Limited-time offer: LAUNCH50 gives 50% off forever. Auto-applied at checkout.See pricing

Outlook / Microsoft 365

Is Outlook HIPAA Compliant for Medical Clinics?

What small clinics need to know about Outlook's HIPAA BAA availability under Microsoft 365, required admin configuration, and the risks that persist even after signing.

Short answer

Outlook is covered under Microsoft's HIPAA BAA when the clinic uses a qualifying Microsoft 365 plan and has executed the agreement through Microsoft's online services terms. Microsoft includes a BAA as part of its Online Services Terms at no additional cost for covered plans, but the clinic must apply specific admin controls in the Microsoft 365 Admin Center and understand which services are in and out of scope.

Short answer

Outlook, operating through Microsoft Exchange Online as part of a qualifying Microsoft 365 plan, is covered under Microsoft’s HIPAA BAA terms. The BAA is accepted through Microsoft’s Online Services Terms rather than a separate agreement. Consumer Outlook.com and Hotmail accounts have no coverage and must never carry PHI. Even with enterprise coverage, the clinic must configure admin controls and treat email as a risk channel.

BAA availability

Microsoft handles its HIPAA BAA through the Online Services Data Protection Addendum (DPA), which is incorporated into the Microsoft Customer Agreement when a qualifying Microsoft 365 subscription is purchased. The clinic does not need to negotiate a custom BAA — it is accepted through the standard terms process. Qualifying plans include Microsoft 365 Business Basic, Business Standard, Business Premium, and Enterprise (E1, E3, E5) subscriptions. Consumer Microsoft accounts (Outlook.com, Hotmail, live.com) are never covered.

  • The clinic’s admin should review the DPA and the covered services list to confirm which Microsoft 365 products are in scope.
  • Not every Microsoft product is covered. The DPA specifies which “Online Services” fall under BAA terms.
  • The admin must be aware of which Microsoft 365 features are in use and confirm each against the covered services list.

Exchange Online (the back-end service for Outlook) is covered under Microsoft’s standard enterprise terms for qualifying plans. The Microsoft Purview compliance features — including audit log retention, data loss prevention, and message encryption — must be configured by the admin; they are not active by default.

Required admin configuration

Microsoft’s HIPAA compliance documentation identifies several steps the admin must take:

  • Enable audit logging. In the Microsoft 365 Compliance Center, enable unified audit logging. This captures user and admin activity and is required for HIPAA access log obligations.
  • Configure message encryption. Microsoft Purview Message Encryption (OME) allows the clinic to require encryption on emails that may contain PHI. This is not on by default.
  • Enable data loss prevention (DLP) policies. DLP policies in Microsoft Purview can detect PHI patterns in email and apply protective actions (block, warn, encrypt) before messages leave the organization.
  • Set retention policies. Define how long email is retained and when it is destroyed, consistent with the clinic’s HIPAA retention policy.
  • Enforce multi-factor authentication. All accounts with access to PHI-containing mailboxes must require MFA.

What is not covered by Microsoft’s BAA

Microsoft’s BAA does not cover:

  • Consumer Microsoft accounts (Outlook.com, Hotmail, live.com)
  • Microsoft Teams personal accounts
  • Third-party Outlook add-ins that access mailbox data unless those vendors have their own BAAs with the clinic
  • Microsoft Copilot for Microsoft 365 (AI features) — check current DPA coverage status before enabling

What to keep out of Outlook even with a BAA

A signed BAA does not eliminate the inherent risks of email as a PHI channel:

  • Do not include PHI in email subject lines; subjects may appear in notification previews and are often less protected than message body
  • Do not send unencrypted attachments containing patient records to recipients outside the organization
  • Do not use shared or alias mailboxes for PHI-adjacent work without audit logging configured
  • Do not use personal @outlook.com or @hotmail.com accounts for any patient-related communication

When Outlook is not enough

PHIGuard commercial baseline

PHIGuard uses flat per-clinic pricing rather than per-user fees. A Business Associate Agreement is included on every public plan. The primary trial path is a 30-day free trial with no credit card required. See current PHIGuard pricing for plan names, monthly list prices, annual totals, and current launch details.

FAQ

Questions clinics ask before using this software with PHI

Do I need to sign a separate BAA with Microsoft for Outlook?

Microsoft incorporates BAA language into its Online Services Terms (now the Data Protection Addendum). When a clinic signs up for a qualifying Microsoft 365 plan, they accept these terms. Review the current DPA at aka.ms/DPA to confirm the covered services list.

Does Microsoft 365 Business Basic qualify for HIPAA BAA coverage?

Microsoft's BAA coverage applies to covered services across Microsoft 365 plans. Verify the current covered services list in Microsoft's documentation, as coverage varies by product and plan. Not all Microsoft 365 applications are covered under the same terms.

Can staff use their personal Outlook.com accounts for patient-related email?

No. Consumer Outlook.com and Hotmail accounts are not covered by Microsoft's enterprise BAA. Any PHI sent from or to a personal Microsoft consumer account has no contractual protection.

Does Microsoft Purview help with HIPAA compliance in Outlook?

Microsoft Purview (formerly Compliance Center) includes tools for audit logging, data loss prevention, and message encryption that support HIPAA compliance. These must be configured by the admin — they are not active by default.

Operational assurance

Turn vendor research into a system your clinic can actually run.

PHIGuard gives small clinics a BAA-ready operating layer, recurring compliance work, and a safer home for patient-adjacent tasks.

BAA included Legal baseline available on every plan.
Audit history Compliance actions stay reviewable later.
No card upfront Start evaluation before billing setup.

No credit card required. Add billing details later if you want service to continue after the trial.