← ALL FRAMEWORKS

HITRUST CSF

Information Security

Issued by HITRUST Alliance

HITRUST CSF is a certifiable security and privacy framework that consolidates requirements from more than 70 external standards and regulations — including HIPAA, NIST, ISO 27001, and PCI DSS — into one set of controls, assessed at three tiers: e1 (foundational, one-year), i1 (moderate assurance), and r2 (comprehensive, two-year certification). It's used mainly by US healthcare organizations, health plans, and their vendors handling protected health information, typically as a contractual requirement imposed by payers and large health systems. The current release is CSF v11.8.0 (May 2026).

Get notified the moment HITRUST CSF actually changes — reviewed by a human before it ever reaches you.

Get started free

Most recent update

No published updates yet

This framework hasn't had a confirmed update yet — check back after the next monitoring run.