Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
Practice Operations

Is Microsoft Teams HIPAA Compliant? Yes, on Commercial 365

Teams is in scope under Microsoft's HIPAA BAA, which attaches through the Data Protection Addendum. The work is the admin configuration. Here is what to set.

Patient ProtectPatient Protect Editorial Team·April 15, 2026·10 min read

Written and reviewed by the Patient Protect team — Joseph A. Perrin, CTO (federal infrastructure background, platform security architect), Angie Perrin, CSO (Certified HIPAA Consultant, 10+ years clinical practice), and Alexander Perrin, CEO (20 years enterprise SaaS, primary author of the Secure Care Research Institute research program). See editorial standards.

Share
Microsoft Teams HIPAA compliance settings and configuration guide

Microsoft Teams can be HIPAA compliant — but it is not compliant by default. What separates a covered deployment from a violation is not chasing down a signature. Microsoft has already made the BAA available. What it comes down to is being on a commercial Microsoft 365 subscription rather than a free or personal account, and completing a series of admin configurations that most independent practices never finish.

The free version of Teams does not qualify. Microsoft does not offer a BAA for free-tier accounts. If your practice is using Teams Free or a personal Microsoft account for any communication involving patient information, that is an active HIPAA violation regardless of what is discussed. For the broader category, see our guide to HIPAA-compliant messaging.

Here is exactly what Microsoft provides, what you need to configure, and where Teams fits — and does not fit — in your compliance program.

What Microsoft Provides for HIPAA Compliance

Microsoft's arrangement here is unusual enough that it is worth being precise, because a lot of published guidance — including an earlier version of this page — describes it wrongly.

There is no separate BAA to sign. Microsoft states that its HIPAA Business Associate Agreement "is available through the Microsoft Online Services Data Protection Addendum by default to all customers who are covered entities or business associates under HIPAA." The DPA is already part of your commercial agreement. You do not request the BAA, negotiate it, or execute it in the admin center — it attaches. You can view and download the document from the Service Trust Portal for your files, and for an auditor you should.

The gate is service scope and customer status, not a plan tier. Two conditions decide it: the service has to be on Microsoft's in-scope list, and you have to actually be a covered entity or business associate. Microsoft Teams is named on the in-scope Commercial list, alongside Exchange Online, SharePoint Online, OneDrive for Business, Microsoft Entra ID, Microsoft Purview and Microsoft 365 Copilot.

What is genuinely excluded is the consumer side. Teams Free and personal Microsoft accounts are not commercial subscriptions and sit outside the arrangement entirely.

The BAA is not specific to Teams — it covers the full set of in-scope services, which is why the same agreement carries Outlook, SharePoint and OneDrive with it.

Where your subscription lands

  • Microsoft 365 Business Basic, Standard, and Premium — commercial subscriptions, in scope
  • Microsoft 365 Enterprise E3 and E5 — in scope, with more compliance tooling at E5
  • Office 365 GCC and GCC High — in scope, on the government cloud service description
  • Microsoft Teams Free, personal Microsoft accounts — not commercial subscriptions, out of scope

Business Basic is worth calling out. It is the cheapest commercial tier and it is in scope. The widespread belief that HIPAA coverage starts at Enterprise is not something Microsoft's documentation says.

Built-in security and compliance features

Microsoft 365 includes several features relevant to HIPAA's Security Rule requirements:

  • Encryption: AES-256 at rest, TLS 1.2+ in transit for all Teams communications including chat, calls, and file transfers
  • Compliance Manager: Includes HIPAA assessment templates that map Microsoft 365 controls to specific HIPAA requirements
  • Data Loss Prevention (DLP): Policy engine that can detect and block PHI patterns — Social Security numbers, medical record numbers, ICD codes — in Teams chats, channels, and shared files
  • Audit logging and eDiscovery: Unified audit log captures Teams activity including message edits, deletions, file access, and guest interactions
  • Sensitivity labels: Classify and protect documents and messages containing PHI with automatic or manual labeling
  • Information barriers: Prevent specific groups from communicating within Teams when required by compliance policy
  • Microsoft Purview: Centralized compliance management portal for retention, DLP, audit, and information governance
  • Conditional access: Enforce device compliance, location restrictions, and sign-in risk policies before granting access

The feature set is substantial. The problem is that almost none of it is active by default.

Settings You Must Configure

Because the BAA attaches on its own, all ten steps here are configuration. These are what satisfy HIPAA's administrative, technical and physical safeguard requirements once Teams is in scope.

1. Retrieve your BAA and file it

There is no signature step and no toggle in the admin center. The agreement is already part of your Data Protection Addendum. What you do need is a copy: download the Microsoft HIPAA Business Associate Agreement from the Service Trust Portal and file it with your compliance documentation. When an auditor asks for your BAA with Microsoft, that document is the answer, and finding it during an investigation is worse than finding it now.

2. Enable multi-factor authentication

MFA is required for every user account. Configure this through Azure Active Directory > Security > MFA or via Conditional Access policies. SMS-based MFA is acceptable under HIPAA but authenticator app or FIDO2 key is significantly stronger.

3. Configure Data Loss Prevention policies

In Microsoft Purview > Data Loss Prevention > Policies, create policies targeting Teams chat messages, channel messages, and shared files. Use the built-in sensitive information types for U.S. Social Security numbers, DEA numbers, and health-related identifiers. Set actions to block or notify when PHI patterns are detected.

4. Set up sensitivity labels

In Microsoft Purview > Information Protection, create sensitivity labels for PHI classification. Apply labels to Teams channels, SharePoint sites, and individual documents. Configure encryption and access restrictions for labeled content.

5. Restrict guest access

In Teams Admin Center > Org-wide settings > Guest access, limit what external guests can access. Disable guest access entirely if your practice has no clinical need for external collaboration. If guest access is required, restrict it to specific teams and disable file sharing for guest accounts.

6. Disable unvetted third-party apps

In Teams Admin Center > Teams apps > Permission policies, block all third-party apps by default. Only allow apps from vendors who have signed a BAA with your practice. Every Teams integration that can access chat content, files, or user data is a potential business associate.

7. Configure retention policies

In Microsoft Purview > Data lifecycle management > Retention policies, set retention and deletion schedules for Teams chat messages, channel messages, and files. HIPAA requires you to retain records for six years from the date of creation or the date the policy was last in effect — whichever is later.

8. Enable audit logging

In Microsoft Purview > Audit, verify that unified audit logging is active. It should be enabled by default for E5 plans, but confirm it. Configure audit log retention — the default is 90 days, which is insufficient for HIPAA. E5 plans support one-year retention; configure it.

9. Set conditional access policies

In Azure Active Directory > Security > Conditional Access, create policies that require device compliance (managed devices only), block access from untrusted locations, and enforce session controls. This prevents staff from accessing Teams PHI on personal, unmanaged devices.

What Teams Does Not Do

Microsoft Teams is a communication and collaboration tool. It is not a compliance program. Understanding the boundary matters because conflating the two is one of the most common mistakes independent practices make.

Teams does not:

  • Perform your risk assessment. HIPAA's Security Rule (§164.308(a)(1)) requires a documented, organization-wide risk analysis. Teams does not assess your practice's risks. It is one of many systems included in that assessment.
  • Train your workforce. HIPAA requires documented security awareness training for all workforce members (§164.308(a)(5)). Teams provides no training content and does not track completion.
  • Track BAAs for non-Microsoft vendors. Your EHR, billing platform, answering service, cloud backup, and every other vendor that handles PHI each require separate BAAs. Teams does not manage those relationships.
  • Monitor your overall compliance status. Compliance Manager maps Microsoft 365 controls to HIPAA requirements. It does not evaluate your practice-wide compliance state, your physical safeguards, or your administrative policies outside of Microsoft's ecosystem.
  • Make free-tier accounts compliant. There is no configuration, policy, or workaround that makes Teams Free HIPAA eligible. The BAA is the threshold, and it is not available on free plans.

Common Mistakes Practices Make With Teams

These are the failures we see repeatedly in practices that believe they are covered because they use Microsoft 365.

Using free Teams or personal Microsoft accounts for practice communication. This is the most common and most consequential mistake. If any staff member discusses patient information on a non-BAA-covered account, the practice has an active violation — regardless of whether the paid subscription also exists.

Signing the BAA but skipping configuration. The BAA establishes Microsoft as your business associate. It does not configure your environment. Without DLP policies, retention schedules, audit logging, and access controls, the BAA is a legal agreement over an unsecured system.

Allowing unmanaged personal devices. Staff accessing Teams on personal phones or home computers without conditional access policies means PHI is stored on devices your practice does not control, cannot encrypt, and cannot remotely wipe.

Not restricting guest access or external sharing. Default Teams settings allow external users to join meetings, access shared files, and participate in channels. In a clinical context, this creates uncontrolled PHI exposure paths.

Using third-party Teams integrations without verifying HIPAA status. Every app installed in Teams that can access message content or files is a potential business associate. If that vendor has not signed a BAA with your practice, the integration is a compliance gap. See the broader inventory of HIPAA-compliant tools a practice typically needs to track.

Staff sharing PHI in general channels instead of private channels. General channels are visible to every team member by default. PHI discussions should occur only in private channels with membership restricted to authorized personnel.

Where Teams Fits in Your Compliance Program

Microsoft Teams is your communication and collaboration layer. It handles chat, video calls, file sharing, and team coordination. With the right plan and configuration, it handles those functions in a HIPAA-compliant manner.

It is not your compliance program. A compliant Teams deployment still leaves you without:

  • A documented, current risk assessment
  • Written HIPAA policies and procedures
  • Workforce training with completion tracking
  • Vendor management and BAA tracking across all business associates
  • Incident response and breach notification procedures
  • Physical safeguard documentation
  • Ongoing compliance monitoring and evidence collection

These are separate obligations under the HIPAA Security, Privacy, and Breach Notification Rules. Teams satisfies none of them.

Patient Protect covers the full compliance surface — risk assessment, policy generation, workforce training, BAA management, breach intelligence monitoring, and ongoing compliance state tracking — starting at $39/month. Your Microsoft 365 environment is one of the vendors we help you manage. It is not a replacement for the program itself. For a head-to-head against documentation-first vendors, see our comparison of HIPAA compliance platforms.

Frequently Asked Questions

Is Microsoft Teams Free HIPAA compliant?

No. Microsoft does not offer a Business Associate Agreement for the free tier of Teams. Without a BAA, Teams Free cannot be used for any communication involving protected health information, regardless of what settings you configure.

Does Microsoft sign a BAA for Teams?

Yes, and you do not have to go and get it. Microsoft makes the HIPAA BAA available through the Online Services Data Protection Addendum by default to every customer that is a covered entity or business associate, and Teams is on the in-scope Commercial services list. There is no request flow and no signature step in the admin center. Download the agreement from the Service Trust Portal so you have it on file, then spend your time on the configuration work — that is the part that is actually yours.

Can I use Teams for telehealth appointments?

Yes, provided you are on a commercial Microsoft 365 subscription — which brings the BAA with it — and have applied the admin configurations described above. Teams supports HIPAA-compliant video calls, including screen sharing and file transfer during sessions. For practices that need a dedicated telehealth workflow, Microsoft also offers the Teams EHR Connector for integration with Epic and Cerner.

Which Microsoft 365 plan is HIPAA compliant?

Microsoft 365 Business Basic, Business Standard, Business Premium, Enterprise E3, and Enterprise E5 all qualify for a BAA. The E5 plan includes the most advanced compliance features — extended audit log retention, advanced DLP, and auto-classification with sensitivity labels. For most independent practices, Business Premium or E3 provides sufficient coverage.

Is Teams chat encrypted?

Yes. Teams encrypts chat messages, calls, and file transfers using TLS 1.2+ in transit and AES-256 at rest. End-to-end encryption (E2EE) is available for one-on-one calls but is not enabled by default and currently does not support group calls, recording, or transcription. Standard Microsoft-managed encryption satisfies HIPAA's transmission security requirement (§164.312(e)(1)).

Was this useful? Share it.

Share

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →

Next step

What would an OCR investigator find on your website?

Free 30-second scan — tracking pixels, security gaps, missing policies. See what’s visible before they do.

Stay informed

Subscribe to HIPAA Pulse.

Breach alerts, enforcement updates, and compliance intelligence — every two weeks.

© 2026 Patient Protect LLC. All rights reserved. Content may not be reproduced, scraped, or used to train AI models without written permission. Terms · DMCA