Shared Responsibility and Inheritance Program
The Shared Responsibility and Inheritance Program is a HITRUST offering that helps organizations clarify which security controls are handled by a service provider (such as a cloud vendor) versus by the customer using that service. It also lets a customer reuse, or 'inherit,' controls that a qualifying service provider has already put in place, which can streamline third-party risk management and the customer's own HITRUST assessment. Because this is a HITRUST program run by a private organization, participation is not a legal requirement and does not by itself establish HIPAA compliance.
A HITRUST program that defines shared responsibility models and inheritance mechanisms for organizations pursuing HITRUST CSF assessments. It uses Shared Responsibility Matrices (SRMs) to delineate control ownership between service providers and their customers in cloud and other outsourced environments, and to support control inheritance, whereby a customer can leverage a participating provider's already-implemented and scored controls in its own assessment rather than reimplementing and re-scoring them independently. The program is intended to simplify third-party risk management and reduce duplication of assessment effort. As a HITRUST offering, its scope is limited to the HITRUST CSF and related assurance processes; it is distinct from HIPAA, and inheritance or program participation does not, by itself, satisfy HIPAA obligations, which for covered entities and business associates attach through their defined relationships and applicable rules. Specific SRM contents vary by service provider and by the applicable HITRUST CSF version, which readers should verify against the current HITRUST CSF release.
Why it matters
In cloud and other outsourced environments, one of the most common sources of compliance failure is ambiguity over who is responsible for a given control. When a customer assumes a cloud provider is handling a safeguard that the provider actually expects the customer to configure, gaps can go unnoticed until an assessment or an incident exposes them. The Shared Responsibility and Inheritance Program addresses this problem within the HITRUST context by using Shared Responsibility Matrices to clearly delineate which controls sit with the service provider and which remain with the customer, reducing the guesswork that often accompanies shared infrastructure.
The program also matters because it can reduce duplication of effort. Rather than independently reimplementing and re-scoring controls that a qualifying provider has already put in place, a customer may inherit those controls in its own HITRUST assessment. Major service providers, including AWS and Salesforce, participate in the program, which can streamline both third-party risk management and the assessment process itself for their customers. This can save time and resources for organizations already relying on those providers.
It is important to be precise about scope. The Shared Responsibility and Inheritance Program is a HITRUST offering run by a private organization, and it applies to the HITRUST CSF and related assurance processes. Participation and control inheritance do not, by themselves, establish HIPAA compliance. For covered entities and business associates, HIPAA obligations attach through their defined relationships and the applicable rules, and cannot be delegated away simply by relying on a provider's inherited controls. Organizations should treat inheritance as a way to reduce assessment effort, not as a substitute for their own compliance responsibilities.
Who it's relevant to
Inside SRIP
Common questions
Answers to the questions practitioners most commonly ask about SRIP.