Search17 Results

Defines the minimum requirements for hosting HIPAA workloads in University-managed Azure environments.
Describes the approved implementation pattern for workload resiliency, operational continuity, backup, recovery, restoration, and service availability for HIPAA workloads hosted within University-managed Azure environments.
Describes the approved implementation pattern for data protection, encryption, backup, recovery, retention, and data lifecycle management for HIPAA workloads hosted within University-managed Azure environments.
Describes the approved implementation pattern for using enterprise shared services to support HIPAA workloads hosted within University-managed Azure environments while maintaining workload isolation, governance requirements, security controls, and regulatory boundaries.
Describes the approved implementation pattern for networking and connectivity for HIPAA workloads hosted in University-managed Azure environments.
Describes the approved implementation pattern for monitoring, logging, alerting, and audit visibility for HIPAA workloads hosted in University-managed Azure environments.
Describes the approved implementation pattern for identity and access management for HIPAA workloads hosted in University-managed Azure environments.
The University of Arkansas will use Azure Management Groups as the primary governance boundary for cloud environments.

Security, compliance, operational, and platform controls will be applied through Management Group inheritance rather than direct configuration of individual subscriptions whenever practical.
The University of Arkansas will use centralized enterprise identity services as the authoritative identity provider for HIPAA workloads hosted in Azure.

Authentication, authorization, privileged access, and workload identities will be managed through approved enterprise identity services and implemented through standardized identity patterns.
The University of Arkansas will permit approved shared platform services to support HIPAA workloads when those services do not process, store, or expose protected health information (PHI).

Shared services may be consumed by regulated workloads when they satisfy approved security, governance, and operational requirements.
Defines the monitoring, logging, auditing, alerting, and operational visibility requirements for HIPAA workloads hosted in University-managed Azure environments.
The University of Arkansas will use subscription-level isolation as the primary boundary for regulated workloads hosted in Azure.

Workloads requiring HIPAA controls will be deployed into dedicated subscriptions governed through approved standards, architecture patterns, and policy assignments rather than sharing a common multi-tenant regulated environment.
Defines the requirements for creation, governance, management, ownership, and lifecycle management of Azure subscriptions within University-managed Azure environments, establishing Azure subscriptions as the primary workload isolation, administrative, operational, and accountability boundary for cloud workloads.
Defines the requirements for protecting Protected Health Information (PHI) and other regulated data within University-managed Azure environments through approved controls for encryption, backup, recovery, retention, resiliency, and access protection.
Defines the networking, connectivity, segmentation, boundary protection, traffic management, and network governance requirements for HIPAA workloads hosted within University-managed Azure environments.