First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/HIPAA Compliance Assessment for Microsoft 365
AssessmentCompliance

HIPAA Compliance Assessment for Microsoft 365

Microsoft will sign a Business Associate Agreement for Microsoft 365 — but a BAA plus default settings is not a HIPAA-compliant tenant. IT Partner assesses your Microsoft 365 environment against the HIPAA Security Rule safeguards in 3 weeks for a fixed $4,950: BAA coverage verification, then a safeguard-by-safeguard review of access controls, audit logging, encryption, data loss prevention, retention, and sharing across Exchange, SharePoint, Teams, and OneDrive — ending in a prioritized remediation roadmap your team or ours can execute. One thing we will never sell you: 'HIPAA certification.' No such certificate exists, from anyone, and a vendor offering one is telling you something about themselves.

Timeline 3 weeksService owner Dan ApplebyMicrosoft 365Microsoft PurviewExchange Online

What this engagement is

Clinics, behavioral-health practices, billing companies, and the vendors that serve them run on the same Microsoft 365 as everyone else — which means protected health information ends up in email threads, Teams chats, shared OneDrive links, and SharePoint folders configured for convenience rather than for the Security Rule. Microsoft's side of the arrangement is genuinely solid: the Business Associate Agreement is built into the Microsoft Product Terms and Data Protection Addendum for in-scope services, and the platform carries the underlying controls. But HIPAA's shared-responsibility line puts the configuration burden on you: who can access PHI, whether that access is logged and for how long, whether PHI leaving the tenant is detected, whether email carrying PHI is encrypted, and whether anything is retained — or destroyed — on purpose. This assessment maps your actual tenant against the HIPAA Security Rule's administrative and technical safeguards (45 CFR §164.308 and §164.312), with the physical-safeguard questions covered where Microsoft 365 and device posture reach them. We verify your BAA coverage and which of your subscribed services fall inside it, then review the estate control by control: identity and MFA, Conditional Access, privileged roles, audit logging and its retention period, DLP for PHI patterns, encryption in transit and at rest including encrypted email, retention and disposition, external sharing and guest access across SharePoint, OneDrive, and Teams, and mobile-device exposure. Every finding lands in a gap report tied to the specific safeguard citation, ranked by exposure, with a remediation roadmap sequenced by risk and effort. We are Microsoft 365 engineers who work in regulated tenants — not a law firm. The assessment tells you what your tenant does today and what defensible looks like; interpreting HIPAA's application to your business, and the policy and training obligations beyond the platform, belong with your compliance officer and counsel. And because it needs saying plainly: HHS recognizes no HIPAA certification. This engagement makes your posture demonstrable; nobody's engagement can make it 'certified.'

Success criteria

01BAA coverage is verified and documented, including which subscribed Microsoft services fall inside it and any in use that do not.
02Every in-scope Security Rule safeguard has a written finding: in place, partially in place, or absent — each tied to the specific configuration evidence behind it.
03Audit logging status and retention period for the tenant are documented against the client's investigation and breach-response needs.
04PHI exposure paths — external sharing, guest access, mail flow, mobile access — are enumerated with current-state risk noted.
05The client receives a remediation roadmap prioritized by exposure and effort, concrete enough that each item names the setting, workload, and owner.
06Leadership and the compliance officer understand, from the executive readout, which gaps matter most and why.
07No deliverable claims or implies certification, and every limitation of scope is stated in the report itself.

What you receive

BAA verification memo: how the Microsoft BAA applies to your agreement and subscriptions, which in-scope services it covers, and any services in active use that sit outside it.
Safeguard-by-safeguard gap report mapped to HIPAA Security Rule citations (45 CFR §164.308 administrative and §164.312 technical safeguards, with §164.310 addressed where the platform and device posture reach it).
Identity and access review: MFA coverage, Conditional Access posture, privileged role assignments, and inactive-account exposure.
Audit logging review: whether auditing is enabled and complete, current retention period versus your licensing, and gaps against investigation needs.
DLP review: whether PHI patterns are detected in Exchange, SharePoint, OneDrive, and Teams today, and what a right-sized PHI policy set would add.
Encryption posture review: transport encryption, encryption of stored data, and email encryption options for PHI-bearing mail under your current licenses.
Sharing and collaboration review: external sharing settings, anonymous links, guest access, and Teams external-access configuration where PHI lives.
Retention and disposition review: what is currently retained by default, for how long, and where policy-driven retention is absent.
Mobile and endpoint exposure summary: how PHI reaches unmanaged devices today and the control options available under your licensing.
Prioritized remediation roadmap with each item tied to a finding, sequenced by risk reduction per unit of effort, and marked for client-executable versus engagement-scale work.
Executive readout session for leadership and the compliance officer, delivered live with the written report.

How the work unfolds

1. Kickoff and scope confirmation (week 1)

Confirm covered-entity or business-associate status as the client understands it, the workloads and user populations in scope, licensing, and access. Collect the client's existing policies where they exist — the assessment reads them; it does not write them.

2. BAA and licensing verification (week 1)

Verify the Microsoft BAA's application to the tenant's agreement and enrolled services, inventory subscriptions against the BAA's in-scope service list, and flag any workload carrying PHI outside that boundary.

3. Technical configuration review (week 1-2)

Review the tenant against the technical safeguards: identity, MFA and Conditional Access, privileged access, audit logging and retention, DLP, encryption in transit and at rest, email encryption, external sharing, guest access, retention, and mobile access — using least-privilege, read-oriented access wherever feasible.

4. Administrative safeguard mapping (week 2)

Map findings to the administrative safeguards the platform evidences — access management, workforce access review, audit and activity review, security incident visibility — and interview the client's IT and compliance owners on the process side of each.

5. Findings validation and roadmap (week 3)

Validate draft findings with the client's stakeholders, resolve open evidence questions, rank gaps by exposure and effort, and assemble the remediation roadmap with named settings and owners.

6. Executive readout (week 3)

Deliver the report and roadmap to leadership and the compliance officer, walk the priority items, and agree what the client executes internally versus what, if anything, is scoped as follow-on implementation.

Prerequisites

An active Microsoft 365 tenant carrying, or intended to carry, PHI — commercial, nonprofit, or GCC.
The client's understanding of its covered-entity or business-associate status; we do not make that legal determination.
Administrative access sufficient for read-oriented review of Microsoft 365, Entra ID, Purview, and Exchange/SharePoint/Teams/OneDrive admin settings, granted for the engagement window.
A named compliance or privacy officer (or equivalent owner) available for interviews and the findings validation.
An inventory, even informal, of where PHI is believed to live and flow — mailboxes, sites, Teams, shared drives, third-party integrations.
Copies of existing security policies, prior risk analyses, or audit findings, where they exist — absence is itself a finding, not a blocker.
IT staff availability for configuration questions during weeks 1-2 and validation in week 3.
An agreed secure channel for exchanging assessment evidence; PHI itself is not copied out of the tenant for this engagement.

Who does what

IT Partner

  • Verify BAA application and the in-scope service boundary.
  • Review the tenant's configuration against the Security Rule safeguards and document evidence for every finding.
  • Map each finding to its specific safeguard citation.
  • Rank gaps by exposure and produce the prioritized remediation roadmap.
  • Deliver the executive readout and answer the compliance officer's platform questions in plain language.
  • State scope limits explicitly in the report — what was assessed, what was not, and why.

Your team

  • Provide access, stakeholders, and existing documentation on the agreed schedule.
  • Own the legal determination of HIPAA applicability and covered-entity/business-associate status.
  • Own Privacy Rule obligations — notices, authorizations, training, minimum-necessary policy — which sit outside a tenant assessment.
  • Validate draft findings for factual accuracy within the review window.
  • Decide remediation priorities and own risk acceptance for gaps deliberately left open.
  • Execute the roadmap internally or scope follow-on implementation separately.
  • Maintain the assessed posture over time — a point-in-time report ages as the tenant changes.

What's not included

Legal advice of any kind: HIPAA applicability determinations, BAA negotiation with your own downstream vendors, breach-notification counsel, or OCR investigation representation.
'HIPAA certification' — it does not exist. HHS recognizes no certification for HIPAA compliance, and no deliverable from this engagement will use the word except to say this.
The organization-wide risk analysis required by §164.308(a)(1)(ii)(A) across all systems: this assessment is deep evidence for the Microsoft 365 portion of that analysis, not a substitute for the enterprise-wide exercise covering your EHR, practice management, billing platforms, and paper.
Assessment of non-Microsoft systems — EHR platforms, telehealth products, e-prescribing, clearinghouses, or any third-party SaaS, even where integrated with Microsoft 365.
Privacy Rule program work: policy authoring, workforce training, notices of privacy practices, or minimum-necessary procedures.
Remediation implementation — every roadmap item is executable as follow-on work, most directly DLP policy configuration, encrypted email implementation, retention and lifecycle management, and information protection labeling, each scoped separately.
Microsoft licensing purchases, including any upgrades or add-ons the roadmap identifies as genuinely required.
Penetration testing, vulnerability scanning, or simulated attacks.
Physical facility assessment — server closets, workstation placement, media disposal — beyond what tenant and device configuration evidences.
Ongoing compliance monitoring, managed security operations, or recurring re-assessment; a periodic re-assessment can be scheduled as its own engagement.

Limitations & technical notes

!There is no such thing as a HIPAA-certified organization, product, or tenant. HHS recognizes no certification, and this engagement will not produce one — it produces evidence and a defensible posture, which is what actually exists.
!This is a point-in-time assessment. Configuration drift, new workloads, licensing changes, and staff turnover all age the findings; the report is dated and says so.
!Findings depend on the access and information provided. Undisclosed PHI locations, shadow IT, and systems outside the tenant are outside what this assessment can see.
!A well-configured Microsoft 365 tenant is necessary but not sufficient for HIPAA compliance: the Security Rule's organizational, policy, and training requirements — and the entire Privacy Rule — live outside any platform's settings.
!Available controls vary by licensing. The report distinguishes gaps fixable by configuration from gaps that genuinely require a licensing change, and will not recommend an upgrade a configuration change can cover.
!Regulatory expectations evolve — HHS has proposed Security Rule updates whose final form and dates are not settled at the time of writing. The assessment reflects the rule as in force at delivery, and the readout flags where proposed changes would raise the bar.
!The assessment reviews configuration and evidence; it does not access, read, or export patient records, and clinical content stays in the tenant.

Frequently asked questions

Is Microsoft 365 HIPAA compliant?

The honest answer is that the question is malformed — and vendors who answer 'yes' without qualification are selling something. Microsoft 365 is HIPAA-eligible: Microsoft signs a BAA covering in-scope services and provides the control machinery. Whether YOUR Microsoft 365 is defensible depends on how those controls are configured — access, auditing, encryption, DLP, retention, sharing. Default settings are tuned for collaboration, not for the Security Rule. Measuring that gap is exactly what this assessment does.

Do we need to sign a separate BAA with Microsoft?

Generally no separate signature ceremony exists: for eligible subscriptions the BAA is incorporated into the Microsoft Product Terms and Data Protection Addendum and applies to in-scope services. The catch is knowing whether your specific agreement, subscription mix, and the services your PHI actually touches all fall inside that coverage — which is precisely what our BAA verification memo documents, with the evidence trail.

Can you get us HIPAA certified?

No — and neither can anyone else, because no HIPAA certification exists. HHS recognizes no certifying body and no certificate. What a covered entity or business associate can actually have is a documented, evidence-backed security posture and a current risk analysis. This assessment produces the Microsoft 365 portion of that evidence. If a vendor offers you a HIPAA certificate, what you are buying is a decorative PDF.

Who is this assessment for?

Covered entities and business associates running Microsoft 365 — medical and dental clinics, behavioral-health practices, home health, billing and revenue-cycle companies, third-party administrators, and software vendors handling PHI for healthcare clients. The engagement assumes an SMB-to-midmarket tenant; if you are a hospital system with a dedicated GRC team, we should talk about scope before you book it.

What exactly gets assessed?

The Microsoft 365 estate: Exchange Online, SharePoint, OneDrive, and Teams, plus the identity and security layers around them — Entra ID, MFA and Conditional Access, privileged roles, Purview audit and its retention, DLP, encryption in transit and at rest, email encryption, retention policies, external sharing and guest access, and mobile exposure. Each finding is mapped to its Security Rule safeguard citation, so your compliance officer can drop the report straight into the organization's risk documentation.

Does this cover our EHR or telehealth platform?

No. The assessment boundary is Microsoft 365 and its identity and device perimeter. Your EHR, telehealth, e-prescribing, and billing platforms have their own vendors, BAAs, and control questions — they belong in your organization-wide risk analysis, alongside our report as the Microsoft 365 chapter. Where an integration touches the tenant (an EHR sending mail through Exchange, for instance), we note the touchpoint and its exposure.

Is this the risk analysis HIPAA requires?

It is a substantial component of it, not the whole thing. §164.308(a)(1)(ii)(A) requires an accurate and thorough risk analysis across everywhere ePHI lives — and for many SMB healthcare organizations, Microsoft 365 is the largest and least-examined part of that surface. Our report gives that portion real depth: specific settings, specific citations, specific evidence. Your compliance officer still owns the enterprise-wide analysis that also covers the EHR, other systems, and physical handling.

What does the remediation roadmap look like?

A ranked list, not a lecture. Each item names the finding it closes, the workload and setting involved, the safeguard citation it serves, an effort estimate, and whether it is client-executable or engagement-scale. Quick wins — MFA gaps, anonymous-link settings, audit retention — are separated from projects like a PHI DLP rollout or a retention design, so your team can start reducing exposure the week after the readout.

Can you fix what you find?

Yes, as separately scoped follow-on work — deliberately not bundled into the assessment, so the findings stay honest and you keep leverage on what to fix and with whom. The most common follow-ons map to services we already run: DLP policy configuration, encrypted email (OME) implementation, Purview retention and lifecycle management, and information-protection labeling. Many clients execute the quick wins themselves from the roadmap alone, which we consider a good outcome.

How disruptive is the assessment to our staff?

Minimally. The technical review is read-oriented work in admin portals — no configuration changes, no downtime, no agents deployed, and no access to patient-record content. The human load is a handful of interviews: the compliance owner, IT, and whoever owns HR and training processes, plus a validation pass in week 3 and the readout.

We are a behavioral-health practice — anything different for us?

The platform mechanics are the same, but the stakes and data sensitivities are higher — psychotherapy notes carry extra protection under HIPAA, and 42 CFR Part 2 may apply to substance-use records, which is a determination for your counsel. Sharing hygiene and retention discipline tend to matter disproportionately. We wrote up our architectural approach in Microsoft 365 for behavioral health: HIPAA-ready architecture.

What happens if we get audited or investigated by OCR?

OCR asks for documentation: your risk analysis, your safeguards, your evidence. This report is built to be part of that answer for the Microsoft 365 estate — dated findings, safeguard citations, and a remediation trail showing diligence. What we cannot do is represent you in an investigation or predict its outcome; that is counsel's work, and the report is written so counsel can use it.

Why is the price fixed at $4,950?

Because the scope is fixed: one Microsoft 365 tenant, the defined workload set, the Security Rule safeguard map, three weeks. The price is quoted in writing before work begins and you pay after you approve delivery. If your environment is genuinely bigger than the scope — multiple tenants, a merged practice mid-migration — we say so in the scoping call and quote the difference before anything starts, not after.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$4,950 per project
3 weeks
Book a HIPAA assessment call