Cloud & M365 — Is Microsoft 365 HIPAA compliant?

Microsoft 365 can be configured to support HIPAA compliance, but out of the box it is not. A Business Associate Agreement (BAA) must be signed with Microsoft, and specific security settings must be enabled and maintained. We handle this as part of your managed environment.

Security — Is MFA required under HIPAA?

HIPAA does not explicitly mandate MFA by name, but it requires access controls and authentication measures that reasonably protect PHI. MFA is the industry-accepted standard for meeting that requirement and is what we enforce on all systems handling patient data.