Is Office 365 Hipaa Compliant
Hipaa hitech act implementation guidance for azure and for dynamics 365 and office 365.
Is office 365 hipaa compliant. A common concern in the healthcare industry is that using office 365 and teams exposes an organization to hipaa violations. The truth is office 365 and teams can be easily. Office 365 by microsoft is the brand name its chosen as it moves its services such as email storage and chat into the cloud.
Office 365 meets many of the compliance regulation requirements for healthcare organizations around the globe. Office 365 hipaa compliance configuration. Office 365 business is not a hipaa compliant package as hipaa requires audit logs to be created and maintained and this option is not available with office 365 business.
Strive to maintain least privileged access from the beginning of your office 365 implementation. Microsoft is very clear that in the end the responsibility for hipaa compliance lies with the customer. For the purposes of this post we will focus on the email component of office 365.
Here are some best practices for you to configure and set up office 365 for hipaa. The adoption of microsoft office 365 is widespread. Audit logs are available with office 365 business essentials and office 365 business premium so both of these packages can be hipaa compliant.
As always when pressed with legalese consult with a lawyer with expertise in hipaa compliance. Office 365 hipaa best practices. Tools such as excel word powerpoint onenote publisher access and outlook continue to be the leading solutions businesses use.
As a healthcare organization or a vendor that services healthcare clients it is imperative to ensure that the tools used to conduct business are hipaa compliant. The vendor recommends that all companies establish a set of procedures and policies to help their personnel use office 365 in a way that supports compliance. While all appropriate privacy and security controls have been implemented by microsoft to ensure that office 365 can be used by hipaa covered entities while remaining compliant with hipaa and the hitech act use of office 365 does not guarantee compliance even if a baa has been obtained from microsoft.