How to sign a Business Associate Agreement and add encryption

Unfiltered Aesthetics Co 0 Reputation points
2026-03-06T17:05:17.73+00:00

We are trying to add encryption to our business email to receive Protected Health Information.

Microsoft 365 and Office | Subscription, account, billing | For business | Other
0 comments No comments

2 answers

Sort by: Most helpful
  1. Kristen-L 15,650 Reputation points Microsoft External Staff Moderator
    2026-03-06T19:19:58.2133333+00:00

    Hi @Unfiltered Aesthetics Co,

    Thank you for reaching out to Microsoft Q&A forum.

    I understand you’re looking to set up a Business Associate Agreement (BAA) with Microsoft and enable email encryption so your organization can securely send and receive Protected Health Information (PHI).

    Below is a clear overview of how the BAA works in Microsoft 365 and the available encryption options.

    1/ Business Associate Agreement (BAA)

    Microsoft’s HIPAA BAA is provided automatically through the Microsoft Online Services Data Protection Addendum (DPA) and is available by default to customers who qualify as covered entities or business associates under HIPAA.

    To keep a copy of the BAA for your compliance records, Microsoft provides it through the Service Trust Portal (STP). In the portal, you’ll find a downloadable document - typically titled “Microsoft General – HIPAA BAA” - with versioned releases.

    Reference: Health Insurance Portability and Accountability Act (HIPAA) & Health Information Technology for Eco…

     

    To download and retain the BAA document

    • Go to the Service Trust Portal and sign in with your Microsoft 365 admin credentials.
    • Navigate to the HIPAA/BAA documentation page.
    • Download and save the BAA to your organization’s compliance repository.

    Note: If you attempt to sign in with a personal Microsoft account, access to these compliance documents may be restricted. A business or school account is required.

    Compliance reminder: Having a BAA in place is only one part of HIPAA compliance - it does not make your environment compliant by itself. You must still configure and operate Microsoft 365 according to HIPAA requirements.

     

    2/ Enabling Email Encryption for PHI in Microsoft 365

    Microsoft offers several encryption methods you can use to protect PHI:

    • Microsoft Purview Message Encryption (recommended)
    • S/MIME
    • Information Rights Management (IRM)
    • TLS (for transport-level encryption)

    Microsoft Purview Message Encryption is the most commonly used option since it works with most email providers (Gmail, Yahoo, etc.) and supports encrypted replies.

     

    For reference:

     

    A/ Setting up Microsoft Purview Message Encryption (Admin)

    1. Go to the Microsoft 365 admin center> Exchange.
    2. In the Exchange admin center, navigate to Mail flow > Rules to create or edit rules that apply encryption.
    3. Configure rules according to your organization’s policies (e.g., encrypt emails containing PHI).

     

    User's image

     

    User's image

    Important limitation for inbound PHI:

    It’s not possible to automatically encrypt incoming messages from external senders using a mail flow rule. If an outside sender emails you directly, that message will arrive unencrypted unless the sender encrypts it on their end.

    To handle inbound PHI securely, organizations typically:

    • Send outbound encrypted mail and allow recipients to reply securely, or
    • Use a secure external intake method when guaranteed inbound encryption is required.

     

    B/ End-user option: Encrypt directly in Outlook (when available)

    Users can send messages encrypted with S/MIME or Microsoft Purview Message Encryption, and that availability depends on your organization and licensing.

    For more detail: Send S/MIME or Microsoft Purview encrypted emails in Outlook

     

    C/ If you need stronger controls (revocation/expiration): Advanced Message Encryption

    If you need the ability to revoke access or set expiration for encrypted emails sent externally, Microsoft offers Advanced Message Encryption

    • Revocation capability is part of Advanced Message Encryption.
    • Expiration for encrypted email can also be configured (via custom branding templates and PowerShell as documented).
    • Licensing is typically tied to specific plans like Microsoft 365 E5 / Office 365 E5 / A5, per Microsoft’s documentation.

     

    I hope this information helps. Please try the steps and let me know whether they resolve the issue. If the problem persists, we can work together to find a solution.  

    As other users will also search for information in this community, your vote can significantly help those with similar inquiries quickly locate the most relevant resources. 

    Thank you for your kindness and for contributing to the forum.   


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".       

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?


  2. AI answer

    2026-03-06T17:05:31.2+00:00

    Microsoft 365 provides the technical capabilities to encrypt email that may contain Protected Health Information (PHI), but signing and managing a Business Associate Agreement (BAA) is handled through Microsoft’s commercial and compliance channels and is not covered in the provided context.

    From the context, the following options are available to add encryption to business email so that only intended recipients can read PHI:

    1. Use Microsoft Purview Message Encryption (recommended for Microsoft 365 Business)
      • Message encryption lets an organization send and receive encrypted email to internal and external recipients (including Outlook.com, Gmail, Yahoo!, and others).
      • Email content is converted from readable plain text into scrambled cipher text; only recipients with the appropriate key can decrypt it.
      • Admins can configure:
        • Automatic encryption via mail flow rules (for example, encrypt all messages sent outside the organization, or messages containing specific words/phrases related to PHI).
        • Manual encryption where users choose to encrypt specific messages in Outlook.
      • To implement:
        1. Set up Microsoft Purview Message Encryption for the tenant using the guidance in “Set up Message Encryption.”
        2. Optionally configure automatic mail flow rules to encrypt PHI-related messages.
        3. Train users to manually send encrypted email from Outlook when needed.
    2. Use S/MIME encryption and digital signatures
      • S/MIME is a certificate-based solution that provides both encryption and digital signatures.
      • Each user must have a digital ID (certificate); senders need recipients’ public keys, and recipients must protect their private keys.
      • S/MIME ensures:
        • Message confidentiality (only the intended recipient can read the message).
        • Sender authentication and integrity via digital signatures.
      • In Outlook, S/MIME can be configured once certificates are issued and installed for users.
    3. Use IRM (Information Rights Management) for additional restrictions
      • IRM uses Azure Rights Management to encrypt messages and apply usage restrictions (for example, Do Not Forward, Do Not Print, prevent copy/paste).
      • Any message with IRM protection or a digital signature is automatically encrypted.
      • Admins can define transport rules or Outlook protection rules to automatically apply IRM to messages that meet PHI-related criteria.
    4. General encryption behavior in Microsoft 365
      • Microsoft 365 encrypts data at rest and in transit using technologies such as TLS/SSL, IPSec, and AES.
      • Email encryption features (S/MIME, Microsoft Purview Message Encryption, IRM) add an additional layer to protect message content.

    To receive PHI securely over email, an organization should:

    1. Ensure the Microsoft 365 subscription includes the necessary encryption capabilities (for example, Microsoft 365 Business Premium or plans that include Microsoft Purview Message Encryption).
    2. Configure Microsoft Purview Message Encryption and/or S/MIME as the primary method to encrypt PHI-related email.
    3. Optionally configure IRM policies (such as Do Not Forward) for PHI messages.
    4. Train staff to recognize when PHI is present and to use the configured encryption options consistently.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.