Cherry Bekaert: Risk & Cybersecurity · Cherry Bekaert

HITRUST CSF Framework: Understanding the Basics

·27 min·5 clips
The episode opens with a straightforward question: what is HITRUST, and why do clients keep asking for it? Keith explains that HITRUST began as an information protection standards organization focused on concerns around PHI, or protected health information. The discussion stays grounded in business reality, because the pressure here usually comes from customers and other third parties rather than abstract policy goals. Brian and Keith keep coming back to the same point: certification has to be sized to the actual requirement. That means tracing the demand back to its source and figuring out what level of assurance is really being requested. From there, the episode walks through the three main assessment paths. E1 is the basic option, built around foundational cybersecurity controls and a fixed set of 44 controls. I1 sits in the middle and covers a more moderate level of assurance with 182 controls. R2 is the most comprehensive path and gets into broader risk management and tailoring. The episode makes clear that this is not just compliance theater. The choice can affect whether a company keeps a client, wins a deal, or makes procurement less painful. It also touches on insurance concerns, including the possibility of better cyber insurance terms or lower cost. The tone stays measured throughout, with questions doing most of the work of moving the conversation along. The speakers keep returning to the practical consequences of certification instead of treating HITRUST as a badge for its own sake. That makes the episode useful for teams that need to explain HITRUST internally before they can act on it. It also gives a clean entry point for companies hearing the term for the first time and trying to understand why it now has commercial weight. The episode treats certification as both a security measure and a business decision, and that mix is what makes it land.

As heard by us

A clear HITRUST primer that connects certification choices to business pressure and assurance levels.

HITRUST reads as a practical guide to a certification process organizations may need to understand, especially when client demands or insurance concerns are in play.

Read the full review in PlayNext →

Why you'd press play

Need a plain-English guide to HITRUST certification paths?

Read the full recommendation in PlayNext →
Listen to the show on