Top Qs
Timeline
Chat
Perspective

HITRUST

American company From Wikipedia, the free encyclopedia

Remove ads

HITRUST (formerly known as Health Information Trust Alliance) is an organization headquartered in Frisco, Texas, that provides information risk management and compliance assessments and certifications.[1][better source needed]

Quick Facts Company type, Industry ...
Remove ads

History

HITRUST was formed in 2007 in response to heightened concerns about healthcare data breaches, expanding federal and state compliance mandates, and the need for a standardized approach to information protection in healthcare.[2] Initially focused on HIPAA and other U.S. healthcare privacy and security laws, HITRUST later adapted its framework for broader use in different industries, including financial services and defense contracting.[3][4]

In response to emerging AI concerns, the organization developed AI-specific control requirements and certifications to address related risks in 2024.[5]

In December 2024, the organization announced a cyber insurance consortium in partnership with Lloyd’s of London.[6]

In 2025, the organization announced the general availability of its HITRUST Assessment XChange App for ServiceNow.[7]

Remove ads

HITRUST Framework

Summarize
Perspective

HITRUST's assessments are based on its cybersecurity framework, the HITRUST CSF (originally the HITRUST Common Security Framework), which integrates requirements from multiple regulations and standards.[3]

The HITRUST Framework incorporates control requirements from more than 60[8][better source needed] regulations and standards for assessing security and compliance.[9] It is divided into 19 control domains,[3] such as endpoint protection, access control, business continuity, and incident management.[2] The certification model built on the framework adjusts security requirements based on an organization’s size, risk profile, and regulatory obligations.[2]

According to the HITRUST’s 2025 Trust Report, certified environments reported an incident rate under 1%. However, independent validation of the finding is unclear.[10]

Critics argue that HITRUST certification can be expensive and time-consuming, especially for smaller entities with limited budgets and staffing.[2] Some also caution that while the framework covers many cybersecurity controls, it does not guarantee full compliance with every niche regulation (e.g., certain OSHA requirements and CMS’s conditions of Medicare and Medicaid participation).[3]

Remove ads

Board of Directors

HITRUST is led by a management team and governed by a Board of Directors made up of leaders from across a variety of industry. These leaders represent the governance of the organization, but other founders also comprise the leadership.[11][better source needed]

The Board Members are:

  • Daniel S. Nutkis - Chief Executive Officer, HITRUST
  • Robert Booker - Chief Strategy Officer, HITRUST
  • Pamela Arora - President and Chief Executive Officer, AAMI
  • Caroline Budde - Associate General Counsel, Digital & Data Assets, McKesson
  • Dr. Kevin Charest - Chief Information Security Officer, Accumulus Synergy
  • George DeCesare, JD - Senior Vice President, Chief Technology Risk Officer, Kaiser Permanente
  • Kimberly Gray, Esq - CIPP Chief Privacy Officer, Global, IQVIA
  • Omar Khawaja - Vice President, Security, and Field Chief Information Security Officer, Databricks
  • Stirling Martin - Senior Vice President, Epic and President, Epic Hosting
  • Roy R. Mellinger - Senior Vice President, Security, Privacy, IT Risk and Compliance and Global Chief Information Security Officer, Aimbridge Hospitality
  • Aman Raheja - Chief Information Security Officer, HP Enterprise

References

Loading related searches...

Wikiwand - on

Seamless Wikipedia browsing. On steroids.

Remove ads