How to make my email hipaa compliant?

DB Baksic 0 Reputation points
2026-04-07T03:28:43.3766667+00:00

I own a behavioral health practice and would like to make our email hipaa complaint. Please point me in the correct direction of the BAA and directions to complete this process.

Microsoft Security | Intune | Compliance

1 answer

Sort by: Most helpful
  1. AI answer

    2026-04-07T03:28:55.99+00:00

    To make email HIPAA-compliant with Microsoft cloud services, focus on three areas: (1) using in-scope services under Microsoft’s HIPAA Business Associate Agreement (BAA), (2) configuring safeguards for PHI, and (3) managing your own organizational policies and procedures.

    1. Confirm use of HIPAA in-scope Microsoft services
    • HIPAA applies to covered entities such as behavioral health practices and to their business associates, including cloud service providers that create, receive, maintain, or transmit PHI.
    • Microsoft offers a HIPAA Business Associate Agreement that covers specific cloud services, including Microsoft 365/Office 365 components such as Exchange Online, OneDrive for Business, SharePoint Online, Microsoft Teams, and others listed as “in-scope services.”
    • For Office 365/Microsoft 365, use plans that include in-scope services for HIPAA, such as Exchange Online for email.
    1. Obtain and rely on Microsoft’s HIPAA BAA
    • HIPAA requires a Business Associate Agreement between the covered entity (your practice) and the business associate (Microsoft) to ensure PHI is protected.
    • Microsoft’s HIPAA BAA is provided through the Microsoft Online Services Data Protection Addendum and is available by default to customers who are covered entities or business associates under HIPAA.
    • The BAA clarifies and limits how Microsoft, as a business associate, can handle PHI and is automatically included as part of the Online Services Terms for qualifying cloud services.
    • To review the BAA details, use the Microsoft HIPAA Business Associate Agreement available via the Service Trust Portal as referenced in the documentation.
    1. Configure technical safeguards for email and identity Even with a BAA in place, HIPAA compliance depends on how services are configured and used.

    Key areas from the guidance:

    • Integrity safeguard:
      • Protect files and emails across all devices.
      • Discover and classify sensitive data.
      • Encrypt documents and emails that contain sensitive or personal data.
    • Transmission security safeguard:
      • Implement technical security measures to guard against unauthorized access to PHI transmitted over electronic networks.
      • Review Azure and Microsoft 365 encryption capabilities for data in transit and at rest.
      • Use Microsoft Purview features (such as Data Lifecycle Management and Records Management) to apply retention policies and labels that help manage and protect PHI in email and related content.
    • Identity and access:
      • Use Microsoft Entra ID to implement person or entity authentication safeguards (for example, strong authentication, MFA, and appropriate access controls) so only authorized staff can access PHI in email.
    1. Use Microsoft Purview Compliance Manager for HIPAA
    • Microsoft Purview Compliance Manager provides a premium HIPAA/HITECH assessment template.
    • This can be used to:
      • Assess current configuration of Microsoft 365 services against HIPAA-related controls.
      • Track improvement actions to reduce risk around PHI in email and other workloads.
    1. Organizational responsibilities
    • The organization remains wholly responsible for ensuring overall HIPAA compliance.
    • The Microsoft BAA and technical capabilities support compliance, but policies and procedures must be implemented and enforced internally, including:
      • When PHI may be sent by email.
      • Required encryption and access controls.
      • Workforce training on handling PHI.
      • Incident response and breach notification processes.

    Summary path to proceed

    1. Use Microsoft 365/Office 365 plans that include HIPAA in-scope services (especially Exchange Online for email).
    2. Ensure the Microsoft HIPAA BAA (via the Online Services Data Protection Addendum/Online Services Terms) is in place for the tenant.
    3. Configure Microsoft Entra ID, encryption, and Purview-based controls to protect PHI in email (integrity, authentication, and transmission security safeguards).
    4. Use Microsoft Purview Compliance Manager’s HIPAA template to assess and track your compliance posture.
    5. Work with legal/compliance counsel to align these technical measures with your behavioral health practice’s HIPAA policies.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

    3 people found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.