Solutions / HIPAA compliance
HIPAA compliance built on the Microsoft 365 you already pay for.
A HIPAA-covered entity running Microsoft 365 E3 or E5 already holds most of the technical controls the Security Rule asks for. Identra configures Entra ID Protection, Conditional Access, Purview DLP with the medical-records sensitive-info types, Defender for Endpoint on managed devices, and audit logging with 6-year retention, then delivers the evidence pack an OCR audit or a Business Associate assessment can accept.
- Regulation
- HIPAA 45 CFR §164.308 §164.312 §164.316
- Enforcement body
- HHS Office for Civil Rights (OCR)
- License footprint
- M365 E3 or E5 (Entra P2 for full)
- Delivery
- Fixed scope, fixed price
01 / What we configure
Four safeguard groups, mapped 1-to-1 to Microsoft 365 controls.
- 01
Access Management §164.308(a)(4)
Conditional Access enforces role-based access to ePHI systems by user, device compliance, and location. Access reviews on every group that reaches a PHI-holding SharePoint site, mailbox, or database. Emergency access accounts documented and audited.
Conditional AccessAccess reviewsBreak-glass - 02
Audit Controls §164.312(b)
Purview audit log retention set to 6 years (HIPAA record retention) tenant-wide. Alerts on privileged role changes, mass PHI download, unusual sign-in patterns, and Insider Risk indicators pointing at PHI content.
Purview Audit6-year retentionInsider Risk - 03
Transmission Security §164.312(e)(1)
Purview DLP rules with the HIPAA / HITECH sensitive-info type templates catch ePHI in Exchange, SharePoint, OneDrive, and Teams. Sensitivity labels enforce encryption on PHI-marked content. Mail-tip warnings on external recipients when PHI-classified content is in the message body.
Purview DLPHIPAA sensitive-info typesSensitivity labels - 04
Person or Entity Authentication §164.312(d)
Phishing-resistant MFA (Windows Hello for Business, FIDO2, passkeys) enforced on every account that reaches an ePHI system. Legacy authentication disabled tenant-wide. Sign-in risk policy adds step-up authentication for anomalous sign-ins.
FIDO2Windows HelloSign-in risk
02 / What it looks like
Three engagements, same HIPAA safeguards.
Different covered entity types, different starting states, same shape of work: the licensed controls exist, they are just not enforced.
CISO at a 400-provider medical group
Situation. Migrated to Microsoft 365 E5 two years ago as part of an EHR modernisation. Conditional Access sits in report-only. Audit log retention still at the M365 default. Recent OCR investigation flagged missing access-review evidence.
Outcome. CA policies moved to enforcement in three graduated waves. Audit retention set to 6 years. Access reviews scheduled quarterly on every group with a link to a PHI SharePoint site. Evidence pack delivered as a bound quarterly report the compliance officer signs.
IT Director at a HIPAA-covered health plan
Situation. Business Associate onboarding takes weeks because the BA cannot see how Microsoft 365 covers the HIPAA technical safeguards. Compliance team ends up hand-drafting a control matrix for every new BA.
Outcome. Pre-built Identra HIPAA control matrix maps each 45 CFR §164 subsection to the specific tenant setting that satisfies it. New BA onboarding drops from weeks to hours because the matrix is annually re-verified and dated.
Security Officer at a specialty hospital
Situation. Clinical staff work from personal iPads outside the clinical setting. No device compliance policy. A stolen device would reach every PHI mailbox in the tenant.
Outcome. Intune enrolment mandatory for iPad access to Exchange and Teams. Conditional Access blocks the mailbox from unmanaged iOS. App protection policy prevents PHI copy-out to third-party apps. Break-glass account isolated with alerting on any use.
03 / Frequently asked
What buyers ask first.
- Is Microsoft 365 HIPAA-compliant out of the box?
- The platform is HIPAA-eligible under a signed Business Associate Agreement with Microsoft, which is included with commercial licences. Eligibility is not compliance. The covered entity is still responsible for configuring the tenant so the technical, administrative, and physical safeguards are actually enforced. Identra does the configuration work.
- Do we need Microsoft 365 E5?
- Full HIPAA coverage benefits from E5 because Entra ID Protection (sign-in risk), Purview Audit Premium (long retention), Defender for Endpoint P2, and Purview Insider Risk are E5 features. E3 tenants can still reach a defensible HIPAA posture using Entra ID P1, Purview Audit Standard, and Defender for Endpoint P1, with more manual steps in access review and audit.
- What does an OCR audit ask for on Microsoft 365?
- OCR investigations typically ask for evidence of the risk assessment (§164.308(a)(1)(ii)(A)), access-authorisation records (§164.308(a)(4)), audit logs covering the incident window, workforce training records, and the BAA with Microsoft. The tenant configuration is not the audit deliverable; the evidence pack derived from the tenant configuration is.
- How long does a HIPAA engagement take?
- Typical engagement runs 8 to 12 weeks. Weeks 1 to 2 assess the current tenant against the Security Rule. Weeks 3 to 8 configure and stage-enforce the controls. Weeks 9 to 12 build the evidence pack and hand over runbooks to the internal IT and compliance teams.
- Do you cover Business Associate risk as well as covered entity risk?
- Yes. Many Identra customers are Business Associates rather than covered entities themselves. The safeguard map is the same, and the BAA obligations that flow down from the covered entity typically map to the same tenant configuration. The difference is documentation: the BA usually has to demonstrate to multiple covered entities, so the evidence pack is templated for reuse.
04 / Related
Where this fits.
Identity
Microsoft Entra consulting
Conditional Access, PIM, ID Protection turned on to enforcement, with a documented handover.
Data governance
Purview compliance
Sensitivity labels and DLP moved from test into enforcement, audit-ready.
Threat detection
Defender XDR deployment
Endpoint, identity, email and cloud alerts correlated into single incidents.