Navigating HITRUST V11 Requirements: What Has Changed For Healthcare Orgs

Recently, we have observed that Healthcare organizations are facing various kinds of cybersecurity issues while protecting their patient data. They also have to secure their systems while keeping the clinical systems, cloud infrastructure, API, and various digital applications operational. The implementation of HITRUST v11 will redefine cybersecurity assurance in healthcare organizations.

Organizations can secure sensitive information through a shift to a more threat-adaptive approach, nested assessment levels, and better alignment with existing cybersecurity risks. New versions of the v11 framework keep adding new requirements and authoritative source mappings.

This HITRUST migration guide is designed to explain the most important changes, differences between HITRUST e1, i1, and r2 requirements, the migration process, and typical mistakes of migration to v11.

Key Takeaways

v11 includes e1, i1, and r2 evaluations.
E1 is the baseline security evaluation, and I1 adds another 182 controls for threats.
r2 takes i1 a step further by requiring risk-based controls.
MFA, Cloud computing, APIs, Ransomware, and Encryption need better controls.
Begin the migration process with a gap assessment, not a MyCSF assessment.
Gathering evidence continuously will help avoid any assessment gaps and delays.
Source: https://qualysec.com/hitrus ...
返回 下一个