DRAFT: ADR HIPAA Identity Model

Summary

The University of Arkansas will use centralized enterprise identity services as the authoritative identity provider for HIPAA workloads hosted in Azure.

Authentication, authorization, privileged access, and workload identities will be managed through approved enterprise identity services and implemented through standardized identity patterns.

Body

Decision

HIPAA workloads will use centralized enterprise identity services for authentication and authorization.

Access to HIPAA resources will be assigned using role-based access controls and approved identity governance processes.

HIPAA workloads will not implement independent identity systems when approved enterprise identity capabilities satisfy business and regulatory requirements.

Technical Reasoning

Using a centralized identity model improves consistency, reduces operational complexity, simplifies lifecycle management, and supports a common governance approach across regulated and non-regulated workloads.

A shared enterprise identity platform enables workloads to inherit established authentication, authorization, auditing, and access management capabilities while maintaining workload isolation boundaries.

Consequences

HIPAA workloads must integrate with approved enterprise identity services.

Identity requirements must be implemented through approved standards and architecture patterns rather than workload-specific identity solutions.

Identity architecture patterns must define approved approaches for workforce identities, privileged access, service identities, and application access.

Governance & Compliance

This ADR establishes the identity architecture model for HIPAA workloads.

Implementation requirements will be defined through the HIPAA Identity Standard and related architecture patterns.

Strategic Alignment

  • Consistency
  • Operational Sustainability
  • Security
  • Standardization

Details

Details

Article ID: 2159
Created
Mon 8/31/26 2:40 AM
Modified
Tue 9/1/26 11:48 AM
Audience
Staff