Research paper on HITRUST(Health Information Trust Alliance)

profilepotlibharat
FinalAnnotatedBibliography.docx

Annotated Bibliography for Health Information Trust Alliance (HITRUST)

Travis Good (2018). Datica Academy. What is HITRUST? Retrieved on November 3, 2019, from https://datica.com/academy/what-is-hitrust/

· Travis is the MD, Co-founder, and Chief technology officer of Datica Academy. Therefore he possesses extensive knowledge on the issue of data security, and he expounds the topics regarding HITRUST with so much precision.

· He clearly explains HITRUST as the organization that created the Common Security Framework (CSF). CSF is described as the framework that brings together several other frameworks that include HIPAA, PCI,ISO, and NIST.

· This article published on November 3, 2019.

· The article goes further and clearly states in fewer details the nineteen different domains of CSF and explains that CSF does not provide for a broad aspect of security and administrative controls, unlike HIPAA. HITRUST, however, has an additional 135 specific controls that are all implemented on different levels. The article also highlights the difference between HITRUST and HIPAA.

Bojana Dobran (2018). PhoenixNap. HITRUST vs. HIPAA certification. What are the differences? Retrieved on November 3, 2019, from https://phoenixnap.com/blog/hitrust-certification-vs-hipaa

· The article is written by Bojana, an experienced writer, and senior marketing specialist, about the major differences between HITRUST and HIPAA. Her work clearly explains the differences in how to become HITRUST certified and how to become HIPAA certified.

· The article published on November 3, 2019.

· The information provided in this article is credible because the research is done by a person who possesses adequate knowledge in the field of computer security and cloud computing. Therefore, the information can be relied on to provide insight on the two closely related yet completely different aspects of protecting patient data.

· The source is not biassed towards any side of the divide, but it focuses on the basic concepts and their explanations. The source is very informative, and it can be very useful in the writing of a research paper that requires a clear outlining of the requirements for achieving both the HITRUST certification and the HIPAA certification.

Rob Pierce (2018). Linford Co. What is HITRUST? A practical guide of certification. Retrieved on November 3, 2019, from https://linfordco.com/blog/what-is-hitrust/

· Rob Pierce the article writer is a person who has extensive experience in the field of data security. Therefore, he possesses adequate knowledge in the field of HITRUST certification.

· This article published on November 3, 2019.

· In the article, it is clearly explained to the reader what HITRUST certification is and that it provides a Common Security Framework (CSF), which can be used by organizations to ensure that their data is secure.

· The article also briefly expounds on the differences between HITRUST and HIPAA certification. HITRUST myCSF is also explained very well as being a major HITRUST tool that is organization-specific.

· The information provided in the article is very useful in the sense that it accurately provides details on the various aspects of HITRUST certification as well as the CSF.

Lelah Hassibi (2017).Datica Academy. 5 steps to HITRUST CSF certification. Retrieved on November 3, 2019, from https://datica.com/blog/5-steps-to-hitrust-csf-certification/

· Lelah is the vice president of marketing at Datica Academy, and she is well informed about the struggles that people go through in the process of getting HITRUST certifications. She clearly states that the process is very challenging, unlike what most people might think.

· This article published on November 3, 2019.

· In her quest to ensure that people are well aware of what they are getting themselves into while they embark on the journey to get certified, she outlines five major steps that are followed. She calls the five painful steps of HITRUST CSF certification. The first step is to investigate the process.

· The article explains that the process is done on a yearly basis, as well. The article is very useful for the purposes of writing an academic paper because, unlike other articles that address a wide range of concepts around HITRUST, it is focused on one specific topic.

Ryan Rich (2018). Datica Academy. Configuring Popular Managed Database Services To Comply with HITRUST CSF. Retrieved on November 3, 2019, from https://datica.com/blog/configuring-popular-managed-database-services-for-hitrust-csf/ .

· Ryan is the Chief Product Officer at Datica academy, and in this article is provides insight on an area that most of the other articles have either very shallowly addressed or not addressed at all. The article goes further and explains the advantages of configuring the databases so that they align with the HITRUST CSF.

· This article published on November 3, 2019.

· In the article, he acknowledges that the process is complex especially because people must be creative enough to know how the configuration should look like. The article goes further and explains the advantages of configuring the databases so that they align with the HITRUST CSF. He also explains why it is good to start with databases.

· The article provides information about the configuration and why it is necessary so it can be used for academic papers. However, it is important to note that the article is slightly biased in favor or Datica Academy as the writer talks about how and why they do it that way at Datica Academy.

Thompson, E.C.(2017). Selecting Security Measures. In building HIPPA-Complaint Cybersecurity Program (pp.27-51). Apress, Berkeley, CA. doi https://doi.org/10.1007/978-1-4842-3060-2_3

· Thompson is a well-informed individual when it comes to the field of data security, and he provides information in a very detailed way when it comes to organizations choosing the best security measures.

· This article published in 2017.

· The information details how the published frameworks can be of help to cybersecurity personnel in their quest to ensure that all the data is safe and secure.

· I find the information provided to be very useful as it is given in detail, and therefore, it can be used to write a very good academic paper. The information provided is also not biased, and it provides a platform for more research and learning.

ISO/IEC 27002:2005

Information technology – Security techniques – Code of practice for information security management

· This law was regulated by International Standard Organization (ISO), formed in February 23, 1947 which provides industrial and commercial standards. International Electrotechnical Commission(IEC) formed in 1906

· This law was regulated in 2005.

· The CSF includes the control objectives and control specifications based on the ISO/IEC 27001:2005 and ISO/IEC 27002:2005 standards. These guidelines from ISO were enhanced, leveraging the NIST 800-series framework documents, ISO/IEC 27799:2008 Health Informatics (guidance for information security management for healthcare organizations using ISO/IEC 27002), HIPAA, PCI, COBIT, HITECH, State requirements, and the experience and best practices of the HITRUST community