Pressures on healthcare technology
Protect patient information without slowing clinical work.
Clinicians need systems that are available and simple. Patients need their information kept private.
Technology controls support your obligations; they do not by themselves create legal compliance.
What success looks like
Secure, available technology that supports care rather than interrupting it
- Patient information access controlled and auditable
- Reliable systems during clinical hours
- Fast onboarding and clean offboarding of staff
- Shared and mobile devices managed securely
- Security evidence ready for accreditation reviews
- Support that understands clinical priorities
The plan
A simple plan to get there
- 1
Understand
We assess your environment, risks and business priorities.
- 2
Fix
We resolve the underlying problems and establish a secure, modern foundation.
- 3
Improve
We manage, monitor and continuously improve your technology environment.
How healthcare providers use Microsoft 365
Physician practices, primary care groups, specialist and dental practices, behavioral health and therapy providers, ambulatory and outpatient clinics, diagnostic and imaging providers, laboratories, home health providers, healthcare networks, medical billing businesses and other business associates rely on Microsoft 365 for email, Microsoft Teams, SharePoint, OneDrive, scheduling and administration, referral coordination, billing administration, HR, finance, shared mailboxes, mobile access, collaboration with vendors, communication with patients and integration with healthcare applications.
PHI or ePHI may enter Microsoft 365 through email, attachments, shared documents, Teams messages, exports, reports or integrated applications — even when the primary clinical record lives in a separate EHR or practice-management system.
A securely licensed platform is not sufficient by itself. The healthcare organisation must configure, govern, monitor and use the environment appropriately.
Healthcare cybersecurity risks
Healthcare providers face a distinctive combination of clinical, operational and information-security risks. Common Microsoft 365 exposures include:
Understanding HIPAA and Microsoft 365 Responsibilities
The obligations that apply to any specific healthcare organisation depend on whether it is a covered entity or business associate, the services delivered, states of operation, contracts and systems in use. The following is general information and is not legal advice.
HIPAA Privacy Rule
The Privacy Rule establishes standards for the use and disclosure of protected health information and provides individual rights relating to that information. In Microsoft 365 this maps to role-based access, minimum-necessary access, external-sharing governance, authorised disclosures, auditability, workforce access management, appropriate retention, access to records, vendor management, and policies and procedures. Microsoft 365 controls support these activities but do not replace the provider's privacy policies, patient-rights processes, authorisations or compliance program.
HIPAA Security Rule
- Administrative safeguards: Security-risk analysis, risk-management planning, assigned security responsibility, workforce security, access authorisation, security-awareness training, incident procedures, contingency planning, evaluation, business-associate arrangements, policies and documentation. Mycelium 365 supports Microsoft 365 security assessment, risk and remediation register, responsibility matrix, user-access processes, security configuration documentation, incident-response procedures, backup and recovery planning, scheduled control reviews and security reporting. Customers remain responsible for the formal HIPAA risk analysis, legal interpretation, compliance-program ownership, workforce training and sanctions, policy approval, patient processes and executive risk decisions. A Microsoft 365 technical review alone does not constitute the complete HIPAA risk analysis.
- Physical safeguards: Facility access considerations, workstation use, workstation security, device and media controls, disposal, reuse and asset accountability. Mycelium 365 supports Microsoft Intune, encryption, device inventory, compliance policies, remote wipe, endpoint security, secure decommissioning and device recovery procedures. Customer-controlled facility and physical-access controls remain the customer's responsibility unless separately contracted.
- Technical safeguards: Unique user identification, access control, emergency access, automatic logoff, encryption, audit controls, integrity controls, person or entity authentication and transmission security. These map to Microsoft Entra ID, MFA, Conditional Access, PIM, Microsoft Intune, device encryption, session controls, Microsoft Defender, Microsoft Purview, audit logging, DLP, sensitivity labels, secure email, Teams and SharePoint sharing controls, and monitoring and alerting. Required and addressable implementation specifications must be evaluated in the context of the regulated entity's risks and circumstances; addressable does not mean optional or ignorable.
HIPAA Breach Notification Rule
Covered entities must assess suspected breaches of unsecured PHI and may have notification obligations to affected individuals, the Department of Health and Human Services and, in certain circumstances, the media. Business associates must notify the covered entity as required. Mycelium 365 supports detection, alert investigation, account containment, session revocation, device isolation, log preservation, technical scoping, timeline development, identification of affected systems, incident documentation, recovery, remediation and coordination with your legal, compliance and executive teams. Mycelium 365 does not make the final legal breach determination unless separately engaged and qualified to do so.
HITECH Act
HITECH strengthened privacy, security, breach-notification and enforcement requirements and expanded direct obligations for business associates. Detailed legal interpretation should be obtained from qualified advisers.
Business Associate Agreements
A Business Associate Agreement may be required when a service provider creates, receives, maintains or transmits PHI on behalf of a covered entity. A BAA is a contractual and legal component, not a substitute for security controls. The customer must confirm that required agreements are in place with relevant vendors. Microsoft service eligibility, licensing and contractual terms must be verified for the customer's exact services. Mycelium 365's contractual status and handling of PHI is confirmed during scoping — no single agreement covers every Microsoft 365 product or configuration automatically.
State privacy and breach laws
State privacy, medical-record, consumer-health-data and breach-notification laws may apply in addition to HIPAA. Requirements can vary by state, provider type, information type, consumer-health application, contract, licensing body, Medicaid or government program, and substance-use-disorder services. A single national Microsoft 365 configuration cannot be presented as satisfying every state law.
42 CFR Part 2
Healthcare organisations handling substance-use-disorder records may be subject to additional confidentiality requirements under 42 CFR Part 2. Standard HIPAA controls alone do not automatically satisfy Part 2, and these providers require specific legal and compliance review.
HIPAA Security Rule changes
Healthcare organisations should monitor HHS rulemaking and update their security program as regulatory requirements change. Proposed changes are not final law until formally adopted; the current status of any HIPAA Security Rule amendments should be verified using official HHS sources.
How Mycelium 365 supports HIPAA-aligned safeguards
A summary of how Microsoft 365 controls and Mycelium 365 services align with common HIPAA safeguard areas. This mapping is illustrative — each organisation's obligations should be confirmed with qualified advisers.
| HIPAA area | Security or privacy objective | Microsoft 365 control | Mycelium 365 service | Customer responsibility | Evidence produced |
|---|---|---|---|---|---|
| Risk management | Identify and manage risks to ePHI | Microsoft 365 security configuration, Defender risk signals | Microsoft 365 security assessment, configuration review, prioritised remediation, security roadmap | Enterprise-wide HIPAA risk analysis, risk acceptance, clinical and operational assessment | Findings report, risk register, remediation records, review minutes |
| Workforce access | Unique identification and access control | Entra ID, MFA, Conditional Access, RBAC, access reviews | Unique accounts, role groups, access approvals, MFA, access reviews, termination workflow, session revocation | Approving roles, workforce policies, sanctions, authorised-user decisions | User reports, group membership, access-review records, offboarding tickets, authentication logs |
| Privileged access | Least privilege for administrators | PIM, separate admin identities, strong authentication | Separate admin identities, least privilege, PIM, administrator reviews, emergency-access governance | Approving privileged roles, executive oversight | Administrator inventory, role assignments, access logs, review reports |
| Device security | Protect endpoints handling ePHI | Microsoft Intune, encryption, compliance policies, endpoint protection | Intune administration, encryption, compliance, patching, MAM, remote wipe, device inventory | Device procurement decisions, workforce mobility policy | Compliance reports, encryption status, patch reports, endpoint alerts, device records |
| Audit controls | Record and examine activity in systems containing ePHI | Microsoft 365 audit, sign-in logs, Defender alerts, mailbox auditing | Audit configuration, sign-in logging, security alerts, mailbox auditing, sharing reports, SOC monitoring, log-retention recommendations | Approval of retention periods, review of investigations | Audit logs, investigation records, alert reports, monthly security reports |
| Information protection | Protect PHI from unauthorised use or disclosure | Sensitivity labels, DLP, retention, sharing controls | Label rollout, DLP tuning, SharePoint permission reviews, external-sharing restrictions, secure email, guest-user governance | Information classification decisions, records retention approval | DLP incidents, sharing reports, permission reports, label reports, policy configurations |
| Transmission security | Protect ePHI in transit | Encryption, domain authentication, Conditional Access | Secure Microsoft 365 communication configuration, encryption controls, domain security, approved sharing methods, restrictions on legacy authentication | Approving mail-flow rules, third-party sharing decisions | Configuration records, authentication reports, mail-flow reports, policy settings |
| Availability and contingency planning | Recover ePHI and Microsoft 365 services | Independent backup, recovery procedures | Independent Microsoft 365 backup, recovery testing, administrative recovery, incident-response support, configuration documentation | Clinical downtime procedures, patient-safety planning, emergency operations, business-continuity approval | Backup reports, test results, restoration records, recovery documentation |
| Incident response | Detect, contain and recover from security incidents | Defender, SOC monitoring, identity risk, endpoint alerts | Monitoring, triage, investigation, containment, log preservation, recovery, remediation, technical reporting | Legal determinations, regulatory notifications, patient notifications, media notifications, law-enforcement decisions, compliance sign-off | Alert records, incident timelines, investigation and remediation reports |
What our managed Microsoft 365 service includes
An ongoing management, security, cybersecurity and continuous-improvement program for healthcare — not one-off technical support.
Microsoft 365 administration
- Users, licences, Exchange Online and Teams
- SharePoint, OneDrive and Entra ID
- Intune and security policies
- Administrative governance and change management
- Service health and support
Identity and access management
- Multi-factor authentication and Conditional Access
- Privileged access and risk-based sign-ins
- Guest access, access reviews and session controls
- Restrictions on legacy authentication
- Emergency-access account governance
User onboarding and termination
- Standardised account creation and role-based licensing
- Device setup and secure access configuration
- Timely account disablement and session revocation
- Mailbox retention and file ownership transfer
- Device recovery procedures
Endpoint and device management
- Microsoft Intune for Windows, macOS, iOS and Android
- Encryption, compliance and screen-lock policies
- Patching and endpoint protection
- BYOD and mobile application management
- Remote wipe and lost-device response
Information protection
- Sensitivity labels and data loss prevention
- Retention policies and audit configuration
- SharePoint and OneDrive permission reviews
- External sharing and guest-user governance
- Oversharing remediation
Email and collaboration security
- Anti-phishing, Safe Links and Safe Attachments
- Impersonation protection and domain authentication
- Mailbox auditing and shared-mailbox governance
- Teams security and external-sharing controls
- Referral and inter-provider communication protection
Managed cybersecurity and SOC
- Microsoft Defender and identity monitoring
- Endpoint alert monitoring
- Managed SOC, triage and investigation
- Containment, log preservation and remediation
- Incident documentation and reporting
Backup and recovery
- Independent Microsoft 365 backup
- Exchange Online, SharePoint, OneDrive and Teams protection
- Recovery testing and restoration procedures
- Long-term retention options
- Protection against ransomware and accidental deletion
Reporting and governance
- Monthly service and security posture reporting
- Access and device-compliance reviews
- Risk register and remediation tracking
- Licence optimisation and technology roadmap
- Executive reporting
Backup services complement — but do not replace — Microsoft platform resilience and native retention. Independent backup adds protection against accidental deletion, ransomware, malicious activity and long-term recovery needs.
Healthcare-specific use cases
Microsoft Copilot and AI governance
Copilot and other AI tools can expose overshared or poorly governed information and introduce new PHI-handling risks. Mycelium 365 helps healthcare organisations prepare responsibly by:
General-purpose Microsoft 365 Copilot should not be used to diagnose patients, determine treatment or replace clinical judgment.
Why Mycelium 365
Mycelium 365 helps United States healthcare organisations translate security, privacy and operational requirements into practical Microsoft 365 controls. We manage and monitor the technology and provide supporting evidence, while each healthcare organisation retains responsibility for its HIPAA compliance program, policies, workforce, legal decisions and patient obligations.
- On-the-ground resources across the United States
- Security by design
- Managed services rather than reactive support
- Microsoft 365 expertise
- HIPAA-supporting safeguards
- Managed cybersecurity and SOC
- Evidence and reporting
- Multi-location delivery
- Centralised governance
- Continuous improvement
Our service approach
A repeatable five-step model that scales from a single practice to a multi-state healthcare group.
Discover
- •Microsoft 365 environment, users, devices and administrators
- •Licences, sharing, security controls and backups
- •EHR and practice-management integrations
- •Regulatory, contractual and policy context
Assess
- •Risk findings and control-gap analysis
- •Priority remediation plan
- •Responsibility matrix
- •HIPAA safeguard mapping and roadmap
Secure
- •Identity, device, email and information controls
- •Backup, logging and monitoring
- •Administrative governance
- •Documented configurations and evidence
Manage
- •Administration, support, onboarding and termination
- •Monitoring, incident response and backup oversight
- •Reporting and control reviews
- •Multi-location coordination
Improve
- •Security and HIPAA-support reviews
- •Trend analysis and remediation tracking
- •Licence optimisation and user feedback
- •Technology roadmap and continuous improvement
Does Your Microsoft 365 Environment Support Your HIPAA Obligations?
Microsoft 365 can provide strong security and compliance capabilities, but those capabilities must be appropriately licensed, configured, governed, monitored and used.
Mycelium 365 can assess your environment, identify priority risks and establish a practical roadmap for HIPAA-supporting Microsoft 365 safeguards.
Frequently asked questions
Is Microsoft 365 HIPAA compliant?+
Microsoft 365 includes services and security capabilities that can be used within a HIPAA compliance program when the appropriate services, licensing, contractual arrangements and safeguards are in place. Compliance depends on how the healthcare organisation configures and uses the platform, manages its workforce, handles PHI and fulfils its broader legal obligations.
Does Microsoft sign a Business Associate Agreement?+
Microsoft offers a HIPAA Business Associate Agreement (BAA) for eligible services and customers. Coverage depends on the specific Microsoft services in use, licensing and how the environment is configured. Each customer should verify the current BAA scope, terms and eligible services directly with Microsoft.
Does a BAA make Microsoft 365 compliant?+
No. A BAA is a contractual and legal component of a compliance program, not a substitute for security controls. Even with a BAA in place, the covered entity or business associate must still configure, govern, monitor and use Microsoft 365 in line with HIPAA and its own policies.
What are HIPAA administrative safeguards?+
Administrative safeguards are policies and procedures that manage the selection, development, implementation and maintenance of security measures to protect ePHI — including risk analysis, risk management, assigned security responsibility, workforce security, security awareness and training, incident procedures, contingency planning, evaluation, business-associate arrangements and documentation.
What are HIPAA physical safeguards?+
Physical safeguards address the physical protection of information systems and related buildings and equipment — including facility access controls, workstation use and security, and device and media controls covering disposal, reuse, accountability and backup.
What are HIPAA technical safeguards?+
Technical safeguards address the technology and related policies used to protect ePHI and control access — including access control, audit controls, integrity, person or entity authentication and transmission security. Required and addressable implementation specifications must be evaluated in the context of the entity's risks and circumstances.
How does Microsoft 365 support access control?+
Microsoft Entra ID provides unique user identification, authentication and authorisation. Conditional Access, MFA, Privileged Identity Management, role-based groups, access reviews and session controls help enforce least privilege and support HIPAA access-control requirements.
How can Microsoft Intune protect healthcare devices?+
Microsoft Intune can enforce encryption, screen-lock, compliance and update policies on Windows, macOS, iOS and Android devices, deploy applications, protect ePHI in mobile apps for both corporate and personal devices, and support remote wipe of lost or stolen devices.
Does HIPAA require multi-factor authentication?+
HIPAA does not name specific technologies, but authentication and access-control safeguards are required. MFA is a widely accepted control to help address these requirements and is consistent with current guidance and healthcare cybersecurity practices.
Does HIPAA require encryption?+
Encryption is an addressable implementation specification under the Security Rule, meaning covered entities and business associates must assess it in the context of their risks and either implement it, adopt an equivalent alternative or document why it is not reasonable and appropriate. In practice, encryption of ePHI at rest and in transit is a common expectation.
Do healthcare providers need Microsoft 365 backups?+
Microsoft provides service availability and short-term retention, but this is not a substitute for independent backup. A dedicated Microsoft 365 backup service protects Exchange Online, SharePoint, OneDrive and Teams-related data against accidental deletion, ransomware, malicious activity and long-term recovery needs.
How should terminated workforce access be removed?+
Access should be disabled promptly on termination, active sessions revoked, MFA and app passwords reset, mailboxes and files retained per policy, and devices recovered or remotely wiped. Standardised, ticketed offboarding produces evidence that supports HIPAA workforce security requirements.
Can Mycelium 365 guarantee HIPAA compliance?+
No technology provider can independently guarantee a healthcare organisation's HIPAA compliance. Mycelium 365 helps implement, manage and document Microsoft 365 safeguards that support HIPAA requirements. The healthcare organisation remains responsible for its compliance program, risk analysis, policies, workforce practices, patient rights and legal decisions.
Can you support multi-state healthcare groups?+
Yes. Mycelium 365 standardises Microsoft 365 administration, identity, device management, security and support across multiple facilities and states, with consistent policies, common reporting and coordinated response, while recognising legitimate differences between locations.
Can you help prepare for a HIPAA breach investigation?+
Mycelium 365 supports detection, alert investigation, account containment, session revocation, device isolation, log preservation, technical scoping, timeline development, identification of affected systems, incident documentation, recovery and remediation, and coordinates with your legal, compliance and executive teams. Legal breach determinations rest with the covered entity and its advisers.
Does 42 CFR Part 2 apply to our organisation?+
42 CFR Part 2 imposes additional confidentiality requirements on providers that hold substance-use-disorder records from federally assisted programs. Standard HIPAA controls alone do not automatically satisfy Part 2. Providers should seek specific legal and compliance review.
Do state privacy laws apply in addition to HIPAA?+
Yes, potentially. State privacy, medical-record, consumer-health-data and breach-notification laws may apply in addition to HIPAA and can vary by state, provider type, information type, contract, licensing body and program. A single national Microsoft 365 configuration cannot be presented as satisfying every state law.
Can Microsoft Copilot be used with PHI?+
Microsoft 365 Copilot operates against content the user can already access, so poorly governed SharePoint or OneDrive permissions can expose PHI through Copilot responses. Copilot use with PHI requires appropriate licensing, contractual coverage, permission remediation, data classification, DLP, acceptable-use policies, human oversight and monitoring. General-purpose Copilot should not be used to diagnose patients or determine treatment.
What evidence can you provide for a security review?+
Depending on the services engaged, Mycelium 365 can provide access-review reports, sign-in and audit logs, Conditional Access configuration, device compliance and patch status, DLP and sharing reports, backup and recovery-test records, incident timelines, remediation records and monthly service reporting.
Can you work with our EHR provider?+
Microsoft 365 can be managed alongside EHR and practice-management systems. Mycelium 365 reviews integrations for identity, security, access and data-protection risks so those systems remain safely connected, while the EHR vendor remains responsible for its own software and configuration.
Authoritative sources
- US Department of Health and Human Services (HHS)
- HHS Office for Civil Rights (OCR) — HIPAA Privacy, Security and Breach Notification Rule guidance
- Substance Abuse and Mental Health Services Administration (SAMHSA) — 42 CFR Part 2 guidance
- State attorneys general and state health departments for applicable state privacy and breach laws
Verify the current legal status and effective dates of any recently proposed or final HIPAA rule changes using official HHS sources before making compliance decisions.
Related services
This page covers the US healthcare vertical. For our United States presence generally — including Cori Avery, who is based in Florida and supports US clients in their local timezone — see Microsoft 365 support in Florida.
