Industries / Healthcare
Microsoft security for healthcare that a HIPAA auditor accepts.
Hospitals, medical groups, and health plans running Microsoft 365 face the same three questions from every HIPAA audit: who reaches ePHI, is transmission encrypted, and can you produce the audit trail. Identra configures the tenant so the answer to each question is a screenshot from the admin center and a Sentinel query, not an incident-response scramble the week before the OCR visit.
- Regulation
- HIPAA Security Rule + HITECH
- Vertical scope
- Hospitals, medical groups, health plans, digital health
- License footprint
- M365 E3 or E5 (E5 for full Insider Risk)
- Delivery
- Fixed scope, fixed price
01 / What we configure
Four healthcare-specific configuration patterns.
- 01
Clinical device access
Shared iPads and workstations on ward rounds treated as a distinct device class in Intune with rapid session timeout, no local ePHI storage, and app protection preventing PHI copy-out. Ambient device (kiosk) mode locks the workstation to the EHR client and blocks browser sideloading.
IntuneShared devicesApp protection - 02
EHR vendor and Business Associate access
EHR support technicians and imaging vendors reach the tenant via guest access with time-boxed Conditional Access, MFA, and session recording via Global Secure Access. BA activity logs exported to Sentinel with alerts on out-of-hours or unusual data access.
Guest accessGSABA logging - 03
PHI Data Loss Prevention
Purview DLP with the HIPAA / HITECH sensitive-info types on Exchange, SharePoint, OneDrive, and Teams. Sensitivity labels enforce encryption on PHI-marked content. Mail-tip warnings flag external recipients on messages containing PHI classification.
Purview DLPHIPAA templatesEncryption - 04
6-year audit retention
Purview audit retention set to 6 years to match HIPAA record retention. Sentinel workbook produces the audit review pack the Privacy Officer signs monthly. Break-glass account alerting on any use.
Purview Audit6-year retentionBreak-glass
02 / What it looks like
Three healthcare engagements.
Different healthcare organisations, same HIPAA and clinical-workflow constraints.
CISO at a 400-provider medical group
Situation. Providers work across five clinical sites plus a growing telehealth practice. Personal-device use is high because the group cannot issue a laptop to every part-time provider.
Outcome. App protection policy on Outlook, Teams, and the EHR mobile app lets personal devices reach ePHI without enrolling in Intune. Sign-in risk policy blocks unusual sign-ins. Six-year audit retention configured for the next HIPAA cycle.
IT Director at a specialty hospital
Situation. Radiology workstations in the reading room are shared across three shifts. Historical incidents traced to workstations left signed in between shifts.
Outcome. Windows shared-device mode enforced on reading-room workstations. Idle sign-out after 5 minutes. EHR client re-authenticates on wake. Post-implementation audit found zero cross-shift session events over 90 days.
Security Officer at a Business Associate handling claims
Situation. BA processes claims for multiple covered entities. Each CE requires HIPAA control evidence in a slightly different format. Compliance team spends two weeks per year hand-drafting per-CE control matrices.
Outcome. Templated HIPAA evidence pack in Identra format satisfies all covered entities without per-CE re-work. New CE onboarding drops from weeks to two days. BAA renewal cycle runs smoothly.
03 / Frequently asked
What buyers ask first.
- Is Microsoft 365 acceptable for ePHI?
- Yes, under a signed Business Associate Agreement with Microsoft, which is included with commercial licences. Acceptability is not compliance; the covered entity or BA still has to configure the tenant so the HIPAA Security Rule technical safeguards are enforced. Identra does the configuration.
- Do we need Microsoft 365 E5 for HIPAA?
- E5 makes the work faster because Entra ID Protection, Purview Audit Premium, Defender for Endpoint P2, and Insider Risk are E5 features. E3 tenants can still reach a defensible HIPAA posture using P1 equivalents, with more manual steps in the access-review and audit-retention workstreams.
- What about state-level regulations like Texas HB 300 or California CMIA?
- State privacy laws typically layer on top of HIPAA. Texas HB 300 adds broader definitions of Covered Entity, training requirements every two years, and mandatory breach notification to state authorities. California CMIA adds strict provider disclosure controls. The Microsoft 365 tenant controls that satisfy HIPAA also satisfy these state add-ons; the difference is in policy documentation and training records, both of which sit inside the Purview and Entra evidence pack.
- How do you handle telehealth?
- Telehealth introduces personal device access and mobile app usage patterns that the traditional HIPAA workstream did not cover. Identra uses Intune app protection policies (rather than device enrolment) to let personal devices reach ePHI in Outlook and Teams while preventing copy-out to third-party apps. The tenant policy is documented so the Privacy Officer can point to the specific control satisfying the safeguard on personal devices.
- How long does a healthcare engagement take?
- Typical hospital engagement runs 10 to 14 weeks. Medical group or BA engagements run 8 to 12 weeks. Weeks 1 to 2 assess the tenant. Weeks 3 to 8 configure clinical-device access, PHI DLP, and audit retention. Weeks 9 to 14 build the evidence pack and train the Privacy Officer.
04 / Related