Solution

HIPAA compliance for azure

The Microsoft BAA covers Microsoft's obligations. Your subscriptions, identities, and data are yours to safeguard.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

The Microsoft BAA covers Microsoft’s obligations. Your subscriptions, identities, and data are yours to safeguard.

What you get

  • Evidence from Defender for Cloud, Entra ID, Key Vault, and Monitor
  • Conditional access and MFA coverage reporting
  • Storage and database encryption verification
  • Subscription-level scope mapping for ePHI workloads

The shared responsibility line

This is where most teams get it wrong. Your provider secures the infrastructure. You secure your configuration, your identities, your data classification, your logging retention, and your workforce. Every enforcement action we have read involved the second half of that sentence, not the first.

How it fits together

LayerWho owns itHow SuperHIPAA helps
InfrastructureProvider (under BAA)We verify your BAA is current and covers the services you use
ConfigurationYouContinuous checks mapped to §164.312
Data classificationYouePHI inventory and flow mapping
WorkforceYouTraining, acknowledgement, access reviews
DocumentationYouPolicies, risk analysis, evidence, all versioned

Start where you are

Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.

Questions

Is a signed BAA from our cloud provider enough?

No. A BAA allocates responsibility; it does not implement safeguards. Your configuration, access control, logging, and workforce practices are still assessed against the Security Rule.

Can we do HIPAA and SOC 2 at the same time?

Yes, and you should. Roughly two-thirds of the control work overlaps. One control set, two outputs — that is how the platform is built.

How fast can we be ready for a customer security review?

Trust centre and questionnaire library go live in days. A defensible full program takes 8–12 weeks. We tell prospects the difference honestly, and so should you.

Do we need to sign a separate BAA with Microsoft for Azure?

For most commercial agreements the BAA is baked into the Microsoft Product Terms and Data Protection Addendum, so it applies automatically. You still need to confirm your specific agreement and the services you use are in scope — and keep a copy in your BAA records, because an auditor will ask for it.

Are preview and beta Azure services covered for ePHI?

Generally no — previews are typically excluded from the compliance commitments in Microsoft's terms. Keep ePHI on generally available services and check scope before promoting a preview-built workload to production.

Is enabling the built-in HIPAA initiative in Azure Policy enough?

It is useful telemetry, not a program. The initiative checks technical configuration but produces no risk analysis, policies, training, or BAA records — the things OCR actually requests first. We consume those signals as evidence and build the rest around them.

Does HIPAA require MFA on our Entra ID accounts?

MFA is not named in the Security Rule, but authentication safeguards are, and single-factor access to ePHI is very hard to defend in 2026. Conditional access with MFA enforced on all ePHI-touching accounts is the practical baseline — we report on coverage gaps continuously.

Does ePHI have to stay in specific Azure regions?

HIPAA has no data residency requirement — that surprises people. Choose regions for latency, redundancy, and any state or contractual constraints, then document where ePHI lives so your risk analysis and BAA records match reality.

How do we scope a hybrid estate with on-prem AD and Azure?

The risk analysis has to cover both sides plus the connective tissue: AD Connect, VPN or ExpressRoute, and any legacy servers syncing identities. Hybrid identity is a favourite attack path, so the boundary between on-prem and cloud belongs in the risk analysis explicitly, not as a footnote.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo