HITRUST Central™

The HITRUST Common Security Framework (CSF) provides the foundation for HITRUST Central, a managed, online community that is designed to be a resource for healthcare information security professionals who wish to more efficiently and cost effectively enhance the security of their organizations, comply with standards and regulations and collaborate with industry peers.

Through HITRUST Central, organizations can:

  • Access the Common Security Framework (CSF)
  • Utilize the CSF Assurance Toolkit for performing self assessments or undergoing an assessment by a HITRUST CSF Assessor
  • License the Common Health Information Protection (CHIP) Questionnaire for performing a self assessment and becoming CSF Validated
  • Collaborate and share experiences with peers through blogs and forums
  • Download documentation and training materials
  • Request support
  • Learn about and submit alternate controls

It is only through registering for a HITRUST Central subscription that individuals can access the CSF. Individuals from qualified organizations* can register to receive a Standard subscription at no charge by visiting HITRUST Central. Access to the online, interactive version of the CSF, authoritative sources and the CSF Assessment Toolkit is available only through a paid subscription.

Subscription levels include:

Description
Standard
Professional
AvailableQualified OrganizationQualified OrganizationNon-qualified Organization
Common Security Framework (CSF)PDF downloadPDF download and Online accessPDF download and Online access
CSF Assurance Toolkit
CSF Validated Report
with Self Assessment
Limited distribution available for additional costUnlimited distributionUnlimited distribution
CSF Authoritative Sources & updates
   HIPAA - Including HITECH
   NIST
   ISO
   PCI
   FTC
   CMS
   COBIT
   New sources
Security Configuration Packs
Customer SupportSubmit up to 10 questions annuallySubmit up to 10 questions annually
CSF Products and Services Guide
Forums
Blogs
CSF Alternate ControlsForum onlyForum and onlineForum and online
Working Group ParticipationCSF commenting onlyCSF and other programsCSF and other programs
Integrated Third-Party ServicesDependant on serviceDependant on serviceDependant on service
Annual subscription feeNo charge$2,375$3,375


* A qualified organization is any organization employing a function or activity involving the use or disclosure of individually identifiable health information, provided that said organization does not provide technology or security products or services. Additionally, any federal, state, or local agency or department may qualify for a Standard subscription. HITRUST has the right to verify eligibility.

Read the HITRUST Central Data Sheet to learn more about the resources found in the community.

HITRUST Central

A Professional subscription provides access to the online, interactive CSF , the CSF Assurance Toolkit, and many other resources developed specifically for healthcare information security professionals.

CSF Assurance Program

Learn how the program simplifies compliance assessment and reporting through a common set of information security requirements.

News Events