
Practical Cybersecurity with Jen Stone · 2026-04-14 · 11 min
Episode Summary In this episode of Practical Cybersecurity , we dive into the complex world of HITRUST certification. Often called the "gold standard" for healthcare security, HITRUST can be a daunting mountain to climb for small and large organizations alike. Jen Stone and experts Peter Briel (Privaxi) and Lee Pierce (SecurityMetrics) break down why scoping is your best friend, why screenshots aren't enough, and why you should never try to "button things down" before talking to an expert. Key Discussion Points: What is HITRUST? Unlike HIPAA, which lacks a formal certification, HITRUST integrates multiple standards (NIST, ISO, etc.) into a "beefy" framework. It provides a definitive answer to security and compliance inquiries in the healthcare space. The Three Levels of HITRUST: E1: The entry-level, static 44-control assessment. I1: The "leading practices" assessment with roughly 180+ controls. R2: The risk-based, "gold standard" that requires heavy factoring and scoping. The "House Alarm" Analogy: You can't protect a house if you don't know how many windows and doors it has.