Skip to content
Open to board advisory and board seats: 2H 2026, then CY 2027-2028.
See details →
Altais · 2020 to 2022

HITRUST Certification and IT Modernization

Led the cross-functional effort to achieve HITRUST certification at a Blue Shield of California company, and modernized corporate IT and endpoint security.

Certification
HITRUST
Modernized
Corporate IT and endpoints
Cyber risk reporting
Executives and board

The problem

At Altais, a Blue Shield of California company, I was Head of Technology & Information Security from 2020 to 2022. This case covers two parts of that job: leading the effort to achieve HITRUST certification, and modernizing corporate IT and endpoint security.

HITRUST describes its CSF as bringing requirements from standards and regulations including ISO/IEC, NIST, HIPAA, PCI, and GDPR into a single, integrated control framework. That breadth is why I don't treat certification as a security project. The controls live in every function that runs a system, a laptop, or a process.

The approach

I led certification as a cross-functional effort. The way I run one: every control gets a named owner in the function that operates it, and security owns the framework, the evidence standard, and the schedule.

The IT modernization covered network design, workstation lifecycle, asset management, and helpdesk. I treat that as part of the same program. You can't show a control on endpoints you can't count, and the workstation lifecycle is where endpoint controls get applied or skipped.

I also presented to executive leadership and the board on cyber risk. I've written up how I report risk to people who don't speak security.

The outcome

Altais achieved HITRUST certification, and corporate IT and endpoint security were modernized from network design through helpdesk. Keeping a certification true is ongoing work after the assessor leaves, the case I make in The Audit Passed in March.

HITRUSTHealthcareIT Modernization