ELEKS

Andrew Park, Healthcare Technology Lead at ELEKS, recognized the need for HITRUST certification to compete in the US healthcare market. Increasingly, prospects were asking for HITRUST, and ELEKS had contractual obligations with several clients to get certified.  

Andrew turned to Oleksandr Pluzhnikov, Head of Cybersecurity at ELEKS, to begin the process. Oleksandr and his team had previously achieved other certifications including SOC 2 Type II, ISO 9001, and ISO 27001 with the help of their existing compliance vendor, so as usual, they began working with the vendor to collect evidence for HITRUST.

Unfortunately, challenges related to scope definition and communication made the HITRUST audit process more complex than expected, requiring multiple attempts to align with certification requirements.

However, when the HITRUST e1 assessment was released, the ELEKS team decided to try again with a different vendor.

Andrew explained, “we saw e1 as an opportunity to gain entry into the HITRUST certification process without it being totally exhaustive and time-consuming.”

They were looking for a compliance partner with HITRUST expertise that would offer flexible, end-to-end support and an efficient workflow. After evaluating three vendors, Andrew, Oleksandr, and the team selected Thoropass to help them get the job done.

Oleksandr explained, “before we entered the agreement, our Thoropass representative spent a lot of time ensuring that we understood all the details and had a common vision. This alignment was key for us.”

Thoropass’ flexible support and HITRUST expertise helped ELEKS tailor the process to their needs

Implementation was painless for the ELEKS team. Unlike their previous vendor, Thoropass’ customer support team provided transparent scoping and timelines from the beginning.

Speaking to this, Oleksandr explained “we agreed on the timeline while we were signing the agreement. It was very straightforward, clear, and all of the tasks were definite. We never had a situation where we were waiting on something from Thoropass that wasn’t delivered in time.”

ELEKS had an end-of-year certification deadline, and Thoropass’ Customer Success Manager (CSM) kept the team on track throughout the process with regular meetings and communication. When certain milestones were delayed, the CSM helped them pivot.

According to Oleksandr Pluzhnikov, “we had all the required attention and resources from the Thoropass side and it was pretty efficient for our team. Overall, it went smoothly.”

Unlike other frameworks, the HITRUST certification process is highly prescriptive. Evidence must be collected and uploaded to HITRUST’s platform, MyCSF. But the Thoropass platform integrates with MyCSF, avoiding duplication of work.

Achieved HITRUST e1 certification by their deadline, unlocking new US healthcare opportunities

The ELEKS team achieved HITRUST e1 certification and met their deadline, fulfilling their contractual obligations and opening up opportunities in the US healthcare market. 

Unlike with their previous attempts, through alignment sessions with the Thoropass team, ELEKS was able to accurately scope their assessment. Speaking to the importance of this, Andrew stated, “scope was the key to success. It was one of the reasons why we didn’t succeed previously, so we spent a lot of time, even before we signed a contract, talking about scope.”

Compliance is more than checking a box

According to Oleksandr, the number one-lesson was to find the right partner. For ELEKS, this meant flexibility.

The Thoropass compliance experts evaluated ELEKS’ current security processes, and worked with them instead of insisting on changing them. Recognizing that ELEKS already had robust controls in place, the Thoropass team used their deep knowledge of HITRUST to fully explain the requirements and create a tailored plan. For the ELEKS team, this personalized service made all the difference.

Product

HITRUST

Industry

Software Engineering

Company size

1000-5000

Location

Estonia