Is Microsoft 365 HIPAA compliant out of the box?

No. Certain Microsoft 365 plans are HIPAA-capable, meaning they include the features required for compliance, but those features must be properly configured. Microsoft also requires a signed business associate agreement before any HIPAA obligations apply. Out of the box, audit logging may not be enabled, data loss prevention policies may not be configured and retention settings may not be aligned with HIPAA requirements. G6 configures your environment for HIPAA compliance, documents the controls for audits and monitors them on an ongoing basis.

Share This
Related FAQs

Still Have Questions?

Send us a note or book a meeting to discuss your specific needs.