top of page

Microsoft 365 HIPAA Compliance: What Does a Small Medical Practice Actually Need?

  • Writer: Shay
    Shay
  • Aug 13
  • 12 min read
What does Microsoft 365 HIPAA compliance actually require?

I have worked with small healthcare organizations that believed they were HIPAA compliant because they were using Microsoft 365. I understand how they got there. Microsoft talks about HIPAA, provides a Business Associate Agreement for covered services and offers security tools that can be used to protect electronic protected health information, commonly called ePHI. If you are a small practice owner who depends on an outside IT company to manage all of this for you, it is reasonable that you would assume having Microsoft 365 means that part of HIPAA has been handled.


The problem is that having Microsoft 365 does not tell me very much about how secure your practice actually is. I need to know how it was configured, how your computers are managed, how employees sign in, who has administrative access, what happens when somebody leaves, where information is being stored and what protections are actually in place. Microsoft itself makes the same basic distinction. Its services can support an organization's HIPAA obligations, but using Microsoft services does not automatically make an organization HIPAA compliant.


I have seen the confusion this creates firsthand.


What does Microsoft 365 HIPAA compliance actually require?

I ran into this situation with a behavioral health organization that was already using Microsoft 365 Business Standard when I started working with them. They had been told by their previous IT company that they were HIPAA compliant, so from their perspective this was something that had already been addressed. They were paying for Microsoft 365, they had antivirus software, they had an IT provider and their patient information was primarily associated with their EHR. There was no obvious reason for them to question what they had been told.


When I started looking at the computers and the rest of the environment, I found a different situation. Employees were working from local Windows accounts and had local administrator rights on their computers. There was no centralized device-management platform in place that allowed those computers to be managed consistently, and there wasn't one central place where I could look at the devices and verify the security configuration I expected to find.


That does not mean Microsoft 365 Business Standard caused the problem. The bigger issue was the assumption that having Microsoft 365 meant the technology side of HIPAA had somehow been taken care of.

It hadn't.


This is why I am careful when someone asks me whether Microsoft 365 is HIPAA compliant. Microsoft offers services that can be used by organizations subject to HIPAA and provides a Business Associate Agreement for applicable services, but there is still a lot that has to happen on the customer's side.


For a small medical practice, I think the better question is whether your use of Microsoft

365 is appropriate for the environment you have and the information you need to protect.


Why I recommend Microsoft 365 Business Premium to my healthcare clients

HIPAA does not say that a medical practice has to buy Microsoft 365 Business Premium. I want to make that distinction very clear because I do not want someone reading this article and coming away thinking that upgrading a Microsoft license checks a HIPAA compliance box.


For the healthcare clients I manage, Business Premium is the Microsoft 365 licensing I recommend because it gives me security and management capabilities that I want available when I am responsible for their environment. Among those capabilities are Microsoft Intune Plan 1 for device management, Microsoft Defender for Business for endpoint protection, Microsoft Entra ID P1 for additional identity and access controls, and Microsoft Defender for Office 365 Plan 1 for additional email and collaboration protection.


The difference becomes much easier to understand when we go back to the behavioral health example. If I am responsible for supporting a practice's computers, I do not want my only way of knowing what is happening on those computers to be logging into them one at a time. I want centralized management available so that policies can be applied consistently and I can have better visibility into the devices accessing company resources.


I also want the identity and security tools available to put appropriate controls around the accounts employees use every day.


There is still work involved after the license is purchased. Intune sitting unused in a Microsoft tenant does not manage anything, and having access to Defender does not mean it has been configured correctly. Business Premium gives me tools that I can use to build the environment I want for a healthcare client, but those tools still have to be implemented and managed.


That distinction is important because it is very easy for a small business owner to look at an invoice, see a Microsoft product name and assume the security associated with that product is already happening behind the scenes.

Sometimes it isn't.


Your EHR is only one part of your IT environment

Another thing I have encountered with small healthcare organizations is the belief that almost everything involving patient information happens inside the EHR. If the EHR vendor takes security seriously and the application is hosted in the cloud, it can feel like most of the technology risk has been handed off to somebody else.


That assumption can fall apart pretty quickly once you start looking at how employees actually work.


Suppose an employee signs into a cloud-based EHR from an office computer and downloads a report containing patient information. That information may now exist outside the EHR. The same thing can happen when someone exports information to Excel, scans a document, downloads an email attachment or saves something into OneDrive. An employee working from home can create another consideration, particularly if that person is using a personal computer or another device that the practice does not manage.


This is why the HIPAA risk analysis is so important. HHS says the risk analysis needs to consider all ePHI that an organization creates, receives, maintains or transmits. The scope is not limited to the EHR, and HHS specifically discusses workstations, networks and portable electronic media when describing the environments that may need to be considered.


When I am looking at the technical side of a small practice, I am interested in how information moves through the business during a normal day. An office manager exporting something from the EHR into a spreadsheet may be much more relevant than a feature buried deep inside a security product. I also need to understand whether information is being emailed, where scanned documents are saved, whether employees work remotely, what is being backed up and which outside vendors have access to the environment.


The answers can be very different from what the practice owner expects.


What about OneDrive and email?

OneDrive is another good example of why I do not like answering healthcare security questions by simply labeling a product "HIPAA compliant" or "not HIPAA compliant."

If a practice is using an applicable Microsoft service covered by Microsoft's HIPAA offering, that gives us part of the picture. I still need to understand how the practice is using the service. If ePHI is stored in OneDrive, I would look at who has access to those files, what sharing has been permitted, how the accounts are protected and which devices can synchronize that information. I would also want to understand what happens to the account and its data when an employee leaves.


Email works the same way. HHS does not simply prohibit the use of email for ePHI; appropriate safeguards still need to be considered.


If a practice tells me it uses Outlook, I still need more information before that tells me anything useful about security. I need to understand what employees send through email, how they access their accounts when they are away from the office, whether information gets forwarded to personal accounts, and what happens when someone downloads an attachment containing patient information onto a computer.


This is one of the reasons I spend so much time talking to clients about how they actually work. The configuration on the screen is only part of the environment.


The computers themselves cannot be ignored

I pay a lot of attention to the computers employees use because those computers can become one of the places where information leaves a well-controlled system and ends up somewhere the practice did not expect.


This is also where centralized management becomes important to me. If a small practice has ten computers, I should not need to physically visit all ten machines every time I need to verify something about them. I want to be able to manage the environment centrally and have a reliable way to understand what I am responsible for.


That includes issues such as encryption, updates, endpoint protection, administrative privileges and the policies being applied to company devices. It also gives me a better foundation for dealing with the inevitable changes that happen in a business. Computers are replaced, employees leave, new employees are hired and somebody eventually loses a laptop.


This is part of why the environment I found at the behavioral health organization concerned me. The issue wasn't simply that the employees had local Windows accounts. It was that there wasn't a larger management structure around those computers that gave the organization the visibility and control I would expect.


A small practice still needs a HIPAA risk analysis

Small practices sometimes assume that the formal parts of HIPAA are really intended for hospitals and large healthcare systems. A behavioral health practice with six employees clearly does not have the same IT department, budget or infrastructure as a regional hospital, and HIPAA does allow organizations to consider factors such as size, complexity, capabilities, technical infrastructure and cost when determining reasonable and appropriate safeguards.


That does not mean the small practice gets to skip the risk analysis.

HHS describes risk analysis as foundational to Security Rule compliance. In plain language, the practice needs to understand where its ePHI exists, what could happen to that information, where vulnerabilities exist and what safeguards are appropriate for the risks it has identified.


I think this is an area where small businesses sometimes get sold technology in the wrong order. Someone recommends a firewall, security software, a Microsoft license or another product before anyone has spent enough time understanding what is already there.

I would rather establish the baseline first and make decisions from there.


What if I don't know what my practice currently has?

You are not unusual. I work with businesses that have accumulated technology over many years, sometimes with several different IT companies involved along the way. Computers were added when new employees started, somebody configured the Wi-Fi years ago, another company set up Microsoft 365 and perhaps somebody else installed the firewall. Eventually the owner knows that everything is working, but nobody has a clear picture of how it all fits together anymore.


That is one of the reasons I offer both a Microsoft 365 Audit and an IT Baseline Assessment.

My Microsoft 365 Audit is focused specifically on the Microsoft environment. I review the tenant configuration, accounts, administrative access, authentication, MFA, security settings, licensing and other areas that can affect the security of Microsoft 365. If the practice is currently using Business Standard, this also gives me an opportunity to explain why I recommend Business Premium for the healthcare environments I manage and what I would actually use the additional capabilities for.


The IT Baseline Assessment goes further because sometimes Microsoft 365 is only a small part of what needs attention. I look at the broader technology environment, which can include the computers, user accounts, administrative access, endpoint protection, device management, firewall, network, Wi-Fi, remote access and backups. The exact scope depends on the business because I am trying to understand the environment that actually exists rather than force every client through the same checklist regardless of how they operate.


You do not need to know what products you need before having an assessment. In many cases, figuring that out is part of the reason for doing the assessment in the first place.


I also document the environments I manage

Documentation is something I put a lot of emphasis on with my Managed IT clients because I do not think important information about a client's environment should exist only in someone's memory.


I maintain a runbook for the environments I manage, and that documentation changes as the client's technology changes. My runbooks maintain version numbers, dates and timestamps, and I keep an appendix showing what was updated and when the change occurred. I originally built my documentation this way for a very practical reason: if something happens six months from now, I want to be able to go back and determine what changed rather than trying to remember whether I modified a setting months earlier.


That history is useful for the client, but I use it constantly for my own reference as well. If a computer was replaced, an account changed, a security setting was modified or something else happened in the environment, I already have documentation to work from when I need to troubleshoot or investigate something later.


For healthcare clients, there is another benefit to having that history. If a question comes up about the IT environment or when a particular change was made, there is documentation available to go back to. The runbook is not a replacement for the actual audit logs maintained by Microsoft 365, a firewall, endpoint-security software or other systems. It is an additional documented history of the environment and the work I have performed.


I would much rather have that information and never need it than have something happen and discover afterward that nobody documented anything.


What about a BAA with your IT company?

Microsoft is not necessarily the only technology company a medical practice needs to think about when it comes to Business Associate Agreements.


Your IT provider may have significant administrative access to your environment. Depending on the services being provided, that could include Microsoft 365, employee computers, servers, backups and other systems where PHI may exist. HHS explains that whether an IT or software vendor is a business associate depends on the services being provided and the vendor's relationship to PHI.


For healthcare organizations receiving Managed IT services from SNL-Tech Services where the relationship involves HIPAA-covered information, I provide a Business Associate Agreement as part of that relationship.


I think this is a reasonable conversation for any healthcare practice to have with an IT company that may have access to PHI while supporting the environment. If the provider will have that type of access, ask about the BAA before there is a problem rather than discovering after an incident that nobody ever addressed it.


The BAA also fits into the larger approach I take with healthcare clients. I want the technical environment managed, I want the work documented and I want the relationship between SNL-Tech Services and the healthcare organization documented appropriately as well.


HIPAA compliance is bigger than IT

There is an important boundary here that I want to be clear about.

HIPAA includes administrative, physical and technical safeguards. I can work with a practice on its technical environment, but I would not tell a client that replacing a firewall, moving to Business Premium or completing one of my assessments suddenly makes the entire organization HIPAA compliant. There are parts of HIPAA that go beyond what an IT provider can accomplish by configuring technology.


What I can do is help a practice understand what is happening on the technical side, identify problems that need attention and build an environment that can be managed rather than assumed to be secure.


For a small independent or specialty practice without an internal IT department, that can answer a very important question:


Do we actually have what we think we have?

That is the question I wish more businesses asked before somebody simply told them they were compliant.


Frequently Asked Questions About Microsoft 365 and HIPAA

Does having Microsoft 365 make my medical practice HIPAA compliant?

No. Microsoft offers services that can support organizations subject to HIPAA and provides a BAA for applicable services, but the practice remains responsible for how its environment is configured and used. Microsoft 365 is one part of a much larger HIPAA compliance program.


Is Microsoft 365 Business Standard HIPAA compliant?

HIPAA does not designate Business Standard, Business Premium or another Microsoft license as a "HIPAA compliant license." For healthcare clients I manage, I recommend Microsoft 365 Business Premium because it provides additional security and centralized management capabilities that I want available when managing the environment.


Why does SNL-Tech Services recommend Microsoft 365 Business Premium for healthcare clients?

Business Premium gives me access to tools including Microsoft Intune Plan 1, Microsoft Defender for Business, Microsoft Entra ID P1 and Microsoft Defender for Office 365 Plan 1. I can use those capabilities for areas such as device management, endpoint protection and identity security. They still have to be properly configured and managed.


Is having a secure EHR enough?

Not necessarily. The practice's risk analysis needs to consider ePHI wherever the organization creates, receives, maintains or transmits it. If employees download information from the EHR, work with patient information in email or spreadsheets, store files elsewhere or access information from other devices, those parts of the environment may need to be considered too.


Does a small medical practice really need a HIPAA risk analysis?

Yes, if the practice is a covered entity subject to the HIPAA Security Rule. HHS describes risk analysis as foundational to compliance with the Security Rule. The safeguards appropriate for a small practice may look different from those used by a large hospital system, but being small does not eliminate the requirement.


Does my IT provider need a BAA?

It depends on the services the IT provider performs and its relationship to PHI. For healthcare organizations receiving Managed IT services from SNL-Tech Services where the relationship involves HIPAA-covered information, I provide a Business Associate Agreement as part of that relationship.


What if I have no idea whether our IT is configured correctly?

That is exactly the situation where establishing a baseline can help. If your concern is primarily Microsoft 365, my Microsoft 365 Audit focuses on that environment. If you need a broader understanding of your technology, my IT Baseline Assessment looks beyond Microsoft 365 at the systems your business relies on.

You do not have to diagnose the problems yourself before asking for help.


Official Resources

If you want to read the government's guidance directly rather than relying on a blog article, these are good places to start.


This article provides general educational information about HIPAA and technology. It is not legal advice, a HIPAA compliance determination or a substitute for a complete HIPAA risk analysis.

Comments


bottom of page