No. Certain Microsoft 365 plans are HIPAA-capable, meaning they include the features required for compliance, but those features must be properly configured. Microsoft also requires a signed business associate agreement before any HIPAA obligations apply. Out of the box, audit logging may not be enabled, data loss prevention policies may not be configured and retention settings may not be aligned with HIPAA requirements. G6 configures your environment for HIPAA compliance, documents the controls for audits and monitors them on an ongoing basis.
Share This
Related FAQs
-
What happens during a Microsoft 365 migration, and how long does it take?
-
Can Microsoft 365 help my business meet CMMC compliance requirements?
-
What is the difference between Microsoft 365 Business Basic, Standard and Premium?
-
What are the biggest Microsoft 365 security risks for small businesses?
-
What is Microsoft 365 governance, and why does my business need it?