HITRUST publishes an annual Trust Report. Last year, my colleague Richard Rieben gave a great breakdown on what could be learned about overall cybersecurity maturity from the 2025 report. 2026, however, has been a complex and revealing year for cybersecurity in general and the assurance space specifically, so I thought it would be good to see what’s been revealed by the fruits of HITRUST’s labors. As an experienced HITRUST assessor, here’s what stood out to me as I reviewed this with my own work and my client’s needs in mind.
With the release of the HITRUST 2026 trust report also came HITRUST’s latest CSF (Common Security Framework), v11.8.0, and we can see from this how the report was used to keep HITRUST relevant, current, and useful. I want to take a moment to look at the identified trends since last year and the ways HITRUST is combating not just the threats themselves, but endemic problems with static frameworks and damaged trust.
The “State of the Union” Per HITRUST
HITRUST continues to see great numbers in terms of breaches for certified organizations (99.62% of HITRUST-certified environments reported zero data breaches in the period between the 2025 report and the 2026 report). That said, two major challenges have taken the spotlight: supply chain vulnerabilities and third-party report weaknesses.
The “Trust Crisis” – Vendor & Third-Party Risk
The 2026 HITRUST report highlights an alarming trend: nearly 30% of all reported security incidents in the prior year involved supply chain problems, nearly double what was seen the year before. The heavy reliance on self-attestation questionnaires and point-in-time surveys is providing neither an accurate picture of the vendor’s security posture nor a reliable image of the reality of a situation.
Even when a true third-party report is used, there are still concerns. With the 2026 stories of inaccurate reports from questionable assessor firms, poorly done third-party assessments, and stale frameworks, you have a recipe for a potential disaster, even when an organization is running its own security processes well. Inherited controls only provide security when the inherited systems are up to the standards required and the processes in place are time-tested and consistently applied. When working on engagements, I often find clients are unsure in this era of heightened need for vendor security: how to reconcile enhanced needs with a slew of third-party reports, security questionnaires, and vendor trust websites.
Inheritance, as well, continues to be a significant factor, with over 70% of HITRUST’s 2025 assessments inheriting controls from cloud providers. When relying on other attestations, the importance of accuracy of the provider’s reports is essential.

The “Other” Growing Concern: LLM & AI
For the first time in 2026, HITRUST’s intelligence engine is explicitly tracking threats aimed at AI and Machine learning, leveraging MITRE ATLAS data and indicators alongside the MITRE ATT&CK data. As everyone is aware, generative AI tools have moved into production in nearly every industry, from healthcare and finance to defense and marketing.
This is compounded when these two problems are viewed together: many traditional vendor questionnaires and frameworks have no inclusion of AI-related risks, and many have it added in as poorly-fitting “bonus” questions, leading to a lack of awareness of both the organization’s use of machine learning and their supplier’s use of it.
From my experience, organizations adding AI are doing so without a history or an industry standard to rely upon. Accurately assessing risks and control effectiveness can be somewhat blind. This is where relying on a vetted existing framework can be very beneficial.
How CSF v11.8.0 Responds to the 2026 Threat Data
CSF v11.8.0 was released on May 7, 2026, part of an aggressive move by HITRUST to keep the framework current. It’s not an across-the-board redesign, but it is a point release designed to keep the framework from getting stale and to address emerging threats expediently. While some frameworks, questionnaires, and tools can lag well behind the reality of today’s threats, the aggressive timing of new CSF releases provides a level of confidence that the data collected is driving quick change at a framework level.
V11.8.0, informed by the most recent threat report, has adapted to recent data and represents up-to-date requirements and controls to address trending and emerging threats. Three noticeable changes were implemented as the landscape changed; 2 of them were sources, and one was the refinement of the framework.

Expanding the Data Sets: New Standards, New Coverage
For the first time, HITRUST has incorporated the OWASP Top 10 for LLMs into the CSF, working to build a framework that acknowledges that AI is no longer a niche IT side project and the threats and vulnerabilities associated with it aren’t afterthoughts.
Additionally, v11.8.0 also added a new handful of source mappings to address regional privacy rules and a trend towards continuous monitoring. Specifically, the incorporation of NIST SP 800-137 helps to close the gap between static audits and real-time awareness, while ISO/IEC 29100:2024 and Virginia SEC530 provide broader coverage for global privacy and regional IT security standards.
Making Informed Changes
With the integration of new threat telemetry and customer feedback used to drive updates, v11.8.0 represents an assessment framework based on real-world threat assessments, strong underlying controls sets, and continues to be one of the most aggressively maintained and applicable frameworks for many industries. Language and intent of the e1, i1, and r2 control sets have been adjusted to reflect the present, with several controls adjusted in language and specific testing.
The Results & the Reality
When you put these two documents side by side, the trust report and the new version of the framework, something becomes very clear. Static frameworks and addressing yesterday’s threats simply aren’t the best plan. The landscape is changing faster than ever before, and a 5-10 year update cycle and a head-in-the-sand approach to new threats put an organization and an organization’s data at risk. CISOs, Security Directors, and Privacy Officers looking for real-time data and a current framework to address current problems might well benefit from HITRUST’s latest report and their latest framework.
If you’re navigating a HITRUST engagement or trying to determine how CSF v11.8.0 affects your upcoming assessment, reach out to our audit team at Linford & Company. We’re happy to help you map out your compliance roadmap.
