Microsoft 365 settings that matter for HIPAA
Many small practices run email and files on Microsoft 365. Microsoft will sign a business associate agreement covering its in-scope services, but the BAA does not configure your tenant. Default settings leave real gaps, and those gaps are where most phishing-driven breaches start.
Start with these eight
- Confirm the BAA. Know where Microsoft's HIPAA BAA applies to your subscription, and keep ePHI in covered services.
- Require MFA for everyone. Security defaults or Conditional Access, with no exceptions for front-desk or shared accounts.
- Block legacy authentication. Older protocols bypass MFA entirely.
- Turn on audit logging. Make sure unified audit logging and mailbox auditing are on, so you can investigate an incident.
- Encrypt email containing PHI. Set up message encryption and teach staff when to use it.
- Restrict external sharing. Limit anonymous links in SharePoint and OneDrive.
- Encrypt devices. BitLocker on Windows laptops, managed and verified where your plan allows.
- Protect admin accounts. Separate admin accounts, strongest MFA, and as few global admins as possible.
Each of these maps to a Security Rule safeguard: access control, audit controls, integrity, person or entity authentication, and transmission security.
Available settings depend on your Microsoft 365 plan. Work with your IT provider before changing tenant-wide settings.
Get the full list
The Microsoft 365 HIPAA Hardening Checklist covers 32 settings, each mapped to the HIPAA safeguard it supports. $19, instant download.
Get the checklistThis guide is educational and is not legal advice. It reflects the HIPAA Security Rule in force as of October 2026. HHS proposed significant Security Rule changes in January 2025; they had not been finalized as of this update.