// HITRUST.jsx — Verigo Global: dedicated HITRUST CSF certification + support page const { V: HV, MAXW: HMW, FONT: HFT } = window; /* ── DATA ─────────────────────────────────────────────────── */ const TIERS = [ { code: 'e1', name: 'Essentials, 1-year', icon: 'shield', controls: '44 requirements', protects: 'Foundational hygiene', cadence: 'Validated assessment, annual', focus: 'A foundational cybersecurity baseline covering the most critical, high-impact controls. The fastest route to a validated HITRUST credential and a natural entry point before stepping up to i1 or r2.', }, { code: 'i1', name: 'Implemented, 1-year', icon: 'gauge', controls: '182 requirements', protects: 'Leading practices', cadence: 'Validated assessment, annual', focus: 'A threat-adaptive assessment built around leading security practices and the controls that counter prevalent threats. Substantial assurance with a moderate, predictable lift — the most common starting point for health-tech vendors.', }, { code: 'r2', name: 'Risk-based, 2-year', icon: 'award', controls: '300+ tailored', protects: 'Comprehensive assurance', cadence: 'Validated assessment every 2 years, interim at year 1', focus: 'The most rigorous, expandable assessment — control selection scales to your organizational, system, and regulatory risk. The gold-standard credential most healthcare buyers and partners expect.', highlight: true, }, ]; const AUTHORITIES = ['HIPAA', 'ISO 27001', 'NIST SP 800-53', 'NIST CSF', 'PCI DSS', 'GDPR', 'SOC 2 (TSC)', 'FedRAMP', 'CIS Controls', 'COBIT']; const DOMAINS = [ ['clipboard', 'Information Protection Program'], ['lock', 'Access Control'], ['server', 'Endpoint Protection'], ['file', 'Portable Media Security'], ['cpu', 'Mobile Device Security'], ['network', 'Wireless Security'], ['layers', 'Configuration Management'], ['target', 'Vulnerability Management'], ['shield', 'Network Protection'], ['globe', 'Transmission Protection'], ['lock', 'Password Management'], ['activity', 'Audit Logging & Monitoring'], ['users', 'Education, Training & Awareness'], ['handshake', 'Third Party Assurance'], ['zap', 'Incident Management'], ['refresh', 'Business Continuity & DR'], ['gauge', 'Risk Management'], ['building', 'Physical & Environmental Security'], ['heart', 'Data Protection & Privacy'], ]; const ROADMAP = [ ['search', 'Scope & select', '2–3 wks', 'Define the system boundary and choose the right assessment type — e1, i1, or r2.'], ['target', 'Readiness assessment', '3–5 wks', 'Benchmark your environment against every required CSF control and score the gaps.'], ['layers', 'Remediate', '3–9 mo', 'Implement controls, write policies, and stand up evidence inside MyCSF.'], ['gauge', 'Maturity scoring', '2–4 wks', 'Score each requirement across the five PRISMA maturity levels and close shortfalls.'], ['clipboard', 'Validated assessment', '4–8 wks', 'An authorized External Assessor tests and validates your control evidence.'], ['award', 'HITRUST QA & certify', '4–8 wks', 'HITRUST performs quality assurance, issues the report, and grants certification.'], ]; const SEEKING = [ ['gauge', 'Pick the right assessment type', 'e1, i1, and r2 differ sharply in scope, effort, and the assurance they convey. Choosing the tier your customers and risk actually require is the single biggest decision — over-reach and you burn months; under-reach and the credential won\u2019t satisfy your buyers.'], ['layers', 'Scope the boundary and inherit', 'A tightly defined system boundary keeps the assessment focused on what matters. We help you map where PHI lives and leverage control inheritance from your cloud and service providers so you don\u2019t re-prove controls someone else already owns.'], ['target', 'Score maturity honestly, then remediate', 'HITRUST scores every requirement across five PRISMA maturity levels — policy, procedure, implemented, measured, managed. An honest self-score before validation is worth far more than an optimistic one. We score, prioritize by risk, and close gaps before an assessor arrives.'], ]; const PREPARE = [ 'A defined assessment scope and system boundary', 'The selected assessment type — e1, i1, or r2', 'A populated MyCSF assessment object', 'Policies and procedures mapped to each requirement', 'Evidence across all five PRISMA maturity levels', 'Named control owners ready for validation interviews', ]; const OUTPUTS = [ ['search', 'Readiness & gap report', 'An independent benchmark of your environment against the CSF requirements for your chosen tier — gaps scored by risk and effort, with a prioritized remediation roadmap.'], ['layers', 'Validated MyCSF object', 'A complete assessment object in the MyCSF platform — every requirement scored across the five PRISMA maturity levels, with evidence mapped requirement by requirement.'], ['award', 'HITRUST CSF certification', 'The validated certification report and letter for your assessment type — the recognized, shareable credential your customers, partners, and regulators expect.'], ['clipboard', 'Corrective Action Plans', 'Tracked, dated CAPs for any requirement not yet fully met, with named owners and target dates — the structured path to closing gaps after validation.'], ['network', 'Inheritance & evidence package', 'Policies, procedures, and configurations organized for reuse — plus the inheritance relationships that cut duplicate effort across cloud and service-provider controls.'], ['handshake', 'HITRUST QA coordination', 'End-to-end coordination with your External Assessor and the HITRUST quality-assurance review, managing exceptions through to a clean, issued certification.'], ]; const TESTIMONIALS = [ { quote: 'Verigo took our r2 from a daunting 300-control wall to a sequenced plan we could actually execute. They scoped the boundary tightly, set up inheritance with our cloud provider, and we cleared HITRUST QA on the first pass.', name: 'Dana Reyes', role: 'CISO', org: 'Regional health-tech platform', initials: 'DR', }, { quote: 'We needed a credible credential fast to unblock an enterprise health system deal. Verigo guided us through i1 in under five months and coached our control owners so the validation interviews were a non-event.', name: 'Marcus Vale', role: 'VP Engineering', org: 'Clinical data SaaS vendor', initials: 'MV', }, { quote: 'What set them apart was the honesty of the maturity scoring. They told us where we really stood across the PRISMA levels before the assessor ever saw it — no surprises, no scramble at the end.', name: 'Priya Nair', role: 'Director of Compliance', org: 'Healthcare BPO provider', initials: 'PN', }, ]; const HITRUST_FAQ = [ ['What is the HITRUST CSF?', 'The HITRUST CSF is a certifiable control framework that harmonizes more than forty authoritative sources — including HIPAA, ISO 27001, NIST SP 800-53, NIST CSF, PCI DSS, and GDPR — into a single, prescriptive, and scalable set of control requirements. Rather than reconciling overlapping mandates yourself, you implement one framework and demonstrate alignment to all of them at once.'], ['Which assessment do we need — e1, i1, or r2?', 'It depends on the assurance your customers require and the sensitivity of the data you handle. The e1 (Essentials) covers a 44-requirement foundational baseline. The i1 (Implemented) tests 182 requirements built around leading, threat-adaptive practices and is the common starting point for health-tech vendors. The r2 (Risk-based) is the most rigorous — 300+ tailored requirements scaled to your risk — and is the credential most large healthcare buyers ultimately expect. We confirm the right tier during scoping.'], ['Does HITRUST replace HIPAA?', 'No. HIPAA is the law; HITRUST is a framework for demonstrating that you meet it — and much more. The CSF maps the HIPAA Privacy, Security, and Breach Notification Rules into testable control requirements, so a HITRUST certification gives you objective, third-party-validated evidence of HIPAA alignment alongside the other authorities the CSF harmonizes.'], ['Who actually performs the assessment?', 'A validated assessment is performed by an authorized HITRUST External Assessor, and then HITRUST itself conducts an independent quality-assurance review before issuing certification. Verigo prepares you for and coordinates that assessment, but to protect its integrity we keep our readiness reviewer independent of the team that implemented your controls.'], ['How long is a HITRUST certification valid?', 'The e1 and i1 certifications are valid for one year. The r2 certification is valid for two years, with an interim assessment at the one-year mark to confirm controls remain in place. Because we embed evidence collection into how you operate, each renewal draws on evidence the business already generates rather than a year-end scramble.'], ['Why HITRUST instead of a plain HIPAA attestation?', 'A self-attestation says you believe you comply; a HITRUST certification proves it through independent validation against a prescriptive control set. For healthcare buyers and partners running vendor-risk reviews, that distinction is decisive — a HITRUST credential answers diligence in one recognized report instead of bespoke questionnaires, and it covers far more ground than HIPAA alone.'], ]; /* ── BREADCRUMB ───────────────────────────────────────────── */ const HCrumb = ({ onNav }) => (
The certifiable trust framework for healthcare information — one control set that harmonizes HIPAA, ISO 27001, NIST, and more. Verigo takes you from scoping and readiness to a validated assessment, and through HITRUST quality assurance to certification itself.
Healthcare organizations face a tangle of overlapping obligations — HIPAA, ISO 27001, NIST, PCI DSS, and more — each with its own language and evidence. The HITRUST CSF harmonizes all of them into a single certifiable control set, so you implement once and demonstrate alignment to many.
Crucially, HITRUST is certifiable and independently validated — not a self-attestation. An authorized External Assessor tests your evidence and HITRUST itself performs quality assurance before certification, giving buyers objective proof rather than a promise.
For health-tech vendors, IT contractors, and anyone supporting HIPAA-covered entities, a HITRUST credential has become the credential vendor-risk teams ask for by name.
A validated HITRUST assessment is tested by an authorized External Assessor and quality-assured by HITRUST before any certification is granted. That two-stage independence is exactly why a HITRUST report answers vendor-risk diligence where a self-attestation cannot.
{d}
{t.focus}
A HITRUST credential is won or lost in the decisions you make before remediation begins. Choose the right assessment type and scope, and the path is direct. Get them wrong, and cost and timeline balloon. These are the three things to get right first.
{d}
{d}
{t.quote}
Questions on scope, assessment types, or the validated-assessment process? A senior practitioner will walk you through it.
{a}