Overview
The Vanta and HITRUST MyCSF integration provides a seamless connection between Vanta's and HITRUST's MyCSF assessment application. This integration automates key compliance processes, including:
- Automatic Control Syncing: Ensures Vanta assessments remain current with your HITRUST assessment scope.
- Evidence Export: Allows users to export completed evidence back into MyCSF for review by the HITRUST QA team after an audit.
This integration streamlines HITRUST compliance by reducing manual effort, improving accuracy, and ensuring a consistent connection between platforms.
Step 1: Connect to MyCSF
Vanta requires an API Key and User Name from MyCSF to enable the integration. These credentials are used for secure read-and-write API requests to retrieve controls and import evidence.
Generate an API Key and User Name in MyCSF
Official HITRUST guidance on creating an API user.
Follow these steps to generate the required credentials in MyCSF:
- Log in to MyCSF using an Administrator Account that can manage "Subscribers."
- Navigate to Administration > Subscribers.
- Click "NEW API USER."
- Under Access Type, select "Read and Write" and click "CREATE API USER."
- A User Name and API Key will be generated and displayed on your screen.
- Securely store these values as they are needed to connect Vanta to MyCSF.
- Note: If the API key is lost, it will not be retrievable again. If needed, you must create a new API User.
Step 2: Configure the Connection in Vanta
- Log in to Vanta.
- To access the connection flow, which can be accessed from:
- On the HITRUST framework page, click the connection banner OR
- On the Integration page, click Connect from the HITRUST MyCSF integration card.
- Enter the API Key and User Name generated from MyCSF and click Next
- Select the HITRUST assessment you want to sync into Vanta and click Next
- Validate your selection then select Done.
Please note: A “Syncing requirements from HITRUST MyCSF. This may take some time.” dialog will appear. Once the sync is complete, all the controls in scope for your HITRUST assessment will be uploaded to Vanta, and relevant tests and document mappings will be prepopulated for you.
Export Evidence to MyCSF
After completing your compliance work in Vanta and obtaining auditor validation, you can export evidence back to MyCSF:
- Navigate to the Audit section in Vanta.
- Open your ongoing HITRUST audit
- Click Export followed by Open to export to MyCSF
- Review the list of evidence items to be exported:
- Policies
- Tests
- Documents
- Confirm that you are happy with what will be exported to MyCSF
- Click Export to MyCSF to initiate the export process.
If you need additional assistance, contact support@vanta.com