Purpose
This standard defines the networking requirements for workloads that create, store, process, transmit, or provide access to Protected Health Information (PHI) within University-managed Azure environments.
The standard establishes requirements for workload isolation, secure connectivity, network governance, operational visibility, and integration with approved enterprise services.
Scope
This standard applies to:
- HIPAA applications
- HIPAA databases
- HIPAA data products
- HIPAA platform services
- HIPAA integrations
- HIPAA infrastructure
- Network services supporting HIPAA workloads
within approved HIPAA hosting environments.
Requirements
1. Network Isolation
HIPAA workloads must be deployed within approved network architectures designed to provide appropriate workload isolation and security boundaries.
Network architectures must support segregation of HIPAA workloads from non-regulated workloads.
2. Dedicated HIPAA Hosting Boundaries
HIPAA workloads must operate within approved HIPAA subscriptions and approved network boundaries.
Networking designs must align with approved hosting and landing zone architectures.
3. Approved Connectivity
Network communications must be restricted to approved and necessary communication paths.
Connectivity must be governed through approved architecture standards and operational processes.
4. Ingress Control
Inbound connectivity to HIPAA workloads must be explicitly governed, managed, and monitored.
Unauthorized inbound access paths must not be permitted.
5. Egress Control
Outbound communications from HIPAA workloads must follow approved connectivity paths and approved enterprise networking requirements.
Outbound communications must be governed according to approved security and operational requirements.
6. Network Segmentation
HIPAA workloads must implement logical network segmentation appropriate for workload architecture, operational management, and security requirements.
Segmentation must support workload separation and administrative control.
7. Private Connectivity
Private connectivity mechanisms should be used when supported by the target platform, service, or application architecture.
Network architectures should minimize unnecessary public exposure of HIPAA services.
8. Shared Service Connectivity
HIPAA workloads may communicate with approved enterprise shared services when authorized through approved architecture standards and governance processes.
Shared service connectivity must follow approved security and operational requirements.
9. Identity Service Connectivity
Network architectures must support connectivity to approved enterprise identity services required for authentication, authorization, and access governance.
Identity communications must follow approved security controls.
10. Monitoring Integration
Network architectures must integrate with approved enterprise monitoring and logging services.
Network-related activities must support operational visibility, auditability, troubleshooting, and incident investigation.
11. Data Protection Support
Network architectures must support approved data protection controls, including encryption requirements and data protection standards applicable to HIPAA workloads.
Networking implementations must not circumvent approved protection requirements for regulated data.
12. Operational Visibility
Network services supporting HIPAA workloads must generate monitoring and audit information sufficient to support:
- Operational support
- Security investigations
- Compliance activities
- Audit reviews
- Incident response
13. Governance Alignment
HIPAA network architectures must align with approved governance controls inherited through Management Group placement and related platform governance processes.
14. Architecture Review
Networking implementations that deviate from approved network architecture patterns require architecture review and approval before implementation.
15. Exceptions
Exceptions to this standard require documented approval through the approved architecture exception process.