Share via

Inquiry regarding HIPAA Compliance and BAA Status for OCVMG

Jaskirat Singh 0 Reputation points
2026-02-24T17:56:32.4466667+00:00

Dear Microsoft Support,

I am writing to confirm the HIPAA compliance status for our Microsoft 365 Enterprise [E3/E5] tenant. Could you please provide clarification on the following:

  1. Business Associate Agreement (BAA): Can you confirm that our organization is currently covered under the Microsoft Online Services Data Protection Addendum (DPA) and that the HIPAA BAA is active for our tenant?
  2. Compliance Assessment: Where can I find the most recent HIPAA/HITECH assessment template within our Microsoft Purview Compliance Manager to perform a risk assessment?
  3. Technical Safeguards: Does our current subscription level include automated Data Loss Prevention (DLP) for PHI and Microsoft Purview Message Encryption out-of-the-box, or do these require additional add-on licenses?
  4. Audit Logging: Is advanced audit logging enabled by default for our subscription, or are there specific configurations needed to meet HIPAA retention requirements?

Please let us know if there are any further administrative steps we must take to remain in compliance with HIPAA regulations.
Thank you,
[Moderator note: personal info removed]

 

Microsoft 365 and Office | Subscription, account, billing | For business | Windows
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Kristen-L 10,585 Reputation points Microsoft External Staff Moderator
    2026-02-24T22:23:37.7066667+00:00

    Hi @Jaskirat Singh,

    Welcome to Microsoft Q&A forum.  

    Thank you for reaching out. I understand your need for clear guidance on how Microsoft 365 supports your organization’s HIPAA compliance - especially regarding the Business Associate Agreement (BAA), assessment templates, technical safeguards, and audit logging.

    Below is a clean breakdown of how each element works in Microsoft 365:

    1/ Business Associate Agreement (BAA)

    • Microsoft provides a HIPAA Business Associate Agreement automatically through the Microsoft Online Services Data Protection Addendum (DPA) for covered entities and business associates using eligible Microsoft cloud services. In practice, this means that once your organization uses in‑scope Microsoft 365 services and accepts the Online Services Terms/DPA, you are already covered under Microsoft’s BAA wording: Health Insurance Portability and Accountability Act (HIPAA) & Health Information Technology for Eco….
    • Your administrator can sign in to the Service Trust Portal, go to the HIPAA section, and download the relevant documentation - including the DPA/BAA text and HIPAA support materials.
    • Microsoft’s HIPAA/HITECH information explicitly notes that Microsoft enters into BAAs with covered entity and business associate customers using eligible services.

    2/ HIPAA/HITECH compliance assessment in Compliance Manager

    You can run a compliance assessment directly in Microsoft Purview’s Compliance Manager:

    Licensing notes:

    • All tenants get the Microsoft Data Protection Baseline included.
    • E5/A5/G5 tenants can choose up to three premium regulations at no extra cost.
    • Other regulations - including HIPAA/HITECH in many E3 tenants - may require a paid add‑on. Check Compliance Manager > Regulations to see what is available in your tenant: Compliance Manager regulations list.

    3/ Technical safeguards

    a) Data Loss Prevention (DLP) for PHI

    • E3/E1: Includes core DLP for Exchange Online, SharePoint Online, and OneDrive.
    • E5 / Purview Suite add‑ons: Adds Teams Chat/Channel DLP and Endpoint DLP, both important for PHI protection across devices and Teams collaboration: Learn about data loss prevention.

    b) Microsoft Purview Message Encryption (formerly OME)

    Included in:

    • Microsoft 365 E3/E5
    • Office 365 E3/E5
    • Several government/education plans

    No additional licensing is required if you already have one of these suites: Message encryption FAQ.

    4/ Audit logging & HIPAA retention expectations

    Audit is enabled by default:

    • Unified audit logging is automatically on for all Microsoft 365 tenants. You can view logs under: Purview > Audit: Audit log activities.

    Retention periods: Manage audit log retention policies.

    • Audit Standard (E1/E3): Most workloads retained for 180 days
    • Audit Premium (E5 / Purview / E5 Compliance add‑on):
      • 1‑year default retention for Exchange, SharePoint, OneDrive, and Entra ID
      • Ability to create custom retention policies
      • Other workloads: 180 days
    • 10‑year retention: Available through the Audit (Premium) 10‑year add‑on.

     

    I hope this information is helpful. Please try the steps and let me know whether they resolve the issue. If the problem persists, we can work together to find a solution.  

    As other users will also search for information in this community, your vote can significantly help those with similar inquiries quickly locate the most relevant resources. 

    Thank you for your kindness and for contributing to the forum.   


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".       

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread. 


  2. Q&A Assist
    2026-02-24T17:56:42.58+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more
    1. Business Associate Agreement (BAA): Yes, Microsoft offers a Business Associate Agreement that covers in-scope Microsoft services for organizations that are covered entities or business associates under HIPAA. You can confirm your coverage under the Microsoft Online Services Data Protection Addendum, which includes the HIPAA BAA by default for eligible customers.
    2. Compliance Assessment: You can find the most recent HIPAA/HITECH assessment template in the Microsoft Purview Compliance Manager. It is available in the assessment templates page within the Compliance Manager.
    3. Technical Safeguards: The Microsoft 365 Enterprise E3/E5 subscriptions include features such as Data Loss Prevention (DLP) for PHI and Microsoft Purview Message Encryption. However, you should verify if any additional licenses are required for specific configurations or advanced features.
    4. Audit Logging: Advanced audit logging is not enabled by default for all subscriptions. You may need to configure specific settings to meet HIPAA retention requirements.

    For further administrative steps to remain compliant with HIPAA regulations, it is advisable to consult with your legal advisors and review the compliance guidelines provided by Microsoft.


    References:

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.