How to retrieve our status in O365 vs HIPAA compliance requirement

Benoit Delacrose 0 Reputation points
2025-12-03T11:06:49.88+00:00

Hello

As an HIPAA regulated company CISO, i'm trying to get the status of our company in O365 about our status versus HIPAA compliance. I would like to be registered as such but I can't find how to do it and how I can check for sure we are already registered as such.

Aa an example, in AWS it really easy to find a proof, and get it. in O365, i have already taken hours to search how to get it and nowhere there is an simple explanation and valid URL to get it !

an example : i find this link : https://servicetrust.microsoft.com/ViewPage/MSComplianceGuideV3

in this page : https://learn.microsoft.com/en-us/answers/questions/5295837/where-to-find-the-business-associate-agreement-for

but when i click on it, it fails to get there and I land on this page : https://servicetrust.microsoft.com/ViewPage/HomePageVNext

And there is no HIPAA there ! I did this research many times i always get in circles and get nowhere

Can we have something that work ?

Microsoft 365 and Office | Other
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Benoit Delacrose 0 Reputation points
    2025-12-03T11:18:51.1533333+00:00

    Again this an agent that provide unusable informations, the link you provide just do not work i never get to the location the links are supposed to bring me.

    Read my quesitons in details and see by yourself that the link i gave are not working for me, but there is no explanation of any kind and i can't get the informaiton I NEED !

    0 comments No comments

  2. Benoit Delacrose 0 Reputation points
    2025-12-03T11:27:16.2633333+00:00

    I have receive this response by mail from you

    To retrieve your organization's status regarding HIPAA compliance in Office 365, you should first ensure that you have a Business Associate Agreement (BAA) with Microsoft.

    unfortunately, you wrote this (in your agent reply) :

    Check for a Business Associate Agreement: Ensure that your organization has entered into a BAA with Microsoft. This agreement is automatically included for customers who are covered entities or business associates under HIPAA.

    So if its supposed to be automatic, I would not need to ensure we have it, but because i can't find a way to check we have it, still I don't find much about how to ask for it.again, could you provide a working link to let me request to registered as an HIPAA regulated entity ?

    0 comments No comments

  3. Emmanuel Santana 33,495 Reputation points Independent Advisor
    2025-12-03T12:40:01.3966667+00:00

    Hello. You can try the following steps:

    1. Go to the Service Trust Portal: https://servicetrust.microsoft.com
    2. Sign in using a work (Azure AD) account, personal Microsoft Accounts won’t display restricted compliance documents.
    3. Open the Compliance Reports section.
    4. In the search bar, enter HIPAA.

    You should then see the available materials, such as: • HIPAA / HITECH Act Implementation Guidance • Microsoft’s list of in-scope HIPAA-eligible services • Additional audit and compliance documents depending on your licensing level

    If none of the HIPAA documents appear, the signed-in account likely doesn’t have the required admin or compliance role.

    And as far as I rmemeber HIPAA support is contractual, not a tenant setting or switch. This is documented here: https://learn.microsoft.com/en-us/compliance/regulatory/offering-hipaa-hitech

    According to Microsoft:

    The Microsoft HIPAA Business Associate Agreement is available through the Microsoft Online Services Data Protection Addendum by default to all customers who are covered entities or business associates under HIPAA.


  4. Benoit Delacrose 0 Reputation points
    2025-12-03T13:03:15.2433333+00:00

    Sorry again

    I did, thank you anyway


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.