Undergo an Onsite or Remote Assessment

Partners in Texas Health Informa3on Protec3on Undergo an Onsite or Remote Assessment SECURETexas
Health Information Privacy & Security
Certification Program
©2015 HITRUST, Frisco, TX. All Rights Reserved. SECURETexas Assessment
•   Remote
–   Organizations under $5 Million in annual revenue, or with 150
employees or less, can complete their assessment and submit directly
to HITRUST, who will perform validation of the results
–   Assessment questionnaire is generated in HITRUST’s MyCSF tool – a
web-based tool built on a GRC platform for streamlined and userfriendly assessment management
•   Third Party
–   Organizations over $5 Million in annual revenue with more than 150
employees must engage a CSF Assessor organization to perform an
onsite assessment and validate the results
–   CSF Assessors are qualified resources trained and approved by
HITRUST to perform CSF- related services
2 © 2015 HITRUST, Frisco, TX. All Rights Reserved. SECURETexas Certification – Process
•   Covered Entity engages independent assessor organization*
•   CSF Assessor conducts assessment against the SECURETexas
certification requirements*
•   CSF assessor submits assessment results to HITRUST
•   HITRUST conducts QA review; resolves outstanding issues
•   HITRUST issues report with SecureTexas Certification
“Scorecard”
Assessor engaged* Assessment conducted* Results submiNed to HITRUST HITRUST conducts QA; prepares report *Small organizaDons may conduct a remote-­‐assessment 3 © 2015 HITRUST, Frisco, TX. All Rights Reserved. HITRUST determines scoring; if appropriate recommends THSA grants or denies cerDficaDon OrganizaDon Listed on Website