Body
Purpose
This standard defines the requirements for protecting data associated with HIPAA workloads hosted within University-managed Azure environments.
The standard establishes requirements that support confidentiality, integrity, availability, recoverability, and accountability for regulated data throughout its lifecycle.
Scope
This standard applies to:
- Applications containing PHI
- Databases containing PHI
- Data products containing PHI
- Platform services containing PHI
- File storage containing PHI
- Backup data associated with HIPAA workloads
- Replicated data associated with HIPAA workloads
- Data integration services processing PHI
within approved HIPAA hosting environments.
Requirements
1. Data Classification
Data must be protected according to applicable regulatory, institutional, and business requirements.
Workloads processing or storing PHI must implement protections appropriate for regulated healthcare information.
2. Encryption at Rest
PHI and regulated data must be protected using approved encryption mechanisms when stored within approved HIPAA hosting environments.
3. Encryption in Transit
Communications involving PHI must use approved encrypted communication methods when data is transmitted between services, applications, platforms, enterprise systems, or approved external systems.
4. Access Protection
Access to regulated data must be restricted to approved users, applications, services, and administrative processes.
Data access must align with approved identity and authorization controls.
5. Least Privilege
Access to regulated data must be limited to the minimum access necessary to perform approved business functions.
6. Backup Protection
HIPAA workloads must implement approved backup capabilities sufficient to support recovery of regulated data and supporting services.
Protected data contained within backups must remain protected according to applicable security requirements.
7. Recovery Capability
HIPAA workloads must implement recovery capabilities that support restoration of protected data and operational continuity following system failures, service disruptions, or data loss events.
8. Data Retention
Protected data must be retained according to approved retention requirements and applicable University policies.
Retention periods must be managed through approved governance processes.
9. Data Disposal
Protected data that is no longer required must be disposed of through approved data management processes.
Data disposal activities must align with institutional governance requirements and applicable regulatory obligations.
10. Auditability
Data access, administrative activities, protection-related events, and recovery activities must be auditable through approved monitoring and logging solutions.
11. Monitoring and Protection Events
HIPAA workloads must generate monitoring and audit information sufficient to support:
- Security investigations
- Compliance activities
- Operational reviews
- Data protection reviews
- Incident investigations
12. Shared Service Protection
Shared services supporting HIPAA workloads must protect regulated data according to approved security, operational, and governance requirements when those services process, store, replicate, or otherwise interact with protected data.
13. Architecture Review
Data protection implementations that deviate from approved architecture patterns require architecture review and approval before implementation.
14. Exceptions
Exceptions to this standard require documented approval through the approved architecture exception process.