Skip to content Skip to navigation

HITRUST Adds Privacy Controls to its Common Security Framework

January 7, 2015
by John DeGaspari
| Reprints
The addition of privacy controls will create a fully integrated information security and privacy framework, according to the group

The Health Information Trust Alliance (HITRUST) says it has added privacy controls to version seven of the HITRUST Common Security Framework (CSF) being released later this month. This addition creates a fully integrated privacy and security framework that meets the regulatory requirements of the U.S. healthcare industry, according to the group, which says organizations can now rely on a single framework to manage their information privacy and security risk and compliance.

Developed over the last 18 months by the HITRUST Privacy Working Group, the privacy controls are meant to provide better alignment between healthcare organizations’ security and privacy programs and allow for an integrated approach for protecting health information under Health Information Portability and Accountability Act (HIPAA). After conducting a review of various privacy frameworks, standards and regulations, the working group recommended the inclusion of specific privacy control categories, objectives, specifications and requirements by implementation level.

The HITRUST CSF has evolved into a more comprehensive and robust framework with which organizations can address their security and privacy programs and reduce the burden of compliance with all the applicable healthcare-related requirements, according to the group. Although the HITRUST CSF will incorporate both privacy and security controls, organizations will have the option to obtain certification for privacy, security or both in order to choose the approach and pace most suited to their operational and compliance objectives.

In addition, this release of the HITRUST CSF incorporates the Minimum Acceptable Risk Standards for Exchanges (MARS-E), additional guidance for cyber security, and enhancements to risk factors and assurance methodology. HITRUST is currently updating MyCSF to support the additional privacy controls and enable organizations to perform privacy control assessments, compliance reporting and related remediation tracking within the tool.



AHRQ Developing New Patient Safety Surveillance Tool

With the aim of improving patient safety monitoring, the Agency for Healthcare Research and Quality (AHRQ) within the U.S. Department of Health and Human Services (HHS) is currently developing and testing an improved patient safety surveillance system.

Gates Foundation Awards $210M to UW's Population Health Initiative

The Bill and Melinda Gates Foundation is awarding $210 million to Seattle-based University of Washington’s Population Health Initiative, with the funds going toward the construction of a new building to serve as the initiative’s hub.

AHA Offers Interoperability Standards Recommendations to ONC

The American Hospital Association (AHA) has offered feedback to the ONC on the agency’s draft Interoperability Standards Advisory (ISA) that it issued in August.

Survey: Healthcare Orgs Not Taking Mobile Security Seriously Enough

More than half (56 percent) of healthcare professionals believe their organization could be doing more to educate employees on HIPAA compliance and the rules around sharing protected health information.

Mount Sinai’s Research Arm Using Data Analytics to Address Health Inequities

The Arnhold Institute for Global Health at the Icahn School of Medicine at Mount Sinai is partnering with DigitalGlobe to create the Health Equity Atlas Initiative (ATLAS), a platform that standardizes and maps population data in order to generate insights that address health inequities.

FDA, Hospitals Work to Improve Data Collection about Medical Devices

The U.S. Food and Drug Administration is looking to improve the way it works with hospitals to modernize and streamline data collection, specifically safety data, about medical devices.