DRAFT: HIPAA Data Protection Standard

Summary

Defines the requirements for protecting Protected Health Information (PHI) and other regulated data within University-managed Azure environments through approved controls for encryption, backup, recovery, retention, resiliency, and access protection.

Body

Purpose

This standard defines the requirements for protecting data associated with HIPAA workloads hosted within University-managed Azure environments.

The standard establishes requirements that support confidentiality, integrity, availability, recoverability, and accountability for regulated data throughout its lifecycle.

Scope

This standard applies to:

  • Applications containing PHI
  • Databases containing PHI
  • Data products containing PHI
  • Platform services containing PHI
  • File storage containing PHI
  • Backup data associated with HIPAA workloads
  • Replicated data associated with HIPAA workloads
  • Data integration services processing PHI

within approved HIPAA hosting environments.

Requirements

1. Data Classification

Data must be protected according to applicable regulatory, institutional, and business requirements.

Workloads processing or storing PHI must implement protections appropriate for regulated healthcare information.

2. Encryption at Rest

PHI and regulated data must be protected using approved encryption mechanisms when stored within approved HIPAA hosting environments.

3. Encryption in Transit

Communications involving PHI must use approved encrypted communication methods when data is transmitted between services, applications, platforms, enterprise systems, or approved external systems.

4. Access Protection

Access to regulated data must be restricted to approved users, applications, services, and administrative processes.

Data access must align with approved identity and authorization controls.

5. Least Privilege

Access to regulated data must be limited to the minimum access necessary to perform approved business functions.

6. Backup Protection

HIPAA workloads must implement approved backup capabilities sufficient to support recovery of regulated data and supporting services.

Protected data contained within backups must remain protected according to applicable security requirements.

7. Recovery Capability

HIPAA workloads must implement recovery capabilities that support restoration of protected data and operational continuity following system failures, service disruptions, or data loss events.

8. Data Retention

Protected data must be retained according to approved retention requirements and applicable University policies.

Retention periods must be managed through approved governance processes.

9. Data Disposal

Protected data that is no longer required must be disposed of through approved data management processes.

Data disposal activities must align with institutional governance requirements and applicable regulatory obligations.

10. Auditability

Data access, administrative activities, protection-related events, and recovery activities must be auditable through approved monitoring and logging solutions.

11. Monitoring and Protection Events

HIPAA workloads must generate monitoring and audit information sufficient to support:

  • Security investigations
  • Compliance activities
  • Operational reviews
  • Data protection reviews
  • Incident investigations

12. Shared Service Protection

Shared services supporting HIPAA workloads must protect regulated data according to approved security, operational, and governance requirements when those services process, store, replicate, or otherwise interact with protected data.

13. Architecture Review

Data protection implementations that deviate from approved architecture patterns require architecture review and approval before implementation.

14. Exceptions

Exceptions to this standard require documented approval through the approved architecture exception process.

Details

Details

Article ID: 2169
Created
Tue 9/1/26 8:17 AM
Modified
Tue 9/1/26 11:43 AM
Audience
Staff