Is Microsoft Copilot HIPAA Compliant? A Practical Guide to the BAA, M365, and Azure OpenAI
The answer depends on which Copilot you use and how you license and configure it.
It depends on the product. Microsoft signs a HIPAA Business Associate Agreement (BAA) that covers enterprise Microsoft 365 Copilot and many Azure services, but the free consumer Copilot is not covered.
So there is no single yes or no. Enterprise Microsoft 365 Copilot can handle protected health information (PHI) when it is licensed and configured correctly. The consumer or web-grounded Copilot cannot.
This guide explains what the Microsoft BAA covers, where it stops, and how an organization already on Microsoft can use Copilot or Azure OpenAI with health data. Always verify the current terms on Microsoft's own pages before you rely on them.
The Direct Answer: Some Copilot Surfaces Are Covered, Others Are Not
Enterprise Microsoft Copilot can be used with PHI under Microsoft's HIPAA BAA, but the free consumer Copilot cannot. The product and the license decide the answer, not the Copilot brand name.
Microsoft enters into a Business Associate Agreement with its covered-entity and business-associate customers. Microsoft's own documentation lists Microsoft 365 Copilot and Microsoft 365 Copilot Chat among the in-scope commercial services.
The BAA reaches the enterprise Copilot that runs inside your paid Microsoft 365 tenant. It does not reach the consumer Copilot, personal Microsoft accounts, or Copilot's public web search.
Microsoft also states plainly that a BAA does not by itself make your organization HIPAA compliant. You still carry the configuration and access duties that HIPAA requires.
Want the whole playbook, not just this page? The Complete Medical Practice AI Implementation Guide (2026) is the full step-by-step rollout for medical & dental practices.
Get the guide — $59 (reg. $89)Three Different Copilots, Three Different Answers
Microsoft ships several products under the Copilot name, and they do not share the same HIPAA posture. Knowing which one your staff open is the whole game.
Enterprise Microsoft 365 Copilot is the paid Copilot built into your commercial tenant. It runs under Enterprise Data Protection (EDP), which applies the same Data Protection Addendum and Product Terms that already cover your Exchange email and SharePoint files. This is the surface the Microsoft BAA covers.
Consumer Copilot, free Copilot, and Copilot signed into a personal Microsoft account are a different service. Microsoft treats these under the Microsoft Services Agreement and acts as an independent data controller, so they sit outside the BAA.
Azure OpenAI Service is the build-your-own path. It is an Azure service you run inside your own tenant, and it is covered by the Microsoft BAA when you purchase and configure it correctly.
- Enterprise M365 Copilot: covered by the BAA under EDP, when licensed and configured for PHI.
- Consumer / free / personal-account Copilot: not covered; do not put PHI in it.
- Copilot web search (Bing grounding): not covered, even inside the enterprise app.
- Azure OpenAI Service: covered by the BAA; your recommended path to build health-data AI.
The Consumer Copilot Trap
The most common violation is a staff member pasting PHI into the free consumer Copilot or a personal Microsoft account. That data falls outside the BAA the moment it lands there.
Microsoft handles consumer Copilot under the Microsoft Services Agreement, not the enterprise Data Protection Addendum. In that mode Microsoft is an independent controller, and your HIPAA agreement does not apply.
The trap is easy to fall into because both products say Copilot and often look alike. A nurse or caseworker cannot tell from the logo which contract governs the data.
In our AI-compliance work with healthcare-adjacent and nonprofit clients, the failure mode we see most is exactly this: staff pasting client data into a consumer AI tool with no BAA behind it. The fix is a policy plus a technical block, not a memo alone.
What the Microsoft BAA Covers and What It Does Not
The Microsoft BAA covers the in-scope enterprise services listed in Microsoft's documentation, delivered through the Online Services Data Protection Addendum. You do not sign a separate paper contract.
Microsoft states the BAA is available by default to all customers who are covered entities or business associates under HIPAA. It applies once you use qualifying commercial services.
In-scope services include core Microsoft 365 workloads such as Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams, plus Microsoft 365 Copilot, and Azure and Dynamics 365 services. Check the current list on Microsoft's page, because scope changes over time.
The BAA does not cover Copilot's public web search queries. Microsoft is explicit that HIPAA terms do not apply to web search, because those queries run through the Bing service under a separate agreement.
Most importantly, the BAA does not make you compliant. Microsoft says using its services does not on its own achieve HIPAA compliance. Your safeguards, access rules, and staff practices still have to hold up.
- Covered: in-scope enterprise Microsoft 365, Azure, and Dynamics 365 services, including enterprise Copilot.
- Not covered: consumer Copilot, personal accounts, and Copilot web-search grounding.
- Not automatic: you must confirm your services are in scope and configure them correctly.
Data Residency and Offshore Processing for Non-US Orgs
Data location matters if your organization operates outside the United States, and Microsoft offers boundary options for it. A New Zealand NGO, for example, may face privacy rules about sending client data offshore.
Microsoft supports the EU Data Boundary for European customers, which keeps in-scope processing within the region. Similar in-country and in-geography commitments apply to some other services and regions.
There are limits worth reading closely. Microsoft notes the EU Data Boundary does not apply to Copilot web-search queries, and that some third-party models are excluded from in-region processing commitments.
If your rules restrict offshore processing of health data, confirm the exact residency commitment for your specific service and region before you go live. Do not assume a global default keeps data in your country.
Azure OpenAI: The Recommended Path to Build Health-Data AI
Azure OpenAI Service is the path to prefer when you want to build a custom AI feature on health data. It runs inside your own Azure tenant and is covered by the Microsoft BAA.
Microsoft states that your prompts and completions in Azure OpenAI are not used to train the underlying foundation models. Your data stays in your tenant and is processed within the Azure geography you choose.
This matters for a health organization building its own tool, such as summarizing case notes or drafting patient letters. You get enterprise AI without shipping PHI to a consumer chatbot.
Azure OpenAI does apply abuse-monitoring processes, and eligible customers can apply for modified handling for sensitive workloads. Review Microsoft's current data, privacy, and security documentation for Azure OpenAI before you design around it.
- Runs in your own Azure tenant, not a shared consumer service.
- Covered by the Microsoft BAA through the Data Protection Addendum.
- Your prompts and outputs are not used to train the foundation models.
- Region and abuse-monitoring settings need review for sensitive PHI workloads.
Configuration Checklist for Copilot or Azure OpenAI With PHI
Getting to a defensible setup is a checklist, not a switch. Work through each item before any PHI touches Copilot or Azure OpenAI.
None of these steps replace legal and security review. They are the practical baseline that review will expect to see in place.
- Confirm your BAA: verify your commercial Microsoft 365 and Azure services are in scope under the Data Protection Addendum.
- Use enterprise licensing: deploy the paid enterprise Copilot in your commercial tenant, not the free version.
- Block consumer Copilot: use conditional access and policy to stop staff signing into personal-account or free Copilot with work data.
- Turn on Purview DLP: build data-loss-prevention rules that stop PHI leaving to unapproved destinations.
- Apply sensitivity labels: classify PHI so Copilot and DLP can recognize and protect it.
- Tighten access: fix over-shared files and folders, because Copilot inherits those permissions.
- Enable auditing: log and retain Copilot and Azure OpenAI interactions for review.
- Train staff: teach the difference between enterprise and consumer Copilot, and what may never be pasted in.
- Check residency: confirm the data-boundary commitment for your service and region.
- Get sign-off: have privacy and security review the design against your HIPAA obligations.
Consumer Copilot vs Enterprise M365 Copilot vs Azure OpenAI
The three products sit in very different places for HIPAA. This table is the quick reference for which one to use with sensitive data.
Use it to route work: consumer Copilot for non-PHI convenience, enterprise Copilot for staff productivity on PHI, and Azure OpenAI to build custom health-data features.
- Consumer / free Copilot | HIPAA posture: not covered by the BAA | Use for: general, non-PHI tasks only.
- Enterprise Microsoft 365 Copilot | HIPAA posture: covered under the BAA and EDP when configured | Use for: staff productivity across your PHI-holding Microsoft 365 data.
- Azure OpenAI Service | HIPAA posture: covered under the BAA in your own tenant | Use for: building custom AI tools on health data.
- Copilot web search (Bing grounding) | HIPAA posture: not covered | Use for: public-information lookups with no PHI.
Frequently Asked Questions
- Enterprise Microsoft 365 Copilot can be used with PHI under Microsoft's HIPAA BAA when it is licensed and configured correctly. The free consumer Copilot is not covered by the BAA and must not be used with PHI. Confirm your specific services are in scope on Microsoft's own documentation.
- Yes. Microsoft enters into a HIPAA Business Associate Agreement with covered-entity and business-associate customers. It is delivered through the Microsoft Online Services Data Protection Addendum by default, so there is no separate paper contract to sign for in-scope commercial services.
- Many enterprise Microsoft 365 services are in scope under the Microsoft BAA, including Exchange Online, SharePoint Online, Teams, and Microsoft 365 Copilot. Microsoft is clear that the BAA supports your compliance but does not by itself make your organization HIPAA compliant. Your configuration and safeguards still matter.
- Azure OpenAI Service is covered by the Microsoft BAA as an Azure service and runs inside your own tenant. Microsoft states your prompts and completions are not used to train the foundation models. Review Azure OpenAI's current data, privacy, and abuse-monitoring documentation before designing a PHI workload.
- No. The free or consumer Copilot and personal Microsoft accounts fall outside the Microsoft BAA. Microsoft handles them as an independent data controller under the Microsoft Services Agreement. Putting PHI into the consumer Copilot is a violation, so block it with policy and conditional access.
- No. Microsoft states that HIPAA terms do not apply to Copilot web-search queries, because they run through the Bing search service under a separate agreement. Even inside enterprise Copilot, avoid sending PHI into web-grounded searches.
- Yes, and they are the larger part of the job. You must set access controls, sensitivity labels, DLP rules, auditing, and staff training. Enterprise Copilot only enforces the permissions and labels you configure, so loose file sharing can expose PHI even under a valid BAA.
- Sometimes, depending on the service and region. Microsoft offers boundary options such as the EU Data Boundary, but web-search queries and some third-party models are excluded. If your rules restrict offshore processing, confirm the exact residency commitment for your service before you go live.
The complete AI playbook for medical & dental practices
The Complete Medical Practice AI Implementation Guide (2026): HIPAA-compliant vendor selection, scribes, voice agents, scheduling and intake, front-desk automation, dental-specific plays, and the specialty cuts — for the owner rolling AI into a real practice in 2026.
Get the guide — $59 (reg. $89)