DRAFT: HIPAA Hosting Standard

Purpose

This standard defines the requirements for hosting workloads that create, store, process, transmit, or provide access to Protected Health Information (PHI) within University-managed approved cloud environments.

Scope

This standard applies to:

  • Applications containing PHI
  • Databases containing PHI
  • Data products containing PHI
  • Supporting infrastructure hosting PHI workloads
  • Services designated as HIPAA workloads

This standard does not apply to workloads that do not process or store PHI.

Requirements

1. Approved Hosting Environment

HIPAA workloads must be hosted within approved cloud environments using approved architecture patterns.

2. Subscription Isolation

HIPAA workloads must be deployed into approved HIPAA subscriptions.

HIPAA workloads must not be deployed into shared non-regulated subscriptions.

3. Management Group Governance

HIPAA subscriptions must be placed within approved Management Group structures and inherit required governance controls.

4. Approved Architecture Patterns

HIPAA workloads must use approved architecture patterns for:

  • Hosting

  • Identity

  • Networking

  • Monitoring

  • Data protection

5. Identity and Access Management

HIPAA workloads must use approved identity and access management controls.

Access must be granted using approved role-based access models.

6. Monitoring and Logging

HIPAA workloads must generate audit logs and monitoring telemetry using approved monitoring patterns.

7. Data Protection

PHI must be protected using approved encryption, backup, and recovery mechanisms.

8. Shared Services

HIPAA workloads may use approved enterprise shared services when those services have been approved for supporting regulated workloads.

9. Architecture Review

New HIPAA workloads must complete architecture review before production deployment.

10. Exceptions

Exceptions to this standard require documented approval through the approved architecture exception process.