Skip to content

MYCSF is the Tool Utilized to Manage the HITRUST Certification Process

Oct 14, 2022

What subscription option should I buy?


  • Assess/Report option is limited to 90 days and deleted after the final report is issued, you will have to re-enter your information for any interim or subsequent reports.  Also, options like inheritance and offline assessment features are not available.  This is not recommended to use. 
  • A one-year subscription allows you to use the full capacity of the tool and allows you to retain your work effort after the report is finalized. 

Scoping section in the MYCSF?

The MYCSF tool has a section that is dedicated to determining the number of control requirements that are applicable to reaching HITRUST certification.  Many Health care payers will require you to select the HIPAA regulatory factor as a part of the scope.   We would highly recommend spending a lot of time to ensure this information is correct as HITRUST will be reviewing data flow and organization descriptions to ensure this data is correct.   Using EisnerAmper to scope the environment will help ensure this is conducted in an efficient manner.   

Object versus elements?

Each assessment object requires a separate report while multiple elements can be included in one report.  A company can have multiple objects and reports.  If a business has two distinct service lines then multiple objects can be possible and more efficient. 

Grouping of elements

If a company has 5 facilities that share centralized management and a similar control structure then they can be grouped together for testing and scoping purposes. 

What is version 9 of the HITRUST framework?

HITRUST each year realizes updates to the HITRUST framework, also legacy versions of HITRUST will reach an end of life and will no longer be accepted for submission to HITRUST.  As of June 2020, there are 4 active versions (9.1,9.2, 9.3, 9.4).  We recommend using the latest version as possible.  

What is version 10 of the HITRUST framework?

At this time, version 10 is still being finalized at HITRUST, once version 10 comes out, all version 9.x assessments will have 18 months to get submitted to HITRUST.

What's on Your Mind?

a woman in a suit

Kate M. Siegrist

Kate Siegrist is a Partner with over 20 years of combined experience advising CEOs, CISOs and CIOs. She helps her clients navigate highly regulated industries to ensure business opportunities are not missed due to compliance burden.

Start a conversation with Kate

Receive the latest business insights, analysis, and perspectives from EisnerAmper professionals.