Overview
Schellman Compliance, LLC begins each project with your end goals in mind and to provide preparation for future key project activities. Effective communication and timely coordination of project planning activities are central to our methodology with our clients.
Planning: After the agreement is executed, the first phase of the engagement is planning. This is to ensure that Schellman Compliance, LLC and the Client are fully aware of the “what, who, when, why, and how” prior to the beginning of initial testing. Proper planning is imperative to the success of a project. Schellman Compliance, LLC has standard processes to cover the important pieces of the engagement.
Understanding and Kick-Off: The kickoff is considered the start of the engagement, with a presentation on HITRUST and the project milestones. If needed, Schellman Compliance, LLC will schedule a call at the beginning of, or just prior to, the kickoff to finalize any outstanding items. Schellman Compliance, LLCwill be available to the Client with any questions.
By including communication prior to starting, Schellman Compliance, LLC ensures that no last-minute changes to the project or team have occurred, and the Client has the plan prior to the testing and any on-site visits.
Testing and Gathering: Gathering and testing is the core of the compliance engagement. Due to the planning and understanding processes, this phase will be an accumulation of gathering the evidence needed for the objectives discussed.
Schellman Compliance, LLC has a no surprise policy and has continuous contact with the stakeholders during the testing and gathering activities. The Client will have confidence the Schellman team has completed this phase timely and completely.
Submission and Certification Process / Reporting: Upon conclusion of the gathering and testing phase, Schellman Compliance, LLC performs internal quality assurance reviews to confirms that the Client’s assessment, located in the HITRUST MyCSF portal, has been prepared for submission and that the testing performed corroborates the organization’s scores for each requirement.
Schellman Compliance, LLC continues to work with the Client to confirm that acceptable corrective action plans (CAPs) have been documented for any gaps requiring action. Schellman Compliance, LLC also works with the Client to address any questions from HITRUST during their QA evaluation process. While Schellman Compliance, LLC does not issue the report, involvement with the Client does not end until the final report has been posted by HITRUST.
Services We Provide
• Risk-based (r2) Readiness / Gap Assessments
• Implemented (i1) Readiness / Gap Assessments
• Essentials (e1) Readiness / Gap Assessments
• Risk-based (r2) Validated Assessments – External Assessor
• Implemented (i1) Validated Assessments – External Assessor
• Essentials (e1) Validated Assessments – External Assessor
• Risk-based (r2) Interim Review – External Assessor
• Implemented (i1) Rapid Recertification – External Assessor
Highlights
- Experience: Schellman Compliance, LLC performs over 100 HITRUST assessments annually. This level of experience gives Schellman Compliance, LLC deep knowledge of the best way to perform HITRUST validated assessments. Schellman Compliance, LLC also engages frequently with the HITRUST organization during QA, ensuring that Schellman Compliance, LLC understands what HITRUST expects when an assessment is submitted for certification.
- Dedicated Resources: Schellman Compliance, LLC understands and appreciates the complexities of HITRUST assessments. To that end, Schellman Compliance, LLC utilizes dedicated full-time HITRUST CSF Lead Assessors, who have their HITRUST Certification (CCSFP), to act as external assessors on validated assessments. Schellman Compliance, LLC does not utilize contractors or offshore resources to perform HITRUST work.
- Synergized Audit Approach: Schellman Compliance, LLC has experience and knowledge of how to integrate a HITRUST assessment into an existing compliance program. Schellman Compliance, LLC understands and performs many compliance standards and frameworks, such as ISO 27001 certifications, and how evidence can be utilized across multiple assessments.
Details
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Support
Vendor support
Schellman Compliance, LLC understands the challenges our clients face in today’s business environment and have uniquely positioned ourselves to provide high-quality audits - both in person and remote - that are tailored to each organization’s specific needs. We are able to deliver this quality through Schellman Compliance, LLC’s holistic approach to addressing people, process, and technology as we deliver our services.
Should you have any questions about Schellman Compliance, LLC’s HITRUST capabilities, please contact hitrust@schellman.com to speak with one of our subject matter experts.