ePHI in Microsoft 365: What It Means for Your Organization
If your organization keeps patient information in email, files, chats or forms in Microsoft 365, that information is electronic protected health information (ePHI) and the HIPAA Security Rule applies to how you protect it. Microsoft offers a HIPAA Business Associate Agreement to covered entities and business associates through its Data Protection Addendum, and many Microsoft 365 services are in scope. That agreement covers Microsoft’s side. Your side is how your Microsoft 365 environment is set up: who can sign in, what is shared, what is encrypted, what is kept and what is logged. ALCON DTS can help configure and run the sign-in, sharing, retention, audit and device controls so your security risk analysis has something solid to point to.
This page answers:
At a glance
- What ePHI is: protected health information transmitted by or maintained in electronic media (45 CFR 160.103)
- Microsoft’s BAA: Microsoft says its HIPAA Business Associate Agreement “is available through the Microsoft Online Services Data Protection Addendum by default to all customers who are covered entities or business associates under HIPAA”
- In scope: Microsoft lists services such as Exchange Online, SharePoint Online, OneDrive for Business, Microsoft Teams, Microsoft Entra ID, Microsoft Intune, Microsoft Copilot and others. Check Microsoft’s current list before you rely on a service.
- Your part: Microsoft says “using Microsoft services doesn’t on its own achieve HIPAA compliance”
- Security Rule: administrative safeguards (45 CFR 164.308), physical safeguards (164.310) and technical safeguards (164.312)
- Certification: Microsoft notes there is currently no certification standard that HHS approves for HIPAA
- Official documentation: HIPAA and the HITECH Act (Microsoft Learn) and Guidance on HIPAA and Cloud Computing (HHS)
- Last reviewed: September 30, 2026
What does it mean to keep ePHI in Microsoft 365?
HIPAA defines electronic protected health information as protected health information that is transmitted by electronic media or maintained in electronic media (45 CFR 160.103). In a Microsoft 365 environment, that can include:
- Emails and attachments about patients, referrals, lab results or billing
- Files and spreadsheets in shared sites and personal file storage
- Chats, channel posts, meeting recordings and transcripts
- Form responses from patient intake or scheduling
- AI prompts and responses that reference patient information
HHS says a cloud service provider that creates, receives, maintains or transmits ePHI for a covered entity or business associate is itself a business associate. HHS also says that holds even when the provider stores only encrypted data and has no decryption key. Microsoft agrees that a cloud service provider like Microsoft is a business associate.
What does this cover, and what doesn’t it?
It covers: the Microsoft BAA and which services it reaches, the split between Microsoft’s responsibilities and yours, and the Microsoft 365 settings that support the HIPAA Security Rule safeguards.
It is not:
- Your EHR. Your electronic health record system has its own vendor, contract and settings. It stays with its owner.
- A complete HIPAA program. Privacy practices, breach notification, workforce policies and the security risk analysis all sit outside Microsoft 365 settings.
- Proof of compliance. Microsoft says “using Microsoft services doesn’t on its own achieve HIPAA compliance.” A signed BAA and good settings support your program. They do not replace it.
- Legal advice. Whether you are a covered entity or business associate, and what your contracts require, are questions for your attorney.
Does this apply to you?
This applies to you if you are a HIPAA covered entity (such as a medical, dental, therapy or specialty practice that bills electronically) or a business associate that handles ePHI for one, and any patient information passes through Microsoft 365.
Quick check: does this apply to you?
- You are a covered entity or business associate under HIPAA.
- Patient information is emailed, stored, shared, discussed or recorded anywhere in your Microsoft 365 environment, even occasionally.
If both are true, this very likely applies to you. Confirm with your attorney whether you are a covered entity or business associate and what your contracts with clients or partners require.
What do you need to have in place?
Start with three things: the agreement, a clear picture of who is responsible for what, and settings that match the safeguards the Security Rule describes.
Microsoft’s BAA and which services are in scope
The BAA comes through Microsoft’s standard terms: under the Data Protection Addendum, a covered entity or business associate that puts protected health information in Microsoft’s services executes the BAA when it executes its Microsoft agreement, unless it opts out in writing. Microsoft says its HIPAA Business Associate Agreement “is available through the Microsoft Online Services Data Protection Addendum by default to all customers who are covered entities or business associates under HIPAA.” The current name of that document is the Microsoft Products and Services Data Protection Addendum, which works with the Microsoft Product Terms. Microsoft also says it “can’t use a customer’s Business Associate Agreement,” so you use Microsoft’s terms rather than your own form.
| Area | In scope examples from Microsoft’s HIPAA list | What to check |
|---|---|---|
| Email and calendar | Exchange Online, Microsoft Defender for Office 365 | Services you actually use are on the current list |
| Files and collaboration | SharePoint Online, OneDrive for Business, Microsoft Teams, Forms, Planner, Stream, Office Online (Office for the web) | Features added later, and any add-ins or connected apps |
| Identity and devices | Microsoft Entra ID, Microsoft Intune | Sign-in and device settings are part of your safeguards |
| Compliance tools | Microsoft Purview portal, Compliance Manager, Customer Lockbox, Customer Key | These help you configure and document controls |
| AI | Microsoft Copilot, Microsoft Copilot Chat | Web search queries are not covered by the DPA and BAA. Microsoft’s DPA says its HIPAA terms don’t apply to preview features. Third-party models that require the provider to retain data, and agents or connected services from other publishers, have their own terms. |
Microsoft says services covered under its BAA are audited for ISO/IEC 27001 and HITRUST CSF, and audit reports are available in the Service Trust Portal. Those reports describe Microsoft’s controls, not yours.
Services that are not on the list, third-party apps connected to Microsoft 365, and consumer accounts are not covered by Microsoft’s BAA. Using a cloud provider for ePHI without a business associate agreement is a HIPAA violation, according to HHS (45 CFR 164.308(b)(1) and 164.502(e)).
Who is responsible for what?
Microsoft publishes a shared responsibility model. For software delivered as a service, such as Microsoft 365, it says: “For all cloud deployment types, you own your data and identities.” Microsoft handles the physical datacenters, network and hosts. You always keep responsibility for your data, the devices that connect, user accounts and access management, including multifactor authentication.
| Responsibility | Microsoft | You (with your IT provider) |
|---|---|---|
| Physical datacenters, hosts and network | Yes | No |
| Service-side encryption of stored data and data in transit | Yes | Decide on extra options such as encrypted email and labels |
| Your data, its classification and protection | No | Yes |
| Accounts, sign-in and access | No | Yes |
| Settings and configuration | No | Yes |
| Devices that access Microsoft 365 | Shared | Yes, for protection and compliance of those devices |
| Security risk analysis, policies, training and business associate agreements with others | No | Yes |
HHS makes a similar point from the regulator’s side: where the contract makes the customer responsible for certain security features, “a CSP is not responsible for the compliance failures that are attributable solely to the actions or inactions of the customer,” and each party should confirm in writing how it will address the Security Rule requirements.
Configuration areas mapped to the Security Rule
The Security Rule describes safeguards. It does not name products. The table below shows where common Microsoft 365 settings can support each safeguard. Your security risk analysis decides what is reasonable and appropriate for you.
| Configuration area | What it involves in Microsoft 365 | Security Rule citations it can support |
|---|---|---|
| Multifactor authentication and sign-in | MFA for every user, stronger rules for administrators, legacy sign-in methods blocked, sign-in rules based on user, device and location | 164.312(d) person or entity authentication; 164.308(a)(5)(ii)(D) password management |
| Access and accounts | Unique accounts, least-privilege administrator roles, prompt removal of departed staff, emergency access accounts | 164.312(a)(1) access control, including (a)(2)(i) unique user identification and (a)(2)(ii) emergency access procedure; 164.308(a)(3) workforce security; 164.308(a)(4) information access management |
| Encryption | Microsoft’s service-side encryption, plus sensitivity labels with encryption for the most sensitive files | 164.312(a)(2)(iv) encryption and decryption (addressable) |
| Email encryption | Encrypted email for messages with patient information, including automatic rules for outside recipients | 164.312(e)(1) transmission security and (e)(2)(ii) encryption (addressable) |
| External sharing | Limits on “anyone” links, guest access reviewed, sharing defaults set to specific people | 164.308(a)(4) information access management; 164.312(a)(1) access control |
| Retention | Retention policies so records are not deleted too soon or kept longer than needed | 164.312(c)(1) integrity; 164.316(b)(2)(i) Security Rule documentation (policies, procedures and required records of actions and assessments) kept six years |
| Audit logging | Audit logging on, audit retention set to fit your policies, regular review of sign-ins and access | 164.312(b) audit controls; 164.308(a)(1)(ii)(D) information system activity review; 164.308(a)(5)(ii)(C) log-in monitoring |
| Device management | Devices enrolled, updated, protected and encrypted; lost devices wiped; access limited to compliant devices | 164.310(b) workstation use; 164.310(c) workstation security; 164.310(d)(1) device and media controls; 164.312(a)(2)(iii) automatic logoff |
| Backup and recovery | A tested way to restore email and files, separate from retention settings | 164.308(a)(7)(ii)(A) data backup plan and (B) disaster recovery plan |
Multifactor authentication and access
Microsoft offers a baseline called security defaults at no extra cost. Microsoft says it requires all users to register for multifactor authentication, requires administrators to use it and blocks legacy authentication protocols. More detailed sign-in rules (Conditional Access) based on user, device and location require at least a Microsoft Entra ID P1 license. Rules based on sign-in or user risk require Microsoft Entra ID P2. Check what your plan includes. Microsoft also recommends two cloud-only emergency access accounts for when normal administrator accounts can’t be used.
Encryption and email encryption
Microsoft says Microsoft 365 encrypts customer data at rest with service-side technologies and negotiates TLS by default for data in transit. That covers Microsoft’s side. For email that leaves your organization, Microsoft’s message encryption lets people “send and receive encrypted email messages between people inside and outside your organization,” and admins can set mail flow rules that encrypt messages automatically based on conditions you choose. Sensitivity labels can add encryption to the files that need it most.
Retention and audit logging
Retention policies can keep content for a set period or remove it when it is no longer needed. A retention policy is not a backup. Plan a tested restore separately.
Audit logging records who did what. Microsoft says the default audit retention for its standard audit tier is 180 days for logs generated on or after October 17, 2023. Its premium audit tier keeps Exchange, SharePoint, OneDrive and Microsoft Entra audit records for one year by default for users with qualifying licenses, and custom policies can keep audit logs for up to 10 years with an add-on. The HIPAA audit controls standard does not name a retention period, so set yours based on your risk analysis, your documentation policy and your attorney’s advice.
External sharing and devices
Sharing settings are one of the most common ways patient information ends up in front of the wrong people in Microsoft 365. Set sharing defaults to specific people, limit or turn off “anyone” links for sites that hold patient information, review guests on a schedule and give every shared site an owner.
For devices, Microsoft’s shared responsibility model says that for Microsoft 365, device management is shared but you are responsible for endpoint protection and compliance. Enroll the laptops and phones that reach patient information, keep them updated and encrypted, and require a compliant device before anyone opens ePHI.
How can ALCON DTS help you?
You keep the compliance decisions. We run the controls. You keep the legal obligation and the assessor. ALCON DTS can help configure and run the Microsoft 365 controls that protect patient information and keep records you can produce.
| Need | What ALCON DTS provides |
|---|---|
| Multifactor authentication and access | MFA and enrollment, sign-in rules based on user, device and location (plus sign-in and user risk where you have Microsoft Entra ID P2), least-privilege administrator roles, and joiner, mover and leaver access changes |
| Email protection | Mailbox lifecycle, domain authentication (DMARC, DKIM and SPF), spoofing protection and email security |
| External sharing | Sharing defaults, guest access and permission reviews, with clear ownership for shared content |
| Retention, audit and data loss prevention | Retention and audit logs you can produce, and data loss prevention aligned with how you share |
| Device management | Devices kept updated, protected and encrypted, with device management and patching |
| Monitoring | Alerts routed to a named owner. When an alert fires, ALCON DTS opens a ticket, contacts your named owner and works the issue with you until it is back under control. |
| Backup | Tested backup so you know what is backed up and who can restore it |
| Settings review | A quarterly review of security settings: what changed and why |
| HIPAA program support | Security risk analysis, an evidence file, training with completion records, and BAAs executed where the services we run require them |
The exact controls depend on your ALCON DTS plan and any project work. Your EHR, line-of-business platforms and legal obligations stay with their owners. ALCON DTS does not provide legal advice and does not certify HIPAA compliance.
Not sure what your Microsoft 365 settings say about patient information? We will review sign-in, sharing, email encryption, audit logging and devices in your Microsoft 365 environment and show you what to fix first.
How does ePHI in Microsoft 365 fit with other rules?
- HIPAA security risk analysis (45 CFR 164.308(a)(1)(ii)(A)). Your risk analysis should cover Microsoft 365 as one of the places ePHI lives, and your risk management plan should track the settings you change. See our guide to the HIPAA security risk analysis and our HIPAA Consulting service.
- Business associate agreements (45 CFR 164.308(b), 164.314(a), 164.502(e) and 164.504(e)). Microsoft’s BAA covers Microsoft. Your IT provider, backup service, email security service and any app that touches ePHI need their own agreements where they are business associates. HHS lists IT contractors, managed service providers and cloud providers among business associates. See our guide to business associate agreements.
- Breach notification (45 CFR 164.410 and Texas Bus. and Com. Code Sec. 521.053). A business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery. Texas has its own notice rules for sensitive personal information, which includes health information (Sec. 521.002(a)(2)(B)). See our Texas breach notification guide.
- Texas Cybersecurity Safe Harbor (SB 2610, Bus. and Com. Code Ch. 542). For a business subject to HIPAA, conforming to the current version of HIPAA is one way a cybersecurity program can meet the law’s industry-recognized framework requirement (Sec. 542.004(b)(2)(A)). The program must still meet the chapter’s other requirements, such as administrative, technical and physical safeguards for personal identifying information and sensitive personal information (Sec. 542.004(a)). See Texas SB 2610 Cybersecurity Safe Harbor.
- Texas medical records privacy (Texas Health and Safety Code Ch. 181). Texas defines covered entities more broadly than HIPAA and has its own requirements. Talk with your attorney.
- Proposed Security Rule changes. On January 6, 2025, HHS published a proposed rule to strengthen the Security Rule (90 FR 898). As of September 30, 2026, no final rule has been published in the Federal Register, so the current rule described on this page is the one you follow.
Frequently asked questions
Does Microsoft sign a BAA with us?
Is all of Microsoft 365 covered by the BAA?
Does using Microsoft 365 make us HIPAA compliant?
Is Microsoft 365 email encrypted?
Do we need multifactor authentication?
How long are audit logs kept?
Can staff use personal email or file sharing accounts for patient information?
Who is responsible if a setting is wrong?
Sources
- HIPAA and the HITECH Act (Microsoft Learn)
- Shared responsibility in the cloud (Microsoft Learn)
- Encryption in the Microsoft cloud (Microsoft Learn)
- Message Encryption (Microsoft Learn)
- Security defaults (Microsoft Learn)
- Manage audit log retention policies (Microsoft Learn)
- Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat (Microsoft Learn)
- Service Trust Portal (Microsoft)
- Guidance on HIPAA and Cloud Computing (HHS)
- Business Associates (HHS)
- 45 CFR 160.103, Definitions (eCFR)
- 45 CFR Part 164, Subpart C, Security Standards for the Protection of Electronic Protected Health Information (eCFR)
- 45 CFR 164.410, Notification by a business associate (eCFR)
- HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information, proposed rule, 90 FR 898 (Federal Register)
- Texas Business and Commerce Code, Chapter 542, Cybersecurity Program (Texas Constitution and Statutes)
- Texas Business and Commerce Code, Chapter 521, Unauthorized Use of Identifying Information (Texas Constitution and Statutes)
- Texas Health and Safety Code, Chapter 181, Medical Records Privacy (Texas Constitution and Statutes)
Last reviewed: September 30, 2026
This page is general information about protecting patient information in Microsoft 365 and related rules, not legal advice for your situation.
Talk with ALCON DTS about ePHI in Microsoft 365
Want to know whether your Microsoft 365 settings match what your risk analysis says? We will review sign-in, sharing, email encryption, audit logging and devices, and give you a clear list of what to fix first.
Email: info@alcondts.com ยท Phone: 512-892-6900

