HITRUST Results Distribution System
The HITRUST Results Distribution System (RDS) is a secure, automated platform offered by HITRUST that lets organizations share their HITRUST assessment results electronically and in real time with other parties who need to review them. It is designed to replace slower, manual methods of distributing assessment results. It is a tool for exchanging assurance information and is not itself a legal requirement or a substitute for HIPAA compliance.
RDS is a HITRUST-operated secure electronic platform that enables assessed entities to distribute their HITRUST CSF assessment results to designated relying parties, who can consume those results in real time rather than through manual, one-off exchanges. It functions as a mechanism for streamlining the sharing and consumption of information assurance results derived from the HITRUST CSF, a control framework that harmonizes 60+ frameworks and standards. Note that RDS is a proprietary offering of HITRUST, a private organization, and pertains to the distribution of HITRUST assessment results; use of RDS or possession of HITRUST assessment results does not by itself establish compliance with the HIPAA Privacy, Security, Breach Notification, or Enforcement Rules, which are enforced by HHS OCR. Practitioners should verify current platform capabilities and applicable HITRUST CSF version against HITRUST's current documentation.
Why it matters
Sharing information assurance results with partners, customers, and other third parties has traditionally been a slow, manual process, often involving one-off exchanges of documents. The HITRUST Results Distribution System (RDS) is designed to address that friction by letting an assessed entity distribute its HITRUST CSF assessment results securely and electronically to designated relying parties who can consume them in real time. For organizations that manage large numbers of vendor or partner relationships, this can reduce the administrative overhead of demonstrating assurance repeatedly to different parties.
For healthcare organizations and their vendors, tools like RDS fit into broader third-party risk management and due diligence workflows. Because many covered entities and business associates rely on HITRUST CSF assessments as one signal of a partner's control maturity, a streamlined distribution channel can make it easier to request, receive, and review those results as part of evaluating a relationship.
It is important to keep RDS in perspective. RDS is a proprietary offering of HITRUST, a private organization, and it pertains only to the distribution of HITRUST assessment results. Using RDS, or receiving HITRUST results through it, does not by itself establish compliance with the HIPAA Privacy, Security, Breach Notification, or Enforcement Rules, which are enforced by HHS OCR. Organizations should treat HITRUST results as one input into their compliance and risk decisions, not as a substitute for their own obligations under HIPAA, the HITECH Act, or applicable state law.
Who it's relevant to
Inside RDS
Common questions
Answers to the questions practitioners most commonly ask about RDS.