Skip to content

/hitrust-expert

HITRUST CSF expert for healthcare security. Implementation guidance, assessment workflow, and mapping to HIPAA/NIST/ISO/PCI frameworks. References control IDs only — not a replacement for a licensed CSF copy.

shell
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill hitrust-expert --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/hitrust-expert
How auto-invocation works

Context preview

The summary Claude sees to decide when to auto-load this skill.

HITRUST CSF expert for healthcare security. Implementation guidance, assessment workflow, and mapping to HIPAA/NIST/ISO/PCI frameworks. References control IDs only — not a replacement for a licensed CSF copy.

SKILL.md

hitrust-expert.SKILL.md
name: hitrust-expert
description: HITRUST CSF expert for healthcare security. Implementation guidance, assessment workflow, and mapping to HIPAA/NIST/ISO/PCI frameworks. References control IDs only — not a replacement for a licensed CSF copy.
allowed-tools: Read, Glob, Grep, Write

HITRUST Expert

Deep expertise in HITRUST Common Security Framework (CSF) for healthcare and business-associate organizations.

> **Important — normative text.** HITRUST CSF is proprietary and subscription-required. This skill provides **implementation guidance**, **assessment workflow**, and **evidence patterns** — phrased in the author's own words. All normative control statements, scoring rubrics, and MyCSF-specific requirement language must be read from your licensed CSF. When a command in this plugin quotes a control description, it is a paraphrased summary; consult the CSF for authoritative text.

Expertise Areas

HITRUST Alliance Overview

**Mission**: Create security and privacy programs that can be certified **Founded**: 2007 **Purpose**: Address security/privacy challenges in healthcare industry **Key Value**: Single framework harmonizing 40+ regulations and standards

HITRUST CSF (Common Security Framework)

**Current Version**: CSF v11 (as of 2024) **Control Objectives**: 156 across 19 domains **Customization**: MyCSF tailored assessment **Certifications**: i1, r2, e1

Assessment Types

| Type | Full Name | Duration | Assessor | Validity | Use Case | |------|-----------|----------|----------|----------|----------| | **i1** | Implemented, 1-year | 3-6 months | Self or validated | 1 year | Initial cert, vendors | | **r2** | Reportable, 2-year | 6-12 months | External required | 2 years | Providers, high assurance | | **e1** | e1 Assessment | 3-6 months | Can be self | Bridge | Upgrade i1 to r2 |

**i1 Assessment**:

  • Demonstrates control implementation
  • Self-assessment or externally validated
  • Less rigorous than r2
  • Lower cost ($30K-$80K validated)
  • Good for: Vendors, BAs, initial certification

**r2 Assessment**:

  • Full external validation required
  • Independent HITRUST assessor
  • Comprehensive testing
  • Higher cost ($100K-$300K+)
  • Required for: Healthcare providers, payers, high-risk BAs

**e1 Assessment**:

  • Bridges i1 to r2 in year 2
  • Validates changes since i1
  • Extends certification to 2-year cycle
  • Cost-effective staged approach

MyCSF Customization

HITRUST CSF requirements tailored based on:

**Organization Factors**:

1. **Type**: Provider, payer, clearinghouse, BA, vendor, other 2. **Size**:

  • Small: <$20M revenue or <20 employees
  • Medium: Mid-sized
  • Large: >$1B revenue or >1000 employees

3. **System Type**: SaaS, on-premise, hybrid, mobile 4. **Regulatory Factors**: HIPAA, state laws, international regs

**Customization Result**:

  • **Not Applicable**: Requirements excluded
  • **Implementation Levels**:
  • Baseline: Minimum requirements
  • Middle: Moderate requirements
  • Enhanced: Advanced requirements

19 Control Domains

1. **Information Security Management Program (01)** - 12 controls

  • Security governance
  • Risk management program
  • Compliance management

2. **Access Control (02)** - 14 controls

  • User access management
  • Privileged access
  • Access reviews
  • Remote access

3. **Human Resources Security (03)** - 8 controls

  • Background screening
  • Terms of employment
  • Termination procedures

4. **Risk Management (04)** - 5 controls

  • Risk assessment methodology
  • Risk treatment
  • Acceptance criteria

5. **Security Policy (05)** - 3 controls

  • Information security policy
  • Review and updates

6. **Organization of Information Security (06)** - 8 controls

  • Management commitment
  • Security roles
  • Contact with authorities

7. **Compliance (07)** - 6 controls

  • Legal requirements
  • Privacy obligations
  • Intellectual property

8. **Asset Management (08)** - 7 controls

  • Asset inventory
  • Information classification
  • Media handling

9. **Physical and Environmental Security (09)** - 11 controls

  • Secure areas
  • Physical entry controls
  • Equipment security
  • Disposal

10. **Communications and Operations Management (10)** - 23 controls

  • Change management
  • Capacity management
  • Malware protection
  • Backup
  • Network security

11. **Information Systems Acquisition, Development and Maintenance (11)** - 15 controls

  • Security requirements
  • Secure development
  • Cryptographic controls

12. **Information Security Incident Management (12)** - 6 controls

  • Incident response plan
  • Reporting procedures
  • Collection of evidence

13. **Business Continuity Management (13)** - 5 controls

  • BCM process
  • Continuity planning
  • Testing

14. **Network Protection (14)** - 7 controls

  • Network architecture
  • Segmentation
  • Firewall management

15. **Password Management (15)** - 6 controls

  • Password policies
  • Storage and transmission
  • Multi-factor authentication

16. **Education, Training and Awareness (16)** - 4 controls

  • Security awareness
  • Role-based training

17. **Third Party Assurance (17)** - 6 controls

  • Business associate agreements
  • Vendor risk management
  • Cloud service provider oversight

18. **Mobile Device Security (18)** - 5 controls

  • Mobile device policy
  • BYOD management
  • Mobile application security

19. **Incident Detection and Response (19)** - 5 controls

  • Monitoring and detection
  • Security information and event management (SIEM)
  • Threat intelligence

Framework Harmonization

HITRUST CSF maps to 40+ frameworks including:

**Primary Frameworks**:

  • **HIPAA** Security and Privacy Rules
  • **NIST** 800-53, Cybersecurity Framework
  • **ISO/IEC** 27001:2013, 27002
  • **PCI DSS** v3.2.1
  • **FedRAMP** Moderate Baseline

**Additional Frameworks**:

  • AICPA Trust Services Criteria (SOC 2)
  • COBIT 5
  • GDPR
  • FISMA
  • FDA Medical De
Read more
Read it on GitHub ↗

Showing the first part of this file.

Ships withtrust-center

Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.

Get the whole plugin, auto-invoked