Skip to content
Cyber Horizon
All frameworks

// Healthcare

HITRUST CSF Healthcare Security Framework Compliance Software

Comprehensive certifiable framework for healthcare organisations.

Framework at a glance

Short name

HITRUST

Version

Category

Healthcare

Controls

64

What HITRUST covers

64 controls across 50 domains — every one tracked, owned and evidenced in Cyber Horizon.

Identity & Access

3 controls
  • 01.a Access Control Policy
  • 01.b User Registration
  • 01.d User Password Management

Privileged Access

1 controls
  • 01.c Privilege Management

Access Review

1 controls
  • 01.e Review of Access Rights

Passwords

1 controls
  • 01.f Password Use

Physical

2 controls
  • 01.g Unattended Equipment
  • 01.h Clear Desk / Clear Screen

Governance

2 controls
  • 02.a Roles and Responsibilities
  • 05.a Management Commitment

Screening

1 controls
  • 02.b Screening

Policy

2 controls
  • 02.c Terms of Employment
  • 03.c Acceptable Use

People

1 controls
  • 02.e Information Security Awareness

Inventory

1 controls
  • 03.a Asset Inventory

Ownership

1 controls
  • 03.b Ownership of Assets

Classification

1 controls
  • 04.a Information Classification

Coordination

1 controls
  • 06.a Information Security Coordination

Privacy

2 controls
  • 06.d Data Protection and Privacy
  • 13.d Privacy and Personal Data

Asset Management

1 controls
  • 07.a Inventory of Assets

Access

1 controls
  • 07.b Physical Entry Controls

Physical Security

1 controls
  • 08.a Physical Security Perimeter

Procedures

1 controls
  • 09.a Documented Operating Procedures

Network Security

2 controls
  • 09.ab Network Monitoring
  • 09.ae Segregation of Networks

Change Management

2 controls
  • 09.b Change Management
  • 15.c Managing Supplier Changes

Segregation

1 controls
  • 09.c Separation of Development

Monitoring

2 controls
  • 09.d Monitoring System Use
  • 15.b Monitoring Supplier Services

Malware

1 controls
  • 09.e Protection Against Malicious Code

Backup

1 controls
  • 09.f Information Backup

Software Control

1 controls
  • 09.g Control of Software

Development

1 controls
  • 10.a Security Requirements

Data Validation

1 controls
  • 10.b Input Data Validation

Key Management

1 controls
  • 10.c Cryptographic Key Management

Patching

1 controls
  • 10.d Vulnerability Management

Operations

1 controls
  • 11.a Incident Management Procedures

Reporting

1 controls
  • 11.b Reporting Security Weaknesses

Response

2 controls
  • 11.c Responsibilities and Procedures
  • 16.c Response to Security Incidents

Improvement

2 controls
  • 11.d Learning from Information Security Incidents
  • 16.d Post-incident review and improvement

Forensics

2 controls
  • 11.e Collection of Evidence
  • 16.e Collection and Preservation of Evidence

Planning

3 controls
  • 12.a BCM Planning
  • 16.a Responsibilities and Procedures for Incidents
  • 17.c Developing and Implementing Continuity

Business Continuity

1 controls
  • 12.b Business Continuity and Risk Assessment

Compliance

1 controls
  • 13.a Identification of Applicable Legislation

Legal

1 controls
  • 13.b Intellectual Property Rights

Records

1 controls
  • 13.c Protection of Records

Audit

1 controls
  • 13.e Independent Security Review

Policy Compliance

1 controls
  • 13.f Compliance with Security Policies

Technical Compliance

1 controls
  • 13.g Technical Compliance Checking

Logging

1 controls
  • 14.a Audit Logging

Services

1 controls
  • 14.b Security of Network Services

Segmentation

1 controls
  • 14.c Segregation in Networks

Third-Party

1 controls
  • 15.a Supplier Relationships

Triage

1 controls
  • 16.b Assessment and Decision on Security Events

Integration

1 controls
  • 17.a Information Security in BCM

BIA

1 controls
  • 17.b Business Impact Analysis

Testing

1 controls
  • 17.d Testing BCM Plans

How Cyber Horizon automates HITRUST

Every HITRUST control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is HITRUST CSF Healthcare Security Framework?

Comprehensive certifiable framework for healthcare organisations.

How many controls does HITRUST CSF Healthcare Security Framework have?

HITRUST CSF Healthcare Security Framework has 64 controls in Cyber Horizon's catalogue, organised across 50 domains.

How does Cyber Horizon help with HITRUST CSF Healthcare Security Framework?

Cyber Horizon maps HITRUST CSF Healthcare Security Framework into a shared control library alongside every other framework you run, so evidence collected once counts towards HITRUST and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See HITRUST mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of HITRUST in Cyber Horizon.