HITRUST 2026 Trust Report: From Supply Chain Attacks to LLM Risks, What CSF v11.8.0 Means for Compliance

By Brian Sandenaw Published on August 19, 2026
In this Article
What to know from the HITRUST 2026 trust report

HITRUST publishes an annual Trust Report. Last year, my colleague Richard Rieben gave a great breakdown on what could be learned about overall cybersecurity maturity from the 2025 report. 2026, however, has been a complex and revealing year for cybersecurity in general and the assurance space specifically, so I thought it would be good to see what’s been revealed by the fruits of HITRUST’s labors. As an experienced HITRUST assessor, here’s what stood out to me as I reviewed this with my own work and my client’s needs in mind.

With the release of the HITRUST 2026 trust report also came HITRUST’s latest CSF (Common Security Framework), v11.8.0, and we can see from this how the report was used to keep HITRUST relevant, current, and useful. I want to take a moment to look at the identified trends since last year and the ways HITRUST is combating not just the threats themselves, but endemic problems with static frameworks and damaged trust.

The “State of the Union” Per HITRUST

HITRUST continues to see great numbers in terms of breaches for certified organizations (99.62% of HITRUST-certified environments reported zero data breaches in the period between the 2025 report and the 2026 report). That said, two major challenges have taken the spotlight: supply chain vulnerabilities and third-party report weaknesses.

The “Trust Crisis” – Vendor & Third-Party Risk

The 2026 HITRUST report highlights an alarming trend: nearly 30% of all reported security incidents in the prior year involved supply chain problems, nearly double what was seen the year before. The heavy reliance on self-attestation questionnaires and point-in-time surveys is providing neither an accurate picture of the vendor’s security posture nor a reliable image of the reality of a situation.

Even when a true third-party report is used, there are still concerns. With the 2026 stories of inaccurate reports from questionable assessor firms, poorly done third-party assessments, and stale frameworks, you have a recipe for a potential disaster, even when an organization is running its own security processes well. Inherited controls only provide security when the inherited systems are up to the standards required and the processes in place are time-tested and consistently applied.  When working on engagements, I often find clients are unsure in this era of heightened need for vendor security: how to reconcile enhanced needs with a slew of third-party reports, security questionnaires, and vendor trust websites.

Inheritance, as well, continues to be a significant factor, with over 70% of HITRUST’s 2025 assessments inheriting controls from cloud providers. When relying on other attestations, the importance of accuracy of the provider’s reports is essential.

 

LLM and AI concerns

The “Other” Growing Concern: LLM & AI

For the first time in 2026, HITRUST’s intelligence engine is explicitly tracking threats aimed at AI and Machine learning, leveraging MITRE ATLAS data and indicators alongside the MITRE ATT&CK data. As everyone is aware, generative AI tools have moved into production in nearly every industry, from healthcare and finance to defense and marketing.

This is compounded when these two problems are viewed together: many traditional vendor questionnaires and frameworks have no inclusion of AI-related risks, and many have it added in as poorly-fitting “bonus” questions, leading to a lack of awareness of both the organization’s use of machine learning and their supplier’s use of it.

From my experience, organizations adding AI are doing so without a history or an industry standard to rely upon. Accurately assessing risks and control effectiveness can be somewhat blind. This is where relying on a vetted existing framework can be very beneficial.

How CSF v11.8.0 Responds to the 2026 Threat Data

CSF v11.8.0 was released on May 7, 2026, part of an aggressive move by HITRUST to keep the framework current. It’s not an across-the-board redesign, but it is a point release designed to keep the framework from getting stale and to address emerging threats expediently. While some frameworks, questionnaires, and tools can lag well behind the reality of today’s threats, the aggressive timing of new CSF releases provides a level of confidence that the data collected is driving quick change at a framework level.

V11.8.0, informed by the most recent threat report, has adapted to recent data and represents up-to-date requirements and controls to address trending and emerging threats. Three noticeable changes were implemented as the landscape changed; 2 of them were sources, and one was the refinement of the framework.

 

Expanded HITRUST converage

Expanding the Data Sets: New Standards, New Coverage

For the first time, HITRUST has incorporated the OWASP Top 10 for LLMs into the CSF, working to build a framework that acknowledges that AI is no longer a niche IT side project and the threats and vulnerabilities associated with it aren’t afterthoughts.

Additionally, v11.8.0 also added a new handful of source mappings to address regional privacy rules and a trend towards continuous monitoring. Specifically, the incorporation of NIST SP 800-137 helps to close the gap between static audits and real-time awareness, while ISO/IEC 29100:2024 and Virginia SEC530 provide broader coverage for global privacy and regional IT security standards.

Making Informed Changes

With the integration of new threat telemetry and customer feedback used to drive updates,  v11.8.0 represents an assessment framework based on real-world threat assessments, strong underlying controls sets, and continues to be one of the most aggressively maintained and applicable frameworks for many industries. Language and intent of the e1, i1, and r2 control sets have been adjusted to reflect the present, with several controls adjusted in language and specific testing.

The Results & the Reality

When you put these two documents side by side, the trust report and the new version of the framework, something becomes very clear. Static frameworks and addressing yesterday’s threats simply aren’t the best plan. The landscape is changing faster than ever before, and a 5-10 year update cycle and a head-in-the-sand approach to new threats put an organization and an organization’s data at risk. CISOs, Security Directors, and Privacy Officers looking for real-time data and a current framework to address current problems might well benefit from HITRUST’s latest report and their latest framework.

If you’re navigating a HITRUST engagement or trying to determine how CSF v11.8.0 affects your upcoming assessment, reach out to our audit team at Linford & Company. We’re happy to help you map out your compliance roadmap.

About The Author

Brian Sandenaw
Brian Sandenaw

Brian has over 2 decades of experience in System Administration and Information Security, having worked at all levels of Government (City, County, State, and Federal) and with companies ranging from startup to Fortune-20.  He transitioned to auditing in 2018 and has delivered audits and attestations as varied as SOC 1 and 2, HITRUST, FISMA, FERPA, PCI, CSA-star and HIPAA.  With Linford and Co, he focuses primarily on HITRUST and SOC 2.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
I understand and agree to the Linford & Company LLP privacy policy.**