// Healthcare
HITRUST CSF Healthcare Security Framework Compliance Software
Comprehensive certifiable framework for healthcare organisations.
Framework at a glance
Short name
HITRUST
Version
—
Category
Healthcare
Controls
64
What HITRUST covers
64 controls across 50 domains — every one tracked, owned and evidenced in Cyber Horizon.
Identity & Access
3 controls- 01.a Access Control Policy
- 01.b User Registration
- 01.d User Password Management
Privileged Access
1 controls- 01.c Privilege Management
Access Review
1 controls- 01.e Review of Access Rights
Passwords
1 controls- 01.f Password Use
Physical
2 controls- 01.g Unattended Equipment
- 01.h Clear Desk / Clear Screen
Governance
2 controls- 02.a Roles and Responsibilities
- 05.a Management Commitment
Screening
1 controls- 02.b Screening
Policy
2 controls- 02.c Terms of Employment
- 03.c Acceptable Use
People
1 controls- 02.e Information Security Awareness
Inventory
1 controls- 03.a Asset Inventory
Ownership
1 controls- 03.b Ownership of Assets
Classification
1 controls- 04.a Information Classification
Coordination
1 controls- 06.a Information Security Coordination
Privacy
2 controls- 06.d Data Protection and Privacy
- 13.d Privacy and Personal Data
Asset Management
1 controls- 07.a Inventory of Assets
Access
1 controls- 07.b Physical Entry Controls
Physical Security
1 controls- 08.a Physical Security Perimeter
Procedures
1 controls- 09.a Documented Operating Procedures
Network Security
2 controls- 09.ab Network Monitoring
- 09.ae Segregation of Networks
Change Management
2 controls- 09.b Change Management
- 15.c Managing Supplier Changes
Segregation
1 controls- 09.c Separation of Development
Monitoring
2 controls- 09.d Monitoring System Use
- 15.b Monitoring Supplier Services
Malware
1 controls- 09.e Protection Against Malicious Code
Backup
1 controls- 09.f Information Backup
Software Control
1 controls- 09.g Control of Software
Development
1 controls- 10.a Security Requirements
Data Validation
1 controls- 10.b Input Data Validation
Key Management
1 controls- 10.c Cryptographic Key Management
Patching
1 controls- 10.d Vulnerability Management
Operations
1 controls- 11.a Incident Management Procedures
Reporting
1 controls- 11.b Reporting Security Weaknesses
Response
2 controls- 11.c Responsibilities and Procedures
- 16.c Response to Security Incidents
Improvement
2 controls- 11.d Learning from Information Security Incidents
- 16.d Post-incident review and improvement
Forensics
2 controls- 11.e Collection of Evidence
- 16.e Collection and Preservation of Evidence
Planning
3 controls- 12.a BCM Planning
- 16.a Responsibilities and Procedures for Incidents
- 17.c Developing and Implementing Continuity
Business Continuity
1 controls- 12.b Business Continuity and Risk Assessment
Compliance
1 controls- 13.a Identification of Applicable Legislation
Legal
1 controls- 13.b Intellectual Property Rights
Records
1 controls- 13.c Protection of Records
Audit
1 controls- 13.e Independent Security Review
Policy Compliance
1 controls- 13.f Compliance with Security Policies
Technical Compliance
1 controls- 13.g Technical Compliance Checking
Logging
1 controls- 14.a Audit Logging
Services
1 controls- 14.b Security of Network Services
Segmentation
1 controls- 14.c Segregation in Networks
Third-Party
1 controls- 15.a Supplier Relationships
Triage
1 controls- 16.b Assessment and Decision on Security Events
Integration
1 controls- 17.a Information Security in BCM
BIA
1 controls- 17.b Business Impact Analysis
Testing
1 controls- 17.d Testing BCM Plans
How Cyber Horizon automates HITRUST
Every HITRUST control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is HITRUST CSF Healthcare Security Framework?
Comprehensive certifiable framework for healthcare organisations.
How many controls does HITRUST CSF Healthcare Security Framework have?
HITRUST CSF Healthcare Security Framework has 64 controls in Cyber Horizon's catalogue, organised across 50 domains.
How does Cyber Horizon help with HITRUST CSF Healthcare Security Framework?
Cyber Horizon maps HITRUST CSF Healthcare Security Framework into a shared control library alongside every other framework you run, so evidence collected once counts towards HITRUST and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
More Healthcare frameworks
See HITRUST mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of HITRUST in Cyber Horizon.