• Menu
  • Skip to right header navigation
  • Skip to main content
  • Skip to secondary navigation
  • Skip to footer

Before Header

Bryghtpath

Business Continuity and Crisis Management Consultants

  • About
        • About Bryghtpath

        • Our Core Values

        • Meet our Team

        • About Bryghtpath
          • Case Studies & Results
          • Certifications and Awards
          • Contact Bryghtpath
          • Contract Vehicles
          • Media & Professional Appearances
          • Our Clients
          • Our Proven Process
          • Security & Compliance
          • Strategic Partners
          • Work with Us
  • Capabilities
        • Our Capabilities
        • We help your organization strategically navigate uncertainty and disruption.

        • Case Studies & Results

        • Business Continuity as a Service

        • Business Continuity
          • Business Continuity - Overview
          • Business Continuity as a Service (BCaaS)
          • Business Continuity Software
          • Coaching
          • IT Disaster Recovery
          • Resiliency Diagnosis®️
        • Crisis Management
          • Crisis Management - Overview
          • Crisis Communications
          • Crisis Exercises
          • Cyber Crisis Exercises
          • Cyber Incident Response Planning
          • Crisis Playbook®️
          • Global Security Operations Center (GSOC)
          • Resiliency Diagnosis®️
        • Other Capabilities
          • Coaching
          • Intelligence & Global Security Consulting
          • Speaking
          • Training
        • Case Studies & Results
        • Industries
  • Insights
  • Products
        • Our Products

          College Classroom - Mature Teacher
        • Crisis Playbook™️

        • Exercise in a Box™️

        • Exercise in a Day™️

        • Books
          • From Panic to Poise: Crisis Management in the Modern World
          • The Continuity Code: Mastering Business Resilience
        • Crisis Playbook™️
          • Overview
          • Active Shooter Plan
          • Emergency Response Guide
          • Fatality
          • Food/Product Recall
          • Protest
          • Violent Attack
        • Maturity Models
          • Overview
          • ASIS Workplace Violence and Active Assailant
          • FFEIC Maturity Model – Business Continuity
          • ISO 22301 – Business Continuity
          • ISO 22361 – Crisis Management
          • ISO 27031 - IT Disaster Recovery
          • NIST 800-53 Contingency Planning Maturity Model
        • Templates & More
          • After-Action Process & Templates
          • Awareness Collateral
          • Business Continuity Plan Templates
          • Crisis Management Plan Templates
          • Disaster Recovery Plan Templates
          • Job Descriptions
  •  

Mobile Menu

  • About
    • About Bryghtpath
      • Case Studies & Results
      • Certifications and Awards
      • Contact Bryghtpath
      • Contract Vehicles
      • Media & Professional Appearances
      • Our Clients
      • Our Proven Process
      • Security & Compliance
      • Strategic Partners
      • Work with Us
  • Capabilities
    • Our Capabilities
    • Business Continuity
      • Business Continuity – Overview
      • Business Continuity as a Service (BCaaS)
      • Business Continuity Software
      • Coaching
      • IT Disaster Recovery
      • Resiliency Diagnosis®️
    • Crisis Management
      • Crisis Management – Overview
      • Crisis Communications
      • Crisis Exercises
      • Cyber Crisis Exercises
      • Cyber Incident Response Planning
      • Crisis Playbook®️
      • Global Security Operations Center (GSOC)
      • Resiliency Diagnosis®️
    • Other Capabilities
      • Coaching
      • Intelligence & Global Security Consulting
      • Speaking
      • Training
    • Case Studies & Results
    • Industries
  • Insights
  • Products
    • Books
      • From Panic to Poise: Crisis Management in the Modern World
      • The Continuity Code: Mastering Business Resilience
    • Crisis Playbook™️
      • Overview
      • Active Shooter Plan
      • Emergency Response Guide
      • Fatality
      • Food/Product Recall
      • Protest
      • Violent Attack
    • Maturity Models
      • Overview
      • ASIS Workplace Violence and Active Assailant
      • FFEIC Maturity Model – Business Continuity
      • ISO 22301 – Business Continuity
      • ISO 22361 – Crisis Management
      • ISO 27031 – IT Disaster Recovery
      • NIST 800-53 Contingency Planning Maturity Model
    • Templates & More
      • After-Action Process & Templates
      • Awareness Collateral
      • Business Continuity Plan Templates
      • Crisis Management Plan Templates
      • Disaster Recovery Plan Templates
      • Job Descriptions
  •  

Achieving HITRUST Certification for a Major Healthcare Technology Provider

A major healthcare technology provider retained Bryghtpath to ensure their resilience program for business continuity, crisis management, and IT disaster recovery met the requirements for HITRUST certification.

You are here: Home / Capabilities / Case Studies / Achieving HITRUST Certification for a Major Healthcare Technology Provider

A major healthcare technology provider retained Bryghtpath to ensure their resilience program for business continuity, crisis management, and IT disaster recovery met the requirements for HITRUST certification.

The Opportunity

Bryghtpath was retained by the General Counsel and the Chief Security Officer to review the organization’s current resilience capabilities for business continuity, crisis management, and IT disaster recovery to prepare the organization to obtain HITRUST certification.

Approach and Results

Bryghtpath began this engagement by utilizing our Resiliency Diagnosis® process to evaluate the organization’s resilience capabilities for business continuity, crisis management, and IT disaster recovery. This review focused on assessing the program’s maturity against the ISO 22301 standard and the HITRUST controls they would be evaluated against later in the year.

Once our evaluation was completed, we worked across three specific workstreams within the client’s organizations to mature their business continuity, crisis management, and IT disaster recovery programs. In particular, the organization needed to refresh and exercise its business continuity and crisis management plans. A more in-depth business impact analysis (BIA) process was developed and executed across the organization.

From an IT Disaster Recovery perspective, the organization needed to create new IT Disaster Recovery Plans for more than 80 critical applications and services representing a mix of on-premise and cloud-hosted environments (Amazon Web Services & Microsoft Azure).

Once plans were completed, we worked with the infrastructure, operations, and product teams to test their recovery plans and capture the necessary evidence for HITRUST certification.

The engagement ended with our consultants coaching the client through HITRUST assessment interviews, assembling required evidence for the assessors, and developing a post-assessment action plan for identified opportunities.

The organization achieved its HITRUST certification with ease. We’ve since assisted them in recertification efforts every two years since the initial work was completed.

Key Activities

  • Review of existing resilience capabilities utilizing our Resiliency Diagnosis® methodology focused on both ISO 22301 and the HITRUST requirements
  • Revision of the organization’s business continuity, crisis management, and IT disaster recovery plans and related documentation to meet HITRUST requirements
  • Discovery meetings with more than 30 stakeholder teams across the organization
  • Established standards and requirements for business continuity, crisis management, and IT disaster recovery exercises
  • Facilitated multiple business continuity & crisis management exercises, documenting lessons learned in line with HITRUST requirements
  • Oversaw the creation of more than 80 disaster recovery plans and the execution of disaster recovery tests for on-premise and cloud-native applications & services
  • Coached internal teams through HITRUST assessment interviews and evidence collection

Outcomes

  • Achievement of HITRUST certification for on-premises and cloud-based systems
  • Completion of multiple business continuity & crisis management exercises within a sustainable process
  • New IT Disaster Recovery Plans for more than 80 applications and services, each thoroughly tested and documented.
  • Improvements to resilience program documentation, plans, and processes for business continuity, crisis management, & IT disaster recovery

Download a PDF copy of this case study






We can help.

Let the experts at Bryghtpath put their decades of experience to work for your organization

We’ve designed, facilitated, and evaluated active shooter exercises for
Fortune 500 organizations around the world.

Our team has the experience, tools, and partnerships to help your organization successfully navigate the rough waters ahead – and ensure your organization is prepared.

I’D LIKE TO TALK TO BRYGHTPATH

Footer

Contact

BRYGHTPATH LLC
+1.612.235.6435

PO Box 131416
Saint Paul, MN 55113
USA


contact@bryghtpath.com

  • Facebook
  • LinkedIn
  • RSS
  • Twitter
  • YouTube

Our Capabilities

  • Business Continuity
    • Business Continuity as a Service (BCaaS)
    • Business Continuity Software
    • Coaching
    • IT Disaster Recovery Consulting Services
    • Resiliency Diagnosis®️
  • Crisis Communications
  • Crisis Management
    • Crisis Exercises
    • Cyber Crisis Exercises
    • Cyber Incident Response Planning
    • Global Security Operations Center (GSOC)
  • Speaking
  • Training

Our Free Courses

Business Continuity 101

Crisis Communications 101

Crisis Management 101

Our Products

After-Action Templates

Books

Business Continuity Plan Templates

Communications & Awareness Collateral Packages

Crisis Plan Templates

Crisis Playbook®

Disaster Recovery Templates

Exercise in a Box®

Exercise in a Day®

Maturity Models

Ready-Made Crisis Plans

Resilience Job Descriptions

Pre-made Processes & Templates

Site Footer

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.


Bryghtpath®, Crisis Management Academy®, Crisis Playbook®, Exercise in a Box®, Exercise in a Day®, Resiliency Diagnosis®, Resilience Operating Model®
and their respective logos are registered trademarks of Bryghtpath LLC in the United States and other countries.


About Bryghtpath LLC | Disclaimer | Privacy | Status Page | Terms of Use

Proudly powered by Mai Theme, the Genesis Framework, and Wordpress.