Ensuring devices meet organizational security and compliance policies
To make email HIPAA-compliant with Microsoft cloud services, focus on three areas: (1) using in-scope services under Microsoft’s HIPAA Business Associate Agreement (BAA), (2) configuring safeguards for PHI, and (3) managing your own organizational policies and procedures.
- Confirm use of HIPAA in-scope Microsoft services
- HIPAA applies to covered entities such as behavioral health practices and to their business associates, including cloud service providers that create, receive, maintain, or transmit PHI.
- Microsoft offers a HIPAA Business Associate Agreement that covers specific cloud services, including Microsoft 365/Office 365 components such as Exchange Online, OneDrive for Business, SharePoint Online, Microsoft Teams, and others listed as “in-scope services.”
- For Office 365/Microsoft 365, use plans that include in-scope services for HIPAA, such as Exchange Online for email.
- Obtain and rely on Microsoft’s HIPAA BAA
- HIPAA requires a Business Associate Agreement between the covered entity (your practice) and the business associate (Microsoft) to ensure PHI is protected.
- Microsoft’s HIPAA BAA is provided through the Microsoft Online Services Data Protection Addendum and is available by default to customers who are covered entities or business associates under HIPAA.
- The BAA clarifies and limits how Microsoft, as a business associate, can handle PHI and is automatically included as part of the Online Services Terms for qualifying cloud services.
- To review the BAA details, use the Microsoft HIPAA Business Associate Agreement available via the Service Trust Portal as referenced in the documentation.
- Configure technical safeguards for email and identity Even with a BAA in place, HIPAA compliance depends on how services are configured and used.
Key areas from the guidance:
- Integrity safeguard:
- Protect files and emails across all devices.
- Discover and classify sensitive data.
- Encrypt documents and emails that contain sensitive or personal data.
- Transmission security safeguard:
- Implement technical security measures to guard against unauthorized access to PHI transmitted over electronic networks.
- Review Azure and Microsoft 365 encryption capabilities for data in transit and at rest.
- Use Microsoft Purview features (such as Data Lifecycle Management and Records Management) to apply retention policies and labels that help manage and protect PHI in email and related content.
- Identity and access:
- Use Microsoft Entra ID to implement person or entity authentication safeguards (for example, strong authentication, MFA, and appropriate access controls) so only authorized staff can access PHI in email.
- Use Microsoft Purview Compliance Manager for HIPAA
- Microsoft Purview Compliance Manager provides a premium HIPAA/HITECH assessment template.
- This can be used to:
- Assess current configuration of Microsoft 365 services against HIPAA-related controls.
- Track improvement actions to reduce risk around PHI in email and other workloads.
- Organizational responsibilities
- The organization remains wholly responsible for ensuring overall HIPAA compliance.
- The Microsoft BAA and technical capabilities support compliance, but policies and procedures must be implemented and enforced internally, including:
- When PHI may be sent by email.
- Required encryption and access controls.
- Workforce training on handling PHI.
- Incident response and breach notification processes.
Summary path to proceed
- Use Microsoft 365/Office 365 plans that include HIPAA in-scope services (especially Exchange Online for email).
- Ensure the Microsoft HIPAA BAA (via the Online Services Data Protection Addendum/Online Services Terms) is in place for the tenant.
- Configure Microsoft Entra ID, encryption, and Purview-based controls to protect PHI in email (integrity, authentication, and transmission security safeguards).
- Use Microsoft Purview Compliance Manager’s HIPAA template to assess and track your compliance posture.
- Work with legal/compliance counsel to align these technical measures with your behavioral health practice’s HIPAA policies.
References: