Is Microsoft Teams HIPAA Compliant? A Complete 2026 Guide for Healthcare Organizations

One wrong file share can turn a routine workday into a reportable HIPAA breach. That is the real weight behind a simple question: is Microsoft Teams HIPAA compliant? Healthcare providers ask it every day, and the answer is not as clear as a yes or no.

Teams was built for general business, not for protecting patient data. It can handle protected health information safely, but only after you set it up the right way. Miss a step, and you expose the very information you are trying to save.

This guide, backed by ComplyAssistant’s 25+ years of experience helping providers meet HIPAA, walks you through it in plain terms. You will get a direct answer first, then clear steps on plans, Business Associate Agreements, settings, telehealth, and the new AI features in Teams, so you can protect your patients and your practice with confidence.

Ready to Simplify HIPAA Compliance?

Our intuitive HIPAA compliance software helps you stay secure, meet all regulations, and streamline your processes. Get started today and stay compliant with ease!

Is Microsoft Teams HIPAA Compliant? The Short Answer

Yes, but only when you set it up the right way. It can be used in a HIPAA-compliant way once you do four things: 


Here is the part people miss. Teams is not HIPAA compliant on its own, straight out of the box. Compliance comes from the plan you pick, the settings you turn on, and the habits your team builds. Microsoft gives you the tools. The rest is your job.

Why Microsoft Teams Isn’t HIPAA Compliant by Default

Out of the box, Teams treats a medical clinic the same as a marketing agency. Same features, same default settings, none of them built around patient data. That works fine until someone drops a lab result into a chat. From that moment, the gap between a normal business tool and a HIPAA-ready one is yours to close.

What Counts as ePHI Inside Microsoft Teams

Electronic protected health information, or ePHI, is any patient health data in digital form that can identify a person. Protecting it is what HIPAA is all about, and inside Teams, ePHI can show up in more places than you might expect.

  • Chat and channel messages where staff discuss a patient by name or case
  • Files shared in a chat, channel, or meeting, such as lab results, images, or intake forms
  • Meeting content and recordings from telehealth visits or care coordination calls
  • Voicemail, transcripts, and call logs tied to a specific patient


Once you know a patient can be identified through any of these, you have to treat that content as ePHI and protect it. If a use of Microsoft Teams never touches patient data, the rules below do not apply to that use.

When Microsoft Teams Doesn’t Need to Be HIPAA Compliant

HIPAA only applies when you handle patient information. Plenty of healthcare work never touches a single patient detail, and for that work, Microsoft Teams does not need special HIPAA setup. These cases include:

  • Staff scheduling and shift planning
  • New employee onboarding and training
  • Internal announcements and team check-ins
  • Wellness chats with frontline staff


Picture your front desk team using a Teams channel to sort out next month’s schedule. No patient data changes hands, so HIPAA does not apply. But the second someone posts a patient’s lab result in that same channel, everything changes, and your setup needs to be ready for it.

The Shared Responsibility Model: What Microsoft Secures vs. What You’re Accountable For

HIPAA compliance with any cloud tool is a shared job. Microsoft handles one part. You handle the other. Confusing the two is one of the most common reasons practices get caught out.

Microsoft secures the platform itself. It encrypts data, runs secure data centers, and signs a Business Associate Agreement that commits it to protect the patient data you store in covered services. What Microsoft does not do is decide who on your team sees what, whether you turn on multi-factor sign-in, or whether your staff know the rules. Those choices belong to you. As the covered entity, you stay accountable for how the tool is set up and used every day.

How to Make Microsoft Teams HIPAA Compliant, Step by Step

Here is where the real work happens. These five steps cover the plan, the agreement, the settings, the integrations, and the people who use it all. Do them in order. Skip one, and you leave a gap a data breach can walk right through.

Step

What to do

Why it matters

1

Choose a qualifying Microsoft 365 or Office 365 plan

Free and personal accounts can’t be covered by a BAA

2

Accept Microsoft’s Business Associate Agreement (BAA)

HIPAA requires a BAA before Teams handles patient data

3

Configure Teams security settings

Turns a plain account into one ready for patient data

4

Vet third-party apps and EHR integrations

Every connected app can open a new path for data to leak

5

Train your workforce on compliant use

Most breaches come from human error, not the software

Step 1: Choose a Qualifying Microsoft 365 or Office 365 Plan

Not every Microsoft plan supports HIPAA-grade security. Free and personal Teams accounts do not, and Microsoft will not sign an agreement to cover them. To handle patient data, you need a business or enterprise plan that includes the right security and compliance features.

Plans that commonly support HIPAA use include:

  • Microsoft 365 Business Standard or Business Premium
  • Office 365 E3 or E5
  • Microsoft 365 E3, E5, F3, or F5
  • Microsoft Cloud for Healthcare, the most complete option for care settings


Each plan carries a different mix of controls. Some lower-cost and frontline plans lack full identity and access management, so check that your plan includes the security tools you need before you commit. Also remember that every user who touches patient data needs a licensed account under the plan, which affects your cost.

Step 2: Accept and Understand Microsoft’s Business Associate Agreement

A Business Associate Agreement, or BAA, is a contract that makes a vendor legally responsible for protecting the patient data it handles for you. HIPAA requires one with any third party that processes ePHI, and Microsoft counts as that third party when you use Teams for patient data.

Microsoft provides its BAA through the Microsoft Product Terms and the Data Protection Addendum. For customers on a qualifying plan, this agreement applies automatically once you use an in-scope service to handle patient data, so you do not sign a separate paper document. 

One thing to plan for: Microsoft offers one standard BAA and will not change it to fit a single customer. Because it serves millions of organizations, it cannot rewrite terms for each one. So your choice is to accept Microsoft’s terms as written or pick a different platform. Read the terms with your compliance lead before you rely on Teams for care.

Step 3: Configure Teams Security Settings

This is the step that turns a plain business account into one ready for patient data. Your IT admin should switch on and double-check the controls below. Each one backs up a specific HIPAA safeguard.

  • Encryption in transit and at rest. Teams encrypts data by default but confirms it stays on for all messages, files, and recordings.
  • Multi-factor authentication (MFA). Require a second sign-in step for everyone who touches patient data, so a stolen password alone cannot open the door.
  • Least-privilege access. Give each person access only to the teams, channels, and files their role needs, and nothing more.
  • Audit logging. Turn on audit log search in Microsoft Purview so you can track who viewed or shared patient data and spot unusual activity.
  • Data Loss Prevention (DLP) policies. Set rules that detect and block patient data from being shared with the wrong people.
  • Retention policies. Decide how long chats, files, and recordings are kept, and set Teams to store or remove them in line with your rules.
  • Conditional access. Allow only managed, trusted devices to reach patient data in Teams.
  • Guest and external access limits. Restrict who outside your organization can join your teams, channels, or meetings, and control what they can do.
  • Recording controls. Only record calls when needed, and store recordings securely, since Teams’ built-in recording alone may not meet your storage rules.


A tip from our compliance team: write down each setting you turn on and why. That record becomes your proof during an audit and saves hours of scrambling later.

Step 4: Vet Third-Party Apps and EHR Integrations

Teams connects to hundreds of outside apps, and that is a big reason people like it. But every app you add can open a new path for patient data to leak if that app does not protect it. So each one needs its own review before you switch it on.

Check whether an app handles patient data, whether its maker will sign a BAA, and whether it meets the same security bar as Microsoft Teams itself. This matters most for anything that connects to your electronic health record (EHR). Treat every connected app as part of your compliance picture, not an afterthought. 

Step 5: Train Your Workforce on Compliant Use

The strongest settings in the world cannot stop a well-meaning staff member from making a mistake. Most breaches come down to human error, not broken software. Training is what closes that gap.

Teach your team which channels are safe for patient data and which are not, how to spot a guest account, when recording is allowed, and how to share files the right way. Run refreshers, not just a one-time session, and keep a record of who completed each one. People who understand the “why” behind a rule follow it far more reliably.

The Microsoft Teams HIPAA Compliance Checklist

Use this as a quick reference. If you can check every box, your Microsoft Teams setup covers the main HIPAA bases. If any box is empty, that is your next task.

  • Subscribed to a qualifying Microsoft 365 or Office 365 business plan
  • Microsoft’s BAA in place and reviewed with your compliance lead
  • A license for every user who handles patient data
  • Encryption confirmed on for all data
  • Multi-factor authentication required for all relevant users
  • Least-privilege access set across teams and channels
  • Audit logging turned on in Microsoft Purview
  • DLP policies built to catch patient data
  • Retention policies set for chats, files, and recordings
  • Conditional access limiting sign-ins to trusted devices
  • Guest and external access restricted to what is needed
  • Every connected app and EHR integration reviewed
  • Staff trained, with completion records kept
  • A written record of your settings and policies for audits

Using Microsoft Teams for HIPAA-Compliant Telehealth

Plenty of practices run telehealth visits on Teams, and it handles them well. But a video visit brings risks a private staff chat does not. Once a patient joins from their own home or phone, you lose control of the room they are sitting in, so a few extra habits go a long way.

Scheduling and Running Virtual Visits Securely

Microsoft Teams lets you schedule, host, and manage virtual visits in one place. Providers can set up appointments, send secure join links, and meet patients face-to-face over video.

Keep visits inside your organization’s secured Teams account, never a personal one. Use waiting-room-style controls so patients do not enter until you admit them, and avoid sharing sensitive details in the meeting chat unless you know it is protected. Small habits like these keep a convenient tool from becoming a liability.

Connecting Teams to Your EHR

Teams can link to certain EHR systems so providers launch virtual visits straight from a patient’s chart. As of now, the supported systems are Epic and Oracle Health (formerly Cerner). This link can save time and keep records in order.

To set up this connection, you need a subscription to Microsoft Cloud for Healthcare or the Microsoft Teams EHR Connector. The setup is not instant. Plan for the connection to take several days, plus more time to test it before you rely on it for live patient care.

Verifying Patient Identity and Protecting PHI During Sessions

HIPAA expects you to confirm you are talking to the right patient before you discuss their health. On a video call, that step is easy to rush, but it protects both you and the patient.

Confirm the patient’s identity at the start of each visit. Then use good judgment about the setting. If the patient is in a public place or family members are in the room, pause and check what you can safely say. The tool cannot make that call for you, so your judgment is the last safeguard.

The Guest-Access and Data Loss Prevention Dilemma

Here is a real snag that catches many practices. Patients usually join a Microsoft Teams visit as guests. Your Data Loss Prevention rules are designed to stop patient data from reaching guests. So the same setting that protects you can also block you from sharing a test result or an image with your own patient.

When that happens, some providers get frustrated and reach for a less secure tool to get the file across, which is exactly the wrong move. Better options exist. You can register the patient as a temporary team member for the visit or share results through another secure, covered channel such as an encrypted patient portal. Plan for this before it comes up, so no one is tempted to break the rules in the moment.

Top HIPAA Risks and Common Mistakes with Microsoft Teams

Even a well-set-up Microsoft Teams account carries risk, because most breaches start with a person, not a system. These are the mistakes we see most often and the ones worth keeping an eye on.

Unauthorized Access and Weak Authentication

The biggest risk is the simplest: the wrong person getting in. A stolen or guessed password can open the door to patient data if that is all it takes to sign in.

Multi-factor authentication is your best defense here, since a password alone is no longer enough to get in. Pair it with least-privilege access so that even a compromised account cannot reach data it never needed.

Insecure File Sharing and Guest Exposure

Files are easy to share in Microsoft Teams, which is both the point and the problem. A staff member can drop a document into the wrong channel or share it with a guest in seconds.

Set clear rules about where patient files may live, and use DLP policies to catch mistakes automatically. Remind staff to double-check who is in a chat or channel before they attach anything with patient data.

Risky Third-Party Integrations

Every app you connect to Teams widens your risk. If an app handles patient data without proper protection or a signed BAA, it can create a breach even when Teams itself is locked down.

One common case: a practice adds a scheduling or note-taking app inside Teams, and that app quietly sends appointment details to a vendor with no BAA. That is a reportable breach. Review each integration before you enable it, and keep a running list of which vendors are covered.

Improper Recording, Retention, and Records Storage

Recordings and stored messages are patient data too, and they are often forgotten. Teams does not automatically file a telehealth recording or chat under the right patient record, so the job of storing and finding that data falls to you.

Decide what you record, where recordings go, and how long you keep them. HIPAA also gives patients the right to access their information, so you need a way to find and produce it on request. A clear retention and storage plan keeps you ready.

The Cost of Getting It Wrong: HIPAA Penalties for Microsoft Teams Violations

Getting this wrong is expensive. HIPAA civil penalties fall into four tiers, set by how much the organization knew about the problem and whether it fixed it. The 2025 adjusted amounts set a $145 minimum per violation at the lowest tier, where the organization did not know, rising to a $2,190,294 maximum per violation at the highest tier, which covers willful neglect left uncorrected. A yearly cap of $2,190,294 also applies to repeat violations of the same requirement. 

Civil penalties are only part of the risk. Serious or intentional misuse of patient data can also bring criminal charges, including fines and prison time. 

Microsoft 365 Copilot and AI in Teams: New HIPAA Considerations for 2026

Microsoft Teams now comes with AI built in through Microsoft 365 Copilot. It can sum up a meeting, draft a message, or pull an answer from your files in seconds. That saves real time, but it raises HIPAA questions most older guides never touch. If patient data goes anywhere near these features, here is what to watch.

Does Copilot Touch PHI, and Is It Covered by Microsoft’s BAA?

Microsoft 365 Copilot for business is an in-scope service under Microsoft’s HIPAA BAA, so it can be covered when your organization runs it on a qualifying commercial plan and has the BAA in place. That is the good news.

But two catches matter. First, Copilot only stays covered when the data it touches lives in covered services like Teams, SharePoint, and OneDrive; some connected tools and consumer versions of Copilot are not covered at all. Second, Copilot can reach whatever a user already has access to. If your file permissions are too loose, Copilot may surface patient data to someone who should not see it. It follows your access rules, so those rules have to be right. Never use a personal or consumer Copilot account with patient data.

Governing AI Features in Microsoft Teams Without Violating HIPAA

Federal regulators have made clear that AI handling patient data falls under the same HIPAA safeguards as any other system. So the tools that govern Copilot are the same ones you already know, applied with extra care.

  • Tighten file and folder permissions before you turn Copilot on, so it cannot surface data broadly.
  • Use sensitivity labels to mark patient data and control how AI features treat it.
  • Extend your DLP and audit policies to cover Copilot prompts and responses.
  • Train staff never to paste patient data into an AI prompt in a tool that is not covered.


Because
AI in healthcare is still new, a written AI governance approach helps you set the rules, record the choices you made, and show regulators you took it seriously. Putting that in place early is far easier than explaining its absence later.

Keeping Microsoft Teams HIPAA Compliant Over Time

Compliance is not a one-time setup. Rules change, staff come and go, new apps get added, and settings drift. A Microsoft Teams environment that was compliant last year can fall out of line without anyone noticing. Staying compliant means building a rhythm of review.

Ongoing HIPAA Risk Assessments and Audits

HIPAA requires regular risk assessments, and regulators increasingly want to see that you not only found risks but also reduced them. A risk assessment looks at where patient data lives in Teams, what could go wrong, and how likely each problem is.

Run these reviews on a set schedule, not just when something breaks. Regular HIPAA audits catch a misconfigured setting or an over-shared file before it becomes a breach. Document what you find and what you fixed, since that record is what protects you if regulators come knocking.

Continuous Monitoring, Logging, and Oversight

Turning on audit logs is only the start. Someone has to actually watch them. Continuous monitoring means reviewing access logs, watching for unusual activity, and acting quickly when something looks off.

Set alerts for high-risk events, such as a large file download or a sign-in from an unusual location. Assign clear ownership so monitoring does not fall through the cracks. A compliance management platform can pull these signals into one view, so you are not stitching together spreadsheets and separate reports.

Managing BAAs and Vendor Risk Across Every Integration

Your Teams setup is only as safe as the vendors connected to it. Every app, EHR link, and outside service that touches patient data needs its own BAA and its own review. Tracking all of that by hand gets hard fast.

Keep a live list of every vendor, whether each one has a signed BAA, and when each was last reviewed. When you add a new integration, check it before you enable it. Keeping this record current is the difference between a clean audit and an unpleasant surprise.

Is Microsoft Teams Worth It? Costs, Benefits, and Alternatives

After all of this, one question is fair to ask: is Teams the right tool for your practice? For some, it is a clear yes. For others, a smaller or purpose-built option fits better. It comes down to weighing what you get against the cost and the effort to set it up.

What Microsoft Teams Offers Healthcare Organizations

Microsoft Teams brings a lot together in one place, and that is its main draw. Instead of paying for and managing several separate tools, your team gets messaging, video, file sharing, and telehealth under one roof.

  • Dedicated teams and channels for specific units, care groups, or projects
  • Fast access to shared documents so care planning moves quicker
  • Video visits, group calls, and EHR links in a single platform
  • Fewer tools to manage, which can lower overhead and confusion


For a practice already using Microsoft products, this fit is convenient and familiar.

Licensing and Cost Considerations

Cost is where Teams gives some practices pause. To use it under a BAA, every user who touches patient data needs a licensed business or enterprise account. For a small clinic with only a few providers, that can feel steep.

You may also pay for features you never use, since the higher plans bundle in tools built for large organizations. Add the possible need for IT help to set things up, and the true cost is more than the sticker price. Add up your real needs before you pick a plan, so you are not paying for capacity you will never touch.

Should You Upgrade from Skype for Business to Microsoft Teams?

Microsoft has retired Skype for Business, so most organizations have already moved or are planning to do so. If you are still deciding, the upgrade makes sense when you will use Teams’ wider set of features, like channels, file sharing, and telehealth.

If you only ever used Skype for Business for basic video visits, you are likely already on a plan and BAA that carry over to Teams, so the switch is more about gaining new tools than fixing a compliance gap. Match the move to what your practice will actually use.

How ComplyAssistant Helps You Keep Microsoft Teams HIPAA Compliant

Setting up Microsoft Teams is one thing. Keeping it compliant across every setting, vendor, and staff change is where practices need support. ComplyAssistant is a healthcare-focused company with 25+ years of experience in compliance and cybersecurity, trusted by hospitals, health systems, and provider groups, and endorsed by healthcare associations. We help you turn the checklist above into an ongoing, documented practice.

Here is how our tools and services support a compliant Microsoft Teams environment:

  • GRC software to document your Teams safeguards, track tasks, and keep audit-ready records in one place instead of scattered files.
  • HIPAA audits and risk assessments that check your Teams settings against HIPAA and flag gaps before they become breaches.
  • Vendor risk management to assess third-party privacy and security vulnerabilities through custom assessments and confirm each vendor has a signed BAA.
  • Virtual CISO services and HIPAA consultants who guide your governance, risk, and compliance initiatives, policies, procedures, and staff training with expert guidance.
  • Policy management software to share and track your organization’s policies.
  • AI governance support to set safe rules for Copilot and other AI features before they touch patient data.


Our software grows with you, whether you run a small practice or a large health system, and our team treats your compliance like our own. If you want help making Teams safe for patient care and keeping it that way,
reach out to our professional team, and we will walk you through it.

Is Microsoft Teams HIPAA Compliant? Final Thoughts

So, is Microsoft Teams HIPAA compliant? Yes, when you build it that way. The platform can protect patient data well, but only after you choose the right plan, accept Microsoft’s BAA, set up the security controls, review every integration, and train your team.

Keep the biggest watch-outs in mind. Read Microsoft’s standard BAA before you rely on it. Plan for the guest-access snag in telehealth so no one turns to a risky workaround. Weigh the per-user cost against your real needs. And treat compliance as an ongoing habit, with regular reviews, not a one-time task.

Follow the steps in this guide, and you can use Teams with confidence, knowing your patients’ information stays protected. If any part of that feels like a lot to carry alone, that is exactly the kind of work ComplyAssistant helps healthcare teams handle every day.

FAQs

Is Microsoft Teams HIPAA compliant out of the box? 

Microsoft Teams is not HIPAA compliant on its own. It becomes compliant only after you subscribe to a qualifying business plan, put Microsoft’s BAA in place, turn on the right security settings, and train your staff to use it safely.

Does Microsoft sign a BAA for Teams, and can it be customized?

Yes, Microsoft provides a BAA for organizations on qualifying plans, delivered through its Product Terms and Data Protection Addendum. It cannot be customized. Microsoft offers one standard agreement for all customers, so you either accept its terms or choose another platform.

Which Microsoft 365 plans support HIPAA compliance for Teams? 

Plans that commonly support HIPAA use include Microsoft 365 Business Standard and Business Premium, Office 365 E3 and E5, Microsoft 365 E3, E5, F3, and F5, and Microsoft Cloud for Healthcare. Free and personal Teams accounts do not qualify.

Can I use a free or personal Teams account for telehealth? 

No. Free and personal Teams accounts lack the security features HIPAA requires, and Microsoft will not sign a BAA to cover them. Even if a patient asks to use one, you should meet them through your organization’s secured, licensed account instead.

Which EHRs integrate with Microsoft Teams? 

Teams supports integration with Epic and Oracle Health (formerly Cerner). To connect them, you need a subscription to Microsoft Cloud for Healthcare or the Microsoft Teams EHR Connector, plus time to set up and test the link.

Is Microsoft Teams meeting and call recording HIPAA compliant? 

Recording can be compliant if you store recordings securely and manage them as patient data. Teams’ built-in recording alone may not meet your storage and retention needs, so record only when needed and confirm recordings are kept in a covered, protected location.

Do we still need HIPAA training if Teams is configured correctly? 

Yes. Most breaches come from human error, not broken software. Even a perfect setup cannot stop a staff member from sharing a file with the wrong person. Regular training, with completion records, is what keeps your team using Teams the right way.

Ken Reiher

After more than 20 years of consulting and management experience in healthcare, I understand how quickly things can shift. My prior work in revenue cycle, finance, corporate compliance and auditing helped me appreciate the importance of building relationships to develop strategies and facilitate required change. In my current role as VP of Operations for ComplyAssistant, I wear quite a few hats, managing business operations, supporting consulting engagements, assisting with product development and supporting client engagement. I enjoy working directly with clients, listening to their needs, and working hand-in-hand with the software development team to create solutions that work for the modern needs of security and compliance in healthcare and other verticals. I received my BS and MBA degrees from Fairleigh Dickinson University Madison. And, I’m honored in my role to contribute to various industry publications, and to be affiliated with HIMSS (NJ, NY, Delaware Valley and National), NJPCA, NJAMHAA and HFMA (NJ and National).