HITRUST readiness starts before evidence is uploaded or an assessment is opened in MyCSF. The early decisions an organization makes about business drivers, assessment type, scope, control ownership, and timing can shape the effort that follows. This article builds upon our webinar, “Getting HITRUST Ready: Scope, Timeline, & Key Considerations,” with five questions teams can use to pressure-test readiness before validation begins.
1. What Is Driving the HITRUST Request?
Start with gaining and understanding the reason the organization is pursuing HITRUST: a customer contract, procurement requirement, market expectation, internal risk objective, or planned expansion may point to different levels of assurance. The reason should be specific enough to guide the next steps.
If a contract or request for proposal refers to HITRUST without naming an assessment, clarify what the requesting party will accept. That conversation can reduce the risk of pursuing a level of assurance that doesn’t satisfy the business need or creates effort beyond what stakeholders expect.
2. Which Assessment Matches the Risk?
HITRUST offers three validated assessment options: the e1, i1, and r2. The e1 uses a set of 43 to 44 foundational controls and may fit lower-risk environments or organizations beginning their HITRUST journeys. The i1 uses 182 curated controls and provides a moderate level of assurance. The r2 is tailored to the organization’s scope and risk factors and is designed for higher-risk environments or more demanding assurance needs.
The decision should account for the sensitivity of the data, the criticality of the systems, contractual expectations, the organization’s control maturity, and how the report will be used. Cost and timing matter, but selecting the shortest path without first confirming the required assurance may create rework.
It’s helpful to note that these paths can build upon one another. Your organization can move between tiers year to year as contracts and risks shift. So, work done for an e1 can be a stepping stone toward an i1 or an r2. The e1 and i1 certifications are valid for one year. Qualifying organizations may use the i1 Rapid Recertification option to maintain certification for an additional year with a reduced set of requirements, provided the scope remains consistent and the control environment has not materially changed or degraded. The r2 certification spans two years, with an interim touchpoint in year two before revalidation in year three.
3. Can the Scope Be Explained Clearly?
A workable scope connects the business service being assessed to the systems, data, people, processes, facilities, and third parties that support it.
Scope can shape the cost, timeline, and strength of an organization’s certification. Strong scoping traces the systems in play, the data flows in and out, the people and process owners who can speak to those platforms, the facilities involved, and the third-party dependencies customers and regulators care about.
Two mistakes, scoping too broadly and scoping too narrowly, can stall organizations. Scoping too broadly can lead to scope creep and unnecessary work by including unnecessary systems, even an Excel file that holds no source data. Scoping too narrowly can miss interfacing systems that materially touch a core platform. Find the honest middle by mapping how data enters, how it moves, and how it leaves. Include process owners early. Ask where the data actually lives. That discipline can keep an organization’s boundaries defensible.
Also, a data-flow discussion can be a useful starting point. Identify where sensitive data enters the environment, where it’s stored or processed, how it moves between systems, and where it leaves. Then identify the owners who can explain each part of that flow and provide supporting evidence.
4. Who Owns the Controls & Evidence?
HITRUST readiness is a cross-functional effort. Security and compliance teams may coordinate the assessment, but evidence often sits within information technology, human resources, legal, vendor management, facilities, and business process owners. Assigning ownership by control area is prudent and can reveal gaps even before fieldwork begins.
Evidence also must show that a control is operating, not only that a policy exists, and the type of evidence dictates the time period which must be covered by the evidence. HITRUST requires incubation periods before validation begins: 60 days for policy and procedure updates and 90 days for newly built controls, as those new controls must sit before they can be tested. Scoring is quantitative and is weighed against certification thresholds by domain, so aim for the right maturity rather than perfection. Sampling is similar to that found within SOC 2, ISO, and PCI engagements, drawing from populations across daily-to-annual controls.
Organizations that use cloud or other service providers also should identify which controls may be supported through inheritance and which remain their responsibility. For example, an organization running on AWS or Azure can inherit controls from those providers’ HITRUST work, pulling tested results into the engagement much like an inclusive approach. Inheritance can reduce duplicated effort, but it doesn’t remove the need to understand shared responsibilities or maintain evidence for the organization’s portion of the control.
5. Is the Timeline Based on Readiness or a Target Date?
A desired certification date is useful, but it shouldn’t be the only anchor for the project plan. The timeline needs to reflect scope definition, control implementation, evidence availability, internal review, assessor fieldwork, and time to address gaps. If remediation is still underway, the required operating period for updated controls may affect when testing can begin.
A Readiness Assessment can help teams test assumptions before the validated assessment. It can also identify unclear scope boundaries, unsupported control statements, evidence gaps, or ownership issues while there is still time to respond.
It’s also helpful to choose an experienced assessor and bring them in from the start. Late-stage scrambling is optional. Early planning can make a difference.
HITRUST Readiness: Key Items to Address
As you embark on your HITRUST readiness effort, consider the following steps before validation begins to help reduce rework:
- Confirm the business or contractual reason for pursuing HITRUST and what level of assurance is expected.
- Map the in-scope service, data flows, systems, shared services, third parties, and process owners.
- Assign a named owner for each control area, and identify where supporting evidence is maintained.
- Review newly implemented or remediated controls against applicable operating-period requirements.
- Discuss scope, assessment selection, inheritance, and timing with a qualified HITRUST assessor prior to validation.
How Forvis Mazars Can Help
Forvis Mazars has a dedicated SOC & HITRUST practice serving HITRUST clients across the United States. Our professionals assist organizations with assessment selection, scoping, readiness, control evaluation, validated assessments, and more. If you have questions about preparing for HITRUST, connect with us today.