HIPAA and HITRUST assessments, by certified assessors.
Protecting PHI isn't optional, and neither is proving it. SubRosa's certified HIPAA and HITRUST assessors evaluate your administrative, physical, and technical safeguards, run the risk assessment the law requires, and guide you to HITRUST CSF certification, with the templates, project management, and turnaround to get there without derailing your team.
HIPAA Security Rule · HITRUST CSF · Risk assessment · Certification support
What's the difference between HIPAA and HITRUST?
HIPAA is the U.S. law requiring healthcare organizations and their business associates to protect electronic protected health information (ePHI), including a mandatory Security Risk Assessment of administrative, physical, and technical safeguards. HITRUST CSF is a certifiable framework that maps HIPAA and other standards into prescriptive, testable controls, so you can prove your security with an independent certification. SubRosa's certified assessors handle both: the HIPAA risk assessment the law requires, and the HITRUST certification the market increasingly expects.
A complete healthcare compliance assessment.
We evaluate every critical area of your HIPAA and HITRUST program, end to end.
HIPAA Security Risk Assessment
The risk analysis the HIPAA Security Rule requires (45 CFR §164.308), administrative, physical, and technical safeguards, scored with a clear Plan of Action and Milestones (POA&M).
HITRUST CSF readiness & certification
Readiness assessments, mock assessments, and full support through HITRUST CSF certification, using optimized templates that cut your time to certification.
Control & safeguard assessment
Hands-on evaluation of the controls protecting your ePHI against HIPAA, HITRUST, and DHHS requirements, by assessors who do this every day.
Policies, training & ongoing support
Policy development, leadership and workforce training, and ongoing support, so compliance sticks long after the assessment is done.
Risk analysis, done to the standard.
HIPAA and HITRUST are different obligations with different work. This covers both, and the first step is establishing which one you actually need.
- 01
Scoping: HIPAA, HITRUST, or both
HIPAA is a legal obligation; HITRUST is a certifiable framework that many covered entities and their partners require contractually. They are related but not the same, and buying the wrong one is expensive. We establish which applies before quoting.
- 02
Asset and ePHI inventory
Where ePHI lives, how it moves, who touches it, and which vendors handle it. Almost every organisation we assess finds ePHI somewhere it did not expect — a mailbox, a reporting tool, a legacy share.
- 03
Security Risk Analysis
The Security Risk Analysis is explicitly required by the Security Rule and is the single most commonly cited deficiency in enforcement actions. We conduct it to the standard and document it so it stands as evidence, not as an internal note.
- 04
Safeguard assessment
Administrative, physical and technical safeguards are assessed individually with findings recorded against each. Where a safeguard is addressable rather than required, we document the reasoning for your choice, because that reasoning is itself what regulators ask to see.
- 05
Remediation and documentation
Gaps are prioritised by risk to ePHI, with policies, procedures and workforce training produced or revised to match. Documentation is the deliverable regulators actually inspect.
- 06
Certification support
For HITRUST we prepare you through readiness and support you through the certification process with your chosen external assessor.
Certified assessors, faster certification.
Certified HIPAA & HITRUST assessors
Certified assessors on staff guide you through the HIPAA risk assessment and the HITRUST certification process, so you're working with people who've done it many times over.
Optimized templates
Our optimized HIPAA and HITRUST policy and control templates cut preparation time and shorten your path to certification.
Full project management
We manage the assessment end to end, POA&M tracking, evidence, and timelines, so nothing falls through the cracks and your team keeps doing its job.
HIPAA and HITRUST controls, evidenced continuously.
Sable maps your safeguards to the HIPAA Security Rule and HITRUST CSF, tracks your POA&M, and collects evidence continuously, so your next assessment is an export, not a fire drill, and you stay compliant between certifications.
- 18 / 18Administrative safeguardsComplete
- 9 / 9Physical safeguardsComplete
- 11 / 13Technical safeguards2 POA&M
- 6 / 7Organizational requirements1 POA&M
Common questions
- What is the difference between HIPAA and HITRUST?
- HIPAA is the U.S. law that requires healthcare organizations and their business associates to protect electronic protected health information (ePHI), including a mandatory Security Risk Assessment. HITRUST CSF is a certifiable framework that maps HIPAA and other standards into prescriptive, testable controls, so you can prove your security with an independent certification. HIPAA is the obligation; HITRUST is a way to certify you meet it.
- Is a HIPAA risk assessment required?
- Yes. The HIPAA Security Rule explicitly requires covered entities and business associates to conduct an accurate and thorough risk analysis of the confidentiality, integrity, and availability of ePHI (45 CFR 164.308(a)(1)(ii)(A)). The absence of a genuine risk assessment is the single most common finding in HHS Office for Civil Rights enforcement actions.
- What is HITRUST certification?
- HITRUST CSF certification is an independent validation that your security controls meet the HITRUST Common Security Framework. It comes in tiers (e1, i1, and r2) of increasing rigor, and is widely requested by healthcare customers and partners as proof that a vendor protects PHI. SubRosa provides readiness assessments, mock assessments, and full support through certification.
- What is the difference between HIPAA compliance and HITRUST certification?
- HIPAA is a legal obligation with no certificate — no body certifies HIPAA compliance, whatever a vendor may imply. HITRUST is a certifiable framework that incorporates HIPAA requirements alongside others, and many covered entities require it contractually from their partners. They are related but distinct, and buying the wrong one is expensive.
- Do we really need a Security Risk Analysis?
- Yes. It is explicitly required by the HIPAA Security Rule, and its absence or inadequacy is the single most commonly cited deficiency in enforcement actions. A risk analysis that exists as an internal note rather than as documented evidence conducted to the standard will not help you.
- What is an addressable versus a required safeguard?
- Required safeguards must be implemented. Addressable ones must be implemented if reasonable and appropriate — and where they are not, you must document why and what you did instead. Addressable does not mean optional, and treating it that way is a frequent and consequential misreading.
- Can you take us through HITRUST certification?
- We prepare you through readiness and support you through certification with your chosen external assessor. As with SOC 2 and ISO 27001, we do not both remediate and certify — the independence is the point of the certificate.
Protect PHI, and prove it.
Let's scope your HIPAA risk assessment or HITRUST certification and map the fastest path to compliance.