Body
Purpose
This standard defines the requirements for hosting workloads that create, store, process, transmit, or provide access to Protected Health Information (PHI) within University-managed approved cloud environments.
Scope
This standard applies to:
- Applications containing PHI
- Databases containing PHI
- Data products containing PHI
- Supporting infrastructure hosting PHI workloads
- Services designated as HIPAA workloads
This standard does not apply to workloads that do not process or store PHI.
Requirements
1. Approved Hosting Environment
HIPAA workloads must be hosted within approved cloud environments using approved architecture patterns.
2. Subscription Isolation
HIPAA workloads must be deployed into approved HIPAA subscriptions.
HIPAA workloads must not be deployed into shared non-regulated subscriptions.
3. Management Group Governance
HIPAA subscriptions must be placed within approved Management Group structures and inherit required governance controls.
4. Approved Architecture Patterns
HIPAA workloads must use approved architecture patterns for:
-
Hosting
-
Identity
-
Networking
-
Monitoring
-
Data protection
5. Identity and Access Management
HIPAA workloads must use approved identity and access management controls.
Access must be granted using approved role-based access models.
6. Monitoring and Logging
HIPAA workloads must generate audit logs and monitoring telemetry using approved monitoring patterns.
7. Data Protection
PHI must be protected using approved encryption, backup, and recovery mechanisms.
8. Shared Services
HIPAA workloads may use approved enterprise shared services when those services have been approved for supporting regulated workloads.
9. Architecture Review
New HIPAA workloads must complete architecture review before production deployment.
10. Exceptions
Exceptions to this standard require documented approval through the approved architecture exception process.