HomeBlogCompliance

Microsoft 365 HIPAA Compliance: The BAA, Copilot and Required Settings

Illustration of a robot in a bright medical office holding a tablet checklist, beside a shield and padlock icon and an open file drawer

Microsoft 365 can support HIPAA compliance, but only after you configure it. Microsoft 365 HIPAA compliance starts with a BAA that Microsoft includes by default: its Data Protection Addendum says that when a covered entity or business associate puts PHI in the service, its customer agreement includes Microsoft’s HIPAA BAA. Configuring the tenant is your job.

We checked Microsoft’s pages in September 2026. This is general information, not legal advice. Our Microsoft 365 security hardening service covers tenant security for any business; this post maps those controls to HIPAA.

Does Microsoft sign a BAA?

Yes, and there is nothing separate to sign. Microsoft’s HIPAA and HITECH page says its BAA is available through the Data Protection Addendum “by default to all customers who are covered entities or business associates under HIPAA.” The May 2026 Data Protection Addendum says executing the customer’s agreement includes executing the BAA, points to the full text at aka.ms/BAA, and lets a customer opt out by written notice. Microsoft adds that it cannot use a customer’s own BAA, because its services are standardized.

The full BAA sits on Microsoft’s Service Trust Portal, which did not display the document to our reader, so this summary comes from the addendum and Microsoft’s HIPAA page. Microsoft is direct about the limit: asked whether its BAA ensures HIPAA compliance, its answer is no, and your organization stays responsible for its compliance program.

Which Microsoft 365 services are in scope?

For commercial tenants, Microsoft’s in-scope list includes Exchange Online, SharePoint Online, OneDrive for Business, Microsoft Teams, Forms, Planner, Stream, Office Online and Office Pro Plus, Microsoft Entra ID, Defender for Office 365, the Microsoft Purview portal, Power Apps, Power BI, and Microsoft Copilot and Copilot Chat. Microsoft Intune and Windows 365 appear on its list of in-scope cloud services as well.

Some things sit outside it. Copilot’s web search queries go to Bing under separate terms and are not covered by the addendum or the BAA. Models Microsoft labels Anthropic models with Data Retention fall under Anthropic’s terms, not Microsoft’s, and stay off until an administrator opts in. Third-party apps and agents follow their own terms, and a personal Outlook.com or OneDrive account is not on the list.

Is Copilot HIPAA compliant?

Microsoft says Microsoft Copilot and Copilot Chat, formerly Microsoft 365 Copilot, support HIPAA compliance for properly configured implementations (see Microsoft’s enterprise data protection notes, checked September 2026). The configuration that matters most is permissions. Copilot respects each user’s identity and access, inherits sensitivity labels and applies retention policies, so a SharePoint site shared too widely becomes one Copilot will summarize for everyone it is shared with. Fix SharePoint oversharing before Copilot, decide whether web search stays on for staff who handle PHI, and confirm Anthropic models with Data Retention are still off. How Copilot compares with ChatGPT and Claude is in our AI tools BAA comparison.

Which Microsoft 365 settings does HIPAA require?

HIPAA names safeguards, not settings. This is how the technical safeguards in 45 CFR 164.312 map to the Microsoft 365 controls we use:

Security Rule safeguardMicrosoft 365 control
Unique user identification, 164.312(a)(2)(i)One named Entra ID account per person; no shared front-desk logins
Person or entity authentication, 164.312(d)MFA for everyone: security defaults on any plan, or Conditional Access with at least Entra ID P1
Automatic logoff, 164.312(a)(2)(iii)Intune screen-lock policies on shared workstations
Encryption and decryption, 164.312(a)(2)(iv)BitLocker on every Windows device through Intune, recovery keys escrowed
Audit controls, 164.312(b)Purview Audit, on by default with 180-day retention; Audit (Premium) keeps key records a year
Transmission security, 164.312(e)Purview Message Encryption rules and forced TLS connectors

Two administrative requirements complete the picture: regular review of audit logs and access reports (164.308(a)(1)(ii)(D)) and a data backup plan with retrievable exact copies of ePHI (164.308(a)(7)(ii)(A)). Retention policies preserve data for compliance, but they are not a restore plan, so we pair tenants with independent Microsoft 365 backup.

Which Microsoft 365 plan fits a medical practice?

Most of that table assumes Microsoft 365 Business Premium or an E3 or E5 plan. Microsoft says Business Premium includes Entra ID P1, full Intune and Defender for Business for organizations of up to 300 users, and its message encryption FAQ lists Business Premium, E3 and E5 among the plans with Purview Message Encryption. Business Basic and Business Standard can add Azure Information Protection Plan 1 for encryption, but Conditional Access needs at least Entra ID P1. Our HIPAA email guide covers the encryption rules in detail.

Where NetSys fits

Our own stack runs on these tools: Intune and Windows Autopilot for devices, Microsoft Defender for Business, and Microsoft 365 administration, with 24/7 monitoring and support for managed clients. Through our HIPAA compliance work for practices we set these controls, export the evidence and track Microsoft’s BAA in your vendor register. A HIPAA compliance audit shows how far your tenant is from the table above, and our healthcare practice IT page covers the rest of the clinic. For how BAAs work with every other vendor, see our IT provider BAA guide.

Frequently asked questions

Is Office 365 HIPAA compliant?

Office 365 can support HIPAA compliance the same way Microsoft 365 does. Microsoft lists Office 365 among the cloud services covered by its HIPAA BAA, with Exchange Online, SharePoint Online, OneDrive for Business and Teams in scope for commercial tenants. The BAA covers the services; configuring them to meet the Security Rule is still up to you.

Is Microsoft Teams HIPAA compliant?

Teams is on Microsoft’s list of in-scope services, so chats, meetings and files in Teams fall under the BAA when PHI is involved. Compliance still depends on your settings: who can join as a guest, who can record meetings, where recordings and shared files are stored, and how long they are kept.

Do we have to sign anything to get Microsoft’s BAA?

No. Microsoft’s Data Protection Addendum says that for covered entities and business associates that put PHI in their data, executing the customer agreement includes executing the HIPAA BAA. Keep a dated copy of the addendum and the BAA with your HIPAA records, and note that Microsoft allows opting out by written notice.

How long does Microsoft 365 keep audit logs?

Purview Audit (Standard) keeps records for 180 days. Audit (Premium) keeps Entra ID, Exchange, OneDrive and SharePoint records for one year by default, with ten-year retention as a per-user add-on. The Security Rule’s audit controls standard sets no retention period, and its six-year rule covers required documentation, so decide log retention in your risk analysis.

Sources (checked September 2026)

Microsoft Copilot Consulting

Discuss microsoft copilot consulting for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.

Explore Microsoft Copilot Consulting 845-203-3914