HIPAA Security Rule
U.S. healthcare security standard (45 CFR 164 Subpart C) protecting electronic Protected Health Information. Assessed via the dedicated HIPAA scanner.
Official documentation14
Controls
0
Auto-Remediable
6
Domains
Entra ID(4)
HIPAA-A-002Risky sign-ins monitored by Identity Protection
HIPAA-T-005Sensitivity labels with encryption deployed
HIPAA-T-009Break-glass account excluded from all Conditional Access policies
HIPAA-T-010Entra ID audit logs exported to SIEM or storage
Purview(3)
HIPAA-A-001Alert policies active in Microsoft Purview / Defender
HIPAA-T-001Unified Audit Log enabled
HIPAA-T-002Audit log retention configured (90+ days)
Exchange(3)
HIPAA-T-003Exchange Admin Audit Log enabled
HIPAA-T-004Mailbox auditing enabled org-wide
HIPAA-T-007Office Message Encryption (OME) configured
Intune(2)
HIPAA-P-001Device compliance policy requiring encryption enforced
HIPAA-P-002Remote wipe capability configured for managed devices
SharePoint(1)
HIPAA-T-006SharePoint document versioning enabled
Teams(1)
HIPAA-T-008Teams end-to-end encryption available
