In today's ever-changing security landscape, there is an increasing scrutiny from regulators, bigger penalties, and ever-increasing security and privacy concerns. The challenges faced by the organisations may vary from increasing precision of computer abuse and computer cybercrime, inconsistent business partner requirements and compliance expectations, gaining the assurances needed to allow organisations to safely engage with their customers and trading partners, and inefficient internal compliance management processes. Our HITRUST assurance programme will provide insights to build a proactive approach for covered entities and their business associates for data protection and security risk mitigation.
Your journey to security starts with our HITRUST expertise
As a HITRUST external assessor, KPMG in India is offering HITRUST assurance programme which provides organisations with a coordinated approach. This approach ensures all programmes related to security and privacy are aligned, maintained, and thorough to support an organisation’s risk management and compliance objectives. It acts as a central gatekeeper which takes into consideration internationally recognised security standards like NIST, HIPAA, FTC, PCI DSS, COBIT, Red Flags, ISO, and GDPR
Roadmap for HITRUST Journey
Assessment options to meet every level of assurance
HITRUST certification caters to varying levels of budget, resources, and risk profile of an organisation
Applicability of our HITRUST Assurance Programme
- Companies that access, create, transmit or store sensitive health information of US-based customers
- Companies concerned about the HIPAA law and penalties being levied by US regulators and
- Service providers already providing or intending to provide any of the following services to US-based healthcare service providers such as:
KPMG in India, A trusted and certified HITRUST external assessor
KPMG in India HITRUST Service Offerings
Assist organisations in assessing their current readiness towards HITRUST CSF certification requirements
Prepare organisations for the validated assessment
Assist organisation to establish the baseline of its system compliance and capability
Identify high risk areas of non-compliance, residual compliance score, and corrective action plans
Assist service organisations with a SOC 2+ report based on Trust Service Criterias (TSCs), as defined by AICPA, and additional category by HITRUST
Opinion on fairness of presentation of description and suitability of design and operating effectiveness of controls based on relevant TSCs and HITRUST CSF
Enable organisations to meet the applicable TSCs and the HITRUST CSF security and privacy criteria in a single report
Enable organisations to communicate information about their compliance with regulatory requirements and organisation’s controls over protected sensitive information.
Assist organisations in performing a HITRUST CSF validated assessment
Assist organisations in submitting results to HITRUST for validation and certification
Perform QA validation and provide responses to QA queries
Assist organisations in framing Corrective Action Plan (CAP) and GAP analysis.
Assist organisations by performing the necessary testing to express an opinion on SOC 2 report, and perform HITRUST CSF validated assessment in parallel to achieve HITRUST CSF certification
Leverage the evidence, testing, and documentation across SOC 2 and HITRUST examination, ensuring synergies between these assessments and reducing audit fatigue.
Explore the advantages of our HITRUST Assurance program
A comprehensive program delivering unparallel benefits from risk mitigation to a strengthened security posture