Is Microsoft Teams HIPAA Compliant?

Microsoft Teams can meet HIPAA requirements with the right plan and configuration — but compliance is your organization's responsibility.

Get started for free
Yes, with conditions

Yes, with conditions. Microsoft lists Teams as an in-scope service for HIPAA and includes a BAA by default through the Online Services Data Protection Addendum. But using Teams does not automatically make an organization HIPAA compliant — Microsoft states that the organization is responsible for configuring Teams and maintaining its own compliance program.

Why?

Microsoft includes a BAA by default

The HIPAA Business Associate Agreement is available through the Microsoft Online Services Data Protection Addendum by default to all customers who are covered entities or business associates under HIPAA.

Source: Microsoft HIPAA and HITECH compliance offering

Organization responsible for configuration

Microsoft states that using its services does not on its own achieve HIPAA compliance. The HIPAA Security Rule places the burden on the covered entity to configure DLP policies, retention settings, audit logging, and access controls.

Source: HHS HIPAA Security Rule

Audit and eDiscovery included at standard tiers

Audit (Standard), audit log search, and eDiscovery (Standard) are included with standard M365 licensing. Advanced audit and eDiscovery (Premium) require additional licensing.

Source: Microsoft Teams security and compliance

What Microsoft Teams says

Microsoft's HIPAA compliance page states: "By offering a Business Associate Agreement, Microsoft helps support your HIPAA compliance. However, using Microsoft services doesn't on its own achieve HIPAA compliance. Your organization is responsible for ensuring that you have an adequate compliance program and internal processes in place."
Source: Microsoft HIPAA and HITECH compliance offering

What you would need to configure

Required plan: Microsoft 365 E3, E5, or Business Premium

  1. BAA is included by default through the Data Protection Addendum — no separate signing step
  2. Enable multi-factor authentication for all users
  3. Configure Data Loss Prevention policies in Microsoft Purview to prevent PHI leaking to unauthorized channels
  4. Set retention policies for HIPAA record-keeping requirements
  5. Enable audit logging in Microsoft Purview
  6. Restrict guest access and external sharing as appropriate
  7. Train staff on compliant use of Teams for PHI

Requires IT staff who can configure and maintain Microsoft 365 security and compliance settings. Not a one-time setup — policies need ongoing review as Microsoft updates Teams features and defaults.

HIPAA-compliant alternatives

BloomText

Purpose-built HIPAA messaging that ships compliant out of the box. Signed BAA included at signup on every plan, including the free plan. No M365 environment required.

TigerConnect

Enterprise clinical messaging for hospitals and health systems with role-based routing, EHR integrations, and care team assignments.

Spruce Health

HIPAA-compliant communication platform for medical practices with secure messaging, phone, fax, and telehealth in one system.

Frequently Asked Questions

Is Microsoft Teams HIPAA compliant?

Yes, conditionally. Microsoft lists Teams as an in-scope HIPAA service and includes a BAA by default. But the organization must configure DLP, retention, audit, and access controls to meet HIPAA requirements.

Does Microsoft sign a BAA for Teams?

Yes. The HIPAA Business Associate Agreement is included through the Microsoft Online Services Data Protection Addendum by default for all eligible customers. No separate signing step is required.

What Microsoft 365 plan do I need for HIPAA-compliant Teams?

Microsoft 365 E3, E5, or Business Premium include the enterprise security and compliance features needed for HIPAA-governed Teams use. Lower-tier plans may not include the required compliance tools.

Can a small practice use Teams for HIPAA messaging?

Technically yes, but configuring and maintaining M365 compliance settings requires IT expertise. Smaller practices without dedicated IT staff may find the overhead disproportionate to the messaging need.

Sources

Last verified May 26, 2026.

  1. BloomText pricing
  2. Microsoft HIPAA and HITECH compliance offering
  3. Microsoft Teams security and compliance
  4. HHS HIPAA Security Rule

Need HIPAA-compliant messaging?

Get started for free

Trusted by today's leading healthcare professionals

Streamlined appointment schedulingWith BloomText Broadcast SMS Messaging, I literally took the job of 20 employees and I can do it by myself in three and a half hours.Chief Administrative Officer, Radiology
Best HIPAA app on the marketBloomText has brought our clinic into the modern age, and our patients love being able to communicate with us via text or through our website.Office Administrator, Family Medicine
Excellent for acute careBloomText is the nervous system for my business. It helps us differentiate ourselves in terms of our communication and our quality of care.Clinical Director, Acute Care