Federal Resources
Authoritative federal and Microsoft guidance for organizations running PHI on Azure. Listed with newest or most actively referenced materials first.
Core References (1–10)
- HIPAA Security Rule – Official TextCurrent regulatory text and definitions.
- HITECH Act Breach Notification GuidanceUpdated breach reporting requirements.
- Azure HIPAA / HITRUST Blueprint OverviewReference architecture for health data on Azure.
- NIST SP 800-66 Rev. 2 (HIPAA Security Rule)Practical implementation guidance mapped to NIST.
- Microsoft Product Terms – BAA LanguageWhere the Azure BAA commitments appear.
- OCR Audit Protocol (current)What auditors typically examine.
- FedRAMP Moderate Baseline (relevant controls)Useful cross-walk for government-adjacent workloads.
- Azure Policy – HIPAA/HITRUST InitiativeBuilt-in policy set for continuous assessment.
- HITRUST CSF v11 SummaryCommon certifiable framework built on HIPAA.
- CMS Information Security RequirementsRelevant for Medicare/Medicaid related systems.
Additional groups of resources will be added as new guidance is published. Always verify the latest version on the issuing agency site.