4 min read
Microsoft 365 for Medical and Dental Offices: The HIPAA Settings That Matter
The short answer
Yes, a practice can use Microsoft 365 for patient information. Microsoft includes a HIPAA business associate agreement in its standard terms for covered services, but says that alone doesn't cover your HIPAA obligations. The settings are your job: MFA for everyone, encrypted email, limits on outside sharing, protected devices and a backup of mail and files.
Plenty of practices already run their email on Microsoft 365. The question tends to come up later: when someone starts keeping patient files in OneDrive, when the front desk wants to message a referring office in Teams, or when an insurer asks how email is protected.
The answer depends less on which product you bought and more on how it’s set up.
What Microsoft’s business associate agreement covers
Under HIPAA, a cloud provider that holds patient information for a practice is a business associate, and Microsoft says so plainly. Its HIPAA business associate agreement is included by default, through the Microsoft Online Services Data Protection Addendum, for customers who are covered entities or business associates.
The agreement covers the services Microsoft lists as in scope. For a practice on Microsoft 365, those include:
- Exchange Online (email and calendars)
- SharePoint Online and OneDrive for Business (files)
- Microsoft Teams
- Microsoft Entra ID (sign-ins)
- Microsoft Intune (device management)
- Forms, Planner and the Office apps on the web
Personal Microsoft accounts and apps from other companies added into Teams or Outlook aren’t on that list. Check a service is covered before patient information goes into it.
What stays your job
The agreement covers Microsoft’s side: running and protecting the service itself. How your practice uses it is on your side. You decide who can see what, how the settings are configured, how staff are trained and how you’d recover if something went wrong.
In Microsoft 365, the Security Rule’s basics look like this: knowing where patient files and mail sit, limiting who opens them, keeping them protected and being able to restore them. The tools for each are already there. Most of them are settings someone has to switch on and check.
The settings to check first
Microsoft’s own security guidance for small businesses is a good outline. For a medical or dental office, these come first:
- Multi-factor authentication (MFA) for everyone. Microsoft’s security defaults turn it on in every business plan. Business Premium adds Conditional Access, which lets you set stricter rules, such as blocking sign-ins from devices the practice doesn’t manage. Give administrators separate admin accounts that aren’t used for everyday email.
- Encrypted email. Microsoft Purview Message Encryption protects messages that leave the practice. Recipients on Gmail, Yahoo or other services get a link and sign in to read the message. A mail rule can encrypt messages automatically, for example anything sent outside the practice with an attachment.
- Limits on outside sharing. Decide whether files in OneDrive and SharePoint can be shared outside the practice at all. If they can, require people to sign in, and turn off “anyone with the link” sharing. Do the same for guests in Teams.
- Protected devices. Every computer and phone that opens practice email or files should be encrypted, kept up to date and managed, so work data can be removed from a lost phone. Business Premium includes Intune for this; the other plans include a more basic mobile device management option.
- Phishing protection. Every plan filters spam, malware and spoofed mail. Business Premium adds a check on links when someone clicks them, in email and in Teams, and tests email attachments in a safe space before they’re delivered.
- Sign-in and activity logs. Make sure they’re kept and that someone knows how to search them, so you can answer “who opened that file?” if you ever need to.
- A backup of mail and files, kept separately from Microsoft, with restores tested. If a mailbox is ever taken over or files are scrambled by ransomware, here’s what to do in the first hour.
Business Basic, Standard or Premium for a practice
All three are Microsoft 365 business plans, and all three include the email, file and Teams services the business associate agreement covers. The differences that matter to a practice are in security:
| What you get | Business Basic | Business Standard | Business Premium |
|---|---|---|---|
| Email, OneDrive, SharePoint and Teams | Yes | Yes | Yes |
| Desktop Office apps | No (web and mobile only) | Yes | Yes |
| MFA through security defaults | Yes | Yes | Yes |
| Conditional Access for stricter sign-in rules | No | No | Yes |
| Device management with Intune | No (basic mobile only) | No (basic mobile only) | Yes |
| Message encryption | No | No | Yes |
| Extra protection for links and attachments | No | No | Yes |
If your practice handles patient information, Premium is the plan to aim for, at least for everyone who touches it, because the security pieces it adds are the ones the settings above lean on.
Google Workspace works too
If your practice runs on Google instead, Google offers a business associate agreement as well. An administrator reviews and accepts it in the Google Admin console, and patient information should only go into the services Google lists as covered. The same settings apply: MFA, sharing limits, managed devices and a separate backup. We support both, so if what you have is working, there’s no need to switch.
How we set up Microsoft 365 for practices
We set up and look after Microsoft 365 and Google Workspace for medical and dental practices across Orange County: the security settings above, email encryption, phishing filtering, and backups of mail and files that we test. See our business email and productivity page for the details, or our HIPAA checklist for medical practices for the rest of the picture.
If you’d like someone to look over how your practice’s Microsoft 365 is set up, book a free IT check-in. You can also read more about our IT support for medical practices and dental offices, or our guide to what a dental office needs from its IT.
This guide is general information, not legal advice. For questions about your practice’s specific obligations, talk to your attorney or compliance advisor.
