Identra

Solutions / HIPAA compliance

HIPAA compliance built on the Microsoft 365 you already pay for.

A HIPAA-covered entity running Microsoft 365 E3 or E5 already holds most of the technical controls the Security Rule asks for. Identra configures Entra ID Protection, Conditional Access, Purview DLP with the medical-records sensitive-info types, Defender for Endpoint on managed devices, and audit logging with 6-year retention, then delivers the evidence pack an OCR audit or a Business Associate assessment can accept.

Regulation
HIPAA 45 CFR §164.308 §164.312 §164.316
Enforcement body
HHS Office for Civil Rights (OCR)
License footprint
M365 E3 or E5 (Entra P2 for full)
Delivery
Fixed scope, fixed price

01 / What we configure

Four safeguard groups, mapped 1-to-1 to Microsoft 365 controls.

  • 01

    Access Management §164.308(a)(4)

    Conditional Access enforces role-based access to ePHI systems by user, device compliance, and location. Access reviews on every group that reaches a PHI-holding SharePoint site, mailbox, or database. Emergency access accounts documented and audited.

    Conditional AccessAccess reviewsBreak-glass
  • 02

    Audit Controls §164.312(b)

    Purview audit log retention set to 6 years (HIPAA record retention) tenant-wide. Alerts on privileged role changes, mass PHI download, unusual sign-in patterns, and Insider Risk indicators pointing at PHI content.

    Purview Audit6-year retentionInsider Risk
  • 03

    Transmission Security §164.312(e)(1)

    Purview DLP rules with the HIPAA / HITECH sensitive-info type templates catch ePHI in Exchange, SharePoint, OneDrive, and Teams. Sensitivity labels enforce encryption on PHI-marked content. Mail-tip warnings on external recipients when PHI-classified content is in the message body.

    Purview DLPHIPAA sensitive-info typesSensitivity labels
  • 04

    Person or Entity Authentication §164.312(d)

    Phishing-resistant MFA (Windows Hello for Business, FIDO2, passkeys) enforced on every account that reaches an ePHI system. Legacy authentication disabled tenant-wide. Sign-in risk policy adds step-up authentication for anomalous sign-ins.

    FIDO2Windows HelloSign-in risk

02 / What it looks like

Three engagements, same HIPAA safeguards.

Different covered entity types, different starting states, same shape of work: the licensed controls exist, they are just not enforced.

CISO at a 400-provider medical group

Situation. Migrated to Microsoft 365 E5 two years ago as part of an EHR modernisation. Conditional Access sits in report-only. Audit log retention still at the M365 default. Recent OCR investigation flagged missing access-review evidence.

Outcome. CA policies moved to enforcement in three graduated waves. Audit retention set to 6 years. Access reviews scheduled quarterly on every group with a link to a PHI SharePoint site. Evidence pack delivered as a bound quarterly report the compliance officer signs.

IT Director at a HIPAA-covered health plan

Situation. Business Associate onboarding takes weeks because the BA cannot see how Microsoft 365 covers the HIPAA technical safeguards. Compliance team ends up hand-drafting a control matrix for every new BA.

Outcome. Pre-built Identra HIPAA control matrix maps each 45 CFR §164 subsection to the specific tenant setting that satisfies it. New BA onboarding drops from weeks to hours because the matrix is annually re-verified and dated.

Security Officer at a specialty hospital

Situation. Clinical staff work from personal iPads outside the clinical setting. No device compliance policy. A stolen device would reach every PHI mailbox in the tenant.

Outcome. Intune enrolment mandatory for iPad access to Exchange and Teams. Conditional Access blocks the mailbox from unmanaged iOS. App protection policy prevents PHI copy-out to third-party apps. Break-glass account isolated with alerting on any use.

03 / Frequently asked

What buyers ask first.

Is Microsoft 365 HIPAA-compliant out of the box?
The platform is HIPAA-eligible under a signed Business Associate Agreement with Microsoft, which is included with commercial licences. Eligibility is not compliance. The covered entity is still responsible for configuring the tenant so the technical, administrative, and physical safeguards are actually enforced. Identra does the configuration work.
Do we need Microsoft 365 E5?
Full HIPAA coverage benefits from E5 because Entra ID Protection (sign-in risk), Purview Audit Premium (long retention), Defender for Endpoint P2, and Purview Insider Risk are E5 features. E3 tenants can still reach a defensible HIPAA posture using Entra ID P1, Purview Audit Standard, and Defender for Endpoint P1, with more manual steps in access review and audit.
What does an OCR audit ask for on Microsoft 365?
OCR investigations typically ask for evidence of the risk assessment (§164.308(a)(1)(ii)(A)), access-authorisation records (§164.308(a)(4)), audit logs covering the incident window, workforce training records, and the BAA with Microsoft. The tenant configuration is not the audit deliverable; the evidence pack derived from the tenant configuration is.
How long does a HIPAA engagement take?
Typical engagement runs 8 to 12 weeks. Weeks 1 to 2 assess the current tenant against the Security Rule. Weeks 3 to 8 configure and stage-enforce the controls. Weeks 9 to 12 build the evidence pack and hand over runbooks to the internal IT and compliance teams.
Do you cover Business Associate risk as well as covered entity risk?
Yes. Many Identra customers are Business Associates rather than covered entities themselves. The safeguard map is the same, and the BAA obligations that flow down from the covered entity typically map to the same tenant configuration. The difference is documentation: the BA usually has to demonstrate to multiple covered entities, so the evidence pack is templated for reuse.

Next step

Book a HIPAA scoping call.

Thirty minutes on your current Conditional Access, audit retention, and DLP posture against the HIPAA Security Rule. Written scoping note within two business days.