HITRUST CSF v11 — Gap Analysis
HITRUST Common Security Framework — Healthcare-focused, Risk-basedAbout HITRUST CSF v11
The HITRUST CSF is a certifiable framework integrating dozens of authoritative sources (HIPAA, HITECH, ISO 27001/27002, NIST CSF, NIST SP 800-53, PCI DSS, GDPR, COBIT and many more) into a unified, scalable, risk-based set of controls. Although born in healthcare, HITRUST is used across regulated industries. HITRUST certification has 3 tiers (e1, i1, r2) of progressively rigorous assurance levels.
Issuing Body
HITRUST Alliance (Health Information Trust Alliance)
Edition
2023
Coverage
14 control categories aligned with HIPAA, HITECH, ISO 27001/2, NIST CSF, NIST SP 800-53, PCI DSS, GDPR and 40+ other authoritative sources.
Typical Users
US healthcare organisations, business associates, payers, providers, health-tech companies and their service providers.
How to use this tool
1. Work through each clause. For each requirement, choose Compliant, Partial, Non-compliant, or leave as Not assessed.
2. Add notes against any requirement to record evidence, gaps, or corrective actions.
3. Click Save progress — data is stored locally in your browser, never uploaded.
4. Export the report as TXT, CSV, JSON or print to PDF for your audit file.
Note: This tool is a guided self-assessment. It does not replace a third-party audit and the authoritative version of the standard must be obtained from the issuing body.
ISO Xpert — Get in touch
UK-based consultancy specialising in management-system gap analysis, training and certification preparation across ISO, API, Halal, GFSI, ESG, cybersecurity and industry-specific standards.
Phone / WhatsApp
Office
71-75 Shelton Street, Covent Garden, London WC2H 9JQ, UK