/hitrust-expert
HITRUST CSF expert for healthcare security. Implementation guidance, assessment workflow, and mapping to HIPAA/NIST/ISO/PCI frameworks. References control IDs only — not a replacement for a licensed CSF copy.
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill hitrust-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/hitrust-expert
Context preview
The summary Claude sees to decide when to auto-load this skill.
HITRUST CSF expert for healthcare security. Implementation guidance, assessment workflow, and mapping to HIPAA/NIST/ISO/PCI frameworks. References control IDs only — not a replacement for a licensed CSF copy.
SKILL.md
hitrust-expert.SKILL.mdname: hitrust-expert
description: HITRUST CSF expert for healthcare security. Implementation guidance, assessment workflow, and mapping to HIPAA/NIST/ISO/PCI frameworks. References control IDs only — not a replacement for a licensed CSF copy.
allowed-tools: Read, Glob, Grep, Write
HITRUST Expert
Deep expertise in HITRUST Common Security Framework (CSF) for healthcare and business-associate organizations.
> **Important — normative text.** HITRUST CSF is proprietary and subscription-required. This skill provides **implementation guidance**, **assessment workflow**, and **evidence patterns** — phrased in the author's own words. All normative control statements, scoring rubrics, and MyCSF-specific requirement language must be read from your licensed CSF. When a command in this plugin quotes a control description, it is a paraphrased summary; consult the CSF for authoritative text.
Expertise Areas
HITRUST Alliance Overview
**Mission**: Create security and privacy programs that can be certified **Founded**: 2007 **Purpose**: Address security/privacy challenges in healthcare industry **Key Value**: Single framework harmonizing 40+ regulations and standards
HITRUST CSF (Common Security Framework)
**Current Version**: CSF v11 (as of 2024) **Control Objectives**: 156 across 19 domains **Customization**: MyCSF tailored assessment **Certifications**: i1, r2, e1
Assessment Types
| Type | Full Name | Duration | Assessor | Validity | Use Case | |------|-----------|----------|----------|----------|----------| | **i1** | Implemented, 1-year | 3-6 months | Self or validated | 1 year | Initial cert, vendors | | **r2** | Reportable, 2-year | 6-12 months | External required | 2 years | Providers, high assurance | | **e1** | e1 Assessment | 3-6 months | Can be self | Bridge | Upgrade i1 to r2 |
**i1 Assessment**:
- Demonstrates control implementation
- Self-assessment or externally validated
- Less rigorous than r2
- Lower cost ($30K-$80K validated)
- Good for: Vendors, BAs, initial certification
**r2 Assessment**:
- Full external validation required
- Independent HITRUST assessor
- Comprehensive testing
- Higher cost ($100K-$300K+)
- Required for: Healthcare providers, payers, high-risk BAs
**e1 Assessment**:
- Bridges i1 to r2 in year 2
- Validates changes since i1
- Extends certification to 2-year cycle
- Cost-effective staged approach
MyCSF Customization
HITRUST CSF requirements tailored based on:
**Organization Factors**:
1. **Type**: Provider, payer, clearinghouse, BA, vendor, other 2. **Size**:
- Small: <$20M revenue or <20 employees
- Medium: Mid-sized
- Large: >$1B revenue or >1000 employees
3. **System Type**: SaaS, on-premise, hybrid, mobile 4. **Regulatory Factors**: HIPAA, state laws, international regs
**Customization Result**:
- **Not Applicable**: Requirements excluded
- **Implementation Levels**:
- Baseline: Minimum requirements
- Middle: Moderate requirements
- Enhanced: Advanced requirements
19 Control Domains
1. **Information Security Management Program (01)** - 12 controls
- Security governance
- Risk management program
- Compliance management
2. **Access Control (02)** - 14 controls
- User access management
- Privileged access
- Access reviews
- Remote access
3. **Human Resources Security (03)** - 8 controls
- Background screening
- Terms of employment
- Termination procedures
4. **Risk Management (04)** - 5 controls
- Risk assessment methodology
- Risk treatment
- Acceptance criteria
5. **Security Policy (05)** - 3 controls
- Information security policy
- Review and updates
6. **Organization of Information Security (06)** - 8 controls
- Management commitment
- Security roles
- Contact with authorities
7. **Compliance (07)** - 6 controls
- Legal requirements
- Privacy obligations
- Intellectual property
8. **Asset Management (08)** - 7 controls
- Asset inventory
- Information classification
- Media handling
9. **Physical and Environmental Security (09)** - 11 controls
- Secure areas
- Physical entry controls
- Equipment security
- Disposal
10. **Communications and Operations Management (10)** - 23 controls
- Change management
- Capacity management
- Malware protection
- Backup
- Network security
11. **Information Systems Acquisition, Development and Maintenance (11)** - 15 controls
- Security requirements
- Secure development
- Cryptographic controls
12. **Information Security Incident Management (12)** - 6 controls
- Incident response plan
- Reporting procedures
- Collection of evidence
13. **Business Continuity Management (13)** - 5 controls
- BCM process
- Continuity planning
- Testing
14. **Network Protection (14)** - 7 controls
- Network architecture
- Segmentation
- Firewall management
15. **Password Management (15)** - 6 controls
- Password policies
- Storage and transmission
- Multi-factor authentication
16. **Education, Training and Awareness (16)** - 4 controls
- Security awareness
- Role-based training
17. **Third Party Assurance (17)** - 6 controls
- Business associate agreements
- Vendor risk management
- Cloud service provider oversight
18. **Mobile Device Security (18)** - 5 controls
- Mobile device policy
- BYOD management
- Mobile application security
19. **Incident Detection and Response (19)** - 5 controls
- Monitoring and detection
- Security information and event management (SIEM)
- Threat intelligence
Framework Harmonization
HITRUST CSF maps to 40+ frameworks including:
**Primary Frameworks**:
- **HIPAA** Security and Privacy Rules
- **NIST** 800-53, Cybersecurity Framework
- **ISO/IEC** 27001:2013, 27002
- **PCI DSS** v3.2.1
- **FedRAMP** Moderate Baseline
**Additional Frameworks**:
- AICPA Trust Services Criteria (SOC 2)
- COBIT 5
- GDPR
- FISMA
- FDA Medical De
Read more
name: hitrust-expert description: HITRUST CSF expert for healthcare security. Implementation guidance, assessment workflow, and mapping to HIPAA/NIST/ISO/PCI frameworks. References control IDs only — not a replacement for a licensed CSF copy. allowed-tools: Read, Glob, Grep, Write
HITRUST Expert
Deep expertise in HITRUST Common Security Framework (CSF) for healthcare and business-associate organizations.
> **Important — normative text.** HITRUST CSF is proprietary and subscription-required. This skill provides **implementation guidance**, **assessment workflow**, and **evidence patterns** — phrased in the author's own words. All normative control statements, scoring rubrics, and MyCSF-specific requirement language must be read from your licensed CSF. When a command in this plugin quotes a control description, it is a paraphrased summary; consult the CSF for authoritative text.
Expertise Areas
HITRUST Alliance Overview
**Mission**: Create security and privacy programs that can be certified **Founded**: 2007 **Purpose**: Address security/privacy challenges in healthcare industry **Key Value**: Single framework harmonizing 40+ regulations and standards
HITRUST CSF (Common Security Framework)
**Current Version**: CSF v11 (as of 2024) **Control Objectives**: 156 across 19 domains **Customization**: MyCSF tailored assessment **Certifications**: i1, r2, e1
Assessment Types
| Type | Full Name | Duration | Assessor | Validity | Use Case | |------|-----------|----------|----------|----------|----------| | **i1** | Implemented, 1-year | 3-6 months | Self or validated | 1 year | Initial cert, vendors | | **r2** | Reportable, 2-year | 6-12 months | External required | 2 years | Providers, high assurance | | **e1** | e1 Assessment | 3-6 months | Can be self | Bridge | Upgrade i1 to r2 |
**i1 Assessment**:
- Demonstrates control implementation
- Self-assessment or externally validated
- Less rigorous than r2
- Lower cost ($30K-$80K validated)
- Good for: Vendors, BAs, initial certification
**r2 Assessment**:
- Full external validation required
- Independent HITRUST assessor
- Comprehensive testing
- Higher cost ($100K-$300K+)
- Required for: Healthcare providers, payers, high-risk BAs
**e1 Assessment**:
- Bridges i1 to r2 in year 2
- Validates changes since i1
- Extends certification to 2-year cycle
- Cost-effective staged approach
MyCSF Customization
HITRUST CSF requirements tailored based on:
**Organization Factors**:
1. **Type**: Provider, payer, clearinghouse, BA, vendor, other 2. **Size**:
- Small: <$20M revenue or <20 employees
- Medium: Mid-sized
- Large: >$1B revenue or >1000 employees
3. **System Type**: SaaS, on-premise, hybrid, mobile 4. **Regulatory Factors**: HIPAA, state laws, international regs
**Customization Result**:
- **Not Applicable**: Requirements excluded
- **Implementation Levels**:
- Baseline: Minimum requirements
- Middle: Moderate requirements
- Enhanced: Advanced requirements
19 Control Domains
1. **Information Security Management Program (01)** - 12 controls
- Security governance
- Risk management program
- Compliance management
2. **Access Control (02)** - 14 controls
- User access management
- Privileged access
- Access reviews
- Remote access
3. **Human Resources Security (03)** - 8 controls
- Background screening
- Terms of employment
- Termination procedures
4. **Risk Management (04)** - 5 controls
- Risk assessment methodology
- Risk treatment
- Acceptance criteria
5. **Security Policy (05)** - 3 controls
- Information security policy
- Review and updates
6. **Organization of Information Security (06)** - 8 controls
- Management commitment
- Security roles
- Contact with authorities
7. **Compliance (07)** - 6 controls
- Legal requirements
- Privacy obligations
- Intellectual property
8. **Asset Management (08)** - 7 controls
- Asset inventory
- Information classification
- Media handling
9. **Physical and Environmental Security (09)** - 11 controls
- Secure areas
- Physical entry controls
- Equipment security
- Disposal
10. **Communications and Operations Management (10)** - 23 controls
- Change management
- Capacity management
- Malware protection
- Backup
- Network security
11. **Information Systems Acquisition, Development and Maintenance (11)** - 15 controls
- Security requirements
- Secure development
- Cryptographic controls
12. **Information Security Incident Management (12)** - 6 controls
- Incident response plan
- Reporting procedures
- Collection of evidence
13. **Business Continuity Management (13)** - 5 controls
- BCM process
- Continuity planning
- Testing
14. **Network Protection (14)** - 7 controls
- Network architecture
- Segmentation
- Firewall management
15. **Password Management (15)** - 6 controls
- Password policies
- Storage and transmission
- Multi-factor authentication
16. **Education, Training and Awareness (16)** - 4 controls
- Security awareness
- Role-based training
17. **Third Party Assurance (17)** - 6 controls
- Business associate agreements
- Vendor risk management
- Cloud service provider oversight
18. **Mobile Device Security (18)** - 5 controls
- Mobile device policy
- BYOD management
- Mobile application security
19. **Incident Detection and Response (19)** - 5 controls
- Monitoring and detection
- Security information and event management (SIEM)
- Threat intelligence
Framework Harmonization
HITRUST CSF maps to 40+ frameworks including:
**Primary Frameworks**:
- **HIPAA** Security and Privacy Rules
- **NIST** 800-53, Cybersecurity Framework
- **ISO/IEC** 27001:2013, 27002
- **PCI DSS** v3.2.1
- **FedRAMP** Moderate Baseline
**Additional Frameworks**:
- AICPA Trust Services Criteria (SOC 2)
- COBIT 5
- GDPR
- FISMA
- FDA Medical De
Showing the first part of this file.
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Other skills on trust-center.
- /academic-research-companion
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication. Use this skill whenever the user shares a research idea, asks to "flesh out" a topic, wants sources
Open skill - /aws-inspector-expert
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Open skill - /azure-inspector-expert
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Open skill - /crowdstrike-inspector-expert
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Open skill - /datadog-inspector-expert
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.
Open skill - /drata-inspector-expert
Interpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.
Open skill

