The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Practical Cybersecurity with Jen Stone
Practical Cybersecurity with Jen Stone artwork

Protecting the House: Why Asset Management and "Storytelling" are Keys to HITRUST (ep.5)

Practical Cybersecurity with Jen Stone · 2026-04-14 · 11 min

0:00--:--

Episode notes

Episode Summary In this episode of Practical Cybersecurity , we dive into the complex world of HITRUST certification. Often called the "gold standard" for healthcare security, HITRUST can be a daunting mountain to climb for small and large organizations alike. Jen Stone and experts Peter Briel (Privaxi) and Lee Pierce (SecurityMetrics) break down why scoping is your best friend, why screenshots aren't enough, and why you should never try to "button things down" before talking to an expert. Key Discussion Points: What is HITRUST? Unlike HIPAA, which lacks a formal certification, HITRUST integrates multiple standards (NIST, ISO, etc.) into a "beefy" framework. It provides a definitive answer to security and compliance inquiries in the healthcare space. The Three Levels of HITRUST: E1: The entry-level, static 44-control assessment. I1: The "leading practices" assessment with roughly 180+ controls. R2: The risk-based, "gold standard" that requires heavy factoring and scoping. The "House Alarm" Analogy: You can't protect a house if you don't know how many windows and doors it has.

More from Practical Cybersecurity with Jen Stone

All episodes →
  • Which PCI SAQ Do You Actually Need? (ep. 10)81 / 100
  • The Expert Guide to Defeating eSkimmers (ep. 8)86 / 100
  • Passkeys: An Upgrade You Didn't Know You Needed (ep. 9)
  • Cybersecurity Priorities for 2026: The Two Vulnerabilities to Focus on in the AI Era (ep. 7)
  • The SAQ A Deep Dive: Two QSAs Set the Record Straight (ep. 6)
Explore the best B2B Ops podcasts →
All Practical Cybersecurity with Jen Stone episodes →