1. What is HITRUST CSF certification?
The HITRUST Common Security Framework (CSF) is a comprehensive, certifiable framework purpose-built for healthcare. It harmonizes the controls required by HIPAA, NIST 800-66, ISO 27001, PCI DSS, and several other authoritative sources into a single assessable framework, and adds healthcare-specific controls (PHI handling, business-associate management, breach notification) that are rigorous beyond any individual source.
HITRUST certification is performed by an authorized external assessor and validated by HITRUST itself, making it stronger than a self-attested compliance posture and substantially deeper than SOC 2 alone. It is the certification most U.S. health systems require of vendors handling PHI at scale.
2. Our certification
Medonix maintains active HITRUST CSF certification across the platform: the customer-facing dashboard, AI Suite, EHR / PMS modules where deployed, integrations layer, and underlying production infrastructure. Re-certification follows the standard HITRUST cadence with annual assessment cycles.
3. Control areas covered
- Information protection program governance and risk management.
- Access control, authentication, and identity lifecycle management.
- Asset management, configuration management, and vulnerability management.
- Cryptography: encryption in transit, at rest, and key management.
- Physical and environmental security (cloud-provider-attested).
- Operations security, incident response, and business continuity.
- Communications security and network controls.
- Supplier relationships and third-party risk management.
- Compliance: internal controls, audit, and regulatory mapping.
4. How to request our HITRUST certification documentation
Customers and qualified prospects can request our HITRUST certification letter, validated assessment summary, and control-mapping documentation via [email protected] with the subject "HITRUST request." Most documentation is available under NDA; the certification letter itself can be shared publicly.