Hexaview Technologies implements Microsoft Fabric for enterprises in financial services, wealth management, insurance, and healthcare — where data governance, audit readiness, and compliance are requirements that must be built into the platform from day one, not added after delivery.
With 20+ certified Microsoft Fabric experts, 16+ years of data delivery experience in regulated industries, and a track record of zero post-integration audit failures, Hexaview configures Fabric governance controls — OneLake governance zones, sensitivity labels, data lineage, and audit logging — to meet the specific obligations of FINRA, HIPAA, SOC 2, and applicable state and federal regulations before the first workload goes live.
Every regulated-industry engagement begins with a compliance assessment: a formal mapping of each applicable regulatory obligation to a specific Fabric configuration decision, so the data team and the compliance team are working from the same document before implementation begins.

A general-purpose Microsoft Fabric implementation and a regulated-industry Microsoft Fabric implementation are built from the same platform but configured in fundamentally different ways. The difference is not in which Fabric workloads are used — it is in how governance, access, lineage, and auditability are designed into every layer of the architecture from the first sprint.
General-purpose implementations prioritize speed to insight. Data moves from source to Lakehouse to Power BI report, and governance is added incrementally as the platform matures. This is appropriate for organizations whose data is not subject to external regulatory obligations.
Regulated-industry implementations must satisfy a different set of constraints from day one:
FINRA examiners, HIPAA auditors, and SOC 2 auditors require organizations to demonstrate that every data element in a report can be traced back to its source. In Microsoft Fabric, data lineage is configured using Microsoft Purview — mapping every transformation, pipeline, and report dependency so that a complete data provenance record exists for any field in any report. For regulated organizations, Purview lineage is configured during implementation, not after the first audit finding.
HIPAA mandates that PHI is accessible only to individuals who need it for their specific job function. FINRA requires that access to customer account data is controlled and audited. In Fabric, minimum necessary access is enforced through a combination of workspace-level role-based access controls (restricting who can see items in a workspace), item-level permissions (restricting access to specific lakehouses, warehouses, or pipelines), row-level security in semantic models (restricting which rows a user can query), and sensitivity labels (restricting what can be done with data — who can copy, export, or print it). All four control layers must be configured for regulated data — not just workspace-level access.
Every data access event, every data export, and every administrative change in a Fabric environment generates an audit log entry. For regulated organizations, audit logs must be retained for defined periods (FINRA requires six years for certain record types) and must be reviewable by compliance teams and external auditors without requiring the engineering team to produce them manually. In Fabric, audit logging is configured to export automatically to a compliant storage destination before the environment goes live.
Organizations in financial services and healthcare are increasingly deploying Fabric Copilot and AI analytics capabilities. Without a governed semantic layer, AI tools can query any data in the Fabric environment — including sensitive fields, PII, and PHI that should never be accessible through a natural language interface. The semantic layer is the control point for AI in regulated environments. Hexaview builds and validates the semantic layer before Copilot is activated, ensuring that AI capabilities are available only on data that has been explicitly approved for that access pattern.
Each regulatory framework imposes specific technical requirements on data systems. Microsoft Fabric addresses each through a combination of platform-native capabilities and Hexaview-configured governance controls applied during implementation.
FINRA: Rule 17a-4 requires broker-dealers to retain electronic records in a format that is non-rewriteable and non-erasable — commonly referred to as WORM (Write Once, Read Many) — and to make those records available to FINRA examiners on request. FINRA also requires firms to maintain accurate books and records that reflect every client transaction, every communication, and every advisory recommendation.
Microsoft Fabric addresses FINRA requirements through three mechanisms. First, immutable storage: Azure infrastructure underlying OneLake supports WORM-compliant storage configurations for designated record categories, ensuring that audit-relevant records cannot be altered after they are written. Second, comprehensive audit logging: Fabric's unified audit log captures every data access event, every administrative change, and every pipeline execution, creating the verifiable activity record FINRA examiners require. Third, data lineage: Microsoft Purview lineage maps every data element from its source system — custody systems, order management systems, CRM platforms — through every transformation to every report and dashboard, providing the provenance documentation that supports data integrity verification.
How Hexaview Configures This:
Hexaview maps FINRA Rule 17a-4 retention categories, Rule 17a-3 record type requirements, and any applicable SEC rules to specific Fabric workspace, storage, label, and audit configuration decisions before implementation begins. Compliance is a configuration output, not a project phase that starts after go-live.
HIPAA: The HIPAA Security Rule requires covered entities and business associates to implement technical safeguards that protect the confidentiality, integrity, and availability of electronic protected health information (ePHI). The core requirements are access control (only authorized individuals may access ePHI), audit controls (hardware, software, and procedural mechanisms that record and examine activity in systems that contain ePHI), integrity controls (mechanisms to ensure ePHI is not improperly altered or destroyed), and transmission security (encrypting ePHI when transmitted over electronic networks).
Microsoft Fabric satisfies HIPAA technical safeguard requirements through the following platform-native capabilities. OneLake encrypts all data at rest using AES-256 and all data in transit using TLS 1.2 or higher, satisfying the encryption requirements of the HIPAA Security Rule. Microsoft provides a Business Associate Agreement (BAA) covering Fabric services, establishing the contractual relationship required when a covered entity uses a cloud provider to process ePHI. Sensitivity labels in Fabric workspaces enforce access control policies — PHI is labeled, and those labels govern who can read, copy, export, or share data containing ePHI. Fabric's unified audit log records all data access events for compliance review, satisfying the audit control requirement.
How Hexaview Configures This:
Hexaview configures HIPAA-aligned governance controls during implementation: workspace structure that segregates PHI from non-PHI workloads, sensitivity label taxonomy that maps to the organization's data classification policy, row-level security on semantic models that restricts PHI access to authorized roles, and audit log retention settings that satisfy the HIPAA requirement for six-year retention of security-related documentation.
SOC 2: is an auditing standard developed by the American Institute of Certified Public Accountants (AICPA) that evaluates an organization's controls over security, availability, processing integrity, confidentiality, and privacy — collectively known as the Trust Services Criteria. A SOC 2 Type II report demonstrates that an organization's controls were operating effectively over a defined audit period (typically six to twelve months), providing assurance to clients and partners that their data is handled appropriately.
Microsoft Fabric provides the control infrastructure for SOC 2 compliance across multiple Trust Services Criteria. For the Security criterion, Fabric workspace-level RBAC, item-level permissions, sensitivity labels, and network controls (private endpoint options, IP allowlisting) provide the access restriction and perimeter controls that SOC 2 auditors evaluate. For the Availability criterion, Fabric's SLA-backed uptime commitments, automated failover, and Hexaview's managed service monitoring provide the operational continuity evidence auditors require. For the Confidentiality criterion, OneLake encryption, sensitivity labels, and semantic model column-level security restrict confidential data to authorized contexts. For the Processing Integrity criterion, data lineage in Purview and pipeline execution logging demonstrate that data is processed completely, accurately, and in accordance with documented processes.
How Hexaview Configures This:
Hexaview's regulated-industry implementation approach produces SOC 2 audit evidence as a design output, not a retrospective task: control documentation is written during implementation, audit log configuration is set before go-live, and Purview lineage maps are validated before any business unit begins using the platform for production reporting.
OneLake is the single, unified storage layer that underlies all Microsoft Fabric workloads. Every Lakehouse, Data Warehouse, and pipeline in a Fabric environment reads from and writes to OneLake — there is no separate storage system for each workload type. This architectural decision has a specific consequence for regulated industries: governance policies configured on OneLake propagate to every Fabric workload automatically.
In most pre-Fabric data architectures, governance is applied at the tool level: sensitivity labels set in Power BI do not automatically apply to the underlying SQL Server data, and access controls on an Azure Synapse workspace do not automatically restrict who can access the Azure Data Lake Storage containers connected to it. Each tool layer requires its own governance configuration, and gaps between tool layers are where compliance exposure most commonly develops.
In Microsoft Fabric with OneLake, a sensitivity label applied to a data asset in OneLake governs how that data can be accessed, copied, or exported across every Fabric workload that reads it. A row-level security policy applied to a semantic model restricts access both in Power BI reports and in Fabric Copilot queries. An audit log policy configured on a Fabric workspace captures events from every workload in that workspace — Data Factory pipelines, Lakehouse operations, Data Warehouse queries, and Power BI report access — in a single unified log.
OneLake workspace structure for regulated environments follows a domain-segregation model: The regulated data estate is divided into domains — typically aligned to business function (Finance, Risk, Compliance, Operations) or to data sensitivity tier (Restricted, Confidential, Internal, Public). Each domain corresponds to a Fabric workspace with its own access control configuration. Data cannot move between workspaces without explicit pipeline authorization, creating a governed perimeter around each data domain that auditors can inspect independently. Within each workspace, data is structured across three governance zones:
Microsoft Purview integration provides the lineage, classification, and governance catalog layer that sits across all three zones. Purview scans OneLake automatically, applies data classification rules to newly ingested data, and maintains a lineage map from source through Bronze, Silver, and Gold to every downstream report and AI query. The lineage map is the primary audit evidence artifact for regulators who need to verify data integrity and provenance.
Microsoft Fabric Copilot is a natural language analytics capability that allows business users to query business data by asking questions in plain language — without writing SQL or DAX. The question regulators and compliance teams in financial services and healthcare immediately ask is: what stops Copilot from accessing sensitive data it should not see?
The answer is the semantic layer — and specifically, the architecture of what the semantic layer does and does not expose.
How Fabric Copilot actually works in a governed environment: Fabric Copilot does not query raw data in OneLake. It queries the semantic model — the governed, structured representation of the data estate that a data engineering or analytics team has built and published. The semantic model is a set of defined tables, measures, relationships, and hierarchies that describe what data is available for analysis and how it should be calculated. When a business user asks Copilot "what was total AUM for the northeast region last quarter?", Copilot translates that question into a query against the semantic model, and the semantic model returns the answer based on the data it has been authorized to expose.
Four safety mechanisms operate at the semantic layer level:
RLS policies on the semantic model mean that Copilot's query results are automatically scoped to the data the querying user is authorized to see. An advisor can ask Copilot about their clients, and Copilot returns results only for those clients — the same data the advisor would see in a standard Power BI report. RLS is not a Copilot-specific configuration; it applies to every query against the semantic model, from Power BI reports to Copilot to programmatic API calls.
CLS prevents specific fields from being included in Copilot responses. PII fields such as Social Security numbers, date of birth, or account numbers can be excluded from the semantic model entirely, or restricted to specific roles. If a field is not in the semantic model, Copilot cannot return it, regardless of how the question is phrased.
Data assets in OneLake carry sensitivity labels that govern downstream use. If a sensitivity label on a Gold zone dataset specifies "Confidential — Do Not Export," that label propagates to the semantic model built on top of it and to any Copilot response that draws from it. Users cannot copy, export, or screenshot Copilot responses that contain data labeled as non-exportable.
Every Copilot query generates an audit log entry recording the querying user, the question asked, the semantic model queried, and the timestamp. This audit trail satisfies the access logging requirements of FINRA, HIPAA, and SOC 2 for AI-generated analytics access.
Hexaview's Copilot enablement process for regulated environments:
Hexaview does not activate Fabric Copilot by simply toggling a feature switch. The enablement process has five steps that must be completed before any business user is given Copilot access:
Financial services organizations generate some of the most governance-intensive data environments in any industry. Assets under management, client account records, trade data, risk analytics, and regulatory filings all flow through data systems that must satisfy FINRA, SEC, state-level financial regulations, and, for some organizations, international equivalents. Microsoft Fabric provides the data estate for these environments when it is configured by a partner with specific financial services delivery experience.
Wealth management data platforms manage the reporting, analytics, and operational data for advisors serving high-net-worth and ultra-high-net-worth clients. The data estate in a typical wealth management firm spans custody systems, portfolio management systems, CRM platforms, trust administration systems, financial planning tools, and compliance monitoring systems — most of which do not share a common data format and none of which were designed to integrate directly.
Microsoft Fabric consolidates this environment through a Bronze-Silver-Gold Lakehouse architecture. Custody and portfolio data ingests through Data Factory pipelines with SFTP, API, and direct database connectors. Client relationship data from CRM systems integrates alongside portfolio data in the Silver zone, enabling advisor dashboards that show the full client relationship — not just the investment account. Trust administration data, including trust instruments, beneficiary records, and fiduciary reporting obligations, integrates in a dedicated workspace with restricted access controls matching the fiduciary responsibility model.
Power BI Direct Lake reports replace the Excel-based reporting that most wealth management firms rely on for AUM reporting, performance attribution, and advisor productivity metrics. Direct Lake eliminates the scheduled refresh cycle — data is always current without any manual intervention.
Hexaview has delivered Microsoft Fabric implementations for wealth and trust management organizations serving Advisors, Operations, and Compliance teams across investment management, trust administration, and AUM reporting. Case studies are available on request.
Hedge funds and asset managers operate data environments where the latency and accuracy of position reporting, PnL attribution, and risk analytics directly determine business decisions and regulatory compliance. Trade data, position data, and market data must reconcile continuously, and the reconciliation process must be auditable for prime broker oversight, counterparty risk management, and regulatory capital reporting.
Microsoft Fabric's Real-Time Intelligence workload — KQL databases and event streams — handles the continuous ingestion and query of position data and market data feeds, delivering sub-second query response times on operational data that was previously available only in batch form after nightly processing. Data Activator provides automated alerting when risk thresholds, position limits, or reconciliation discrepancies cross defined boundaries, replacing manual monitoring workflows.
For regulatory capital reporting (Form PF, AIFMD, SFTR, and equivalent filings), Fabric's governed semantic layer provides the single source of truth from which reporting is generated, with Purview lineage maps documenting the provenance of every number in every regulatory filing.
Healthcare organizations face a data challenge unlike any other regulated industry: clinical data from disparate source systems — EHRs, lab systems, imaging systems, claims systems, pharmacy data, and patient monitoring platforms — must be unified for population health analytics, operational reporting, and AI-assisted clinical decision support, while every piece of patient-identifiable data must remain under strict HIPAA governance at every layer of the data estate.
Microsoft Fabric addresses the healthcare data challenge through a unified platform that ingests from all clinical source systems, applies PHI governance at the OneLake level, and exposes governed analytics to clinical and operational users — without PHI ever leaving the controlled environment.
Data Factory pipelines with 200+ connectors ingest from EHR systems (Epic, Cerner, and others using FHIR APIs or direct database connections), lab information systems, claims systems, and patient monitoring platforms into a Bronze zone Lakehouse. FHIR-format data is stored in its native format in Bronze and transformed to flat analytical formats in Silver for reporting use. PHI sensitivity labels are applied at ingestion and propagate through every layer.
PHI data elements — patient identifiers, dates of service, geographic data at sub-state level, diagnoses, procedures, and other HIPAA-defined identifiers — are classified using Purview data classification rules and labeled with PHI sensitivity labels during Bronze ingestion. The sensitivity label policy restricts who can access PHI, prevents PHI from being exported outside approved destinations, and prevents PHI from appearing in Copilot responses unless the querying user holds the appropriate authorized role.
Governed aggregate datasets in the Gold zone enable population health analytics, readmission risk modeling, length-of-stay reporting, and quality measure reporting (HEDIS, CAHPS, and other CMS-required metrics) without requiring clinical analysts to access raw PHI. Row-level security policies on semantic models restrict individual analyst access to the patient cohorts relevant to their role — a quality analyst sees quality measure data for their service line, not the full patient population.
Fabric Copilot in a healthcare environment is activated only after the semantic layer has been validated against HIPAA minimum necessary access requirements. Clinical users can query aggregate population data and their own patient cohort data through Copilot. PHI field exclusions and RLS policies ensure that Copilot cannot surface individual patient records in response to a natural language query unless the user's role explicitly authorizes individual-level access.
Insurance data environments manage claims records, policy data, actuarial models, reinsurance agreements, and regulatory filings across NAIC, state insurance departments, and, for globally operating insurers, Solvency II and equivalent international frameworks. The data volumes in insurance — particularly in claims and policy management — are large, the reconciliation requirements are strict, and the audit trail requirements for regulatory filings are non-negotiable.
Microsoft Fabric serves insurance data platforms by unifying the disparate source systems — policy administration systems, claims management systems, reinsurance platforms, actuarial modeling tools, and agent/broker management systems — into a governed Fabric estate where every downstream report and regulatory filing can be traced to its source data.
Claims data from policy administration and claims management systems ingests into Fabric through Data Factory pipelines. The Bronze zone preserves the raw claims record, including all adjudication history, payments, reserves, and loss development data. Silver zone transformation applies standardized claim status, line of business, and reserve category classifications that align to the actuarial team's modeling requirements. Row-level security in the Gold zone semantic model restricts claims data to the adjusters, actuaries, and analysts whose role authorizes access to specific lines of business or geographic regions.
Actuarial models in Python or R that previously ran against flat file exports from policy administration systems can be connected directly to Fabric Lakehouse through the Lakehouse Spark runtime, eliminating the extract-transform-load cycle between policy system and actuarial model. Loss development factors, IBNR calculations, and reserving models run against the same governed data estate that feeds management reporting — removing the reconciliation gap between actuarial assumptions and reported financials.
NAIC statutory filings, state premium tax filings, and loss run reporting all require data that is traceable, consistent, and auditable. Fabric's Purview lineage maps provide the provenance documentation that supports regulatory examination — demonstrating that every number in a statutory filing can be traced to its source transaction in the policy or claims system. Sensitivity labels and audit logging ensure that data accessed for regulatory reporting is accessed only by authorized personnel and that the access event is captured in the audit log.
Reinsurance bordereau production — the regular reporting of ceded premium and loss data to reinsurers — is a high-volume, high-accuracy process that in most insurance organizations still runs through manual Excel-based workflows. Fabric Data Factory automates bordereau production from the same governed claims and premium data that feeds internal reporting, eliminating the manual reconciliation step and reducing the error rate in ceded data reporting.
Hexaview Technologies is a Microsoft Fabric consulting partner specializing in regulated enterprises across financial services, wealth management, insurance, and healthcare. Hexaview configures Microsoft Fabric governance controls — OneLake data governance zones, workspace-level and item-level access controls, sensitivity labels, data lineage through Microsoft Purview, and audit logging — to meet specific regulatory obligations including FINRA, HIPAA, and SOC 2. Hexaview has 20+ certified Microsoft Fabric experts, a 94% client retention rate, and a track record of zero post-integration audit failures across regulated industry deployments. Regulated-industry engagements begin with a formal compliance assessment that maps applicable regulatory obligations to specific Fabric configuration decisions before any implementation work begins.
Microsoft Fabric addresses FINRA compliance requirements through immutable audit logging, data lineage tracking, sensitivity label controls, and workspace-level access management. Fabric's unified audit log captures all data access events, administrative changes, and pipeline executions, satisfying FINRA Rule 17a-4's requirement for accurate and verifiable electronic recordkeeping. OneLake data lineage tracking through Microsoft Purview records the provenance of every data element from its source system through every transformation to its final report or dashboard, supporting the data integrity and traceability requirements FINRA examiners require. Hexaview maps FINRA Rule 17a-4 retention categories and Rule 17a-3 record type requirements to specific Fabric workspace, storage, label, and audit log configuration decisions before implementation begins. Compliance is a configuration output, not a post-delivery retrofit.
Yes. Microsoft Fabric is eligible for use in HIPAA-regulated environments and Microsoft provides a Business Associate Agreement (BAA) covering Fabric services. OneLake encrypts all data at rest using AES-256 and in transit using TLS 1.2 or higher, satisfying the HIPAA Security Rule's technical safeguard requirements for ePHI protection. Sensitivity labels applied in Fabric workspaces prevent PHI from being accessed, exported, or queried outside approved contexts — including by Fabric Copilot, which queries only through the governed semantic layer. Hexaview configures HIPAA-aligned governance controls during implementation: workspace structure that segregates PHI from non-PHI workloads, sensitivity label taxonomy that maps to the organization's data classification policy, row-level security on semantic models that restricts PHI access to authorized roles, and audit log retention settings that satisfy HIPAA's six-year documentation retention requirement.
Fabric Copilot queries the semantic model — a governed, structured layer built on top of the Fabric data estate — not raw OneLake data. The semantic model is where data governance for Copilot is enforced. Row-level security on the semantic model means Copilot responses are automatically scoped to the data the querying user is authorized to see. Column-level security prevents Copilot from accessing PII, PHI, or other sensitive fields excluded from the semantic model. Sensitivity labels inherited from OneLake restrict whether Copilot responses can be copied or exported. Every Copilot query generates an audit log entry. Hexaview builds and validates the semantic layer as part of the AI and Copilot enablement service — including a data classification review, RLS and CLS validation, and a compliance team sign-off process — before Copilot is activated for any business user in a regulated environment.
Hexaview's Microsoft Fabric readiness assessment for regulated enterprises includes five compliance-specific deliverables in addition to the standard implementation roadmap: (1) Regulatory obligation mapping — applicable regulations (FINRA, HIPAA, SOC 2, or others) mapped to specific Fabric configuration decisions before implementation begins. (2) Data classification inventory — all data assets in scope classified by sensitivity tier and matched to Fabric access control and sensitivity label configurations. (3) Governance architecture design — OneLake workspace structure, data domain boundaries, and access control hierarchy designed to satisfy both operational requirements and audit evidence requirements. (4) Semantic layer compliance specification — defining which fields, measures, and data sources are in scope for Copilot and AI enablement before any AI capability is activated. (5) Audit log configuration plan — audit events, retention period, and export configuration documented for the compliance team before implementation begins. The assessment takes 2 to 3 weeks and produces a funded implementation roadmap that the data team, compliance team, and CFO can all review before any Fabric infrastructure spend is committed.
Hexaview's compliance assessment for regulated enterprises takes 2 to 3 weeks and produces a regulatory obligation map, data classification inventory, governance architecture design, semantic layer compliance specification, and audit log configuration plan — all before any Microsoft Fabric infrastructure spend is committed. It is the document that ensures your compliance team and your data team are working from the same specification before the first line of configuration is written.
Fixed-scope engagement · 2–3 week delivery · No infrastructure spend committed before the compliance assessment is approved · 20+ certified Microsoft Fabric experts