BAA Generator
HomeResourcesDoes Microsoft 365 Sign a HIPAA BAA?
Vendor BAA Guide

Does Microsoft 365 Sign a HIPAA Business Associate Agreement?

By BAA Generator Research Team  ·  Published Apr 19, 2026  ·  Last reviewed Apr 19, 2026  ·  3 min read

Need a BAA right now?

Generate my BAA → See pricing →

Key Takeaways

Direct answer: Yes — Microsoft includes HIPAA Business Associate Agreement obligations in its Online Services Terms (OST) for Microsoft 365 commercial plans. No separate contract is required. The BAA covers core services including Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams on Business and Enterprise plans.

Microsoft 365 is one of the most widely used productivity suites in healthcare — from physician practices using Outlook for scheduling to health systems storing documents in SharePoint. If PHI flows through any Microsoft service, a HIPAA BAA with Microsoft is legally required. Fortunately, Microsoft has streamlined this process considerably.

How Microsoft's BAA Works

Unlike many vendors that require a manual contract request, Microsoft incorporates its HIPAA BAA into the Microsoft Online Services Terms (OST). When your organization subscribes to a qualifying Microsoft 365 commercial plan, the BAA obligations are automatically included — you don't need to separately request or sign a BAA document.

For organizations with an Enterprise Agreement (EA), your Microsoft account representative can also provide a separate signed BAA document if your compliance or legal team requires it.

Which Plans Are Covered?

Microsoft's HIPAA BAA applies to commercial Microsoft 365 plans including:

Not covered: Free Microsoft accounts, consumer Outlook.com, personal OneDrive, Xbox accounts, and Microsoft's consumer products. Personal Microsoft accounts cannot be used for PHI regardless of plan.

Which Services Are Covered Under Microsoft's HIPAA BAA?

ServiceHIPAA BAA Coverage
Exchange Online (Outlook email)✓ Covered
SharePoint Online✓ Covered
OneDrive for Business✓ Covered
Microsoft Teams✓ Covered (including calls and chats)
Microsoft Intune (device management)✓ Covered
Azure Active Directory✓ Covered
Microsoft Purview (compliance tools)✓ Covered
Microsoft Forms✓ Covered
Outlook.com (consumer)✗ Not covered
OneDrive personal (consumer)✗ Not covered
LinkedIn, Bing, Xbox✗ Not covered
Power Apps / Power AutomateRequires separate Azure BAA

What to Check in the Microsoft Trust Center

Microsoft's Trust Center (microsoft.com/en-us/trust-center) provides its current HIPAA compliance documentation including:

Review the in-scope services list annually — Microsoft occasionally adds or removes services from HIPAA coverage.

What Else You Need After the Microsoft BAA

The Microsoft BAA covers Microsoft's obligations. Your organization's compliance obligations don't end there:

More vendor BAA guides

Generate a compliant BAA in 5 minutes

HHS model BAA provisions · 45 CFR § 164.504(e) compliant · clean PDF + editable Word

No subscription · PDF + Word · Free watermarked preview

Related: Cloud platforms

Frequently Asked Questions

Does Microsoft 365 sign a HIPAA BAA?
Yes. Microsoft includes a HIPAA Business Associate Agreement as part of the Microsoft Online Services Terms (OST) for commercial Microsoft 365 plans. Unlike many vendors, Microsoft does not require a separate contract — the BAA obligations are incorporated into the standard terms for Microsoft 365 Business, Enterprise, and Government plans.
Which Microsoft 365 services are covered under the HIPAA BAA?
Microsoft's BAA covers core Microsoft 365 services including Exchange Online (Outlook email), SharePoint Online, OneDrive for Business, Microsoft Teams, Microsoft Intune, Azure Active Directory, and Microsoft Purview (compliance tools). Consumer Microsoft products (Outlook.com, OneDrive personal, Xbox) are not covered.
How do I get a HIPAA BAA from Microsoft?
Microsoft's BAA is incorporated into the Online Services Terms (OST) automatically for eligible commercial plans — you do not need to request a separate document. To confirm BAA coverage, review the Microsoft OST and the HIPAA implementation guide in the Microsoft Trust Center. For Enterprise Agreements, you may also request a dedicated BAA through your Microsoft account representative.