> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# HITRUST CSF

> Achieve HITRUST certification with a comprehensive, risk-based security framework.

HITRUST CSF (Common Security Framework) is a certifiable security framework that incorporates requirements from multiple standards and regulations including HIPAA, SOC 2, ISO 27001, NIST, and PCI DSS. It is widely used in healthcare but applicable to any industry.

## Who needs HITRUST?

<CardGroup cols={2}>
  <Card title="Healthcare organizations" icon="hospital">
    Hospitals, health plans, and healthcare technology companies that need to demonstrate comprehensive security compliance.
  </Card>

  <Card title="Business associates" icon="handshake">
    Vendors serving healthcare clients who need a certification that satisfies multiple compliance requirements simultaneously.
  </Card>
</CardGroup>

## HITRUST assessment types

| Assessment | Description                                              | Duration        |
| ---------- | -------------------------------------------------------- | --------------- |
| **e1**     | Essential, foundational assessment — 44 requirements     | Fastest path    |
| **i1**     | Industry-leading practices — 182 requirements            | Moderate effort |
| **r2**     | Risk-based, comprehensive — customized requirement count | Most thorough   |

## How DSALTA helps

* **HITRUST controls** mapped to CSF requirements
* **Cross-framework efficiency** — leverages existing SOC 2, ISO 27001, and HIPAA evidence
* **Risk-based scoping** aligned with HITRUST methodology
* **Evidence collection** automated through integrations

## Frequently asked questions

<AccordionGroup>
  <Accordion title="How does HITRUST differ from SOC 2?" icon="scale-balanced">
    HITRUST is a prescriptive framework with specific requirements, while SOC 2 is criteria-based and more flexible. HITRUST is preferred in healthcare; SOC 2 is more common in general SaaS.
  </Accordion>

  <Accordion title="Can I use SOC 2 evidence for HITRUST?" icon="diagram-project">
    Yes. HITRUST incorporates SOC 2 requirements. DSALTA maps overlapping controls, so existing SOC 2 evidence accelerates HITRUST certification.
  </Accordion>
</AccordionGroup>

## How DSALTA automates this

**315** of DSALTA's automated checks contribute evidence to this framework, drawn from **73** integrations. Browse them in the [Compliance Tests](/tests/overview) catalog. They are linked through the controls each check satisfies, so a single check usually contributes to several frameworks at once — the count is not a list of checks unique to this one.

## Related pages

* [HIPAA](/frameworks/hipaa/overview)
* [Active Frameworks](/guides/compliance/frameworks-active)
