Skip to main content
Category: HITRUST Assessment Types

HITRUST Results Distribution System

Also known as: RDS, RDS, Results Distribution System, HITRUST RDS
Simply put

The HITRUST Results Distribution System (RDS) is a secure, automated platform offered by HITRUST that lets organizations share their HITRUST assessment results electronically and in real time with other parties who need to review them. It is designed to replace slower, manual methods of distributing assessment results. It is a tool for exchanging assurance information and is not itself a legal requirement or a substitute for HIPAA compliance.

Formal definition

RDS is a HITRUST-operated secure electronic platform that enables assessed entities to distribute their HITRUST CSF assessment results to designated relying parties, who can consume those results in real time rather than through manual, one-off exchanges. It functions as a mechanism for streamlining the sharing and consumption of information assurance results derived from the HITRUST CSF, a control framework that harmonizes 60+ frameworks and standards. Note that RDS is a proprietary offering of HITRUST, a private organization, and pertains to the distribution of HITRUST assessment results; use of RDS or possession of HITRUST assessment results does not by itself establish compliance with the HIPAA Privacy, Security, Breach Notification, or Enforcement Rules, which are enforced by HHS OCR. Practitioners should verify current platform capabilities and applicable HITRUST CSF version against HITRUST's current documentation.

Why it matters

Sharing information assurance results with partners, customers, and other third parties has traditionally been a slow, manual process, often involving one-off exchanges of documents. The HITRUST Results Distribution System (RDS) is designed to address that friction by letting an assessed entity distribute its HITRUST CSF assessment results securely and electronically to designated relying parties who can consume them in real time. For organizations that manage large numbers of vendor or partner relationships, this can reduce the administrative overhead of demonstrating assurance repeatedly to different parties.

For healthcare organizations and their vendors, tools like RDS fit into broader third-party risk management and due diligence workflows. Because many covered entities and business associates rely on HITRUST CSF assessments as one signal of a partner's control maturity, a streamlined distribution channel can make it easier to request, receive, and review those results as part of evaluating a relationship.

It is important to keep RDS in perspective. RDS is a proprietary offering of HITRUST, a private organization, and it pertains only to the distribution of HITRUST assessment results. Using RDS, or receiving HITRUST results through it, does not by itself establish compliance with the HIPAA Privacy, Security, Breach Notification, or Enforcement Rules, which are enforced by HHS OCR. Organizations should treat HITRUST results as one input into their compliance and risk decisions, not as a substitute for their own obligations under HIPAA, the HITECH Act, or applicable state law.

Who it's relevant to

Assessed entities holding HITRUST results
Organizations that have completed a HITRUST CSF assessment may use RDS to distribute their results securely and electronically to designated relying parties, potentially reducing the effort of responding to repeated, individual requests. Possessing or sharing these results does not by itself demonstrate HIPAA compliance.
Relying parties and third-party risk teams
Covered entities, business associates, and others evaluating a partner's controls may be designated as relying parties who can consume shared HITRUST results in real time. Such results should be treated as one input into due diligence, alongside contractual safeguards such as business associate agreements where applicable, and not as a stand-alone conclusion about a partner's HIPAA obligations.
Vendor management and procurement staff
Teams that manage large vendor portfolios may find a standardized distribution channel useful for collecting and reviewing assurance information more efficiently. They should confirm current RDS capabilities and the applicable HITRUST CSF version against HITRUST's documentation, and recognize that HITRUST assessment results address the HITRUST CSF, not HIPAA regulatory requirements directly.
Compliance and privacy/security officers
Officers responsible for HIPAA compliance should understand where RDS fits within their assurance and risk program. Because RDS is a private HITRUST offering and not a legal requirement, its use does not replace obligations under the HIPAA Privacy, Security, Breach Notification, or Enforcement Rules enforced by HHS OCR, nor any additional requirements imposed by the HITECH Act or state law.

Inside RDS

Assessment Report Delivery
The RDS is HITRUST's mechanism for electronically delivering finalized assessment results, such as certification reports and related deliverables, to organizations that have undergone a HITRUST CSF assessment. It serves as the channel through which results are made available rather than being a compliance control in itself.
Controlled Distribution to Authorized Parties
The system typically allows the assessed organization to manage how and with whom its results are shared, supporting distribution to relevant stakeholders such as business partners or clients under access controls set through HITRUST's platform.
Report Types and Deliverables
Results distributed generally reflect the specific HITRUST CSF assessment type performed (for example, validated or certified assessments). The exact report formats, contents, and deliverables should be confirmed against the current HITRUST CSF version and HITRUST's current program documentation, as these are subject to change.
Relationship to HITRUST, Not HIPAA
The RDS is a service provided by HITRUST, a private organization, in connection with the HITRUST CSF, a private certifiable control framework. It is not a HIPAA regulatory mechanism and is not administered by HHS OCR.

Common questions

Answers to the questions practitioners most commonly ask about RDS.

Does receiving a report through the HITRUST Results Distribution System mean an organization is HIPAA compliant?
No. The RDS is a mechanism for securely delivering HITRUST assessment results and certification reports; it does not establish or confirm HIPAA compliance. HITRUST is a private organization and the HITRUST CSF is a certifiable control framework, not a legal requirement. HIPAA is a US federal law enforced by HHS OCR, and compliance is determined by adherence to the Privacy, Security, Breach Notification, and Enforcement Rules rather than by any report distributed through the RDS. A HITRUST report may help demonstrate that certain controls are in place, but it does not by itself satisfy HIPAA obligations.
Is the RDS itself a security control or safeguard that satisfies a HIPAA Security Rule requirement?
No. The RDS is a distribution and access platform for assessment results, not a required or addressable implementation specification under the HIPAA Security Rule. The Security Rule's administrative, physical, and technical safeguards apply to how a covered entity or business associate protects ePHI in its own environment. Using the RDS to share a report does not, on its own, fulfill any specific Security Rule requirement, and organizations should not treat participation in the RDS as a substitute for implementing their own safeguards.
How does an organization typically make its HITRUST results available to a third party through the RDS?
Generally, an organization uses the RDS to grant a requesting party access to its assessment results or certification report rather than sending the report directly. The exact steps, access controls, and options available depend on the current HITRUST platform and CSF version, so organizations should confirm the specific process and features against current HITRUST documentation before relying on them.
Who controls whether a business partner can see results distributed through the RDS?
In most cases the assessed organization controls whether and how its results are shared. Because HITRUST is a private framework and not a legal mandate, distribution decisions are governed by the organization's own agreements and HITRUST's platform terms rather than by HIPAA. Where the results relate to ePHI handled under a business associate relationship, any obligation to share information is generally driven by the underlying contract or business associate agreement, not by the RDS itself.
Should an organization rely solely on a report received through the RDS to assess a vendor's HIPAA posture?
It should not rely on it in isolation. A report delivered through the RDS can be one input into a broader due diligence and vendor management process, but HIPAA obligations attach through defined relationships such as business associate agreements. Organizations typically supplement a HITRUST report with their own review of the vendor's safeguards, contractual commitments, and any additional requirements that state law or the HITECH Act may impose beyond HIPAA.
What are the limits of what an RDS-distributed report can tell a recipient?
A report distributed through the RDS generally reflects the scope, controls, and point in time covered by the underlying HITRUST assessment. It does not confirm ongoing HIPAA compliance, does not cover controls or systems outside the assessment scope, and does not replace the recipient's own compliance obligations. Recipients should confirm the assessment scope, the applicable CSF version, and the report's currency, and verify any compliance conclusions against the relevant regulatory requirements rather than assuming the report addresses them.

Common misconceptions

Receiving a report through the RDS demonstrates HIPAA compliance.
The RDS only distributes HITRUST assessment results. HITRUST certification is a private-sector attestation and is not a legal requirement; it does not by itself establish HIPAA compliance. HIPAA obligations are enforced by HHS OCR under the Privacy, Security, Breach Notification, and Enforcement Rules, independent of any HITRUST deliverable.
The RDS is a HIPAA-mandated or government-operated system.
The RDS is operated by HITRUST, a private organization, in support of the HITRUST CSF. No HIPAA rule requires its use, and it is not part of the federal regulatory framework administered by HHS OCR.
Sharing results through the RDS transfers or discharges an organization's own compliance obligations.
Distributing an assessment report does not alter the legal obligations that attach to covered entities, business associates, or subcontractors. Those obligations, including any that flow through business associate agreements, remain in effect regardless of how or whether HITRUST results are shared.

Best practices

Treat RDS-distributed results as supporting evidence of a HITRUST assessment, not as proof of HIPAA compliance, and maintain a separate, independent HIPAA compliance program aligned to the Privacy, Security, and Breach Notification Rules.
Verify the current report types, formats, and distribution features against the current HITRUST CSF version and HITRUST's program documentation, as these details are subject to change.
Use the system's access controls to limit distribution to authorized recipients only, and document who was granted access and for what purpose.
Confirm that any reliance on a shared report by business partners is governed by appropriate contractual arrangements, and remember that business associate agreements and their obligations exist independently of the RDS.
When responding to third-party requests, clarify in writing that a distributed HITRUST report reflects a point-in-time private-sector assessment and does not substitute for verifying current regulatory compliance.
Coordinate with legal and privacy/security officers to confirm whether state law, the HITECH Act, or other frameworks impose additional requirements beyond what any HITRUST deliverable addresses.