DRAFT: ADR Subscription-based Isolation Strategy

Tags azure ADR HIPAA

Decision

Regulated workloads will be isolated at the Azure subscription level.

Governance controls applicable to HIPAA subscriptions are defined through the Management Group Governance Model and related governance standards. 

Multiple HIPAA subscriptions may exist when operational, organizational, or workload separation is required.

Technical Reasoning

Azure subscriptions provide a clear administrative, governance, billing, monitoring, and security boundary.

Subscription-level isolation aligns with Azure governance capabilities and allows workload teams to operate independently while inheriting common controls through management groups, policy assignments, and platform standards.

This approach supports scalability and avoids creating a single shared HIPAA environment that could become a bottleneck for onboarding new workloads.

Consequences

HIPAA workloads will be deployed into dedicated subscriptions rather than shared environments.

Governance controls will be inherited through management group placement and related architecture patterns.

Provisioning processes, automation, and landing zones must support repeatable deployment of multiple regulated workload subscriptions.

Governance & Compliance

This ADR establishes subscription isolation as the architectural boundary for regulated workloads.

Implementation requirements will be defined through the Azure Subscription Standard, HIPAA Hosting Standard, and related architecture patterns.

Strategic Alignment

  • Consistency
  • Scalability
  • Operational Sustainability