M ManySignal

Compliance — HITRUST CSF

HITRUST r2 monitoring evidence — healthcare's de facto security standard

HITRUST CSF r2 certification is increasingly required by health systems and payers from all their Business Associates and technology vendors. ManySignal automates evidence collection for HITRUST's monitoring and incident management control categories — reducing assessment preparation from weeks to days.

HITRUST control category coverage

Category 01 — Information Security Management Program

Security programme evidence via platform metrics and coverage reporting

Category 06 — Access Control

Privileged access monitoring, access review evidence, and deprovisioning verification

Category 09 — Audit Logging and Monitoring

Full coverage — continuous log collection, automated log review, anomaly alerting

Category 10 — Incident Management

Full coverage — incident detection, response, evidence preservation, and timeline documentation

Category 12 — Malware Protection

Malware detection via endpoint telemetry, process anomaly, and IOC matching

Category 13 — Network Security Controls

Network flow analysis, East-West anomaly detection, and external connectivity monitoring

Certification status

ManySignal's HITRUST r2 certification is in progress. SOC 2 Type II report and current assurance documentation available under NDA at [email protected]. BAA available at /legal/baa.

HITRUST CSF — common questions

What is HITRUST CSF and why is it required in healthcare?

HITRUST CSF (Common Security Framework) is a certifiable security framework that harmonises HIPAA, NIST, ISO 27001, and other standards into a single assessment. Healthcare organisations — payers, providers, and health-tech companies — increasingly require HITRUST r2 certification from their Business Associates and vendors as a condition of contract. It is the de facto standard for demonstrating mature security to large health systems and payers.

How does ManySignal address HITRUST Control Category 09 — Monitoring?

HITRUST Control Category 09 (Information Systems Acquisition, Development and Maintenance) and Category 10 (Incident Management) are the primary monitoring-relevant categories. ManySignal addresses: 09.aa (Audit Logging — continuous log collection), 09.ab (Monitoring System Use — user behaviour analytics), 10.a (Incident Response Procedures — automated response), and 10.h (Collection of Evidence — tamper-evident evidence preservation).

Does ManySignal have HITRUST r2 certification?

ManySignal's HITRUST r2 certification is in progress. Our SOC 2 Type II report (available under NDA at [email protected]) covers the equivalent security controls assessed in HITRUST. Healthcare customers requiring HITRUST-certified vendors should contact [email protected] for the current certification timeline and available assurance documentation.

How does HITRUST differ from SOC 2 for healthcare organisations?

SOC 2 Type II is a general-purpose security audit covering the Trust Services Criteria. HITRUST CSF is specifically designed for healthcare — it incorporates HIPAA requirements and healthcare-specific controls not in SOC 2. Large health systems and payers increasingly require HITRUST over or alongside SOC 2. ManySignal provides continuous monitoring evidence relevant to both frameworks simultaneously.

Can ManySignal help reduce the HITRUST assessment burden?

Yes. HITRUST r2 assessments require evidence across 19 control categories. ManySignal automates evidence collection for the monitoring-heavy categories (09, 10) — providing timestamped, auditor-readable records for the full assessment period. This reduces the manual evidence collection effort that typically accounts for 40–60% of HITRUST assessment preparation time.

Start collecting HITRUST evidence today

Connect your EHR and cloud environments. ManySignal begins collecting Category 09 and 10 evidence from the first day of deployment — ready for your next r2 assessment.