Share via

Questions Regarding HIPAA Compliance for Telehealth via Microsoft Teams

Alicia Millette 20 Reputation points
2026-01-16T14:57:10.26+00:00

Hello,

I work for a small healthcare center with six providers offering telehealth services. We are looking for the best way to provide this service in a HIPAA/HITECH-compliant manner without integrating it into our medical record system.

Zoom is one option, but since we already use Microsoft Teams, we are wondering if we can leverage Teams instead of adding Zoom.

I’ve reviewed some content online, but much of it appears outdated. Could you provide insight on whether using Teams with patients is covered under current HIPAA regulations? The BAA I have is dated 2019 and unsigned, so I need more current information than what I have on hand.

Additionally, does Microsoft retain any information from video calls, including chat features, and if so, for how long?

Thank you for your assistance,

Alicia

Microsoft Teams | Microsoft Teams for business | Meetings and calls | Audio and video
0 comments No comments

Answer accepted by question author

Ryan-N 13,855 Reputation points Microsoft External Staff Moderator
2026-01-16T15:52:01.6766667+00:00

Hi @Alicia Millette,

Welcome to the Microsoft Q&A forum.

Thank you for contacting us. I would like to provide you with the following information:

Microsoft Teams can comply with HIPAA for telehealth sessions, but it is not automatically compliant by default. You need to take specific steps to ensure HIPAA requirements are met. Below are some steps you can take:

  1. Use Microsoft 365 with HIPAA compliance features

You need to use a Microsoft 365 plan such as Microsoft 365 E3/E5 or Microsoft 365 Business Premium, which includes enterprise-grade security and compliance tools. Avoid using personal or consumer Teams accounts—they lack the necessary protections.

  1. Sign a Business Associate Agreement (BAA)

Microsoft provides a BAA for organizations covered by HIPAA (such as healthcare providers). The BAA is included by default in Microsoft 365 for organizations that need compliance, but you should verify that it has been signed/acknowledged in Microsoft 365 compliance documentation. To verify or accept the BAA:

  • Sign in to Microsoft 365 Compliance Center
  • Go to Service Trust Portal > Check “Compliance Manager”
  • Or contact Microsoft Support / your account manager to confirm the BAA status.
  1. Configure Teams for HIPAA compliance

You or your IT administrator should ensure Teams is securely configured:

  • Enable encryption for data at rest and in transit (Microsoft does this by default)
  • Set up Data Loss Prevention (DLP) policies to prevent unauthorized sharing of Protected Health Information (PHI)
  • Disable recording unless it is secured and stored properly (HIPAA requires PHI to be stored safely)
  • Use Multi-Factor Authentication (MFA) for all users
  • Apply role-based access controls (principle of least privilege)
  • Enable auditing and logging in Microsoft Purview.
  1. Train staff on HIPAA-compliant usage
  • Educate employees on handling PHI in Teams
  • Define which channels are safe for PHI and enforce usage policies
  • Conduct regular training and updates.
  1. Monitor and audit activities
  • Enable audit logs to track PHI access and changes
  • Use Microsoft 365 Compliance Center to generate reports and monitor suspicious activity
  • Connect logs to a SIEM tool for centralized monitoring.

 

  1. Address telehealth-specific risks
  • Verify patient identity during online sessions
  • Ensure the patient’s environment is private and secure
  • Be cautious with DLP settings that might block PHI sharing with guests (patients often join as guests).

For more details, you can refer to:

 Note: Microsoft is providing this information as a convenience to you. The sites are not controlled by Microsoft. Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information found there. Please make sure that you completely understand the risk before retrieving any suggestions from the above link.

Regarding the question “Does Microsoft Teams store video call information?” Yes, but details depend on your organization’s policies and configuration:

  • Teams stores chat data, files, and sometimes meeting recordings in SharePoint/OneDrive according to your tenant’s retention policies.
  • Microsoft encrpts data at rest and in transit and provides options for managing encryption keys.
  • Retention periods can be customized via Retention Policies in Microsoft Purview.

I hope this information is helpful.

If you have any questions or need further assistance, please feel free to share them in the comments on this post so I can continue to support you.

I look forward to continuing the conversation.


 If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment". 

Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread. 

Was this answer helpful?

0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Steve Waugh 0 Reputation points
    2026-06-17T11:41:37.7766667+00:00

    Great discussion

    One aspect that is often overlooked is that HIPAA compliance extends beyond selecting Microsoft Teams or any other communication platform. While Teams can support HIPAA-compliant telehealth workflows when configured correctly, healthcare organizations should also evaluate how patient data is stored, shared, integrated, and audited across their broader technology ecosystem.

    For example, organizations working with digital transformation partners such as Infosys, Deloitte, ScienceSoft, or Appinventiv often focus not only on secure video consultations but also on implementing role-based access controls, audit logging, EHR/EMR integrations, data retention policies, and automated compliance monitoring. These measures help reduce operational risks and improve overall governance.

    Another consideration is the shared responsibility model. Even when a vendor provides a Business Associate Agreement (BAA), healthcare providers remain responsible for user permissions, staff training, PHI handling procedures, and ongoing risk assessments. Recent telehealth guidance continues to emphasize secure technology usage, vendor agreements, and privacy safeguards as core compliance requirements.

    In practice, successful telehealth implementations combine a compliant platform like Teams with strong security policies, governance frameworks, and healthcare-specific integration strategies to ensure long-term HIPAA and HITECH readiness.

    Learn in more posts like: https://learn.microsoft.com/en-us/answers/questions/5850751/how-do-make-teams-hipaa-compliant?utm_source=chatgpt.com

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.