Microsoft Azure: HIPAA status
Microsoft's cloud platform. Its HIPAA BAA is part of the standard licensing terms for customers who are covered entities or business associates.
Microsoft Azure signs a Business Associate Agreement. Included by default through the Microsoft Products and Services Data Protection Addendum for in-scope Azure services.
Source: Microsoft — HIPAA (Azure compliance offering) · checked
Microsoft Azure and HIPAA at a glance
Microsoft Azure signs a Business Associate Agreement. A BAA alone does not make its use HIPAA compliant: you still need to confirm each Azure service you use is in scope for the HIPAA BAA, and use Azure Policy's HIPAA/HITRUST initiative to check configuration — it gives a partial view, not proof of compliance. Facts checked against Microsoft's own documentation on 2026-10-06.
| Signs a BAA | Yes |
|---|---|
| How you get it | Included by default through the Microsoft Products and Services Data Protection Addendum for in-scope Azure services. |
| You still need to | Confirm each Azure service you use is in scope for the HIPAA BAA. |
| Main limitation | Microsoft does not inspect, approve or monitor applications you deploy; their compliance is your responsibility. |
| Last checked | 2026-10-06 |
BAA details
| Signs a BAA | Yes | Microsoft — HIPAA (Azure compliance offering) |
|---|
What you still have to configure
- Confirm each Azure service you use is in scope for the HIPAA BAA. source
- Use Azure Policy's HIPAA/HITRUST initiative to check configuration — it gives a partial view, not proof of compliance. source
Limitations
- Microsoft does not inspect, approve or monitor applications you deploy; their compliance is your responsibility. source
Against our criteria
| BAA without a sales process | Yes — Included in standard licensing terms. | Microsoft — HIPAA (Azure compliance offering) |
|---|---|---|
| Safeguards managed for you | No — Infrastructure: you configure and secure your environment. | Microsoft — HIPAA (Azure compliance offering) |