Skip to main content

Healthcare organizations are, like many others, in the midst of a pretty significant digital transformation. Take technology like Microsoft 365 for example. It helps hospital CIOs work more efficiently and avoid mistakes, so they can make smarter, data-driven decisions.

The first steps in your digital journey can be tricky, but working with the right technology partner is the best first step to help get you started.

What is Microsoft 365?

Over the last few years, Microsoft has rebranded its Microsoft Office software package into Microsoft 365. By doing so, Microsoft 365 now includes a wider variety of products and services, including artificial intelligence (AI) features like CoPilot and cloud-based productivity tools like SharePoint.

But like with any new technology, it’s left many healthcare executives scratching their heads when it comes to the compliance regulations they must adhere to.

Is Microsoft 365 HIPAA compliant?

The shift to online services allowed Microsoft to help healthcare organizations and individuals alike meet compliance requirements set by the Health Insurance Portability and Accountability Act, otherwise known as HIPAA.

But, is the cloud-based productivity suite actually HIPAA compliant?

The answer is somewhat complex. Microsoft offers powerful tools; however, its compliance guidelines can be unclear, and they may only cover some aspects of user behavior.

HIPAA compliance is only as strong as its weakest link: people. It’s like locking your front door to your home—you can have the best locks in place, but they won’t do any good if you forget to use them.

While you can use Microsoft 365 and SharePoint in a HIPAA-compliant manner, achieving compliance is not automatic. Healthcare organizations still must add technical safeguards to meet compliance requirements. Can they be used in HIPAA-compliant ways? Yes. But can Microsoft guarantee they as HIPAA compliant? Not without outside help.

Is SharePoint HIPAA compliant?

This is another common question, but again, it’s a bit like asking, “Does this house have locks?” The real issue isn’t whether the locks are there—it’s how you use them.

Some organizations want to use SharePoint exclusively to share Electronic Health Records (EHRs) and other files containing personally identifying information (PII). So, it’s understandable why this leads to the question of whether or not SharePoint is HIPAA compliant.

The answer is that yes, it can be used in HIPAA-compliant ways. But no, it won’t automatically stop someone from violating HIPAA—just like most homes won’t lock themselves when you walk out the door.

With both products, organizations need specific technical safeguards in place if they want to remain HIPAA compliant. But to get into those safeguards, we first need to take a closer look at HIPAA itself and what it means to stay compliant.

What are the core compliance areas of HIPAA?

HIPAA compliance breaks down into three core compliance areas – technical, administrative, and physical compliance.

  • Technical compliance involves the technology itself and the guidelines for how it should be used.
  • Administrative compliance is the largest category, covering all the HIPAA policies and procedures of an organization.
  • Physical compliance is all about the buildings and equipment that help keep information safe.

When it comes to using Microsoft 365 and SharePoint in a medical setting, all three areas of compliance are important. The technical side of Microsoft 365 plays a role, but so do the administrative policies your organization puts in place around SharePoint. Physical compliance matters too, though that’s more about how your equipment is set up than the software you’re using.

What are the technical safeguards of HIPAA?

HIPAA rules require that organizations maintain “reasonable and appropriate” safeguards in all three of the major compliance areas mentioned above. Generally, safeguards fit into this category if they protect EHR from “reasonably anticipated” threats or disclosures, but unfortunately, HIPAA does not specify or define what these safeguards must look like.

On the technical side, HIPAA describes three types of technical safeguards – access control and safeguards for data in motion and at rest.

  • Access control is a fairly straightforward concept… only those who have been granted access to certain data should be able to access said data. For example, a completely open cloud workspace, such as a simple Google Workspace, clearly fails this, while a legacy rights-managed folder-based network generally has the appropriate technical safeguards. Microsoft 365 and SharePoint can be set up as environments using appropriate access control, making them reasonably HIPAA compliant.
  • Data in motion (and data in use) can be harder to protect. These terms describe when data is in transit between systems or actively being used by a system or human operator. Typical safeguards on data in motion include data encryption, access control on systems and specific data, and using metadata or anonymized data for research and analytics rather than raw data.
  • Data at rest refers to data that’s sitting on a server somewhere, either on your on-premises server or a cloud server (for those using a cloud computing service like Microsoft Azure). This data isn’t being used, but your organization needs to maintain it in case it’s needed later on. Data at rest safeguards include encryption and access control. Physical access control usually also comes into play here: an unguarded server in an unlocked room may be a HIPAA violation if it gets breached, for example. The argument then would be that the organization didn’t implement “reasonable and appropriate” safeguards — in this case, locks and access control.

Compliance Is Complex, But We Can Help.

By now we hope we’ve shown you that while it’s possible to use Microsoft 365 and SharePoint in HIPAA-compliant ways, the burden ultimately falls to your organization to ensure that you’re in compliance while using the products. This can get complicated in a hurry.

We help put the right technical safeguards and policies in place to make HIPAA compliance work with Microsoft 365, SharePoint, and other tools you rely on. That way, you can keep your focus on running your business — without stressing over compliance headaches.

If you’re ready to embrace a cloud-forward future without the compliance headaches, reach out to us today. We can help you transition smoothly from where you are to where you want to be.