• Skip to primary navigation
  • Skip to main content
  • Skip to footer
ControlCase No Tag LOGO md

ControlCase

IT Certifications, Continuous Compliance and Cybersecurity Services Provider

  • Company
    • About Us
    • Careers
    • Locations
    • Team
  • Industries
    • Business Process Outsourcing
    • Cloud Service Providers
    • Retail
    • Telecom | Entertainment
    • Managed Service Providers
  • Certifications
    • PCI DSS Certification
    • CSA STAR Certification
    • GDPR Assessment
    • HIPAA Assessment
    • HITRUST Certification
    • ISO 27001 Certification
    • FedRAMP 3PAO Services and NIST 800-53
    • CMMC Certification
    • MARS-E Assessment
    • PCI SSF
    • P2PE Certification
    • SOC2 Report
  • Solutions
    • Continuous Compliance Solution
    • One Audit
    • Card Data Discovery Software
    • Data Security Rating
  • Testing
    • Application Reviews
    • Application Security Training
    • Code Reviews
    • Card Data Discovery
    • External Vulnerability Scans
    • Firewall Security Reviews
    • Internal Vulnerability Scans
    • Log Monitoring
    • Penetration Testing
  • Resources
    • Events
    • News
    • Webinars
    • Courses
    • Blog
    • Tools
    • Become a Partner
  • Contact Us
  • English

ControlCase Validates IWCO Direct against HITRUST CSF™

You are here: Home / News / ControlCase Validates IWCO Direct against HITRUST CSF™

The HITRUST CSF™ Certified Status indicates an organization has met key healthcare regulations and requirements for protecting and securing sensitive healthcare data.

ControlCase, a leading provider of Compliance as a Service (CaaS), Certifications, and IT Governance, Risk and Compliance (GRC) software announced it has validated IWCO Direct, a leading provider of data-driven direct marketing solutions to the HITRUST CSF™ using ControlCase’s “One Audit” service. ControlCase’s assessment for HITRUST CSF™ Certification included Mail-Gard®, a division of IWCO Direct that provides business continuity and disaster recovery services. The certification demonstrates all supporting systems meet key regulations and requirements for protecting and securing sensitive personal healthcare information (PHI).

ControlCase “One Audit” is an enhanced Integrated Compliance and Risk Control Solution for organizations subject to multiple regulations; including ISO, SOC, PCI DSS, NIST 800-53, HIPAA and HITRUST™. It is a blend of enterprise software solutions, hosted solutions, and managed services that streamline the creation, mapping and updating of internal and external controls, thus empowering IT, Security, and Compliance professionals to collect evidence once and map it across multiple regulations.

IWCO Direct met or exceeded established maturity levels in the 19 domains measured in order to achieve HITRUST CSF™ Certification. Upon completion of the assessment, ControlCase submitted the results to HITRUST™, who in turn issued a Certified Assessment Report. This achievement further validates IWCO Direct’s data security practices with the HITRUST CSF™ Certification joining the company’s extensive list of data security certifications, including ISO 27001:2013 and PCI DSS v3.2

Safeguarding personal information demands a comprehensive approach to data security
– said Jim Andersen, CEO of IWCO Direct

The HITRUST CSF™ Certification helps IWCO Direct stay at the forefront of data security and assures our clients that protecting sensitive information is one of our highest priorities.

The One Audit managed solution provides access to the skills, technology and expertise necessary to achieve and maintain compliance with multiple regulations.
– said Kishor Vaswani, CEO of ControlCase.

It features a flexible platform for managing all aspects of IT – GRC in any size organization and not only helps organizations simplify multiple regulatory mandates but also reduces audit preparation time and compliance costs.

About ControlCase

ControlCase is a global provider of Compliance as a Service (CaaS), Enterprise Software and Services. Our offerings enable clients to effectively manage their IT Governance, Risk Management and Compliance Management (IT GRCM or GRC) efforts.
Headquartered in the United States, with locations in North America, Europe, Asia Pacific and the Middle East, ControlCase focuses on providing and developing services, software products, hardware appliances and managed solutions that focus on compliance regulations and standards; including PCI DSS, SOC1, SOC2, SSAE16, PIPEDA, ISO 27001/2, FERC/NERC, Sarbanes Oxley (SOX), GLBA, HIPAA/HITRUST™, CoBIT, and BITS FISAP SIG/AUP.

For more information, please visit the company website at www.controlcase.com


  • Facebook
  • LinkedIn
  • Twitter
  • YouTube

Footer

Connect

Corporate Headquarters
3975 FAIR RIDGE DR STE T25S-D
FAIRFAX, VA 22033

Send us a message

Call Us

Search

About Us

ControlCase is a United States based company, headquartered in Fairfax, Virginia with locations in North America, Europe, Latin America, Asia/Pacific, Australia and the Middle East to serve our clients globally.

Quick Links

  • Company
  • Careers
  • Locations
  • Covid-19 Notice

Certifications, Assessments and Reports

  • PCI DSS Certification
  • CSA STAR Certification
  • GDPR Assessment
  • HIPAA Assessment
  • HITRUST Certification
  • ISO 27001 Certification
  • FedRAMP and 3PAO Services
  • MARS-E Assessment
  • PCI SSF
  • P2PE Certification
  • SOC2 Report

© ControlCase LLC 2025 | Privacy Policy | Impartiality Statement | Legal Notices

  • English
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}