Microsoft 365: HIPAA status
Exchange Online (Outlook), OneDrive, Teams and Office apps. Microsoft's BAA is included by default for customers who are covered entities or business associates.
Microsoft 365 signs a Business Associate Agreement. Included by default through the Microsoft Online Services Data Protection Addendum for covered entities and business associates; covers in-scope services including Exchange Online.
Source: Microsoft — HIPAA & HITECH offering · checked
Microsoft 365 and HIPAA at a glance
Microsoft 365 signs a Business Associate Agreement. A BAA alone does not make its use HIPAA compliant: you still need to turn on security defaults (or Conditional Access) so every user must use multifactor authentication, and set up Microsoft Purview Message Encryption, for example with mail flow rules, to encrypt messages to patients. Facts checked against Microsoft's own documentation on 2026-10-05.
| Signs a BAA | Yes |
|---|---|
| How you get it | Included by default through the Microsoft Online Services Data Protection Addendum for covered entities and business associates; covers in-scope services including Exchange Online. |
| You still need to | Turn on security defaults (or Conditional Access) so every user must use multifactor authentication. |
| Main limitation | Message Encryption is included in Microsoft 365 Business Premium and E3/E5; Business Basic and Business Standard need the Azure Information Protection Plan 1 add-on. |
| Last checked | 2026-10-05 |
BAA details
| Signs a BAA | Yes | Microsoft — HIPAA & HITECH offering |
|---|
What you still have to configure
- Turn on security defaults (or Conditional Access) so every user must use multifactor authentication. source
- Set up Microsoft Purview Message Encryption, for example with mail flow rules, to encrypt messages to patients. source
- Confirm every service you use with PHI is on Microsoft's in-scope list for the BAA. source
Limitations
- Message Encryption is included in Microsoft 365 Business Premium and E3/E5; Business Basic and Business Standard need the Azure Information Protection Plan 1 add-on. source
- Microsoft signs only its standard BAA, not customers' own BAA forms. source
Against our criteria
| Encryption in transit | Yes | Microsoft — Email encryption in Microsoft 365 |
|---|---|---|
| Encryption at rest | Yes | Microsoft — Email encryption in Microsoft 365 |
| Secure delivery to patients | Partial — Recipients on Gmail, Yahoo and others read encrypted mail via a one-time passcode or sign-in; included in Business Premium and E3/E5, add-on for Business Basic/Standard. | Microsoft — Purview service description (licensing) |
| Enforceable MFA | Yes — Security defaults require all users to register for and use MFA, at no extra cost. | Microsoft — Security defaults for Microsoft Entra ID |
| Audit logs for customers | Yes — Audit (Standard) is included in Business Basic, Standard and Premium. | Microsoft — Purview service description (licensing) |