST Assurance Intelligence Engine™ (AI Engine) to identify errors, omissions, and deceit.
  • The Implemented One-Year (i1) Validated Assessment is a “best practices” assessment and recommended for situations that present moderate risk or where a baseline risk assessment is needed. The i1 is designed to provide higher levels of transparency, integrity, and reliability over existing moderate assurance reports, with comparable levels of time, effort, and cost. HITRUST Authorized External Assessors will validate i1 assessments.
  • The industry standard HITRUST CSF Validated Assessment is a risk-based and tailorable assessment, which continues to provide the highest level of assurance for situations with greater risk exposure due to data volumes, regulatory compliance, or other risk factors. The HITRUST CSF Validated Assessment will be renamed the Risk-based, Two-Year (r2) Validated Assessment.

Until now, most low to moderate risk assessment mechanisms were either self-attested or validated against unsuitable or inconsistent control selection and limited and subjective assurance programs; which makes it difficult for relying parties to understand the control requirements and depth, breadth, and consistency of the assurance process, limiting the usefulness and reliability of the results.

“Often, organizations utilize mid-level assurance reports such as a SOC 2 report because they take less time and effort while being less costly. Unfortunately, these mid-level assurance reports lack the consistency and reliability of more comprehensive assessments like HITRUST,” said John Houston, Vice President of Information Security and Privacy at UPMC. “The HITRUST i1 Assessment fills a gap in the market for a medium assurance assessment that delivers a higher level of reliability and consistency while having a similar effort and cost to a SOC 2 report. And it can help the organization move towards full HITRUST CSF Certification—which organizations like UPMC view as the gold standard.”

While reliability is crucial for assurance, the accessibility, usability, and consumption of the results are just as important if organizations are to manage supply chain risk given evolving cyber threats. The current method of obtaining and consuming assessment results by the relying party often results in delays, inefficiencies, and misinterpretations as it is based on the exchange of PDF files that are reviewed to determine the scope, scoring, and corrective action plans before key information is often manually entered into a third-party risk management (TPRM) system.

To meet the expanding demand for effective information risk management across the supply chain, the HITRUST Results Distribution System (RDS) will enable assessed entities to deliver their HITRUST Assessment results through a secure, centralized reporting hub to relying parties, eliminating the need for exchanging PDFs and the manual review and entry into third-party systems that subsequently occurs. Recipients will be able to customize dashboards to view the results that interest them most, including scope, aggregate, or specific control scores. In addition, integration with GRC/VRM platforms will be available via API.

“For third-party risk management systems to achieve their full potential in helping organizations manage their vendor risk, assessment results need to be electronically shared and consumed,” said Jeremy Fisher, Vice President of Product at Archer. “HITRUST’s Results Distribution System is a big step in making that possible and will be a strong complement to our focus on vendor interaction through Archer Engage.”

The expansion of the HITRUST Assessment Portfolio and the addition of the RDS further extend HITRUST’s position as an innovator and leader in information risk management, compliance, and assurance. HITRUST continues to drive higher assurances and greater efficiencies into the assurance ecosystem. “HITRUST is building upon our market leadership in providing Rely-Able assurances by introducing moderate and low-level information assurance products,” said Bimal Sheth, Executive Vice President, Standards Development and Assurance Operations, HITRUST. “No other assessment or certification organization is able to meet the expanding global market need for information assessments and electronic results distribution.”

The industry standard r2 assessment (HITRUST CSF Validated Assessment) is currently available while the bC and i1 assessments will be offered to the market later this year. Any i1 or r2 assessment submitted with a reservation is backed by a service-level guarantee to deliver the assessment report within 45 days.

To Learn More:

Register for the Webinar

Expanded Assessment Portfolio

Results Distribution System

About HITRUST®

Since it was founded in 2007, HITRUST has championed programs that safeguard sensitive information and manage information risk for organizations across all industries and throughout the third-party supply chain. In collaboration with privacy, information security, and risk management leaders from the public and private sectors, HITRUST develops, maintains, and provides broad access to its widely adopted common risk and compliance management frameworks as well as related assessment and assurance methodologies. For more information, visit www.hitrustalliance.net.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

Contact information

Media Contact: Marc Fitzpatrick, e: marc.fitzpatrick@hitrustalliance.net, t: 469.269.1230

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Miro Takes Aim at the Gap Between AI Potential and Organizational Reality19.5.2026 17:00:00 EEST | Press release

Miro®, the AI Innovation Workspace for teams, has announced new innovations across its AI platform, reinforcing its position as the collaboration layer where people, context, and agents from every function converge to solve hard problems, make better decisions, and build the right thing faster. Major upgrades to Miro’s agentic AI tools — including Sidekicks and Flows — alongside new Connectors, help customers close the gap between individual AI productivity and organization-wide transformation. AI is reshaping the pace of work, but often teams are not realising the benefits. In many organizations, a gap has emerged between what individuals can now do and what companies can harness. The reason? Collaboration has fractured. Teams have moved from one mode of working to three — human to human, human to agent, and agent to agent — but these are running in silos, invisible to each other. Within those silos, AI amplifies misalignment rather than correcting it, and the gaps only show up when t

Andersen Global Strengthens Global Mobility Capabilities with Collaborating Firm Graebel19.5.2026 16:30:00 EEST | Press release

Andersen Global continues to enhance its multi-dimensional platform through a Collaboration Agreement with Graebel, a global leader in workforce mobility and managed services headquartered in the U.S. with global capabilities spanning the Americas, Europe, and Asia. Founded in 1950, Graebel works with many of the world’s most recognized organizations to simplify the movement and management of talent. The company helps organizations support employees throughout the workforce journey—from internships and onboarding to domestic and international mobility and career transitions—through services that span strategic planning, departure and destination support, on-assignment assistance, repatriation, and mobility program design. Through strategic advisory and intelligent technology, Graebel enables organizations to make more informed decisions and align talent mobility with broader business and workforce strategies through data-driven insights and deep mobility and governance expertise. “Our

Wolters Kluwer Medi-Span Selected to Provide Personalized Medication Decision Support at The Christie NHS Foundation Trust19.5.2026 16:30:00 EEST | Press release

Wolters Kluwer Health has implemented its industry-leading medication decision support (MDS) solution, Medi-Span®, at the world-renowned specialist oncology center, The Christie NHS Foundation Trust. “The Christie is recognized globally for its excellence and commitment to delivering exceptional patient care,” says Israel Armstrong, Vice President for Medi-Span International at Wolters Kluwer Health. “We’re proud that our first Medi-Span implementation in the NHS should be with such a prestigious institution. We look forward to more collaborations that help streamline processes further and help clinical teams make the most highly informed decisions.” The Christie is a leading expert in cancer care, research and education and is the largest single-site cancer center in Europe. The Christie treats more than 60,000 patients a year and is the first facility in the UK to be accredited as a comprehensive cancer center. Based in Manchester, they serve a population of 3.2 million people across

Nine in 10 Firms Fear In-House Systems Can’t Keep Pace with Executive Pay Demands19.5.2026 16:00:00 EEST | Press release

Managing executive compensation is a growing challenge for financial services firms, with nearly nine in 10 (89%) saying their in-house technology can’t keep pace with demand. New research by CSC, the leading provider of business administration and compliance solutions, shows that rising complexity, regulatory pressure, and expanding global participation place increasing strain on internal systems and teams.1 CSC surveyed 300 senior HR, rewards, and compensation leaders across Europe, Asia Pacific, and North America working in private markets, asset management, insurance, and investment banking. The report, The Future of Reward in Financial Services: Executive Compensation in 2026, explores their responses and examines how firms adapt to increasing complexity in long-term incentive (LTI) schemes. The research revealed that more than four in five (86%) respondents find the administration of compensation schemes is now complex, reflecting the rapid evolution and expansion of LTI structur

Tacton Appoints Manufacturing Technology Leader Mike DiTullio to Board of Directors19.5.2026 16:00:00 EEST | Press release

Tacton, a global leader in Configure, Price, Quote (CPQ) solutions for manufacturers of complex products, today announced the appointment of Mike DiTullio to its Board of Directors. DiTullio is an enterprise software executive with more than three decades of experience working with complex manufacturers. He joins at a pivotal moment in the company’s evolution as Tacton expands beyond CPQ to deliver the Buyer-Centric Smart Factory, a connected approach that unites buyer engagement, engineering, and order fulfillment into a single intelligent system. DiTullio spent 26 years at PTC, most recently as President and Chief Operating Officer, wherehe worked closely with leading manufacturers to transform how they design, sell, and deliver complex products. In that role, he led global commercial operations across seven business units representing more than $1.5 billion in annual revenue and guided the company through its transition to a subscription-based, digital-first business model. His deep

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye