Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » HiTRUST » HITRUST Inheritance Program

HITRUST Inheritance Program

The HITRUST Inheritance Program lets organizations rely on shared security controls provided by internal IT services or external third parties, like service providers, vendors, cloud platforms (SaaS, IaaS/PaaS), colocation data centers, and other managed services.

For example, if you’re using Salesforce, the HITRUST Inheritance Program allows you to incorporate the controls Salesforce uses into your audits and assessments. 

This means you don’t have to review Salesforce’s audit reports individually. Instead, your assessor can rely on the fact that Salesforce has already met the required testing for those controls and their HITRUST assessor has reviewed everything. It simplifies the process and saves time while ensuring compliance.

Now, here’s how you can use HITRUST Inheritance:

  • External Inheritance:  You can adopt up to 85% of the control testing scores from HITRUST-certified third-party Cloud Service Providers (CSPs). 
  • Internal Inheritance: You can also inherit results from your organization’s assessments, but this feature is available only with Corporate and Premium subscriptions.

This makes it easier to leverage existing compliance work and streamline your own assessments.

Additional reading

Top 5 Scrut alternatives to consider in 2026

TL; DR Scrut can be a solid starting point for audit readiness. Friction arises when you need advanced automation across multiple frameworks. Teams note poor UX, limited control mapping, and excessive auditor coordination. This guide compares top Scrut alternatives on control mapping, monitoring, audit workflows, risk and vendor automation, integrations, and platform reliability post-setup. Top…

GDPR Fines In 2026: Penalty Structure, Calculation Criteria, and Biggest Fines So Far

TL,DR: GDPR fines apply when organizations fail to protect personal data or meet privacy obligations. Penalties can result from weak consent, poor security, delayed breach reporting, or unlawful processing. Strong privacy governance, records, controls, and response processes reduce fine exposure. In May 2023, Meta was fined €1.3 billion by the Irish Data Protection Commission for…

Vendor Relationship Management Framework: Strengthen Partnerships and Performance

TL,DR: A vendor relationship management framework governs engagement, monitoring, contracts, and performance reviews. It reduces delays, financial losses, compliance failures, and unclear accountability across vendor work. The article explains how to build structured, long-term vendor relationships with measurable oversight. “83% of companies only discover vendor risk after engagement, and 31% of those risks lead to…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.