Body
Purpose
The HIPAA Monitoring Pattern defines the approved implementation model for monitoring, logging, alerting, auditing, and operational visibility of HIPAA workloads hosted in University-managed Azure environments.
This pattern provides a consistent monitoring architecture that supports operational support, security investigations, auditability, compliance activities, and platform governance for workloads that create, store, process, transmit, or provide access to Protected Health Information (PHI).
Use Cases
This pattern applies when:
- Hosting applications containing PHI
- Hosting databases containing PHI
- Hosting HIPAA platform services
- Deploying HIPAA landing zones
- Deploying HIPAA subscriptions
- Implementing operational monitoring for regulated workloads
This pattern does not apply to:
- Non-regulated development environments
- Sandbox environments without PHI
- Workloads that do not process or store PHI
Design Principles
Centralized Monitoring
Monitoring data should be collected and managed through approved enterprise monitoring services rather than isolated workload-specific monitoring solutions.
Consistent Telemetry
HIPAA workloads should generate a common set of operational, audit, security, and platform telemetry.
Operational Visibility
Operations teams should be able to determine workload health, service health, resource health, and platform health without relying on application-specific tools.
Security Visibility
Security-relevant activities should be observable and available to support security operations and investigations.
Auditability
Monitoring services should provide sufficient visibility to support audits, investigations, operational reviews, and governance activities.
Separation of Duties
Monitoring administration and monitoring services may operate independently from workload administration to support operational governance and investigative independence.
Logical Architecture
HIPAA Workload
↓
Applications
Databases
Infrastructure
Identity Services
↓
Diagnostic Collection
↓
Central Monitoring Platform
↓
Dashboards
Alerting
Reporting
Security Operations
Audit Support
Incident Response
Monitoring Layers
Infrastructure Monitoring
Monitors:
- Subscriptions
- Networks
- Compute resources
- Storage resources
- Platform services
Supports:
- Availability monitoring
- Resource health monitoring
- Capacity management
- Operational support
Platform Monitoring
Monitors:
- Identity services
- Shared platform services
- Management services
- Governance services
Supports:
- Platform operations
- Service management
- Platform reliability
Application Monitoring
Monitors:
- Applications
- APIs
- Background services
- Integration services
Supports:
- Availability management
- Error detection
- Performance troubleshooting
Data Monitoring
Monitors:
- Data services
- Data movement
- Integration processes
- Data storage platforms
Supports:
- Operational support
- Investigation support
- Data platform management
Identity Monitoring
Monitors:
- Authentication events
- Authorization events
- Administrative actions
- Privileged access activities
Supports:
- Security investigations
- Audit activities
- Access reviews
Logging Categories
Operational Logs
Capture:
- Resource operations
- Service operations
- Platform events
- Operational activities
Security Logs
Capture:
- Security events
- Administrative activities
- Security investigations
- Platform security events
Audit Logs
Capture:
- Access activities
- Administrative actions
- Governance activities
- Compliance-related events
Application Logs
Capture:
- Application events
- Application errors
- Service behaviors
- Application performance information
Alerting Model
Operational Alerts
Examples include:
- Resource unavailable
- Resource degraded
- Service outage
- Capacity thresholds exceeded
Security Alerts
Examples include:
- Administrative changes
- Security incidents
- Unexpected access activities
- Investigation triggers
Application Alerts
Examples include:
- Application failure
- Service interruption
- Integration failure
- Critical application errors
Shared Service Usage
Approved monitoring and logging services may operate as shared enterprise services supporting HIPAA workloads.
Shared monitoring services must:
- Follow approved architecture standards
- Protect monitoring data appropriately
- Support workload isolation requirements
- Support auditing and investigations
Operational Responsibilities
Platform Team
- Monitoring architecture
- Monitoring platform administration
- Monitoring standards
- Operational monitoring services
Security Team
- Security visibility requirements
- Security review activities
- Security investigation activities
Workload Owner
- Application telemetry
- Operational support
- Application alert response
Automation Pattern
Monitoring services should be automatically configured through approved landing zone and platform automation whenever practical.
Automation areas include:
- Diagnostic configuration
- Monitoring enrollment
- Alert configuration
- Logging configuration
- Platform monitoring integration
Implementation should be delivered through approved platform automation.
Reference Architecture Outcomes
A workload implementing this pattern should provide:
- Centralized operational visibility
- Centralized security visibility
- Auditability
- Operational supportability
- Incident investigation support
- Consistent monitoring implementation
- Alignment with approved HIPAA hosting architecture