ePHI in Microsoft 365: What It Means for Your Organization

If your organization keeps patient information in email, files, chats or forms in Microsoft 365, that information is electronic protected health information (ePHI) and the HIPAA Security Rule applies to how you protect it. Microsoft offers a HIPAA Business Associate Agreement to covered entities and business associates through its Data Protection Addendum, and many Microsoft 365 services are in scope. That agreement covers Microsoft’s side. Your side is how your Microsoft 365 environment is set up: who can sign in, what is shared, what is encrypted, what is kept and what is logged. ALCON DTS can help configure and run the sign-in, sharing, retention, audit and device controls so your security risk analysis has something solid to point to.

Talk with ALCON DTSSee what you need in place

At a glance

  • What ePHI is: protected health information transmitted by or maintained in electronic media (45 CFR 160.103)
  • Microsoft’s BAA: Microsoft says its HIPAA Business Associate Agreement “is available through the Microsoft Online Services Data Protection Addendum by default to all customers who are covered entities or business associates under HIPAA”
  • In scope: Microsoft lists services such as Exchange Online, SharePoint Online, OneDrive for Business, Microsoft Teams, Microsoft Entra ID, Microsoft Intune, Microsoft Copilot and others. Check Microsoft’s current list before you rely on a service.
  • Your part: Microsoft says “using Microsoft services doesn’t on its own achieve HIPAA compliance”
  • Security Rule: administrative safeguards (45 CFR 164.308), physical safeguards (164.310) and technical safeguards (164.312)
  • Certification: Microsoft notes there is currently no certification standard that HHS approves for HIPAA
  • Official documentation: HIPAA and the HITECH Act (Microsoft Learn) and Guidance on HIPAA and Cloud Computing (HHS)
  • Last reviewed: September 30, 2026

What does it mean to keep ePHI in Microsoft 365?

HIPAA defines electronic protected health information as protected health information that is transmitted by electronic media or maintained in electronic media (45 CFR 160.103). In a Microsoft 365 environment, that can include:

  • Emails and attachments about patients, referrals, lab results or billing
  • Files and spreadsheets in shared sites and personal file storage
  • Chats, channel posts, meeting recordings and transcripts
  • Form responses from patient intake or scheduling
  • AI prompts and responses that reference patient information

HHS says a cloud service provider that creates, receives, maintains or transmits ePHI for a covered entity or business associate is itself a business associate. HHS also says that holds even when the provider stores only encrypted data and has no decryption key. Microsoft agrees that a cloud service provider like Microsoft is a business associate.

What does this cover, and what doesn’t it?

It covers: the Microsoft BAA and which services it reaches, the split between Microsoft’s responsibilities and yours, and the Microsoft 365 settings that support the HIPAA Security Rule safeguards.

It is not:

  • Your EHR. Your electronic health record system has its own vendor, contract and settings. It stays with its owner.
  • A complete HIPAA program. Privacy practices, breach notification, workforce policies and the security risk analysis all sit outside Microsoft 365 settings.
  • Proof of compliance. Microsoft says “using Microsoft services doesn’t on its own achieve HIPAA compliance.” A signed BAA and good settings support your program. They do not replace it.
  • Legal advice. Whether you are a covered entity or business associate, and what your contracts require, are questions for your attorney.

Does this apply to you?

This applies to you if you are a HIPAA covered entity (such as a medical, dental, therapy or specialty practice that bills electronically) or a business associate that handles ePHI for one, and any patient information passes through Microsoft 365.

Quick check: does this apply to you?

  • You are a covered entity or business associate under HIPAA.
  • Patient information is emailed, stored, shared, discussed or recorded anywhere in your Microsoft 365 environment, even occasionally.

If both are true, this very likely applies to you. Confirm with your attorney whether you are a covered entity or business associate and what your contracts with clients or partners require.

What do you need to have in place?

Start with three things: the agreement, a clear picture of who is responsible for what, and settings that match the safeguards the Security Rule describes.

Microsoft’s BAA and which services are in scope

The BAA comes through Microsoft’s standard terms: under the Data Protection Addendum, a covered entity or business associate that puts protected health information in Microsoft’s services executes the BAA when it executes its Microsoft agreement, unless it opts out in writing. Microsoft says its HIPAA Business Associate Agreement “is available through the Microsoft Online Services Data Protection Addendum by default to all customers who are covered entities or business associates under HIPAA.” The current name of that document is the Microsoft Products and Services Data Protection Addendum, which works with the Microsoft Product Terms. Microsoft also says it “can’t use a customer’s Business Associate Agreement,” so you use Microsoft’s terms rather than your own form.

Examples from Microsoft Learn, “HIPAA and the HITECH Act,” reviewed September 30, 2026. The list changes; confirm each service against Microsoft’s current HIPAA in-scope list.
Area In scope examples from Microsoft’s HIPAA list What to check
Email and calendar Exchange Online, Microsoft Defender for Office 365 Services you actually use are on the current list
Files and collaboration SharePoint Online, OneDrive for Business, Microsoft Teams, Forms, Planner, Stream, Office Online (Office for the web) Features added later, and any add-ins or connected apps
Identity and devices Microsoft Entra ID, Microsoft Intune Sign-in and device settings are part of your safeguards
Compliance tools Microsoft Purview portal, Compliance Manager, Customer Lockbox, Customer Key These help you configure and document controls
AI Microsoft Copilot, Microsoft Copilot Chat Web search queries are not covered by the DPA and BAA. Microsoft’s DPA says its HIPAA terms don’t apply to preview features. Third-party models that require the provider to retain data, and agents or connected services from other publishers, have their own terms.

Microsoft says services covered under its BAA are audited for ISO/IEC 27001 and HITRUST CSF, and audit reports are available in the Service Trust Portal. Those reports describe Microsoft’s controls, not yours.

Services that are not on the list, third-party apps connected to Microsoft 365, and consumer accounts are not covered by Microsoft’s BAA. Using a cloud provider for ePHI without a business associate agreement is a HIPAA violation, according to HHS (45 CFR 164.308(b)(1) and 164.502(e)).

Who is responsible for what?

Microsoft publishes a shared responsibility model. For software delivered as a service, such as Microsoft 365, it says: “For all cloud deployment types, you own your data and identities.” Microsoft handles the physical datacenters, network and hosts. You always keep responsibility for your data, the devices that connect, user accounts and access management, including multifactor authentication.

Based on Microsoft Learn, “Shared responsibility in the cloud.” Microsoft notes its model is illustrative guidance and does not change any agreement.
Responsibility Microsoft You (with your IT provider)
Physical datacenters, hosts and network Yes No
Service-side encryption of stored data and data in transit Yes Decide on extra options such as encrypted email and labels
Your data, its classification and protection No Yes
Accounts, sign-in and access No Yes
Settings and configuration No Yes
Devices that access Microsoft 365 Shared Yes, for protection and compliance of those devices
Security risk analysis, policies, training and business associate agreements with others No Yes

HHS makes a similar point from the regulator’s side: where the contract makes the customer responsible for certain security features, “a CSP is not responsible for the compliance failures that are attributable solely to the actions or inactions of the customer,” and each party should confirm in writing how it will address the Security Rule requirements.

Configuration areas mapped to the Security Rule

The Security Rule describes safeguards. It does not name products. The table below shows where common Microsoft 365 settings can support each safeguard. Your security risk analysis decides what is reasonable and appropriate for you.

Citations from 45 CFR Part 164, Subpart C (eCFR). Mapping is general guidance, not legal advice. “Addressable” means you assess whether the safeguard is reasonable and appropriate and document your decision.
Configuration area What it involves in Microsoft 365 Security Rule citations it can support
Multifactor authentication and sign-in MFA for every user, stronger rules for administrators, legacy sign-in methods blocked, sign-in rules based on user, device and location 164.312(d) person or entity authentication; 164.308(a)(5)(ii)(D) password management
Access and accounts Unique accounts, least-privilege administrator roles, prompt removal of departed staff, emergency access accounts 164.312(a)(1) access control, including (a)(2)(i) unique user identification and (a)(2)(ii) emergency access procedure; 164.308(a)(3) workforce security; 164.308(a)(4) information access management
Encryption Microsoft’s service-side encryption, plus sensitivity labels with encryption for the most sensitive files 164.312(a)(2)(iv) encryption and decryption (addressable)
Email encryption Encrypted email for messages with patient information, including automatic rules for outside recipients 164.312(e)(1) transmission security and (e)(2)(ii) encryption (addressable)
External sharing Limits on “anyone” links, guest access reviewed, sharing defaults set to specific people 164.308(a)(4) information access management; 164.312(a)(1) access control
Retention Retention policies so records are not deleted too soon or kept longer than needed 164.312(c)(1) integrity; 164.316(b)(2)(i) Security Rule documentation (policies, procedures and required records of actions and assessments) kept six years
Audit logging Audit logging on, audit retention set to fit your policies, regular review of sign-ins and access 164.312(b) audit controls; 164.308(a)(1)(ii)(D) information system activity review; 164.308(a)(5)(ii)(C) log-in monitoring
Device management Devices enrolled, updated, protected and encrypted; lost devices wiped; access limited to compliant devices 164.310(b) workstation use; 164.310(c) workstation security; 164.310(d)(1) device and media controls; 164.312(a)(2)(iii) automatic logoff
Backup and recovery A tested way to restore email and files, separate from retention settings 164.308(a)(7)(ii)(A) data backup plan and (B) disaster recovery plan

Multifactor authentication and access

Microsoft offers a baseline called security defaults at no extra cost. Microsoft says it requires all users to register for multifactor authentication, requires administrators to use it and blocks legacy authentication protocols. More detailed sign-in rules (Conditional Access) based on user, device and location require at least a Microsoft Entra ID P1 license. Rules based on sign-in or user risk require Microsoft Entra ID P2. Check what your plan includes. Microsoft also recommends two cloud-only emergency access accounts for when normal administrator accounts can’t be used.

Encryption and email encryption

Microsoft says Microsoft 365 encrypts customer data at rest with service-side technologies and negotiates TLS by default for data in transit. That covers Microsoft’s side. For email that leaves your organization, Microsoft’s message encryption lets people “send and receive encrypted email messages between people inside and outside your organization,” and admins can set mail flow rules that encrypt messages automatically based on conditions you choose. Sensitivity labels can add encryption to the files that need it most.

Retention and audit logging

Retention policies can keep content for a set period or remove it when it is no longer needed. A retention policy is not a backup. Plan a tested restore separately.

Audit logging records who did what. Microsoft says the default audit retention for its standard audit tier is 180 days for logs generated on or after October 17, 2023. Its premium audit tier keeps Exchange, SharePoint, OneDrive and Microsoft Entra audit records for one year by default for users with qualifying licenses, and custom policies can keep audit logs for up to 10 years with an add-on. The HIPAA audit controls standard does not name a retention period, so set yours based on your risk analysis, your documentation policy and your attorney’s advice.

External sharing and devices

Sharing settings are one of the most common ways patient information ends up in front of the wrong people in Microsoft 365. Set sharing defaults to specific people, limit or turn off “anyone” links for sites that hold patient information, review guests on a schedule and give every shared site an owner.

For devices, Microsoft’s shared responsibility model says that for Microsoft 365, device management is shared but you are responsible for endpoint protection and compliance. Enroll the laptops and phones that reach patient information, keep them updated and encrypted, and require a compliant device before anyone opens ePHI.

How can ALCON DTS help you?

You keep the compliance decisions. We run the controls. You keep the legal obligation and the assessor. ALCON DTS can help configure and run the Microsoft 365 controls that protect patient information and keep records you can produce.

Need What ALCON DTS provides
Multifactor authentication and access MFA and enrollment, sign-in rules based on user, device and location (plus sign-in and user risk where you have Microsoft Entra ID P2), least-privilege administrator roles, and joiner, mover and leaver access changes
Email protection Mailbox lifecycle, domain authentication (DMARC, DKIM and SPF), spoofing protection and email security
External sharing Sharing defaults, guest access and permission reviews, with clear ownership for shared content
Retention, audit and data loss prevention Retention and audit logs you can produce, and data loss prevention aligned with how you share
Device management Devices kept updated, protected and encrypted, with device management and patching
Monitoring Alerts routed to a named owner. When an alert fires, ALCON DTS opens a ticket, contacts your named owner and works the issue with you until it is back under control.
Backup Tested backup so you know what is backed up and who can restore it
Settings review A quarterly review of security settings: what changed and why
HIPAA program support Security risk analysis, an evidence file, training with completion records, and BAAs executed where the services we run require them

The exact controls depend on your ALCON DTS plan and any project work. Your EHR, line-of-business platforms and legal obligations stay with their owners. ALCON DTS does not provide legal advice and does not certify HIPAA compliance.

Not sure what your Microsoft 365 settings say about patient information? We will review sign-in, sharing, email encryption, audit logging and devices in your Microsoft 365 environment and show you what to fix first.

Talk with ALCON DTS

How does ePHI in Microsoft 365 fit with other rules?

  • HIPAA security risk analysis (45 CFR 164.308(a)(1)(ii)(A)). Your risk analysis should cover Microsoft 365 as one of the places ePHI lives, and your risk management plan should track the settings you change. See our guide to the HIPAA security risk analysis and our HIPAA Consulting service.
  • Business associate agreements (45 CFR 164.308(b), 164.314(a), 164.502(e) and 164.504(e)). Microsoft’s BAA covers Microsoft. Your IT provider, backup service, email security service and any app that touches ePHI need their own agreements where they are business associates. HHS lists IT contractors, managed service providers and cloud providers among business associates. See our guide to business associate agreements.
  • Breach notification (45 CFR 164.410 and Texas Bus. and Com. Code Sec. 521.053). A business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery. Texas has its own notice rules for sensitive personal information, which includes health information (Sec. 521.002(a)(2)(B)). See our Texas breach notification guide.
  • Texas Cybersecurity Safe Harbor (SB 2610, Bus. and Com. Code Ch. 542). For a business subject to HIPAA, conforming to the current version of HIPAA is one way a cybersecurity program can meet the law’s industry-recognized framework requirement (Sec. 542.004(b)(2)(A)). The program must still meet the chapter’s other requirements, such as administrative, technical and physical safeguards for personal identifying information and sensitive personal information (Sec. 542.004(a)). See Texas SB 2610 Cybersecurity Safe Harbor.
  • Texas medical records privacy (Texas Health and Safety Code Ch. 181). Texas defines covered entities more broadly than HIPAA and has its own requirements. Talk with your attorney.
  • Proposed Security Rule changes. On January 6, 2025, HHS published a proposed rule to strengthen the Security Rule (90 FR 898). As of September 30, 2026, no final rule has been published in the Federal Register, so the current rule described on this page is the one you follow.

Frequently asked questions

Microsoft says its HIPAA Business Associate Agreement is available through its Data Protection Addendum by default to customers who are covered entities or business associates. Microsoft says it can’t use a customer’s own BAA form.

Many services are, including Exchange Online, SharePoint Online, OneDrive for Business, Microsoft Teams and Microsoft Copilot. Not everything is. Check Microsoft’s current list, and remember that third-party apps, preview features and Copilot web search queries are not covered.

No. Microsoft says using its services doesn’t on its own achieve HIPAA compliance. You still need a risk analysis, policies, training and settings that fit your organization.

Microsoft encrypts data in transit with TLS by default and stores data encrypted. For email sent outside your organization, message encryption “helps ensure that only intended recipients can view message content,” and rules can apply it automatically.

The Security Rule requires you to verify that a person seeking access to ePHI is who they claim to be (164.312(d)). Multifactor authentication is one of the most effective ways to do that in Microsoft 365, and your risk analysis should address it.

It depends on your plan. Microsoft’s standard audit tier keeps logs for 180 days by default. Longer retention needs qualifying licenses or add-ons.

Consumer accounts are not covered by your agreement with Microsoft. Keep patient information in the Microsoft 365 environment your organization controls.

HHS says a cloud provider isn’t responsible for compliance failures that are attributable solely to the customer’s own actions or inactions, such as a security feature the customer agreed to control but didn’t set up. Settings are your side of the shared responsibility model, which is why they should be reviewed on a schedule.

Talk with ALCON DTS about ePHI in Microsoft 365

Want to know whether your Microsoft 365 settings match what your risk analysis says? We will review sign-in, sharing, email encryption, audit logging and devices, and give you a clear list of what to fix first.

Email: info@alcondts.com ยท Phone: 512-892-6900

Talk with ALCON DTS