HITRUST CSF is a certifiable framework, common in healthcare, that harmonizes requirements from HIPAA, NIST, ISO 27001, PCI-DSS, and other standards into a single assessment.
Rather than running separate audits for each underlying framework, an organization is assessed once against HITRUST's mapped control set. HITRUST offers tiered assessments — e1 (essentials, 1-year validity), i1 (implemented, leading practices), and r2 (risk-based, the most rigorous, 2-year validity) — letting organizations choose assurance depth appropriate to their risk.
Assessment tiers
HITRUST Alliance
HITRUST CSF v11