Microsoft SharePoint is a web-based collaboration and document management platform that organizations use to store, organize, share, and access files, knowledge, and other business information. It integrates with Microsoft 365 services such as Teams, OneDrive, Word, Excel, and Microsoft Copilot.
Is SharePoint HIPAA compliant? Yes, SharePoint Online can be HIPAA compliant in a manner under certain conditions.
What changed this year?
As of July 2026, Microsoft continues to list SharePoint Online as an in-scope service under its HIPAA business associate agreement for commercial Office 365 and Office 365 Government Community Cloud environments. Microsoft published an updated Data Protection Addendum on May 22, 2026, but our review did not identify a publicly disclosed change that removes or narrows SharePoint Online’s HIPAA coverage.
Will Microsoft sign a business associate agreement for SharePoint?
Yes, Microsoft provides a standardized HIPAA business associate agreement that customers can review in the Microsoft Products and Services Data Protection Addendum.
Microsoft makes its HIPAA BAA available by default to customers that are covered entities or business associates and use eligible, in-scope Microsoft services. Customers generally do not need to negotiate or separately sign a custom BAA with a Microsoft representative.
What does the Microsoft BAA cover?
Microsoft states that its HIPAA BAA “covers in-scope Microsoft services.” Its current HIPAA documentation specifically includes SharePoint Online in the list of covered commercial Office 365 and GCC services.
The BAA covers:
- SharePoint Online under eligible commercial Microsoft 365 and Office 365 agreements
- SharePoint Online within the Office 365 GCC environment
- Microsoft’s permitted use and disclosure of PHI processed through covered services
- Safeguards for PHI handled by Microsoft as a business associate
- Security incident and breach-related reporting obligations
- Data access and disclosure obligations under HIPAA and the HITECH Act
Microsoft also states that services covered by the BAA undergo independent audits associated with its ISO/IEC 27001 and HITRUST CSF certifications.
What does the Microsoft BAA exclude?
Microsoft’s BAA is limited to services identified as in scope. Its published HIPAA service list specifically names SharePoint Online, rather than providing blanket coverage for every Microsoft product, every SharePoint deployment, or every service connected to SharePoint.
Organizations operating an on-premises SharePoint Server environment remain responsible for securing and managing that environment and should not assume that Microsoft’s cloud-service BAA covers their independent deployment.
The BAA also does not make a SharePoint environment automatically compliant. Microsoft states that “using Microsoft services doesn't on its own achieve HIPAA compliance.” Healthcare organizations remain responsible for configuring user permissions, external sharing, access controls, authentication, audit logging, retention settings, and internal procedures appropriately.
Any third-party app, connector, migration provider, backup service, or other vendor that creates, receives, maintains, or transmits PHI on behalf of the organization must also be evaluated separately. Depending on its role, the third party may need to enter into its own BAA with the covered entity or business associate.
Conclusion
SharePoint Online is HIPAA-compliant manner because Microsoft provides a BAA that includes it as an in-scope service.
See also: HIPAA Compliant Email: The Definitive Guide
FAQs
What is a business associate agreement?
A BAA is a legally binding contract that establishes the relationship between a HIPAA covered entity and a business associate that creates, receives, maintains, or transmits PHI on its behalf. The agreement establishes the permitted uses and disclosures of PHI and requires the business associate to protect the information appropriately.
What is HIPAA?
The HIPAA establishes national standards for protecting the privacy and security of certain health information.
HIPAA is designed to protect individuals’ health information and to support the secure exchange of that information by healthcare providers, health plans, and other regulated organizations. Violations can result in enforcement action and civil or criminal penalties.
Who does HIPAA apply to?
HIPAA applies to covered entities, including healthcare providers that conduct certain electronic transactions, health plans, and healthcare clearinghouses. It also applies to business associates that perform functions or provide services involving PHI on behalf of covered entities.
