Services
Services
SOC & Attestations
SOC & Attestations
Payment Card Assessments
Payment Card Assessments
ISO Certifications
ISO Certifications
Privacy Assessments
Privacy Assessments
Federal Assessments
Federal Assessments
Healthcare Assessments
Healthcare Assessments
Penetration Testing
Penetration Testing
Cybersecurity Assessments
Cybersecurity Assessments
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
ESG & Sustainability
ESG & Sustainability
AI Services
AI Services
Industry Solutions
Industry Solutions
Cloud Computing & Data Centers
Cloud Computing & Data Centers
Financial Services & Fintech
Financial Services & Fintech
Healthcare
Healthcare
Payment Card Processing
Payment Card Processing
US Government
US Government
Higher Education & Research Laboratories
Higher Education & Research Laboratories
About Us
About Us
Leadership Team
Leadership Team
Careers
Careers
Corporate Social Responsibility
Corporate Social Responsibility
Strategic Partnerships
Strategic Partnerships

HITRUST CSF Certification

Meet the challenges of today's healthcare industry with a defined set of requirements.

Contact a Specialist Build Your Compliance Roadmap

HITRUST Feature Left-1

Why HITRUST CSF?

The HITRUST framework (referred to as the “CSF”) provides organizations with a defined set of requirements to assess their applications and systems. This approach, originally created for healthcare organizations and their business associates, helps organizations across a variety of industries and their subservice organizations with the adoption of prescriptive requirements that span a variety of accepted frameworks and regulations to meet the challenges of the industry and securing and managing data.

HITRUST was developed in collaboration with the healthcare and information security industry. The HITRUST CSF streamlines the myriad of generally accepted frameworks, regulations, and standards into one holistic framework. As HITRUST is both risk and compliance-oriented, organizations have the option to customize the framework by organization type, size, systems, and regulatory requirements (referred to as an “r2 assessment”) or can utilize a standardized set of requirements (referred to as an “i1 assessment”).

HITRUST Feature Left-1

Our Process

We begin each project with your end goals in mind and to provide preparation for future key project activities. Effective communication and timely coordination of project planning activities are central to our methodology with our clients.

Image

Planning

After the agreement is executed, the first phase of the engagement is planning. This is to ensure that Schellman and the Client are fully aware of the “what, who, when, why, and how” prior to the beginning of initial testing.

Proper planning is imperative to the success of a project. Schellman has standard processes to cover the important pieces of the engagement.

Image

Understanding and Kickoff

The kickoff is considered the start of the engagement, with a presentation on HITRUST and the project milestones. If needed, Schellman will schedule a call at the beginning of, or just prior to, the kickoff to finalize any outstanding items. Schellman will be available to the Client with any questions.

By including communication prior to starting, Schellman ensures that no last-minute changes to the project or team have occurred, and the Client has the plan prior to the testing and any on-site visits.

Image

Testing and Gathering

Gathering and testing is the core of the compliance engagement. Due to the planning and understanding processes, this phase will be an accumulation of gathering the evidence needed for the objectives discussed.

Schellman has a no surprise policy and has continuous contact with the stakeholders during the testing and gathering activities. The Client will have confidence the Schellman team has completed this phase timely and completely.

Image

Submission and Certification Process / Reporting

Upon conclusion of the gathering and testing phase, Schellman performs internal quality assurance reviews to confirms that the Client’s assessment, located in the HITRUST MyCSF portal, has been prepared for submission and that the testing performed corroborates the organization’s scores for each requirement.

Schellman continues to work with the Client to confirm that acceptable corrective action plans (CAPs) have been documented for any gaps requiring action. Schellman also works with the Client to address any questions from HITRUST during their QA evaluation process. While Schellman does not issue the report, involvement with the Client does not end until the final report has been posted by HITRUST.

Your HITRUST CSF Specialist,
Doug Kanney

Doug Kanney is a Principal at Schellman. Doug leads the HITRUST and HIPAA service lines and assists with methodology and service delivery across the SOC, PCI-DSS, and ISO service lines. Doug has more than 15 years of combined audit experience in public accounting. Doug has provided professional services for multiple Global 1000, Fortune 500, and regional companies during the course of his career.

Artboard 8-1

 

Your HITRUST CSF Specialist,
Doug Kanney

Doug Kanney is a Principal at Schellman. Doug leads the HITRUST and HIPAA service lines and assists with methodology and service delivery across the SOC, PCI-DSS, and ISO service lines. Doug has more than 15 years of combined audit experience in public accounting. Doug has provided professional services for multiple Global 1000, Fortune 500, and regional companies during the course of his career.
  • Fixed-Fee Using an outcome-based, fixed-fee pricing model based on our extensive experience
  • Scope Creep We see less than 5% of our clients that see amendments and are often the result of a scope expansion
  • Low Overhead Low overhead means a flexible financial structure

How much will your audit cost?

Whether it is an ISO 27001 certification, SOC 2 examination or a FedRAMP assessment, companies are often challenged by the need to address customer requirements while ensuring a return on compliance investment.

The most important factor in scoping a potential assessment is understanding what deliverable the recipient (i.e. your customer or partner) is expecting.

Once we have scoped your environment and needs, there are several factors that contribute to Schellman’s pricing:

  • Fixed-Fee Using an outcome-based, fixed-fee pricing model based on our extensive experience
  • Scope Creep We see less than 5% of our clients that see amendments and are often the result of a scope expansion
  • Low Overhead Low overhead means a flexible financial structure

Contact Us

Fill out this form to talk with one of our specialists. We'll be in touch soon to continue the conversation and help you find what you're looking for.

Contact Us

Fill out this form to talk with one of our specialists. We'll be in touch soon to continue the conversation and help you find what you're looking for.