HITRUST Secrets: AI & Quantum Readiness, Claude Security Risk, and myCSF Report Center Updates
HITRUST Secrets
0:00 / 0:00
HITRUST Secrets: AI & Quantum Readiness, Claude Security Risk, and myCSF Report Center Updates
76 просмотров · 12 дней назад
HITRUST Secrets
74 подписчика
76 просмотров · 12 дней назад
How should security teams evaluate AI connectors and plugins such as Claude MCP?
In this episode of HITRUST Secrets, we host a wide-ranging discussion on AI security, third-party risk, encrypted email, and the evolving HITRUST framework.
🔐 AI & MCP Security
The group discusses how to evaluate AI connectors and plugins just like any other software—including what the connector does, what permissions it requires, developer assurance, update practices, third-party access, and how to monitor for expected versus suspicious activity.
🤖 AI vs. Quantum Security
We also discuss how HITRUST addresses AI through separate AI risk and AI security components, informed by NIST and ISO guidance, as well as the current state of quantum-ready encryption guidance from NSA and NIST.
📧 Encrypted Email & Healthcare
What does HITRUST actually require for email encryption? We explore the baseline requirements and discuss Paubox as an always-on TLS solution that automatically encrypts email without requiring recipients to use a portal.
📊 What's New in HITRUST
Dennis Palmer explains how HITRUST has expanded beyond HIPAA through selectable authoritative sources, Insights Reports, NIST CSF 2.0, and other add-ons. We also preview the retroactive rollout of Report Center v2, including watermarking and improved visibility into shared reports.
Plus, a preview of next week's Third Party Risk Association discussion and a look at the new myCSF Beyond the Basics content covering cloning and replicating work.
Chapters
00:00 Welcome and Introductions
00:36 AI vs Quantum Controls
02:11 AI Use vs AI Services
03:58 Plugins and Connectors Risks
06:43 Updates and Third Party Access
09:46 Managed Risk and Anomaly Tracking
13:11 Encrypted Email in Healthcare
15:36 Paubox Overview and Trial
18:48 Who Uses HITRUST Today
21:28 HITRUST Beyond HIPAA
23:45 Insights Report Addons
24:55 NIST CSF 2.0 Option
26:27 Report Center V2 Launch
27:49 Watermarked Sharing Controls
29:02 Dashboard Trust Benefits
31:34 Retroactive Rollout Details
32:53 Pilot Feedback Banter
34:15 AFCEA Learning Resources
36:06 TPRA Next Week Preview
38:37 Cloning Replicating Video
39:46 Wrap Up And Signoff
#HITRUST #AISecurity #MCP #Claude #Cybersecurity #ThirdPartyRisk #InfoSec