DRAFT: HIPAA Monitoring Pattern

Purpose

The HIPAA Monitoring Pattern defines the approved implementation model for monitoring, logging, alerting, auditing, and operational visibility of HIPAA workloads hosted in University-managed Azure environments.

This pattern provides a consistent monitoring architecture that supports operational support, security investigations, auditability, compliance activities, and platform governance for workloads that create, store, process, transmit, or provide access to Protected Health Information (PHI).

Use Cases

This pattern applies when:

  • Hosting applications containing PHI
  • Hosting databases containing PHI
  • Hosting HIPAA platform services
  • Deploying HIPAA landing zones
  • Deploying HIPAA subscriptions
  • Implementing operational monitoring for regulated workloads

This pattern does not apply to:

  • Non-regulated development environments
  • Sandbox environments without PHI
  • Workloads that do not process or store PHI

Design Principles

Centralized Monitoring

Monitoring data should be collected and managed through approved enterprise monitoring services rather than isolated workload-specific monitoring solutions.

Consistent Telemetry

HIPAA workloads should generate a common set of operational, audit, security, and platform telemetry.

Operational Visibility

Operations teams should be able to determine workload health, service health, resource health, and platform health without relying on application-specific tools.

Security Visibility

Security-relevant activities should be observable and available to support security operations and investigations.

Auditability

Monitoring services should provide sufficient visibility to support audits, investigations, operational reviews, and governance activities.

Separation of Duties

Monitoring administration and monitoring services may operate independently from workload administration to support operational governance and investigative independence.

Logical Architecture

HIPAA Workload

    ↓

Applications
Databases
Infrastructure
Identity Services

    ↓

Diagnostic Collection

    ↓

Central Monitoring Platform

    ↓

Dashboards
Alerting
Reporting
Security Operations
Audit Support
Incident Response

Monitoring Layers

Infrastructure Monitoring

Monitors:

  • Subscriptions
  • Networks
  • Compute resources
  • Storage resources
  • Platform services

Supports:

  • Availability monitoring
  • Resource health monitoring
  • Capacity management
  • Operational support

Platform Monitoring

Monitors:

  • Identity services
  • Shared platform services
  • Management services
  • Governance services

Supports:

  • Platform operations
  • Service management
  • Platform reliability

Application Monitoring

Monitors:

  • Applications
  • APIs
  • Background services
  • Integration services

Supports:

  • Availability management
  • Error detection
  • Performance troubleshooting

Data Monitoring

Monitors:

  • Data services
  • Data movement
  • Integration processes
  • Data storage platforms

Supports:

  • Operational support
  • Investigation support
  • Data platform management

Identity Monitoring

Monitors:

  • Authentication events
  • Authorization events
  • Administrative actions
  • Privileged access activities

Supports:

  • Security investigations
  • Audit activities
  • Access reviews

Logging Categories

Operational Logs

Capture:

  • Resource operations
  • Service operations
  • Platform events
  • Operational activities

Security Logs

Capture:

  • Security events
  • Administrative activities
  • Security investigations
  • Platform security events

Audit Logs

Capture:

  • Access activities
  • Administrative actions
  • Governance activities
  • Compliance-related events

Application Logs

Capture:

  • Application events
  • Application errors
  • Service behaviors
  • Application performance information

Alerting Model

Operational Alerts

Examples include:

  • Resource unavailable
  • Resource degraded
  • Service outage
  • Capacity thresholds exceeded

Security Alerts

Examples include:

  • Administrative changes
  • Security incidents
  • Unexpected access activities
  • Investigation triggers

Application Alerts

Examples include:

  • Application failure
  • Service interruption
  • Integration failure
  • Critical application errors

Shared Service Usage

Approved monitoring and logging services may operate as shared enterprise services supporting HIPAA workloads.

Shared monitoring services must:

  • Follow approved architecture standards
  • Protect monitoring data appropriately
  • Support workload isolation requirements
  • Support auditing and investigations

Operational Responsibilities

Platform Team

  • Monitoring architecture
  • Monitoring platform administration
  • Monitoring standards
  • Operational monitoring services

Security Team

  • Security visibility requirements
  • Security review activities
  • Security investigation activities

Workload Owner

  • Application telemetry
  • Operational support
  • Application alert response

Automation Pattern

Monitoring services should be automatically configured through approved landing zone and platform automation whenever practical.

Automation areas include:

  • Diagnostic configuration
  • Monitoring enrollment
  • Alert configuration
  • Logging configuration
  • Platform monitoring integration

Implementation should be delivered through approved platform automation.

Reference Architecture Outcomes

A workload implementing this pattern should provide:

  • Centralized operational visibility
  • Centralized security visibility
  • Auditability
  • Operational supportability
  • Incident investigation support
  • Consistent monitoring implementation
  • Alignment with approved HIPAA hosting architecture