Works with your ecosystem
What we implement
- Private networking & controlled egress
- Encryption at rest and in transit, customer-managed keys
- Entra ID, conditional access, MFA and privileged identity management
- Microsoft Sentinel detections tuned for healthcare workloads
- Continuous evidence collection for the SOC 2 observation window
- Runbooks, access reviews and an audit evidence pack
- Data residency held to your chosen region
- Optional: penetration test coordination and vendor security reviews
What stays yours
- Clinical and business decisions about your own data
- Your security policies and risk appetite
- Final approval on any change to production
- Your Azure subscription and billing
Your Business Associate Agreement with Microsoft, your policies, your workforce training, your risk analysis and your choice of auditor. The environment is deployed in your tenant, under your billing.
The control areas
Identity & Access
Entra ID with conditional access and MFA. No standing admin rights; privileged access is time-bound and reviewed.
Private Networking
Private endpoints for every data service, no public IPs on the data plane, and egress forced through Azure Firewall with every rule logged.
Encryption
TLS 1.2+ in transit. At rest, platform encryption plus customer-managed keys in Key Vault, with rotation and access logged.
Logging & Monitoring
Diagnostic settings on every resource, centralised in Log Analytics, retained against your regulatory obligation rather than the default.
Threat Detection
Microsoft Sentinel analytics for impossible travel, privilege escalation, mass export and anomalous PHI access — tuned so alerts are worth reading.
Evidence Automation
Continuous collection wired into the platform. A Type II is won or lost on whether evidence exists for every day of the window.
Control Mapping
Each HIPAA safeguard and SOC 2 criterion mapped to the Azure control that enforces it, so an auditor is shown enforcement, not a description.
Runbooks & Handover
Access reviews, key rotation, incident response and restore drills — each written as a procedure your team can run without us.
What success looks like
Every database, storage account and key vault reachable only over a private endpoint.
Privileged roles are requested, time-bound and approved, and every elevation is logged.
Evidence for every control on every day of the SOC 2 observation window, collected automatically.
The whole environment rebuilds from the repository, so drift shows up as a diff.
Scope varies by workload and by which Trust Services Criteria you need. We baseline against your current environment before committing to any of it.
Readiness assessment
Where you stand against the criteria you actually need, with gaps ranked by how long they take to close.
- Gap analysis against HIPAA and the Trust Services Criteria
- Prioritised remediation plan
- Evidence inventory: what you already have, and what is missing
Implementation
The landing zone, controls and evidence pipeline, deployed as code in your tenant.
- Sentinel workspace, runbooks and audit evidence pack
- Policy-as-code guardrails with Azure Policy
- Weekly status + month-end review
Managed operation
We run the environment alongside your team, through the observation window and after it.
- Dedicated team & SLAs
- Your contract and relationship with your chosen auditor
- Quarterly access reviews and control-health reporting
FAQ
Do you work inside our Azure tenant?
Yes. Everything is deployed into your own Azure tenant under your billing, with role-based access. You retain full ownership of the environment, the infrastructure code and the evidence.
How do you charge?
Either a fixed-scope engagement or a retainer for ongoing operation — whichever suits how much of the environment your own team intends to run.
Can you guarantee we pass?
No, and nobody honestly can. HIPAA has no certification body, and a SOC 2 report is issued by a licensed CPA firm after their own fieldwork. What we can do is build the environment and the evidence so that the questions have answers.
Do you stay on after go-live?
Yes — we can stay on through the observation window and sit in fieldwork sessions with your auditor, so your engineers are not learning audit vocabulary under pressure.
Let’s get your environment audit-ready
We’ll review your current Azure environment, map it against HIPAA and the Trust Services Criteria, and come back with a prioritised remediation plan.