As part of our journey in the HITRUST RightStart program, we've been surveying the vendor landscape to see who else has HITRUST certification. Founded in 2007, HITRUST Alliance is a not-for-profit organization whose mission is to champion programs that safeguard sensitive information and manage information risk for organizations across all industries and throughout the third-party supply chain. In this post, we will determine whether Microsoft Azure is HITRUST certified or not. SEE ALSO: How do I make Microsoft Azure HIPAA Compliant? Since Microsoft is such a large company, we'll limit the scope of our HITRUST research to Azure.
Microsoft Azure
Microsoft Azure is a cloud computing service for building, testing, deploying, and managing applications and services through a global network of Microsoft-managed data centers.Microsoft and HITRUST
Although there isn't a formal HIPAA certification issued by the U.S. Department of Health and Human Services ( HHS), HITRUST certification is widely regarding as the closest thing to it. A quick search revealed that Microsoft does mention HITRUST on its website.Is Microsoft Azure HITRUST Certified?
On 3 January 2017, Microsoft announced in a blog post that Azure earned HITRUST certification. According to that post, the following Azure services are HITRUST certified:
Identity and Access Management
- Azure Active Directory
- Rights Management
- Multi-Factor Authentication
Compute
- Virtual Machines
- Cloud Services
- Batch
Networking
- Application Gateway
- VPN Gateway
- Express Route
- Virtual Network
- Load Balancer
- Traffic Manager
Web & Mobile
- Web Apps
- Mobile Apps
- Notification Hubs
Analytics
- HDInsight
Management & Security
- Azure Key Vault
- Scheduler
- Azure Management Portal
- Azure Classic Portal
Media & CDN
- Media Services
Data & Storage
- Redis Cache - including Premium
- SQL Database
- SQL Data Warehouse
- SQL Virtual Machines
- Storage- Blob, Table, Queue, Files, and Disks - including Premium
Hybrid Integration
- Service Bus
- Workflow
Conclusion: Yes, most of Microsoft's Azure platform is HITRUST certified.
HITRUST
Founded in 2007, HITRUST Alliance is a not-for-profit organization whose mission is to champion programs that safeguard sensitive information and manage information risk for organizations across all industries and throughout the third-party supply chain. In collaboration with privacy, information security and risk management leaders from both the public and private sectors, HITRUST develops, maintains and provides broad access to its widely adopted common risk and compliance management and de-identification frameworks; related assessment and assurance methodologies; and initiatives advancing cyber sharing, analysis, and resilience.Subscribe to Paubox Weekly
Every Friday we'll bring you the most important news from Paubox. Our aim is to make you smarter, faster.