A lot of growth stage Digital Health organizations need to demonstrate compliance with a recognized framework or obtain a validated certification, naturally I see HITRUST pop-up in many of these conversations. As a HITRUST practitioner and fan of the standard, it is difficult to obtain and costly both from an upfront monetary and time/resources perspective. Unless potential customers are explicitly requiring the standard, and the contract value outweighs the potentially significant certification costs, the organization may better be served first aligning to NIST or 405(d) standards, ensuring your HIPAA Compliance Program (if applicable) is in order; then if required, bridging to either a SOC 2 or HITRUST i1 Certification having already built a strong foundation aligning to NIST/405(d). Aligning to NIST, 405(d), and HIPAA standards do not require certification bodies, unlike SOC 2 and HITRUST, meaning less upfront cost. Furthermore, both HITRUST and SOC 2 controls map to the other standards growth-stage Digital Health organizations need to demonstrate compliance with a recognized framework or obtain a validated certification. Naturally, I see HITRUST pop up, so building upon the ‘free’ standards sets you up for success to obtain the ‘paid’ certifications.
The post Digital Health Compliance Savings appeared first on Clearwater.