• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer

  • Opinion
  • Health IT
    • Behavioral Health
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Patient Engagement
    • Population Health Management
    • Revenue Cycle Management
    • Social Determinants of Health
  • Digital Health
    • AI
    • Blockchain
    • Precision Medicine
    • Telehealth
    • Wearables
  • Life Sciences
  • Investments
  • M&A
  • Value-based Care
    • Accountable Care (ACOs)
    • Medicare Advantage

KPMG: Two-Third of Organizations Not Ready for HITRUST Standard

by Fred Pennic 10/11/2016 Leave a Comment

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

KPMG: Two-Third of Organizations Are Not Ready for HITRUST Standard

With all of the demands of protecting healthcare information, two-thirds of survey respondents said they are not prepared to comply with HITRUST standards governing cyber security and steps to keep patient records and medical information secure.  According to a survey of 604 healthcare industry professionals targeting vendors conducted by KPMG, half of those surveyed were “not ready” and 17.4 percent were in planning stages for a HITRUST (the Health Information Trust Alliance) CSF assessment – an internal control-based approach that allows organizations to proactively assess and demonstrate the measures they have taken to protect healthcare information.  

There is no legal requirement mandating that organizations comply with HITRUST standard or SOC 2 – a separate data protection standard set by the AICPA.  However, hackers and the high value placed on healthcare information have any organization that gathers patient records, medical billing or other protected healthcare information deeply concerned about its protection.  An increasing number of organizations want their partners and vendors to have HITRUST or SOC 2 verifications that healthcare information security standards are being met.

Regarding the progress that organizations have made to address HITRUST CSF requirements, only 7 percent said they are completely ready and 8 percent described their organization as “well along implementation.”  The remainder (17.4 percent) were in early stages of implementation.

When asked about staffing capabilities to meet this standard, 47 percent responded that they did not have the “right staff with the right level of skills to execute against the HITRUST CSF.” The survey found 53 percent did.   Respondents found that staffing (15 percent) was the biggest barrier to HITRUST CSF readiness, finishing ahead of cultural, technological, and financial concerns. More than a quarter (27 percent) pointed to all of those factors and 23 percent said “none of the above” were barriers.  

“An increasing number of healthcare organizations are requiring their vendors to demonstrate controls for securing PHI (protected health information) to manage their cyber and regulatory risks, especially since healthcare information is a rich target for hackers,” said Emily Frolick, third-party risk and assurance leader for KPMG’s Healthcare practice in a statement. “These vendors are able to accomplish this through a SOC 2® + HITRUST CSF examination or a HITRUST CSF Certification, both of which enable vendors to communicate their good faith effort to protect patient information.”

 “Neither is mandatory under current law, but the marketplace wants to reduce risks tied to cybersecurity with third-party assurances concerning their data protection efforts,” Frolick added.

 

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

Tap Native

Get in-depth healthcare technology analysis and commentary delivered straight to your email weekly

Reader Interactions

Primary Sidebar

Subscribe to HIT Consultant

Latest insightful articles delivered straight to your inbox weekly.

Submit a Tip or Pitch

2026 Predictions & Trends

Healthcare 2026 Forecast: Executives on AI Survival, Financial Reckoning, and the End of Point Solutions

2026 Healthcare Executive Predictions: Why the AI “Pilot Era” Is Officially Over

Most-Read

HHS Launches 'OneHHS' AI Strategy to Integrate AI Across CDC, CMS, and FDA for Efficiency and Public Trust

HHS Launches ‘OneHHS’ AI Strategy to Integrate AI Across CDC, CMS, and FDA for Efficiency and Public Trust

Kristen Hartsell, VP of Clinical Services, RedSail Technologies

The Pharmacy Closures Crisis: How Independent Pharmacies Are Fixing Pharmacy Deserts

From Overwhelmed to Optimized: How AI Agents Address Staffing Challenges and Burnout in Healthcare

From Overwhelmed to Optimized: How AI Agents Address Staffing Challenges and Burnout in Healthcare

The VBC Paradox: Why Hospitals Are Doubling Down on Value-Based Care While Revenue at Risk Lags

The VBC Paradox: Why Hospitals Are Doubling Down on Value-Based Care While Revenue at Risk Lags

Tebra Secures $250M to Challenge Legacy EHRs with AI-Powered Automation

Tebra Secures $250M to Challenge Legacy EHRs with AI-Powered Automation

AstraZeneca Selects Salesforce Agentforce Life Sciences to Deploy AI-Powered Global Customer Engagement

AstraZeneca Selects Salesforce Agentforce Life Sciences to Deploy AI-Powered Global Customer Engagement

Aidoc Partners with NVIDIA MONAI to Scale Open-Source Clinical AI

Aidoc Partners with NVIDIA MONAI to Scale Open-Source Clinical AI

RapidAI Secures FDA Clearance for Five New Deep Clinical AI Modules, Expanding Enterprise Imaging Platform

RapidAI and AWS Deepen Partnership to Scale Clinical AI in Healthcare

Greece and Sword Health to Build AI-Powered Healthcare Front Door

Greece and Sword Health to Build AI-Powered Healthcare Front Door

GE HealthCare Acquires Intelerad for $2.3B to Create Cloud-First, AI-Enabled Imaging Ecosystem

GE HealthCare Acquires Intelerad for $2.3B to Create Cloud-First, AI-Enabled Imaging Ecosystem

Secondary Sidebar

Footer

Company

  • About Us
  • Advertise with Us
  • Reprints and Permissions
  • Op-Ed Submission Guidelines
  • Contact
  • Subscribe

Editorial Coverage

  • Opinion
  • Health IT
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Population Health Management
    • Revenue Cycle Management
  • Digital Health
    • Artificial Intelligence
    • Blockchain Tech
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • Value-Based Care
    • Accountable Care
    • Medicare Advantage

Connect

Subscribe to HIT Consultant Media

Latest insightful articles delivered straight to your inbox weekly

Copyright © 2025. HIT Consultant Media. All Rights Reserved. Privacy Policy |