HIPAA Compliance Assessment for Microsoft 365
Microsoft will sign a Business Associate Agreement for Microsoft 365 — but a BAA plus default settings is not a HIPAA-compliant tenant. IT Partner assesses your Microsoft 365 environment against the HIPAA Security Rule safeguards in 3 weeks for a fixed $4,950: BAA coverage verification, then a safeguard-by-safeguard review of access controls, audit logging, encryption, data loss prevention, retention, and sharing across Exchange, SharePoint, Teams, and OneDrive — ending in a prioritized remediation roadmap your team or ours can execute. One thing we will never sell you: 'HIPAA certification.' No such certificate exists, from anyone, and a vendor offering one is telling you something about themselves.
What this engagement is
Clinics, behavioral-health practices, billing companies, and the vendors that serve them run on the same Microsoft 365 as everyone else — which means protected health information ends up in email threads, Teams chats, shared OneDrive links, and SharePoint folders configured for convenience rather than for the Security Rule. Microsoft's side of the arrangement is genuinely solid: the Business Associate Agreement is built into the Microsoft Product Terms and Data Protection Addendum for in-scope services, and the platform carries the underlying controls. But HIPAA's shared-responsibility line puts the configuration burden on you: who can access PHI, whether that access is logged and for how long, whether PHI leaving the tenant is detected, whether email carrying PHI is encrypted, and whether anything is retained — or destroyed — on purpose. This assessment maps your actual tenant against the HIPAA Security Rule's administrative and technical safeguards (45 CFR §164.308 and §164.312), with the physical-safeguard questions covered where Microsoft 365 and device posture reach them. We verify your BAA coverage and which of your subscribed services fall inside it, then review the estate control by control: identity and MFA, Conditional Access, privileged roles, audit logging and its retention period, DLP for PHI patterns, encryption in transit and at rest including encrypted email, retention and disposition, external sharing and guest access across SharePoint, OneDrive, and Teams, and mobile-device exposure. Every finding lands in a gap report tied to the specific safeguard citation, ranked by exposure, with a remediation roadmap sequenced by risk and effort. We are Microsoft 365 engineers who work in regulated tenants — not a law firm. The assessment tells you what your tenant does today and what defensible looks like; interpreting HIPAA's application to your business, and the policy and training obligations beyond the platform, belong with your compliance officer and counsel. And because it needs saying plainly: HHS recognizes no HIPAA certification. This engagement makes your posture demonstrable; nobody's engagement can make it 'certified.'
Success criteria
What you receive
How the work unfolds
Confirm covered-entity or business-associate status as the client understands it, the workloads and user populations in scope, licensing, and access. Collect the client's existing policies where they exist — the assessment reads them; it does not write them.
Verify the Microsoft BAA's application to the tenant's agreement and enrolled services, inventory subscriptions against the BAA's in-scope service list, and flag any workload carrying PHI outside that boundary.
Review the tenant against the technical safeguards: identity, MFA and Conditional Access, privileged access, audit logging and retention, DLP, encryption in transit and at rest, email encryption, external sharing, guest access, retention, and mobile access — using least-privilege, read-oriented access wherever feasible.
Map findings to the administrative safeguards the platform evidences — access management, workforce access review, audit and activity review, security incident visibility — and interview the client's IT and compliance owners on the process side of each.
Validate draft findings with the client's stakeholders, resolve open evidence questions, rank gaps by exposure and effort, and assemble the remediation roadmap with named settings and owners.
Deliver the report and roadmap to leadership and the compliance officer, walk the priority items, and agree what the client executes internally versus what, if anything, is scoped as follow-on implementation.
Prerequisites
Who does what
IT Partner
- Verify BAA application and the in-scope service boundary.
- Review the tenant's configuration against the Security Rule safeguards and document evidence for every finding.
- Map each finding to its specific safeguard citation.
- Rank gaps by exposure and produce the prioritized remediation roadmap.
- Deliver the executive readout and answer the compliance officer's platform questions in plain language.
- State scope limits explicitly in the report — what was assessed, what was not, and why.
Your team
- Provide access, stakeholders, and existing documentation on the agreed schedule.
- Own the legal determination of HIPAA applicability and covered-entity/business-associate status.
- Own Privacy Rule obligations — notices, authorizations, training, minimum-necessary policy — which sit outside a tenant assessment.
- Validate draft findings for factual accuracy within the review window.
- Decide remediation priorities and own risk acceptance for gaps deliberately left open.
- Execute the roadmap internally or scope follow-on implementation separately.
- Maintain the assessed posture over time — a point-in-time report ages as the tenant changes.
What's not included
Limitations & technical notes
Frequently asked questions
Is Microsoft 365 HIPAA compliant?
The honest answer is that the question is malformed — and vendors who answer 'yes' without qualification are selling something. Microsoft 365 is HIPAA-eligible: Microsoft signs a BAA covering in-scope services and provides the control machinery. Whether YOUR Microsoft 365 is defensible depends on how those controls are configured — access, auditing, encryption, DLP, retention, sharing. Default settings are tuned for collaboration, not for the Security Rule. Measuring that gap is exactly what this assessment does.
Do we need to sign a separate BAA with Microsoft?
Generally no separate signature ceremony exists: for eligible subscriptions the BAA is incorporated into the Microsoft Product Terms and Data Protection Addendum and applies to in-scope services. The catch is knowing whether your specific agreement, subscription mix, and the services your PHI actually touches all fall inside that coverage — which is precisely what our BAA verification memo documents, with the evidence trail.
Can you get us HIPAA certified?
No — and neither can anyone else, because no HIPAA certification exists. HHS recognizes no certifying body and no certificate. What a covered entity or business associate can actually have is a documented, evidence-backed security posture and a current risk analysis. This assessment produces the Microsoft 365 portion of that evidence. If a vendor offers you a HIPAA certificate, what you are buying is a decorative PDF.
Who is this assessment for?
Covered entities and business associates running Microsoft 365 — medical and dental clinics, behavioral-health practices, home health, billing and revenue-cycle companies, third-party administrators, and software vendors handling PHI for healthcare clients. The engagement assumes an SMB-to-midmarket tenant; if you are a hospital system with a dedicated GRC team, we should talk about scope before you book it.
What exactly gets assessed?
The Microsoft 365 estate: Exchange Online, SharePoint, OneDrive, and Teams, plus the identity and security layers around them — Entra ID, MFA and Conditional Access, privileged roles, Purview audit and its retention, DLP, encryption in transit and at rest, email encryption, retention policies, external sharing and guest access, and mobile exposure. Each finding is mapped to its Security Rule safeguard citation, so your compliance officer can drop the report straight into the organization's risk documentation.
Does this cover our EHR or telehealth platform?
No. The assessment boundary is Microsoft 365 and its identity and device perimeter. Your EHR, telehealth, e-prescribing, and billing platforms have their own vendors, BAAs, and control questions — they belong in your organization-wide risk analysis, alongside our report as the Microsoft 365 chapter. Where an integration touches the tenant (an EHR sending mail through Exchange, for instance), we note the touchpoint and its exposure.
Is this the risk analysis HIPAA requires?
It is a substantial component of it, not the whole thing. §164.308(a)(1)(ii)(A) requires an accurate and thorough risk analysis across everywhere ePHI lives — and for many SMB healthcare organizations, Microsoft 365 is the largest and least-examined part of that surface. Our report gives that portion real depth: specific settings, specific citations, specific evidence. Your compliance officer still owns the enterprise-wide analysis that also covers the EHR, other systems, and physical handling.
What does the remediation roadmap look like?
A ranked list, not a lecture. Each item names the finding it closes, the workload and setting involved, the safeguard citation it serves, an effort estimate, and whether it is client-executable or engagement-scale. Quick wins — MFA gaps, anonymous-link settings, audit retention — are separated from projects like a PHI DLP rollout or a retention design, so your team can start reducing exposure the week after the readout.
Can you fix what you find?
Yes, as separately scoped follow-on work — deliberately not bundled into the assessment, so the findings stay honest and you keep leverage on what to fix and with whom. The most common follow-ons map to services we already run: DLP policy configuration, encrypted email (OME) implementation, Purview retention and lifecycle management, and information-protection labeling. Many clients execute the quick wins themselves from the roadmap alone, which we consider a good outcome.
How disruptive is the assessment to our staff?
Minimally. The technical review is read-oriented work in admin portals — no configuration changes, no downtime, no agents deployed, and no access to patient-record content. The human load is a handful of interviews: the compliance owner, IT, and whoever owns HR and training processes, plus a validation pass in week 3 and the readout.
We are a behavioral-health practice — anything different for us?
The platform mechanics are the same, but the stakes and data sensitivities are higher — psychotherapy notes carry extra protection under HIPAA, and 42 CFR Part 2 may apply to substance-use records, which is a determination for your counsel. Sharing hygiene and retention discipline tend to matter disproportionately. We wrote up our architectural approach in Microsoft 365 for behavioral health: HIPAA-ready architecture.
What happens if we get audited or investigated by OCR?
OCR asks for documentation: your risk analysis, your safeguards, your evidence. This report is built to be part of that answer for the Microsoft 365 estate — dated findings, safeguard citations, and a remediation trail showing diligence. What we cannot do is represent you in an investigation or predict its outcome; that is counsel's work, and the report is written so counsel can use it.
Why is the price fixed at $4,950?
Because the scope is fixed: one Microsoft 365 tenant, the defined workload set, the Security Rule safeguard map, three weeks. The price is quoted in writing before work begins and you pay after you approve delivery. If your environment is genuinely bigger than the scope — multiple tenants, a merged practice mid-migration — we say so in the scoping call and quote the difference before anything starts, not after.