1 min read
How to take advantage of the HITRUST Shared Responsibility and Inheritance Program
Chloe Bowen December 18, 2020


What is the HITRUST Shared Responsibility and Inheritance Program?
The HITRUST Shared Responsibility and Inheritance Program is intended to simplify leveraging service provider security controls for a HITRUST CSF Assessment. Assessment scores of any cloud hosting or service provider participating in the HITRUST Shared Responsibility and Inheritance Program can be applied to any other organization’s assessment. In other words, a company can leverage a vendor’s assessment scores when conducting its own HITRUST CSF Assessment, thereby inheriting a vendor’s controls and applying them to its own assessments easily, saving time and resources. This simplifies and streamlines the assessment process.Benefits of the program
Key benefits of the HITRUST Shared Responsibility and Inheritance Program include:- An indication that a vendor has a strong focus on security
- Less required testing
- Inheriting control requirement scores
- Less data entry for applications already hosted on a HITRUST CSF certified environment
How the program works
Participating service providers appear in the official list of organizations that have a HITRUST CSF Validated Assessment. A client indicates which specific control requirement it will inherit and chooses its hosting or service provider from the list. The system validates the relationship by requesting verification from the vendor to confirm the services provided. In order to participate in the program, a vendor must have:- MyCSF Subscription
- Inheritance Module Subscription
- Current HITRUST CSF Validated Assessment in good standing
Subscribe to Paubox Weekly
Every Friday we'll bring you the most important news from Paubox. Our aim is to make you smarter, faster.