Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Microsoft adds HITRUST CSF validation to help healthcare professionals with cloud adoption – onmsft.com

Microsoft adds HITRUST CSF validation to help healthcare professionals with cloud adoption – onmsft.com

Kareem Anderson Kareem Anderson
April 7, 2015
1 min read

Microsoft adds HITRUST CSF validation to it long history of health care certifications

\

Dr. Mohamed Ayad, Industry Specialist, U.S. Health and Sciences at Microsoft, took to the blogs today to discuss Microsoft’s most recent achievement in healthcare certification. Mohamed also took some time to cover the storied history Microsoft has with healthcare.

\

\

I hope you guys are ready for some alphabet soup because Microsoft and healthcare organizations will have you drowning in letters and acronyms by the end of this piece.

\

\

As more and more tech companies begin to lean on the cloud and offer their integrated approach to health, fitness, and well-being, it’s important to understand the history healthcare has with the cloud. Mohamed makes note, “Microsoft was the first major cloud services provider to offer regulated entities an industry co-developed HIPAA Business Associate Agreement. This BAA, jointly developed by a consortium of academic medical centers, memorializes Microsoft’s compliance commitment to implementing the physical, technical and administrative safeguards and breach notification requirements set forth in HIPAA/HITECH.”

\

\

With over 10 million enterprise users from hundreds of organizations all signed with BAA, it’s a rather impressive feat Microsoft can tuck under its belt. Some businesses that have signed Microsoft’s HIPPA BAA include Thomas Jefferson University, Mihills Webb Medical, Steward Healthcare. More recently, the Department of Health and Human Services announced its intent to move 125,000 seats over to using certified Office 365. Wins such as these go a long way in establishing Microsoft’s trustworthiness in regards to the healthcare industries. Companies like Google and Apple are currently seeking to establish this level of trust with their new cloud-connected offerings.

\

Microsoft wasn’t ready to just hang their hats on the BAA or even just being HIPPA/HITECH compliant. The BAA was only one large piece of a much larger industry puzzle, however. The second and arguably more important is the transparency with which businesses who have access to healthcare data are utilizing it. Microsoft is pushing service providers that claim to be HIPPA compliant to be more transparent with how they validate their compliance.

\

Microsoft adds HITRUST CSF validation to it long history of health care certifications

\

Enter HITRUST (CSF) or the Health Information Trust Alliance Common Security Framework. HITURST is designed to help healthcare companies who are reviewing multiple certification standards as they intend to move toward the cloud. Mohamed sheds some more light on the topic. “Their goal was to create a CSF with an accompanying assessment and certification process that would reduce the complexity of managing multiple standards and regulations, including federal (HIPAA, HITECH), third party (PCI, COBIT) and government (NIST, FTC). The HITRUST CSF is modeled after the National Institute of Standards and Technology’s Computer Security Division’s NISTIR 7358 standard – Program Review for Information Security Management Assistance (PRISMA), where an organization can demonstrate 5 different levels of “maturity” for a particular security requirement.” HITRUST partners include:

\

    \

  • Health Care Service Corporation
  • \

  • Humana, Inc.
  • \

  • Children’s Medical Center of Dallas
  • \

  • IMS Health
  • \

  • Highmark Inc.
  • \

  • Anthem, Inc.
  • \

  • UnitedHealth Group
  • \

  • Express Scripts, Inc.
  • \

  • McKesson Corporation
  • \

  • Kaiser Permanente
  • \

  • Blue Cross Blue Shield of Massachusetts
  • \

  • Hospital Corporation of America
  • \

  • CVS Caremark
  • \

\

Microsoft adds HITRUST CSF validation to it long history of health care certifications

\

Now healthcare organizations can rely on the CSF report produced by HITRUST certified assessors to speed up the cloud security vetting processes for most healthcare businesses. Microsoft has also added another ‘first’ notch on its cloud belt. Microsoft Office 365 has undergone the assessment using the CSF and was awarded the highest possible CSF rating — a five by a certified HITRUST assessor. The assessment was initiated by Centura Health, which is 18,000 professionals, 15 hospitals, and 11 more affiliate hospitals, as well as 100 physician clinics working in Colorado and Kansas. Centura Health used the assessment as part of their overall strategy in finally choosing Microsoft and Office 365 as their preferred cloud and office solutions.

\

\

“For Centura Health, it is important that our business partners are securing our information to the same standards that we adhere to,” said Kris Kistler, director, data security, Centura Health. “We believe that the HITRUST Common Security Framework (CSF) is the most comprehensive security framework available.”

\

\

For healthcare organizations contemplating a move to Office 365, Microsoft is ready to sign a HIPAA BAA, as well as provide a CSF assessment report and they are also ready to be as transparent as necessary.

\

Share This Post:

Share this article:
Tags:
Healthcare Office 365
Previous Article A university professor looks to teach the lost art of Microsoft Excel – onmsft.com Next Article Global Build tour is set to visit 23 cities in 17 countries | On MSFT

Related Articles

Chrome and Gemini icons representing Gemini Live voice assistant integration in Chrome

Chrome tests Gemini Live voice assistant in a floating overlay panel

March 14, 2026

Chrome’s Organizer feature may sync Gemini and AI conversations across devices

March 14, 2026

After Chrome, Edge tests launching the browser automatically when you sign into Windows

March 13, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Chrome tests Gemini Live voice assistant in a floating overlay panel
  • Chrome’s Organizer feature may sync Gemini and AI conversations across devices
  • After Chrome, Edge tests launching the browser automatically when you sign into Windows
  • iPhone Fold Latest Rumors: Display, Cameras, RAM and Price Details Revealed
  • Samsung fears first mobile operating loss due to memory price surge

Recent Comments

No comments to show.
OnMSFT.com

OnMSFT.com covers Microsoft news, reviews, and how-to guides. Formerly known as WinBeta, we have been your source for Microsoft news since 1998.

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Chrome tests Gemini Live voice assistant in a floating overlay panel
  • Chrome’s Organizer feature may sync Gemini and AI conversations across devices
  • After Chrome, Edge tests launching the browser automatically when you sign into Windows
  • iPhone Fold Latest Rumors: Display, Cameras, RAM and Price Details Revealed
  • Samsung fears first mobile operating loss due to memory price surge

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy