HITRUST Products
HITRUST Sources
MyCSF Functionality
HITRUST Assurance
HAX & RDS
100

What is the HITRUST Assessment SaaS called?

MyCSF

100

Which HITRUST CSF source, enacted in 1996, aims to protect American medical records?

HIPAA

100

What feature in MyCSF allows results from one assessment to be used in another?

Inheritance

100

What does CAP stand for in HITRUST terminology?

Corrective Action Plan

100

What does HAX stand for?

HITRUST Assessment Xchange

200

What is the name of the HITRUST framework for risk management and regulatory compliance?

HITRUST CSF

200
What standard inspired the structure of the HITRUST CSF?

ISO 27001

200

What is the report functionality called that provides a comprehensive view of an assessment’s scores based on an authoritative source?

Insights Reporting

200

How can an organization book a QA timeslot?

With a Reservation

200

What does RDS stand for?

Results Distribution System

300

Which HITRUST product enables the sharing of assessments?

RDS

300

How many categories are in the HITRUST CSF?

14

300

What is the highest tier of subscription available in MyCSF?

Premier

300

What is the name of an assessment submitted for review by an assessor and HITRUST?

Validated

300

What is the name of the assessment in HAX that calculates a vendor’s risk?

IRQ

400

What product is used from HITRUST for managing third-party risk?

HAX

400

In what year was the HITRUST CSF established?

2007

400

Which assessment type is built on controls linked to specific sources rather than HITRUST tailoring?

Targeted Assessment

400

Which assessment type includes tailoring?

R2

400

What must be generated in RDS and provided to an assessed entity to complete a share?

Token

500

What offers a catalog of software and consulting services for HITRUST compliance?

Product and Services Directory

500

Which major privacy law in the HITRUST CSF is based on European privacy standards?

GDPR

500

What is the name of the Excel spreadsheet that can be loaded into an assessment?

Offline Assessment

500

What document must be completed on the assessed entity’s letterhead?

Representation Letter

500

What HITRUST document inspired the workflows for HAX?

Third Party Risk Management Methodology

M
e
n
u