Skip to main content

4 min read

Microsoft 365 for Medical and Dental Offices: The HIPAA Settings That Matter

The short answer

Yes, a practice can use Microsoft 365 for patient information. Microsoft includes a HIPAA business associate agreement in its standard terms for covered services, but says that alone doesn't cover your HIPAA obligations. The settings are your job: MFA for everyone, encrypted email, limits on outside sharing, protected devices and a backup of mail and files.

Plenty of practices already run their email on Microsoft 365. The question tends to come up later: when someone starts keeping patient files in OneDrive, when the front desk wants to message a referring office in Teams, or when an insurer asks how email is protected.

The answer depends less on which product you bought and more on how it’s set up.

What Microsoft’s business associate agreement covers

Under HIPAA, a cloud provider that holds patient information for a practice is a business associate, and Microsoft says so plainly. Its HIPAA business associate agreement is included by default, through the Microsoft Online Services Data Protection Addendum, for customers who are covered entities or business associates.

The agreement covers the services Microsoft lists as in scope. For a practice on Microsoft 365, those include:

  • Exchange Online (email and calendars)
  • SharePoint Online and OneDrive for Business (files)
  • Microsoft Teams
  • Microsoft Entra ID (sign-ins)
  • Microsoft Intune (device management)
  • Forms, Planner and the Office apps on the web

Personal Microsoft accounts and apps from other companies added into Teams or Outlook aren’t on that list. Check a service is covered before patient information goes into it.

What stays your job

The agreement covers Microsoft’s side: running and protecting the service itself. How your practice uses it is on your side. You decide who can see what, how the settings are configured, how staff are trained and how you’d recover if something went wrong.

In Microsoft 365, the Security Rule’s basics look like this: knowing where patient files and mail sit, limiting who opens them, keeping them protected and being able to restore them. The tools for each are already there. Most of them are settings someone has to switch on and check.

The settings to check first

Microsoft’s own security guidance for small businesses is a good outline. For a medical or dental office, these come first:

  1. Multi-factor authentication (MFA) for everyone. Microsoft’s security defaults turn it on in every business plan. Business Premium adds Conditional Access, which lets you set stricter rules, such as blocking sign-ins from devices the practice doesn’t manage. Give administrators separate admin accounts that aren’t used for everyday email.
  2. Encrypted email. Microsoft Purview Message Encryption protects messages that leave the practice. Recipients on Gmail, Yahoo or other services get a link and sign in to read the message. A mail rule can encrypt messages automatically, for example anything sent outside the practice with an attachment.
  3. Limits on outside sharing. Decide whether files in OneDrive and SharePoint can be shared outside the practice at all. If they can, require people to sign in, and turn off “anyone with the link” sharing. Do the same for guests in Teams.
  4. Protected devices. Every computer and phone that opens practice email or files should be encrypted, kept up to date and managed, so work data can be removed from a lost phone. Business Premium includes Intune for this; the other plans include a more basic mobile device management option.
  5. Phishing protection. Every plan filters spam, malware and spoofed mail. Business Premium adds a check on links when someone clicks them, in email and in Teams, and tests email attachments in a safe space before they’re delivered.
  6. Sign-in and activity logs. Make sure they’re kept and that someone knows how to search them, so you can answer “who opened that file?” if you ever need to.
  7. A backup of mail and files, kept separately from Microsoft, with restores tested. If a mailbox is ever taken over or files are scrambled by ransomware, here’s what to do in the first hour.

Business Basic, Standard or Premium for a practice

All three are Microsoft 365 business plans, and all three include the email, file and Teams services the business associate agreement covers. The differences that matter to a practice are in security:

What you get Business Basic Business Standard Business Premium
Email, OneDrive, SharePoint and Teams Yes Yes Yes
Desktop Office apps No (web and mobile only) Yes Yes
MFA through security defaults Yes Yes Yes
Conditional Access for stricter sign-in rules No No Yes
Device management with Intune No (basic mobile only) No (basic mobile only) Yes
Message encryption No No Yes
Extra protection for links and attachments No No Yes

If your practice handles patient information, Premium is the plan to aim for, at least for everyone who touches it, because the security pieces it adds are the ones the settings above lean on.

Google Workspace works too

If your practice runs on Google instead, Google offers a business associate agreement as well. An administrator reviews and accepts it in the Google Admin console, and patient information should only go into the services Google lists as covered. The same settings apply: MFA, sharing limits, managed devices and a separate backup. We support both, so if what you have is working, there’s no need to switch.

How we set up Microsoft 365 for practices

We set up and look after Microsoft 365 and Google Workspace for medical and dental practices across Orange County: the security settings above, email encryption, phishing filtering, and backups of mail and files that we test. See our business email and productivity page for the details, or our HIPAA checklist for medical practices for the rest of the picture.

If you’d like someone to look over how your practice’s Microsoft 365 is set up, book a free IT check-in. You can also read more about our IT support for medical practices and dental offices, or our guide to what a dental office needs from its IT.

This guide is general information, not legal advice. For questions about your practice’s specific obligations, talk to your attorney or compliance advisor.

Sources

  1. Microsoft Learn: HIPAA and the HITECH Act (Microsoft compliance offerings)
  2. Microsoft Learn: Microsoft 365 for business security best practices
  3. Microsoft Learn: Microsoft Purview Message Encryption
  4. Google Workspace Admin Help: HIPAA Compliance with Google Workspace and Cloud Identity

Frequently asked questions

Does Microsoft sign a business associate agreement?
Yes. Microsoft's HIPAA business associate agreement comes by default, through its Data Protection Addendum, for customers who are covered entities or business associates. It covers the services Microsoft lists as in scope, which include Exchange Online for email, SharePoint, OneDrive for Business and Microsoft Teams. There's nothing separate to sign.
Is Teams OK for talking about patients?
Teams is on Microsoft's list of covered services, so it can be. What matters is the setup: who's in each team and chat, whether guests and people outside the practice can join, and whether staff use it on protected devices. Keep conversations about a patient to the people who need them.
Can we email patient information from Outlook?
Yes, if it's protected. For messages to patients or other offices, use Microsoft Purview Message Encryption, so the recipient opens the message after signing in rather than reading it in the clear. You can set a rule to encrypt messages automatically, which works better than relying on everyone to remember.
Do we need to back up Microsoft 365?
Yes. Microsoft keeps the service running, but getting back mail and files that someone deleted, or that ransomware scrambled, is up to you. A separate backup of mailboxes, OneDrive, SharePoint and Teams, with restores tested from time to time, covers that, and HIPAA expects you to be able to recover patient information.
Which Microsoft 365 plan does a small practice need?
Usually Microsoft 365 Business Premium, for anyone who handles patient information. Business Basic and Business Standard include the covered email and file services and basic MFA, but Premium adds stricter sign-in rules, device management, extra phishing protection and message encryption.