Is Azure HIPAA compliant?
Yes, and unusually there is nothing to sign — the agreement already applies if you bought Azure under a Microsoft licensing agreement, but only services in Microsoft's audit scope may hold patient data and everything you build on top is yours to secure.
Applies to Microsoft Azure and Azure Government. Last reviewed against Microsoft's own documentation. Next review February 6, 2027.
Reviewed by Lisa Tran, CISSP — Healthcare Information Security Executive.
What you must do
- Nothing to request or sign separately. Microsoft states there is no separate contract, because the agreement is available through the Product Terms by default to any customer that is a covered entity or business associate.
- Confirm your purchase route incorporates the Product Terms and the Data Protection Addendum — the addendum is what provides that executing your licensing agreement executes the business associate agreement.
- Keep patient data only inside services Microsoft lists as in audit scope. Azure and Azure Government are the applicable platforms.
- Configure everything above the platform yourself: identity, access, encryption choices, logging, backup. Microsoft says plainly that it does not inspect, approve or monitor the applications you deploy.
- If you sell a healthcare product built on Azure, sign your own agreement with your customers. Microsoft's does not reach them.
- Do not expect Microsoft to sign your paper. It states it cannot use a customer's own agreement, because its services are standardised across all customers.
Does Azure sign a business associate agreement?
Yes. Microsoft offers one. No particular tier. Included by default for covered entities and business associates purchasing under a licensing agreement that incorporates the Product Terms and Data Protection Addendum. Nothing to request. Microsoft states there is no separate contract to sign; the agreement rides on the Product Terms, and the Data Protection Addendum provides that executing your volume licensing agreement executes it.
What this means in practice
Azure is the odd one out among the big three, and the difference trips people up in both directions. There is no button to press and no addendum to accept: Microsoft states there is no separate contract, because the agreement rides on the Product Terms, and the Data Protection Addendum provides that executing your licensing agreement executes it. Organizations spend weeks hunting for a signature page that does not exist.
The other direction is worse. Because nothing was signed, nothing was decided — and the discipline that AWS forces by making you click something never happens. The obligation that remains is the same one: patient data belongs only in services Microsoft lists as in audit scope, and Microsoft is explicit that it does not inspect, approve or monitor what you deploy on top.
One point matters if you sell software rather than buy it. Microsoft's agreement with you does not reach your customers. A practice buying your healthcare product does not inherit anything from your relationship with Microsoft; they need an agreement with you.
How organizations get this wrong
The specific mistakes we see with Azure, not generic advice.
- Hunting for a business associate agreement to sign, concluding none is available, and using Azure for patient data with no idea whether the licensing route actually carried one.
- Buying Azure through a route that does not incorporate the Product Terms and Data Protection Addendum, which is what carries the agreement in the first place.
- Telling a customer they are covered by Microsoft's agreement because your product runs on Azure — it does not extend to them.
- Sending Microsoft your own business associate paper to sign, when it states it cannot use a customer's agreement.
What the agreement does not cover
- Azure services outside Microsoft's published audit scope.
- Your own application code, configuration and access model running on Azure — Microsoft neither reviews nor monitors it.
- Your customers, if you are a SaaS provider. Microsoft's agreement with you does not extend to the practices buying your product.
Alternatives
Listed on merit. We take no payment for placement and use no affiliate links.
Comparable cloud, but the addendum is an explicit click-through in AWS Artifact rather than automatic
Comparable cloud whose agreement covers the whole infrastructure, with a published covered-products list
Signing the agreement is step one. Proving it is step two.
Once you have the agreement with Azure, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.
$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.
Sources
Every statement above comes from Microsoft’s own published documentation, read on the date shown.
- Health Insurance Portability and Accountability Act (HIPAA) & HITECH Act — Microsoft Compliance — Microsoft. Published July 29, 2025. Read August 10, 2026.
- HIPAA — Azure Compliance — Microsoft. Published April 5, 2023. Read August 10, 2026.
Change history
- — First published.
This page is information, not certification and not legal advice. It reflects Microsoft’s published documentation as read on August 10, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.
Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.