Issued2024-11-19

HITRUST AI Security Assessment and Certification

Assessment / CertificationVoluntary

Summary

Provides an independently assessed certification pathway for AI platforms and deployed systems using prescriptive controls focused on AI-specific cybersecurity and information risks, supported by external assessment, centralized HITRUST review, scoring, reporting, and certification.

Healthcare Implications

Healthcare organizations, payers, and AI vendors can use the certification to validate the security of deployed AI systems and third-party platforms, demonstrate control implementation to customers and oversight bodies, and integrate AI-specific assurance into procurement, vendor risk management, and compliance programs.

Impact Level

Medium

Keywords

Safety & Risk; Privacy & Data; Transparency & Governance

Stakeholders

Providers & Health Systems; Payers & Purchasers; Developers & Vendors; Regulators & Government