Is OneDrive HIPAA compliant?
Yes for OneDrive for Business on a Microsoft 365 business subscription, where the agreement applies automatically — but the consumer OneDrive on a personal Microsoft account is a different product and is not covered.
Applies to OneDrive for Business. Last reviewed against Microsoft's own documentation. Next review January 15, 2027.
Reviewed by Lisa Tran, CISSP — Healthcare Information Security Executive.
What you must do
- Use OneDrive for Business, the service Microsoft names on its in-scope tables.
- No signature required — the agreement arrives through the Data Protection Addendum.
- Download the 'Microsoft General – HIPAA BAA' from the Service Trust Portal for your evidence file.
- Set your own sharing controls. Anonymous links, guest access, retention and deletion are your configuration.
- Review which third-party applications can read the drive.
Does OneDrive sign a business associate agreement?
Yes. Microsoft offers one. Applies by default to business and government Online Services customers. Coverage is scoped by service, not subscription tier. Nothing to request. Download the agreement from the Service Trust Portal.
What this means in practice
The list Microsoft publishes says 'OneDrive for Business', and that precision is most of the answer. The agreement arrives automatically through the Data Protection Addendum, and OneDrive for Business is named on the in-scope tables for both the Commercial and Government Community Cloud environments. Nobody has to sign anything.
Consumer OneDrive is a different product under different terms, and it is not the service Microsoft names. Staff who sync a work folder to a personal Microsoft account, or install the consumer client on a home machine and drag records into it, have put files somewhere Microsoft has made no commitment about — and the practice usually finds out only when the person leaves.
Microsoft is explicit that using its services does not on its own achieve compliance, and with storage that responsibility is mostly about sharing. Anonymous links, external guest access, retention schedules and which connected applications can read the drive are all yours to set. Download the agreement from the Service Trust Portal so there is a document to hand over when someone asks.
How organizations get this wrong
The specific mistakes we see with OneDrive, not generic advice.
- Syncing a clinical folder to a staff member's personal Microsoft account, which is consumer OneDrive and outside the named service.
- Leaving anyone-with-the-link sharing enabled, so a records link forwarded outside the practice stays open indefinitely.
- Assuming the agreement extends to every app connected to the drive, when third-party tools are not Microsoft services on the list.
- Never downloading the agreement from the Service Trust Portal, then having nothing to produce when an auditor asks.
What the agreement does not cover
- Consumer OneDrive on a personal Microsoft account — Microsoft's list names 'OneDrive for Business' specifically.
- Any Microsoft service not named on the in-scope table.
- Third-party apps and integrations connected to the drive.
Signing the agreement is step one. Proving it is step two.
Once you have the agreement with OneDrive, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.
$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.
Sources
Every statement above comes from Microsoft’s own published documentation, read on the date shown.
- Health Insurance Portability and Accountability Act (HIPAA) & HITECH Act — Microsoft. Published July 29, 2025. Read July 29, 2026.
Change history
- — First published.
This page is information, not certification and not legal advice. It reflects Microsoft’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.
Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.