Medcurity Get Started
Last updated: March 2026

Is Microsoft 365 HIPAA Compliant?

Quick Answer

Yes, Microsoft 365 can be HIPAA compliant with a signed Business Associate Agreement (BAA), proper configuration, and consistent use of security controls. Microsoft provides BAAs for qualified organizations and includes advanced security features like Azure AD, Teams encryption, and Purview compliance monitoring.

Microsoft 365 BAA Process

Obtaining a Business Associate Agreement

Microsoft provides BAAs for healthcare organizations using Microsoft 365, Azure, and Dynamics. Request a BAA through your Microsoft account manager or the Microsoft Trust Center. The BAA covers all Microsoft 365 services, including Exchange Online, SharePoint, Teams, and OneDrive for Business.

Plan Requirements

HIPAA BAAs are available for Business Standard, Business Premium, and Enterprise plans. Ensure your organization subscriptions align with Microsoft's documented HIPAA-eligible plans. Budget for Microsoft 365 E3/E5 or equivalent SKUs if BAA coverage is required.

Teams Security for PHI Communication

Feature Configuration for HIPAA
Encryption In Transit TLS 1.2+ enforced for all Teams traffic
Encryption at Rest Microsoft-managed encryption; customer-managed keys available for E5
Message Retention Configure retention policies; delete permanently after specified period
Guest Access Disable or restrict to pre-approved domains only
Call Recording Storage Store in OneDrive with encrypted access; configure auto-deletion

Teams Best Practices

Outlook & Exchange Online Security

Email Encryption & DLP

Enable Office 365 Message Encryption (OME) to encrypt sensitive emails. Configure Data Loss Prevention (DLP) policies to scan for PHI patterns and prevent sending unencrypted messages containing health data. Restrict external forwarding and set up rules blocking PHI-containing emails to public domains.

Message Retention & Audit Logging

Set message retention policies to automatically delete email after a specified period aligned with compliance requirements. Enable audit logging for all mailbox activities. Review audit logs monthly for suspicious access patterns.

SharePoint & OneDrive Configuration

Component Compliance Setting
File Sharing Disable "Anyone" links; require sign-in; restrict to organization
External Sharing Limit to specific domains; require email verification
Version History Retain for 90 days minimum; configure auto-deletion
Encryption All files encrypted at rest; TLS in transit
Access Control Implement least-privilege access; regular access reviews

Azure Active Directory (Azure AD) Security

Authentication & Access Management

Device Compliance

Data Loss Prevention (DLP) Policies

DLP Configuration

Create DLP policies to detect Protected Health Information using sensitive information types for medical record numbers, insurance policy numbers, and health conditions. Set policies to warn users before sending PHI via email or external sharing. Block transmission to non-HIPAA compliant external domains.

DLP Rule Examples

Microsoft Purview Compliance

Unified Compliance Management

Use Microsoft Purview to centralize compliance monitoring across all Microsoft 365 services. Set up compliance alerts for DLP policy violations, retention policy changes, and sensitive data access. Generate compliance reports for regulatory audits and document organization's compliance posture.

Key Purview Features

Compliance Checklist & Governance

Before Processing PHI

✓ Signed BAA with Microsoft active
✓ Multi-factor authentication enforced
✓ Conditional Access policies configured
✓ DLP policies deployed and tested
✓ Teams guest access disabled
✓ Exchange Online encryption enabled
✓ SharePoint external sharing restricted
✓ Purview compliance monitoring active
✓ Audit logging enabled for all services
✓ User training completed and documented

Frequently Asked Questions

Do I need E3 or E5 licenses for HIPAA compliance? +
HIPAA BAAs are available for both E3 and E5 plans. E5 provides additional security features like advanced threat protection, but E3 with proper configuration can meet HIPAA requirements. E1 and E2 licenses do not support HIPAA BAAs.
How long does it take to get a Microsoft 365 BAA? +
Microsoft typically processes BAA requests within 2-4 weeks if you meet all requirements. Having a dedicated Microsoft account manager expedites the process. Contact Microsoft Health & Life Sciences or your account manager to initiate the BAA request.
Can we use Office desktop apps (Outlook, Word) with PHI on HIPAA? +
Yes, Office desktop applications are covered under the Microsoft BAA. Ensure devices are enrolled in Intune with encryption, require password authentication, and enforce MFA. All PHI files must be stored in OneDrive or SharePoint, not local drives.
What about third-party integrations with Microsoft 365? +
Third-party apps connecting to Microsoft 365 must have their own HIPAA BAAs if they process PHI. Review app privacy policies and permissions carefully. Consider disabling third-party integrations entirely if not essential, or use Microsoft-native alternatives.

Verify Your Microsoft 365 HIPAA Compliance

Medcurity audits Microsoft 365 deployments to ensure proper BAA coverage, security configuration, and compliance controls. Get peace of mind with a professional assessment.

Schedule Your Compliance Audit