Security Other
Additional security topics and practices that support HIPAA-aligned operations on Azure beyond the core control set. Ordered with the most recent material first.
Security Topics (1–10)
- Threat Modeling for Healthcare ApplicationsSTRIDE adapted for clinical and PHI data flows.
- Microsoft Sentinel Use Cases for PHI EnvironmentsDetection rules and hunting queries that matter.
- Secure CI/CD for Regulated WorkloadsSecrets, approvals, and evidence in the pipeline.
- Third-Party & SaaS Risk under HIPAAVendor questionnaires and shared-responsibility clarity.
- Container Security for AKS Clinical WorkloadsImage scanning, network policy, and runtime protection.
- Data Loss Prevention Patterns on AzurePurview, sensitivity labels, and egress controls.
- Incident Response Playbooks for PHIRoles, timelines, and HITECH notification triggers.
- Zero-Trust Architecture for Hybrid Health SystemsIdentity-centric access across on-prem and Azure.
- Key Management & HSM OptionsWhen to use platform keys vs customer-managed keys.
- Continuous Control Monitoring ApproachesMoving from point-in-time audits to ongoing assurance.
More specialized topics will be added in subsequent groups of ten as they are published.