August 7, 2026
True IT Pro

TL;DR: Microsoft 365 can support HIPAA compliance, but it is not compliant by default. Healthcare organizations are responsible for taking the necessary steps to configure and maintain a HIPAA-compliant Microsoft 365 environment. To meet HIPAA requirements, businesses must choose a HIPAA-eligible Microsoft 365 plan, have a Business Associate Agreement (BAA) on file, and properly configure the correct compliance features. Ongoing monitoring, employee training, and regular risk assessments are also required to maintain a HIPAA-compliant environment.

In this guide, we explain what it takes to make Microsoft 365 HIPAA compliant, including:

Is Microsoft 365 HIPAA Compliant?

A healthcare professional in a white coat wearing a stethoscope, typing at a laptop with a blue overlay of a lock, showing the concept of data encryption for HIPAA compliance

Yes, Microsoft 365 can be HIPAA compliant, but it must be properly configured and used in accordance with HIPAA’s Privacy, Security, and Breach Notification rules. This means that if your business handles protected health information (PHI), simply purchasing a Microsoft 365 subscription doesn’t automatically mean the tools and apps you use are HIPAA compliant.

Healthcare organizations must take the necessary steps to configure and maintain a HIPAA-compliant environment. If these tools are left at their default settings and used incorrectly, patient information could be at risk.

HIPAA Compliance is a Shared Responsibility Between Microsoft and Healthcare Organizations

Microsoft’s shared responsibility model divides security, compliance, and operational duties between Microsoft and the customer. This means HIPAA compliance is a shared responsibility between Microsoft and healthcare organizations:

  • Microsoft is responsible for protecting the cloud infrastructure that runs Microsoft 365. That includes its data centers, servers, networks, and the security of the platform itself.
  • Healthcare organizations are responsible for protecting the patient data stored and shared within Microsoft 365. This includes managing user permissions, enabling and configuring security features, securing connected devices, training employees, and more.

If these responsibilities are neglected, medical organizations may be at risk of HIPAA violations, even if Microsoft’s infrastructure remains fully secure.

How to Make Microsoft 365 HIPAA Compliant

Microsoft 365 offers a wide range of built-in security features that can help healthcare organizations protect patient data. That said, it isn’t secure enough out of the box to meet HIPAA requirements. Many important security features need to be turned on and configured to ensure sensitive patient health information is properly protected.

While every healthcare organization has different needs, below are some of the most important steps you can take to build and maintain a HIPAA-compliant Microsoft 365 environment.

1. Choose a HIPAA-Eligible Microsoft 365 Plan

A healthcare professional in a white lab coat points a stylus at the screen of a laptop, in between two other laptops, displaying Microsoft 365 software. The background is a modern office space with two stories and large windows.

Not every Microsoft 365 subscription includes the same security, compliance, and management features. While many Microsoft 365 commercial and enterprise plans support HIPAA compliance, some are better suited for certain healthcare organizations than others:

Microsoft 365 Plans That Support HIPAA Compliance

Microsoft 365 PlanHIPAA-Relevant FeaturesImportant Considerations
Microsoft 365 Business Premium
(up to 300 users)
BAA coverage, Data Loss Prevention (DLP), Purview, Intune (MDM/MAM), Defender for Business, Entra ID P1Includes many of the security features needed for HIPAA but lacks some enterprise compliance capabilities and limits users.
Microsoft 365 Enterprise E3
(unlimited users)
BAA coverage, Data Loss Prevention (DLP), Purview, Intune (MDM/MAM), Defender for Business, Entra ID P1One of the most common choices for healthcare organizations needing strong security and compliance with no user cap.
Microsoft 365 Enterprise E5
(unlimited users)
BAA coverage, Data Loss Prevention (DLP), Advanced Purview Tools, Intune (MDM/MAM), Defender XDR Suite, Entra ID P2, Power BI ProProvides Microsoft’s most comprehensive security and compliance capabilities with no user cap.

There is no one-size-fits-all HIPAA Microsoft 365 plan. HIPAA compliance depends on choosing a plan with the security and compliance capabilities your organization needs and properly configuring and managing your Microsoft 365 environment.

2. Keep a Copy of Your Microsoft Business Associate Agreement (BAA) on File

A healthcare professional in a white lab coat holding a laptop, pointing to an illustrated overlay of a checklist on a clipboard, showing the concept of HIPAA compliance documentation

If your healthcare organization uses Microsoft 365 to store, process, or transmit protected health information, you should maintain a copy of Microsoft’s Business Associate Agreement (BAA) as part of your HIPAA compliance documentation.

HIPAA compliance requires you to have a BAA with all third-party service providers that store, process, or transmit PHI on your behalf. This is a legal contract that outlines each party’s responsibilities for protecting sensitive health data.

Microsoft 365 includes a HIPAA BAA by default for qualifying commercial and enterprise services. While you do not need to physically sign this agreement for it to be valid, you should keep a copy of it on file.

During a HIPAA audit, security assessment, or compliance review, you may need to provide documentation showing that a valid BAA is in place. Keeping a copy readily available makes it much easier to demonstrate compliance.

How to Download Your Microsoft 365 BAA

To access a copy of Microsoft’s HIPAA Business Associate Agreement, you’ll need to download it through the Microsoft online Service Trust Portal:

  1. Visit Microsoft’s Service Trust Portal
  2. Use the search function to search “HIPAA BAA”
  3. Click the most recent version indicated by the month and year:
    • EXAMPLE: Microsoft General – HIPAA BAA (July 2026)
  4. To download the Microsoft HIPAA BAA, you will need to be signed in to your Microsoft 365 account.
  5. Once you are logged in, download the Microsoft HIPAA BAA.

After downloading the agreement, save a copy of the Microsoft BAA with all your other HIPAA compliance documentation. It’s also a good idea to periodically verify that your agreement is still current, especially if your Microsoft licensing or services change.

Additionally, the specific apps, platforms, and services covered by Microsoft’s BAA can change over time. This makes it incredibly important to regularly check Microsoft’s list of HIPAA-covered services.

Important Note: A Business Associate Agreement is only one piece of HIPAA compliance. You’ll also need to configure Microsoft 365 tools, implement appropriate administrative and technical safeguards, and ensure your staff follows HIPAA security and privacy best practices.

3. Configure Encryption Across Your Microsoft 365 Environment

A healthcare professional in a white lab coat sitting at a desk in front of a laptop, with an illustrated overlay of a document with locks and shields, showing the concept of data security and encryption for HIPAA compliance

Encryption is one of the core HIPAA compliance security rules that every healthcare provider needs to follow. Encryption converts data into an unreadable format for anyone who doesn’t have proper authorization to access it. This secures PHI even if it is intercepted, accessed improperly, or exposed during a security incident.

Microsoft 365 offers powerful encryption capabilities for data being stored in the cloud (at rest) and when it is being sent across networks (in transit). However, they are not all activated or configured for HIPAA compliance by default.

To ensure complete coverage, encryption must be properly configured across the specific Microsoft programs and services handling patient data:

Microsoft Purview (Cloud and App Protection)

Microsoft Purview serves as the central hub for encryption and information protection across Microsoft 365. Through sensitivity labels and data loss prevention (DLP) policies, Purview helps ensure PHI remains secure whether it is stored in the cloud, shared internally, or accessed by authorized users:

  • Exchange Online (Emails): Uses Microsoft Purview Message Encryption to automatically or manually encrypt emails and attachments containing PHI.
  • Microsoft Teams: Encrypts chat logs, shared files, and meeting data streams both while stored in the cloud and during active Teams video calls.
  • SharePoint Online: Encrypts document libraries and files containing patient information that stay with the file wherever it’s stored.
  • OneDrive for Business: Encrypts documents stored in OneDrive and controls who can access or share them.

By configuring Purview encryption across your Microsoft 365 environment, healthcare organizations can better protect PHI wherever it’s stored, shared, or accessed.

Microsoft Intune (Device Protection)

When properly configured, Microsoft Intune enforces encryption across every computer, phone, and tablet used to access PHI in your practice:

  • Microsoft Intune Mobile Device Management (MDM): Encrypts all data on the hard drive of company-owned Windows laptops and desktops via BitLocker and Apple laptops and desktops via FileVault. Unencrypted or non-compliant devices get flagged and blocked from accessing any PHI in your Microsoft environment.
  • Microsoft Intune Mobile Application Management (MAM): Encrypts PHI accessed through Microsoft 365 mobile apps by controlling how data can be shared, copied, downloaded, viewed, or stored on mobile devices.

Microsoft Intune adds an additional layer of protection by ensuring that only secure, compliant devices and applications can access sensitive healthcare data. This helps prevent unauthorized access to PHI via on-site devices and even when employees are working remotely or using mobile devices.

4. Configure Access Controls with Microsoft Entra ID

A healthcare professional in a white lab coat and blue tie sits at a laptop at a desk, holding their phone, with an illustrated overlay of a login screen, showing the concept of multi-factor authentication (MFA) and access controls for HIPAA compliance.

HIPAA requires healthcare providers to establish strict access controls to protect all types of protected health information. Microsoft Entra ID access controls determine who can view, edit, or share PHI across your entire Microsoft 365 environment.

When properly configured, healthcare organizations can use Entra ID to help ensure only authorized personnel have access to the specific information they need to perform their jobs.

Entra Conditional Access Policies

Entra Conditional Access helps organizations create rules that determine when and how users can access Microsoft 365 applications.

Common Conditional Access policies include:

  • Requiring MFA when accessing sensitive information
  • Blocking access from unknown or non-compliant devices
  • Restricting access based on user risk or location
  • Requiring devices to meet security standards before connecting

These policies help prevent unauthorized access while allowing employees to work securely from approved devices and locations.

Multi-Factor Authentication (MFA)

Passwords alone are no longer enough to protect sensitive healthcare data. Multi-factor authentication (MFA) adds another layer of protection by requiring users to verify their identity before signing in. Healthcare organizations should enable MFA through Microsoft Entra ID for all users, especially administrators and anyone with access to sensitive patient information.

Role-Based Access Control (RBAC)

Microsoft Entra role-based access control (RBAC) allows organizations to control who can access information and what actions they can take. You can configure roles, groups, and permissions, so employees only have access to the data and Microsoft tools required to do their jobs.

Important access management practices include:

  • Reviewing user permissions regularly
  • Removing access immediately when employees leave the organization
  • Limiting administrator privileges
  • Creating separate access levels based on job responsibilities

Strong RBAC helps ensure that patient information is only available to the people who need it.

5. Configure Data Loss Prevention Policies

A healthcare professional in blue scrubs typing on a laptop at a desk with a notebook, with an illustrated overlay of a healthcare cross and documents, showing the concept of data security for HIPAA compliance

Microsoft Purview Data Loss Prevention (DLP) policies act as a HIPAA compliance safety net inside Microsoft 365. DLP allows healthcare organizations to create rules that automatically prevent PHI from being shared in ways that violate security policies. It constantly scans outgoing emails, Teams chats, documents, and files and automatically blocks sharing protected health information in an unauthorized way:

Microsoft Purview Data Loss Prevention (DLP)

When Microsoft Purview DLP detects sensitive data being shared outside your approved workflows, it automatically triggers protective actions based on rules you set, such as:

  • Policy Tips: Displays an immediate pop-up notification in emails or Teams, alerting users that their message contains PHI and guiding them to use an encrypted channel instead.
  • Automated Email Encryption: Automatically applies Microsoft Purview Message Encryption if PHI is detected in an outgoing email.
  • External Sharing Restrictions: Instantly blocks external sharing or downloads of documents containing PHI stored in OneDrive or SharePoint.
  • Incident Reports: Sends real-time notifications whenever a high-risk policy violation occurs.

Configuring DLP policies across your Microsoft 365 environment reduces accidental HIPAA violations without disrupting everyday workflows.

6. Enable Microsoft Purview Audit for Activity Monitoring

Two healthcare professionals sit at a desk in front of two desktop monitors and a laptop, in a healthcare clinic, showing the concept of Microsoft 365 software and services

HIPAA requires healthcare organizations to have safeguards in place to detect unauthorized access to PHI. Microsoft Purview Audit provides visibility into actions taken across Microsoft 365. This can include who accessed information, what changes were made, and when those activities occurred.

These activity logs can help you detect unauthorized access, investigate security incidents, and keep the thorough documentation required for HIPAA compliance.

How to Monitor User Activity in Microsoft 365

To support HIPAA compliance, healthcare organizations should configure Microsoft Purview Audit to monitor activities such as:

  • User Sign-Ins: Identify unusual login attempts, failed access attempts, and suspicious account activity that could indicate unauthorized access.
  • File Access and Sharing Activity: Track who viewed, edited, downloaded, or shared documents containing PHI in OneDrive and SharePoint.
  • Email Activity: Monitor mailbox access, forwarding rules, and other actions that could expose sensitive information.
  • Microsoft Teams Activity: Track access, file sharing, and collaboration involving sensitive information shared through Teams.
  • Administrative Changes: Identify changes to security settings, user permissions, and DLP policies that could impact your organization’s security posture.

Purview Audit is most valuable when it is regularly reviewed and connected to an incident response process. To ensure HIPAA compliance, healthcare organizations should establish procedures for investigating suspicious activity, documenting incidents, and taking corrective action when necessary.

7. Perform Routine HIPAA Compliance Assessments

A healthcare professional in a white coat sits at a desk, using a tablet and stylus, with illustrated overlays of clipboards and checklists

HIPAA compliance is an ongoing process. Your Microsoft 365 environment changes over time as employees join or leave, new devices are added, permissions are updated, and Microsoft introduces new features and security capabilities.

HIPAA requires healthcare organizations to regularly evaluate the effectiveness of their security measures, making routine assessments essential. Assessments should evaluate both your Microsoft 365 environment and the policies governing how it’s used.

This helps ensure your security settings continue to protect PHI, identify new risks promptly, and demonstrate that your organization is actively managing HIPAA compliance.

Review Microsoft Purview Compliance Score

Microsoft Purview Compliance Manager assigns you a score based on how many recommended security and compliance controls you’ve implemented. It evaluates your current Microsoft 365 environment, identifies areas for improvement, and provides recommended actions to strengthen your compliance posture.

Healthcare organizations should regularly review their Compliance Score to:

  • Identify Compliance Gaps: Find areas where Microsoft 365 configurations, policies, or processes may not fully support HIPAA requirements.
  • Prioritize Security Improvements: Focus resources on recommended actions that can have the greatest impact on protecting PHI.
  • Track Compliance Progress: Monitor improvements over time and maintain documentation of ongoing compliance efforts.

While the score doesn’t certify HIPAA compliance, it provides a simple way to identify gaps and prioritize the improvements that will most reduce your compliance risk.

Monitor Microsoft Defender Security Alerts

Microsoft Defender continuously monitors your Microsoft 365 environment for suspicious activity, such as abnormal sign-in attempts, malware, and more.

Healthcare organizations should monitor Defender alerts to:

  • Detect Suspicious Activity: Identify unusual login behavior, unauthorized access attempts, and other signs of compromised accounts.
  • Investigate Potential Threats: Review security alerts to determine whether an incident could impact patient information or Microsoft 365 resources.
  • Respond Quickly to Security Issues: Take corrective action to contain threats and reduce the risk of data breaches.

Continuously reviewing security alerts allows you to detect potential threats early and take action before sensitive information is exposed.

Review Microsoft 365 Security Controls

To help ensure your Microsoft 365 environment continues to support HIPAA compliance, you should regularly review and update your:

  • User Access Permissions: Verify that all users only have access to the Microsoft 365 applications, files, and PHI they need to perform their job responsibilities.
  • Security Settings: Review Microsoft 365 configurations, including security defaults, multi-factor authentication settings, conditional access policies, encryption settings, and data protection controls.
  • Data Protection Policies: Confirm that Microsoft Purview DLP, sensitivity labels, retention policies, and encryption settings are correctly configured.
  • Third-Party Applications: Evaluate connected applications, integrations, and vendors that access Microsoft 365 data to ensure they follow appropriate security and compliance requirements.
  • Security Policies: Adjust internal policies as technology, workflows, employee responsibilities, and Microsoft 365 capabilities change.
  • Employee Training: Provide ongoing training so employees understand how to securely handle PHI, recognize malicious activity, and follow internal Microsoft 365 security procedures.
  • Assessment Result Documentation: When your organization identifies a Microsoft 365 security or compliance gap, document it thoroughly, including what needed to be corrected and how the issue was addressed. This documentation is a legal obligation to follow HIPAA compliance rules.

Maintaining a HIPAA-compliant Microsoft 365 environment is an ongoing responsibility. By continuously reviewing security controls, monitoring threats, and improving your compliance posture, you can keep PHI secure and reduce the risk of HIPAA violations.

Contact True IT: A Trusted Microsoft Partner

Healthcare practices are built on trust. Patients rely on you to protect their personal information and provide quality care without disruption. Keeping Microsoft 365 HIPAA compliant requires ongoing attention, technical expertise, and time.

At True IT, we’ve seen the unique challenges that healthcare organizations face firsthand. With over 40 years of experience as a trusted Microsoft Partner, we can help you maximize compliance, efficiency, and security with Microsoft 365 managed services.

Contact us today to schedule a free consultation.