Hi,
Something here might be helpful:
https://learn.microsoft.com/en-us/microsoft-365/compliance/offering-hipaa-hitech?view=o365-worldwide#use-microsoft-compliance-score-to-assess-your-risk
Can my organization enter into a BAA with Microsoft?
Microsoft offers qualified companies or their suppliers a BAA that covers in-scope Microsoft services.
For Microsoft cloud services: The HIPAA Business Associate Agreement is available via the Online Services Terms by default to all customers who are covered entities or business associates under HIPAA. See 'Microsoft in-scope cloud services' on this webpage for the list of cloud services covered by this BAA.
For Microsoft Professional Services services: The HIPAA Business Associate Amendment is available for in-scope Microsoft Professional Services upon request to your Microsoft services representative.
Best regards,
Leon