M365 HIPAA compliance steps 3 user law office

eli honig 0 Reputation points
2026-08-04T16:15:52.46+00:00

Looking for clear steps to apply controls to satisfy Hipaa compliance for a small 3 person law firm. Using M365 Email and Sharepoint primarily. We are currently using M365 Office Standard licensing. Most documentation is geared towards large enterprises. Therw will be 1-2 users accessing PHI. Thank You

Microsoft 365 and Office | SharePoint | For business | Windows

1 answer

Sort by: Most helpful
  1. Ivory 405 Reputation points Independent Advisor
    2026-08-04T16:51:17.4233333+00:00

    Hi Eli,

    While your M365 Business Standard subscription provides the core infrastructure, Business Standard requires Data Loss Prevention (DLP), Microsoft Purview Message Encryption, and Intune device management.

    Microsoft automatically incorporates a HIPAA BAA into the Microsoft Products and Services Data Protection Addendum (DPA) for all commercial M365 tenants.

    No physical signature or tenant toggle is required. you can retain a downloaded copy of the Microsoft Service Trust Portal DPA document for your firm's compliance documentation.

    The BAA covers Exchange Online (Email), SharePoint Online, OneDrive for Business, and Teams.

    You should try the following set up:

    • Enable Multi-Factor Authentication (MFA) on all accounts.
    • Lock down SharePoint external sharing to "Existing Guests" or "Only people in organization" and isolate PHI into a dedicated, restricted folder.
    • Verify device-level encryption (BitLocker / FileVault) and auto-lock passcodes on all laptops and mobile devices.
    • Confirm Microsoft Purview Audit Logging is enabled to log file access and downloads.

    However, you can consider licensing paths for email encryption & data protection by upgrading PHI Users to M365 Business Premium. This will unlocks native Outlook message encryption ("Encrypt / Do Not Forward"), automated block rules for sensitive data, and centralized device wipe controls. You can upgrades only the 1–2 users accessing PHI to manage the costs.

    In case you require a live walkthrough to set up configurations tailored to your organization, you can raise support ticket at https://admin.microsoft.com/#/support/requests    with your admin credentials.

    Technical settings in M365 fulfill technical safeguards, but HIPAA also requires your firm to maintain a basic written risk assessment and internal privacy policies.

    I hope these information provide some information and clarity to your issue. Should you have any questions, please don't hesitate to reach out.


    If the answer is helpful, please click 'Yes' and kindly upvote it. If you have extra questions about this answer, please click "Comment". 

    Note: Please follow the steps in the forum documentation to enable e-mail notifications if you want to receive the related email notification for this thread. 

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.