Healthcare HITRUST & SOC2 Audit
Budget / SalaryHourly project
TypeFreelance project
LocationRemote
Posted1 hour ago
Our healthcare organization needs a seasoned compliance professional to run a full-scale audit against both the HITRUST CSF and SOC 2 frameworks. Operating in a heavily regulated environment, we handle protected health information daily, so the engagement must probe deeply into privacy, security, and overall risk management controls.
What I expect from you is an end-to-end assessment that pinpoints every control gap, ranks the related risks, and guides us all the way to certification readiness. Experience with the HITRUST MyCSF portal, AICPA Trust Services Criteria, and HIPAA-aligned controls is essential because the work will involve mapping requirements across those standards.
To keep the project on track, these concrete deliverables will be required:
• A documented gap analysis for both frameworks, clearly separating “pass” and “needs improvement”.
• A prioritized remediation roadmap with estimated effort, owners, and timelines.
• Draft language or updates for any policies, procedures, and evidence requests uncovered during testing.
• Final readiness report that our external assessor can rely on without repeat walkthroughs.
Access to our existing documentation, GRC ticketing platform, and internal SMEs will be provided once an NDA is in place. I’ll be available throughout for quick clarifications, but I expect you to drive the schedule and provide status updates so leadership can see measurable progress.
If your background includes successful healthcare HITRUST validations and SOC 2 reports—and you’re comfortable coordinating remotely across time zones—let’s get started.
What I expect from you is an end-to-end assessment that pinpoints every control gap, ranks the related risks, and guides us all the way to certification readiness. Experience with the HITRUST MyCSF portal, AICPA Trust Services Criteria, and HIPAA-aligned controls is essential because the work will involve mapping requirements across those standards.
To keep the project on track, these concrete deliverables will be required:
• A documented gap analysis for both frameworks, clearly separating “pass” and “needs improvement”.
• A prioritized remediation roadmap with estimated effort, owners, and timelines.
• Draft language or updates for any policies, procedures, and evidence requests uncovered during testing.
• Final readiness report that our external assessor can rely on without repeat walkthroughs.
Access to our existing documentation, GRC ticketing platform, and internal SMEs will be provided once an NDA is in place. I’ll be available throughout for quick clarifications, but I expect you to drive the schedule and provide status updates so leadership can see measurable progress.
If your background includes successful healthcare HITRUST validations and SOC 2 reports—and you’re comfortable coordinating remotely across time zones—let’s get started.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.