Solution

HIPAA compliance for microsoft 365

Most ePHI leaks happen in email, Teams, and SharePoint — not in the EHR.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

Most ePHI leaks happen in email, Teams, and SharePoint — not in the EHR.

What you get

  • DLP and sensitivity labelling for ePHI in mail and files
  • Teams, SharePoint, and OneDrive sharing controls
  • Retention and legal hold configuration
  • Audit log retention meeting the six-year documentation requirement

The shared responsibility line

This is where most teams get it wrong. Your provider secures the infrastructure. You secure your configuration, your identities, your data classification, your logging retention, and your workforce. Every enforcement action we have read involved the second half of that sentence, not the first.

How it fits together

LayerWho owns itHow SuperHIPAA helps
InfrastructureProvider (under BAA)We verify your BAA is current and covers the services you use
ConfigurationYouContinuous checks mapped to §164.312
Data classificationYouePHI inventory and flow mapping
WorkforceYouTraining, acknowledgement, access reviews
DocumentationYouPolicies, risk analysis, evidence, all versioned

Start where you are

Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.

Questions

Is a signed BAA from our cloud provider enough?

No. A BAA allocates responsibility; it does not implement safeguards. Your configuration, access control, logging, and workforce practices are still assessed against the Security Rule.

Can we do HIPAA and SOC 2 at the same time?

Yes, and you should. Roughly two-thirds of the control work overlaps. One control set, two outputs — that is how the platform is built.

How fast can we be ready for a customer security review?

Trust centre and questionnaire library go live in days. A defensible full program takes 8–12 weeks. We tell prospects the difference honestly, and so should you.

Does Microsoft sign a BAA for Microsoft 365?

Yes — for most commercial and enterprise plans the BAA is part of the Data Protection Addendum and applies without a separate signature. Consumer and personal plans are not covered, which matters when staff use personal accounts for work.

Which Microsoft 365 licence tier do we need for HIPAA?

There is no mandated tier, but the controls you will want — DLP, sensitivity labels, longer audit retention — sit behind E5 or the compliance add-ons. You can run a defensible program on lower tiers with more manual procedure; we tell you which gaps are licence-driven so you can price the trade honestly.

Can we email patients from Exchange Online?

Yes. Transport encryption covers the send, and Purview Message Encryption protects the content beyond your tenant. If a patient asks for plain email after being warned of the risk, HIPAA permits it — document the warning and their preference, and keep clinical detail to the minimum necessary.

Are Teams chats and meeting recordings ePHI?

If they mention identifiable patients, yes — and Teams content is famously under-governed because nobody thinks of chat as a record system. Retention policies, guest access review, and channel-level sharing controls bring it into scope properly.

What is the most common Microsoft 365 violation pattern you see?

Anyone-with-the-link sharing from SharePoint and OneDrive, and work files synced to personal accounts. Both are silent — no alert fires when a spreadsheet of patients becomes publicly linkable. Tenant sharing settings plus DLP policies close it, and we verify they stay closed.

Audit logs only go back 180 days by default. Is that a problem?

It can be. HIPAA requires six years of documentation retention, and when an incident surfaces late you will want the activity history. Extended audit retention (an E5 or add-on feature) or exporting logs to external storage solves it — decide deliberately rather than discovering the gap mid-investigation.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo