Purpose
Defines the monitoring, logging, auditing, alerting, and operational visibility requirements for HIPAA workloads hosted within University-managed Azure environments.
Scope
This standard applies to:
- HIPAA applications
- HIPAA infrastructure
- HIPAA platform services
- HIPAA databases
- Administrative activities
- Identity and access activities
within approved HIPAA hosting environments.
Requirements
1. Centralized Monitoring
HIPAA workloads must generate operational and security telemetry through approved enterprise monitoring platforms.
2. Audit Logging
HIPAA workloads must generate audit records sufficient to support operational reviews, security investigations, and compliance activities.
3. Security Event Visibility
Security-relevant activities must be monitored and made available for investigation through approved monitoring solutions.
4. Identity Activity Monitoring
Authentication, authorization, and privileged administrative activities must be logged through approved monitoring mechanisms.
5. Operational Health Monitoring
HIPAA workloads must expose operational health information sufficient to support supportability, troubleshooting, and service management activities.
6. Alerting
HIPAA workloads must generate alerts for defined operational and security conditions using approved monitoring capabilities.
7. Log Retention
Monitoring and audit records must be retained according to approved retention requirements and applicable University policies.
8. Incident Investigation Support
Monitoring solutions must support investigation of operational and security incidents affecting HIPAA workloads.
9. Architecture Review
Monitoring implementations that deviate from approved monitoring patterns require architecture review and approval before implementation.
10. Exceptions
Exceptions to this standard require documented approval through the approved architecture exception process.