CompyMax

Is Microsoft 365 HIPAA compliant?

Only under specific conditions

Yes — the agreement already applies to business and enterprise subscriptions automatically through Microsoft's Data Protection Addendum, but you must keep patient information inside the services Microsoft lists as in scope.

Applies to Microsoft 365 (Teams, Exchange Online, SharePoint, OneDrive). Last reviewed against Microsoft's own documentation. Next review November 28, 2026.

Reviewed by Lisa Tran, CISSP — Healthcare Information Security Executive.

What you must do

  • No signing ceremony is needed. Microsoft states the agreement is available through the Data Protection Addendum by default to all customers who are covered entities or business associates.
  • Download a copy from the Service Trust Portal for your records — auditors typically ask for the 'Microsoft General – HIPAA BAA' document.
  • Keep patient information inside the in-scope services Microsoft publishes. For Microsoft 365 Commercial these include Exchange Online, SharePoint Online, OneDrive for Business, Teams, Office Online, Forms, Planner, Entra ID, Purview, Defender for Office 365, Microsoft 365 Copilot, Power Apps, Power Automate and Power BI.
  • Configure your own tenant controls. Microsoft is explicit that using its services does not on its own achieve compliance.
  • Microsoft will not sign your organization's own agreement template — you use Microsoft's.

Does Microsoft 365 sign a business associate agreement?

Yes. Microsoft offers one. Applies by default to business and enterprise Online Services customers who are covered entities or business associates. Nothing to request. To keep proof, sign in to the Service Trust Portal and download the 'Microsoft General – HIPAA BAA' document.

See their documentation.

What this means in practice

Microsoft is unusual in that there is no signing ceremony. The agreement is already available through the Data Protection Addendum to business and enterprise customers who are covered entities or business associates, so there is nothing to request and nobody to chase. This confuses people in both directions: some conclude there is nothing to do at all, while others spend weeks trying to get a Microsoft signature that will never arrive, and will not get their own template signed either.

What you do need is proof and boundaries. Download the general HIPAA agreement document from the Service Trust Portal and keep it on file, because auditors and payer security questionnaires ask for a copy and default coverage is hard to evidence otherwise.

The boundary is drawn service by service, not account by account. Exchange Online, SharePoint, OneDrive, Teams, Forms, Purview and Copilot are named in scope for Microsoft 365 Commercial, but the lists differ for government environments, and third-party apps installed into your tenant follow their own vendors' terms. Microsoft is blunt that using its services does not on its own achieve compliance.

How organizations get this wrong

The specific mistakes we see with Microsoft 365, not generic advice.

  • Delaying a project while chasing a Microsoft countersignature that does not exist, when coverage already flows through the Data Protection Addendum.
  • Sending Microsoft the practice's own agreement template and reading the refusal as a refusal to cover you at all.
  • Having nothing on file when an auditor asks for the executed agreement, because nobody downloaded it from the Service Trust Portal.
  • A clinician using a consumer Microsoft subscription on a home machine for practice documents, which is not an Online Service under the addendum.

What the agreement does not cover

  • Any Microsoft cloud service not named on the in-scope list. The published table carries rows for Commercial and Government Community Cloud only.
  • Consumer Microsoft subscriptions, which are not Online Services under the Data Protection Addendum.
  • Third-party apps and add-ins installed into Microsoft 365, governed by their own vendors' terms.

Alternatives

Listed on merit. We take no payment for placement and use no affiliate links.

  • Google Workspace

    Comparable suite with an explicit click-to-accept amendment in the Admin console

Signing the agreement is step one. Proving it is step two.

Once you have the agreement with Microsoft 365, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.

$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.

Sources

Every statement above comes from Microsoft’s own published documentation, read on the date shown.

  1. Health Insurance Portability and Accountability Act (HIPAA) & HITECH ActMicrosoft. Published July 29, 2025. Read July 29, 2026.
  2. Microsoft General – HIPAA BAA (Service Trust Portal)Microsoft. No publication date given. Read July 29, 2026.

Change history

  • First published.
  • Correction: an earlier version of this page said Commercial, GCC, GCC High and DoD each have different in-scope service lists. Re-checked against Microsoft's live table, which carries rows for Commercial and GCC only. GCC High and DoD are described in prose without a published service list.

This page is information, not certification and not legal advice. It reflects Microsoft’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.

Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.