• Skip to primary navigation
  • Skip to main content
  • Skip to footer
ControlCase No Tag LOGO md

ControlCase

IT Certifications, Continuous Compliance and Cybersecurity Services Provider

  • Company
    • About Us
    • Careers
    • Locations
    • Team
  • Industries
    • Business Process Outsourcing
    • Cloud Service Providers
    • Retail
    • Telecom | Entertainment
    • Managed Service Providers
  • Certifications
    • PCI DSS Certification
    • CSA STAR Certification
    • GDPR Assessment
    • HIPAA Assessment
    • HITRUST® Certification
    • ISO 27001 Certification
    • FedRAMP 3PAO Services and NIST 800-53
    • CMMC Certification
    • MARS-E Assessment
    • PCI SSF
    • P2PE Certification
    • SOC2 Report
  • Solutions
    • Continuous Compliance Solution
    • One Audit
    • Card Data Discovery Software
    • Data Security Rating
  • Testing
    • Application Reviews
    • Application Security Training
    • Code Reviews
    • Card Data Discovery
    • External Vulnerability Scans
    • Firewall Security Reviews
    • Internal Vulnerability Scans
    • Log Monitoring
    • Penetration Testing
  • Resources
    • Events
    • News
    • Webinars
    • Courses
    • Blog
    • Tools
    • Become a Partner
  • Contact Us
  • English

HITRUST® Certification

Request DatasheetRequest QuoteRequest Demo
You are here: Home / Certifications / HITRUST® Certification

HITRUST® Assessments and HITRUST CSF®

Data security is becoming an increasingly important concern for most organizations. The HITRUST CSF® was developed to address the multitude of security, privacy, and regulatory concerns. By including federal and state regulations, standards and frameworks, and incorporating a risk-based approach, the HITRUST CSF® helps organizations address these challenges through a comprehensive and flexible framework of prescriptive and scalable security controls.

HITRUST® Authorized External Assessor.

ControlCase is an HITRUST® Authorized External Assessor, which can be verified at  this link
ControlCase provides a cost-effective solution to help organizations assess themselves against the HITRUST CSF.

The HITRUST CSF® Assurance Program delivers simplified compliance assessment and reporting for HIPAA, HITECH, state, and a broad range of business-associated requirements.

HITRUST CSF ®

The foundation of all HITRUST® programs and services is the HITRUST Framework, which supports assessments that lead to certification that provides organizations with a comprehensive, flexible, and efficient approach to regulatory compliance and risk management.

Developed in collaboration with healthcare and information security professionals, the HITRUST CSF® rationalizes healthcare-relevant regulations and standards into a single overarching security framework. Because the HITRUST CSF® is both risk- and compliance-based, organizations can tailor the security control baselines based on a variety of factors, including organization type, size, systems, and regulatory requirements.

By continuing to improve and update the CSF, the HITRUST CSF® has become the most widely-adopted security framework in the U.S. healthcare industry. This commitment and expertise demonstrated by HITRUST ensures that healthcare organizations leveraging the framework are prepared when new regulations and security risks are introduced.

For more on understanding and leveraging the CSF, click here

HITRUST Solutions

HITRUST® offers a tiered suite of cybersecurity and compliance certifications, designed to support organizations at every stage of maturity. Built on the trusted HITRUST CSF®, each solution helps demonstrate assurance, manage third-party risk, and align with regulatory requirements.

  • e1 – Essentials 1-Year Certification
    Baseline cybersecurity validation for low-risk organizations or early-stage vendors. Fast, streamlined, and valid for 1 year.
  • i1 – Implemented 1-Year Certification
    Mid-level certification focused on active cyber threats. Ideal for companies needing credible assurance without full customization.
  • r2 – Risk-Based 2-Year Certification
    HITRUST’s most rigorous certification. Fully scalable and tailored to complex regulatory and risk environments. Valid for 2 years with a 12-month review.

HITRUST® AI Assessments

Focused on governance, privacy, and security for AI systems. Supports regulatory compliance and ethical deployment of AI technologies.

HITRUST® AI Risk Management Framework
  • Focuses on holistic AI Risk Management
  • Harmonizes ISO/IEC 23894:2023 and NIST AI RMF
  • Targeted towards AI providers and users
  • Resulting in an insights report; not a certification
  • 51 relevant AI Risk Management controls
HITRUST® AI Security Assessment
  • Focuses only on AI Security
  • Harmonizes controls from NIST, ISO and OWASP
  • Targeted towards AI providers only
  • Add-on certification to the e1, i1 or r2 assessments
  • Up to 44 AI security requirements

ControlCase Methodology

No matter which ControlCase IT security solutions you choose, our healthcare IT security specialists will apply proven processes and common controls frameworks to identify potential vulnerabilities. At the completion of any IT assessment, you will receive a detailed report combined with a comprehensive consultation to ensure your key staff members understand:

  • Your current compliance posture.
  • Recommended steps for improving compliance.
  • Additional considerations that may require attention in the future.

Our expertise in HITRUST® compliance extends beyond healthcare providers to include service providers (business associates) that fall under newly implemented regulations as part of current healthcare reform.

At ControlCase, our proven HITRUST® methodology adapts to your certification type while maintaining a consistent, efficient approach, helping you put the right foot forward from day one and confidently achieve certification.

  • Facebook
  • LinkedIn
  • Twitter
  • YouTube

Footer

Connect

Corporate Headquarters
3975 FAIR RIDGE DR STE T25S-D
FAIRFAX, VA 22033

Send us a message

Call Us

Search

About Us

ControlCase is a United States based company, headquartered in Fairfax, Virginia with locations in North America, Europe, Latin America, Asia/Pacific, Australia and the Middle East to serve our clients globally.

Quick Links

  • Company
  • Careers
  • Locations
  • Covid-19 Notice

Certifications, Assessments and Reports

  • PCI DSS Certification
  • CSA STAR Certification
  • GDPR Assessment
  • HIPAA Assessment
  • HITRUST® Certification
  • ISO 27001 Certification
  • FedRAMP and 3PAO Services
  • MARS-E Assessment
  • PCI SSF
  • P2PE Certification
  • SOC2 Report

© ControlCase LLC 2025 | Privacy Policy | Impartiality Statement | Legal Notices

  • English
Manage your privacy

We use cookies to enhance your experience and show relevant ads. Consent allows us to process data like browsing behavior. Without consent, some features may not work. If you log in, all cookies are accepted by default. Learn more in our Privacy Policy & Cookies Policy.

Strictly Necessary Cookies Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Functional Cookies
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics Cookies
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing Cookies
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
Manage options
{title} {title} {title}