Is Microsoft Teams HIPAA compliant?
Yes — Teams is named on Microsoft's in-scope services list and the agreement applies to business subscriptions automatically, but you configure the tenant and keep patient information out of anything not on that list.
Applies to Microsoft Teams. Last reviewed against Microsoft's own documentation. Next review January 13, 2027.
Reviewed by Carlos Mendez — IT Security Manager, regional healthcare network.
What you must do
- Nothing to sign. The agreement is available through Microsoft's Data Protection Addendum by default to covered entities and business associates.
- Teams appears on the published in-scope tables for Commercial and Government Community Cloud.
- Download the 'Microsoft General – HIPAA BAA' from the Service Trust Portal and keep it as evidence.
- Configure your own tenant. Microsoft states that using its services does not on its own achieve compliance.
- Use Microsoft's form — it states it cannot accept a customer's own agreement.
- Keep recordings, transcripts and shared files in services that are themselves on the list; OneDrive for Business and SharePoint Online both are.
Does Microsoft Teams sign a business associate agreement?
Yes. Microsoft offers one. Applies by default to business and government Online Services customers. Microsoft frames coverage per service, not per plan. Nothing to request. Download the agreement from the Service Trust Portal for your records.
What this means in practice
Microsoft handles this differently from almost every other vendor: there is no signing ceremony. The agreement is available through the Data Protection Addendum by default to customers who are covered entities or business associates, and Teams appears by name on the in-scope services list for both the Commercial and Government Community Cloud environments.
What that buys is narrower than it sounds. Microsoft answers its own question bluntly — having the agreement does not achieve compliance, and your organization remains responsible for its programme, its internal processes and how the service is actually used. Microsoft will also not accept your own agreement template, because it standardises a single form across all customers.
The real work is tenant configuration and boundary discipline. Meeting recordings, transcripts and shared files come to rest somewhere else, and that destination has to be on the list too; OneDrive for Business and SharePoint Online both are. Anything bolted onto Teams from another vendor is not a Microsoft service and is not reached by Microsoft's agreement.
How organizations get this wrong
The specific mistakes we see with Microsoft Teams, not generic advice.
- Assuming free Teams or a personal Microsoft account is covered, when the agreement rides on business Online Services.
- Recording clinical meetings with no retention rule, so transcripts accumulate indefinitely in OneDrive or SharePoint.
- Adding third-party bots, connectors or meeting apps to a clinical team, none of which Microsoft's agreement covers.
- Citing Microsoft's own security certifications as proof of your compliance rather than of Microsoft's programme.
What the agreement does not cover
- Any Microsoft service not named on the in-scope table for your environment.
- Consumer and free Microsoft subscriptions.
- Third-party apps, bots, connectors and meeting add-ins installed into Teams.
Alternatives
Listed on merit. We take no payment for placement and use no affiliate links.
Paid plans with an agreement you enable yourself, if you want meetings separated from your email tenant
Named on Google's Included Functionality list and covered by the Admin console amendment
Signing the agreement is step one. Proving it is step two.
Once you have the agreement with Microsoft Teams, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.
$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.
Sources
Every statement above comes from Microsoft’s own published documentation, read on the date shown.
- Health Insurance Portability and Accountability Act (HIPAA) & HITECH Act — Microsoft. Published July 29, 2025. Read July 29, 2026.
Change history
- — First published.
This page is information, not certification and not legal advice. It reflects Microsoft’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.
Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.