Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » HiTRUST » HITRUST Inheritance Program

HITRUST Inheritance Program

The HITRUST Inheritance Program lets organizations rely on shared security controls provided by internal IT services or external third parties, like service providers, vendors, cloud platforms (SaaS, IaaS/PaaS), colocation data centers, and other managed services.

For example, if you’re using Salesforce, the HITRUST Inheritance Program allows you to incorporate the controls Salesforce uses into your audits and assessments. 

This means you don’t have to review Salesforce’s audit reports individually. Instead, your assessor can rely on the fact that Salesforce has already met the required testing for those controls and their HITRUST assessor has reviewed everything. It simplifies the process and saves time while ensuring compliance.

Now, here’s how you can use HITRUST Inheritance:

  • External Inheritance:  You can adopt up to 85% of the control testing scores from HITRUST-certified third-party Cloud Service Providers (CSPs). 
  • Internal Inheritance: You can also inherit results from your organization’s assessments, but this feature is available only with Corporate and Premium subscriptions.

This makes it easier to leverage existing compliance work and streamline your own assessments.

Additional reading

NIS2 Scope: Does the Directive Apply to You?

TL,DR: NIS2 is the EU’s cybersecurity directive enforced since January 2023, expanding scope beyond critical infrastructure to cover medium and large organizations across essential and important sectors including energy, healthcare, finance, and digital infrastructure 22% of senior cybersecurity professionals at large UK organizations were unsure whether NIS2 applied to them (Green Raven Limited). Any organization…

HIPAA Compliant Website

TL,DR: A HIPAA compliant website protects patient data collected through forms, portals, chat, and integrations. It requires safeguards such as encryption, access controls, secure hosting, and audit logs. Healthcare websites should review vendors, consent flows, breach response, and data storage. Data breaches may be inevitable for healthcare organizations. But implementing HIPAA safeguards can go a…

Sprinto vs Strike Graph: Choosing the Right Compliance Platform

The strongest compliance programs are built to last. They protect against threats, align with multiple frameworks, and create confidence across customers and partners. Strike Graph and Sprinto may both look like routes to faster compliance, but they are built for different stages of the journey. Strike Graph is strongest when the goal is guided first-time…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.