HITRUST and the AIC Kits

Analog Informatics Corporation (AIC) kits include an auditing package for organizations working toward a HITRUST assessment. Audit records and the Assessment Binder are built in. The same records can feed Competitors, or another package the organization already runs. A HITRUST assessor and HITRUST decide the result. The kits run in a secure enclave, air-gapped or generally connected.

Multiple protective glass layers around a healthcare information archive
HITRUST and the AIC Kits

What Availability Means

The 19 Assessment Domains

DomainWhat the Kit Does
01 Information Protection ProgramThe organization writes the program. The Assessment Binder stores it.
02 Endpoint ProtectionConfiguration compliance checks enrolled systems. Host malware protection stays with the organization.
03 Portable Media SecurityPortable media outside the kit stays with the organization.
04 Mobile Device SecurityMobile device management stays with the organization.
05 Wireless SecurityWireless design stays with the organization.
06 Configuration ManagementConfiguration compliance and Current State Compliance.
07 Vulnerability ManagementFindings can be recorded. Vulnerability analysis is planned as an add-on module.
08 Network ProtectionJump is the managed privileged path. Network devices stay with the organization.
09 Transmission ProtectionValidated cryptography on kit paths.
10 Password ManagementPrivileged Identity Management vaults and rotates credentials.
11 Access ControlPrivileged Access Management, Privileged User Management, and access review on kit accounts.
12 Audit Logging and MonitoringAudit, Windows Event Log, syslog, alerts, and continuous monitoring.
13 Education, Training, and AwarenessTraining and attestation assigns material and records a signature.
14 Third Party AssuranceSupplier review stays with the organization. A Managed Service Provider can operate inside the kit.
15 Incident ManagementIncident Response records the event and can alert.
16 Business Continuity and Disaster RecoveryRecovery stays with the organization. High-availability database failover is available.
17 Risk ManagementCurrent State Compliance records findings. Risk acceptance stays with the organization.
18 Physical and Environmental SecurityFacilities stay with the organization.
19 Data Protection and PrivacyDocument sharing vault and validated cryptography on kit paths. Privacy requests stay with the organization.

See HIPAA for the Security Rule safeguards and Partners and Migration for evidence feeds.

Screenshots

The Assessment Binder builds a living evidence package for each framework, shared by the assessor, the MSP, and the customer.

More on Product Screenshots.

An assessment organization, certification body, or regulator decides whether a requirement is satisfied.

See It on Your Use Case

A live demo of privileged access, compliance evidence, and deployment options for your environment.