Mycelium 365 — Managed IT, Microsoft 365 and Azure across Australia, New Zealand and the United States
    Healthcare · United States

    Secure Microsoft 365 for United States healthcare providers

    Healthcare organisations depend on Microsoft 365 for communication, collaboration, administration and access to sensitive business and patient information. Mycelium 365 helps healthcare providers implement and operate Microsoft 365 safeguards that support HIPAA privacy and security requirements, backed by on-the-ground resources across the United States.

    Pressures on healthcare technology

    Protect patient information without slowing clinical work.

    Clinicians need systems that are available and simple. Patients need their information kept private.

    Patient information exposuresensitive records reachable by too many people
    Clinical uptimesystems that must be available during care delivery
    Distributed workforcesmultiple sites, home visits and shared workstations
    Workforce turnoverconstant onboarding and offboarding of staff
    Device securityshared clinical devices and personal phones
    Jurisdictional requirementsdiffering obligations across regions

    Technology controls support your obligations; they do not by themselves create legal compliance.

    What success looks like

    Secure, available technology that supports care rather than interrupting it

    • Patient information access controlled and auditable
    • Reliable systems during clinical hours
    • Fast onboarding and clean offboarding of staff
    • Shared and mobile devices managed securely
    • Security evidence ready for accreditation reviews
    • Support that understands clinical priorities

    The plan

    A simple plan to get there

    1. 1

      Understand

      We assess your environment, risks and business priorities.

    2. 2

      Fix

      We resolve the underlying problems and establish a secure, modern foundation.

    3. 3

      Improve

      We manage, monitor and continuously improve your technology environment.

    On-the-ground resources across the United States
    Security by design
    Microsoft 365 specialists
    Managed cybersecurity and SOC services
    HIPAA-supporting safeguards
    Multi-location healthcare support
    Documented security controls
    Continuous monitoring and reporting

    How healthcare providers use Microsoft 365

    Physician practices, primary care groups, specialist and dental practices, behavioral health and therapy providers, ambulatory and outpatient clinics, diagnostic and imaging providers, laboratories, home health providers, healthcare networks, medical billing businesses and other business associates rely on Microsoft 365 for email, Microsoft Teams, SharePoint, OneDrive, scheduling and administration, referral coordination, billing administration, HR, finance, shared mailboxes, mobile access, collaboration with vendors, communication with patients and integration with healthcare applications.

    PHI or ePHI may enter Microsoft 365 through email, attachments, shared documents, Teams messages, exports, reports or integrated applications — even when the primary clinical record lives in a separate EHR or practice-management system.

    A securely licensed platform is not sufficient by itself. The healthcare organisation must configure, govern, monitor and use the environment appropriately.

    Healthcare cybersecurity risks

    Healthcare providers face a distinctive combination of clinical, operational and information-security risks. Common Microsoft 365 exposures include:

    Phishing and credential theft
    Business email compromise
    Ransomware and account compromise
    Unauthorised ePHI access
    Excessive administrator privileges
    Former workforce members retaining access
    Poorly secured shared mailboxes
    Weak vendor and third-party access
    Uncontrolled external sharing
    Personal devices accessing ePHI
    Lost or stolen and unencrypted devices
    Inadequate backups and poor audit-log retention
    Unsupported systems and weak incident response
    Misconfigured cloud applications
    Unapproved AI tools handling PHI
    Overshared SharePoint information
    Inconsistent controls between facilities
    Failure to document security decisions

    Understanding HIPAA and Microsoft 365 Responsibilities

    The obligations that apply to any specific healthcare organisation depend on whether it is a covered entity or business associate, the services delivered, states of operation, contracts and systems in use. The following is general information and is not legal advice.

    HIPAA Privacy Rule

    The Privacy Rule establishes standards for the use and disclosure of protected health information and provides individual rights relating to that information. In Microsoft 365 this maps to role-based access, minimum-necessary access, external-sharing governance, authorised disclosures, auditability, workforce access management, appropriate retention, access to records, vendor management, and policies and procedures. Microsoft 365 controls support these activities but do not replace the provider's privacy policies, patient-rights processes, authorisations or compliance program.

    HIPAA Security Rule

    • Administrative safeguards: Security-risk analysis, risk-management planning, assigned security responsibility, workforce security, access authorisation, security-awareness training, incident procedures, contingency planning, evaluation, business-associate arrangements, policies and documentation. Mycelium 365 supports Microsoft 365 security assessment, risk and remediation register, responsibility matrix, user-access processes, security configuration documentation, incident-response procedures, backup and recovery planning, scheduled control reviews and security reporting. Customers remain responsible for the formal HIPAA risk analysis, legal interpretation, compliance-program ownership, workforce training and sanctions, policy approval, patient processes and executive risk decisions. A Microsoft 365 technical review alone does not constitute the complete HIPAA risk analysis.
    • Physical safeguards: Facility access considerations, workstation use, workstation security, device and media controls, disposal, reuse and asset accountability. Mycelium 365 supports Microsoft Intune, encryption, device inventory, compliance policies, remote wipe, endpoint security, secure decommissioning and device recovery procedures. Customer-controlled facility and physical-access controls remain the customer's responsibility unless separately contracted.
    • Technical safeguards: Unique user identification, access control, emergency access, automatic logoff, encryption, audit controls, integrity controls, person or entity authentication and transmission security. These map to Microsoft Entra ID, MFA, Conditional Access, PIM, Microsoft Intune, device encryption, session controls, Microsoft Defender, Microsoft Purview, audit logging, DLP, sensitivity labels, secure email, Teams and SharePoint sharing controls, and monitoring and alerting. Required and addressable implementation specifications must be evaluated in the context of the regulated entity's risks and circumstances; addressable does not mean optional or ignorable.

    HIPAA Breach Notification Rule

    Covered entities must assess suspected breaches of unsecured PHI and may have notification obligations to affected individuals, the Department of Health and Human Services and, in certain circumstances, the media. Business associates must notify the covered entity as required. Mycelium 365 supports detection, alert investigation, account containment, session revocation, device isolation, log preservation, technical scoping, timeline development, identification of affected systems, incident documentation, recovery, remediation and coordination with your legal, compliance and executive teams. Mycelium 365 does not make the final legal breach determination unless separately engaged and qualified to do so.

    HITECH Act

    HITECH strengthened privacy, security, breach-notification and enforcement requirements and expanded direct obligations for business associates. Detailed legal interpretation should be obtained from qualified advisers.

    Business Associate Agreements

    A Business Associate Agreement may be required when a service provider creates, receives, maintains or transmits PHI on behalf of a covered entity. A BAA is a contractual and legal component, not a substitute for security controls. The customer must confirm that required agreements are in place with relevant vendors. Microsoft service eligibility, licensing and contractual terms must be verified for the customer's exact services. Mycelium 365's contractual status and handling of PHI is confirmed during scoping — no single agreement covers every Microsoft 365 product or configuration automatically.

    State privacy and breach laws

    State privacy, medical-record, consumer-health-data and breach-notification laws may apply in addition to HIPAA. Requirements can vary by state, provider type, information type, consumer-health application, contract, licensing body, Medicaid or government program, and substance-use-disorder services. A single national Microsoft 365 configuration cannot be presented as satisfying every state law.

    42 CFR Part 2

    Healthcare organisations handling substance-use-disorder records may be subject to additional confidentiality requirements under 42 CFR Part 2. Standard HIPAA controls alone do not automatically satisfy Part 2, and these providers require specific legal and compliance review.

    HIPAA Security Rule changes

    Healthcare organisations should monitor HHS rulemaking and update their security program as regulatory requirements change. Proposed changes are not final law until formally adopted; the current status of any HIPAA Security Rule amendments should be verified using official HHS sources.

    Disclaimer: This content provides general information about technology controls that may support healthcare privacy, security and HIPAA obligations. It is not legal, regulatory or clinical advice. Healthcare organisations should obtain advice appropriate to their regulatory status, services, states of operation and circumstances.

    How Mycelium 365 supports HIPAA-aligned safeguards

    A summary of how Microsoft 365 controls and Mycelium 365 services align with common HIPAA safeguard areas. This mapping is illustrative — each organisation's obligations should be confirmed with qualified advisers.

    HIPAA areaSecurity or privacy objectiveMicrosoft 365 controlMycelium 365 serviceCustomer responsibilityEvidence produced
    Risk managementIdentify and manage risks to ePHIMicrosoft 365 security configuration, Defender risk signalsMicrosoft 365 security assessment, configuration review, prioritised remediation, security roadmapEnterprise-wide HIPAA risk analysis, risk acceptance, clinical and operational assessmentFindings report, risk register, remediation records, review minutes
    Workforce accessUnique identification and access controlEntra ID, MFA, Conditional Access, RBAC, access reviewsUnique accounts, role groups, access approvals, MFA, access reviews, termination workflow, session revocationApproving roles, workforce policies, sanctions, authorised-user decisionsUser reports, group membership, access-review records, offboarding tickets, authentication logs
    Privileged accessLeast privilege for administratorsPIM, separate admin identities, strong authenticationSeparate admin identities, least privilege, PIM, administrator reviews, emergency-access governanceApproving privileged roles, executive oversightAdministrator inventory, role assignments, access logs, review reports
    Device securityProtect endpoints handling ePHIMicrosoft Intune, encryption, compliance policies, endpoint protectionIntune administration, encryption, compliance, patching, MAM, remote wipe, device inventoryDevice procurement decisions, workforce mobility policyCompliance reports, encryption status, patch reports, endpoint alerts, device records
    Audit controlsRecord and examine activity in systems containing ePHIMicrosoft 365 audit, sign-in logs, Defender alerts, mailbox auditingAudit configuration, sign-in logging, security alerts, mailbox auditing, sharing reports, SOC monitoring, log-retention recommendationsApproval of retention periods, review of investigationsAudit logs, investigation records, alert reports, monthly security reports
    Information protectionProtect PHI from unauthorised use or disclosureSensitivity labels, DLP, retention, sharing controlsLabel rollout, DLP tuning, SharePoint permission reviews, external-sharing restrictions, secure email, guest-user governanceInformation classification decisions, records retention approvalDLP incidents, sharing reports, permission reports, label reports, policy configurations
    Transmission securityProtect ePHI in transitEncryption, domain authentication, Conditional AccessSecure Microsoft 365 communication configuration, encryption controls, domain security, approved sharing methods, restrictions on legacy authenticationApproving mail-flow rules, third-party sharing decisionsConfiguration records, authentication reports, mail-flow reports, policy settings
    Availability and contingency planningRecover ePHI and Microsoft 365 servicesIndependent backup, recovery proceduresIndependent Microsoft 365 backup, recovery testing, administrative recovery, incident-response support, configuration documentationClinical downtime procedures, patient-safety planning, emergency operations, business-continuity approvalBackup reports, test results, restoration records, recovery documentation
    Incident responseDetect, contain and recover from security incidentsDefender, SOC monitoring, identity risk, endpoint alertsMonitoring, triage, investigation, containment, log preservation, recovery, remediation, technical reportingLegal determinations, regulatory notifications, patient notifications, media notifications, law-enforcement decisions, compliance sign-offAlert records, incident timelines, investigation and remediation reports

    What our managed Microsoft 365 service includes

    An ongoing management, security, cybersecurity and continuous-improvement program for healthcare — not one-off technical support.

    Microsoft 365 administration

    • Users, licences, Exchange Online and Teams
    • SharePoint, OneDrive and Entra ID
    • Intune and security policies
    • Administrative governance and change management
    • Service health and support

    Identity and access management

    • Multi-factor authentication and Conditional Access
    • Privileged access and risk-based sign-ins
    • Guest access, access reviews and session controls
    • Restrictions on legacy authentication
    • Emergency-access account governance

    User onboarding and termination

    • Standardised account creation and role-based licensing
    • Device setup and secure access configuration
    • Timely account disablement and session revocation
    • Mailbox retention and file ownership transfer
    • Device recovery procedures

    Endpoint and device management

    • Microsoft Intune for Windows, macOS, iOS and Android
    • Encryption, compliance and screen-lock policies
    • Patching and endpoint protection
    • BYOD and mobile application management
    • Remote wipe and lost-device response

    Information protection

    • Sensitivity labels and data loss prevention
    • Retention policies and audit configuration
    • SharePoint and OneDrive permission reviews
    • External sharing and guest-user governance
    • Oversharing remediation

    Email and collaboration security

    • Anti-phishing, Safe Links and Safe Attachments
    • Impersonation protection and domain authentication
    • Mailbox auditing and shared-mailbox governance
    • Teams security and external-sharing controls
    • Referral and inter-provider communication protection

    Managed cybersecurity and SOC

    • Microsoft Defender and identity monitoring
    • Endpoint alert monitoring
    • Managed SOC, triage and investigation
    • Containment, log preservation and remediation
    • Incident documentation and reporting

    Backup and recovery

    • Independent Microsoft 365 backup
    • Exchange Online, SharePoint, OneDrive and Teams protection
    • Recovery testing and restoration procedures
    • Long-term retention options
    • Protection against ransomware and accidental deletion

    Reporting and governance

    • Monthly service and security posture reporting
    • Access and device-compliance reviews
    • Risk register and remediation tracking
    • Licence optimisation and technology roadmap
    • Executive reporting

    Backup services complement — but do not replace — Microsoft platform resilience and native retention. Independent backup adds protection against accidental deletion, ransomware, malicious activity and long-term recovery needs.

    Healthcare-specific use cases

    Securing physician and administrative mailboxes
    Protecting referral information
    Managing workforce access
    Rapid termination of departed workforce members
    Protecting mobile devices used by clinicians
    Supporting remote clinicians and telehealth staff
    Managing temporary and contract workforce
    Controlling third-party billing access
    Securing multi-location and multi-state collaboration
    Supporting practice acquisitions
    Standardising controls across states and facilities
    Recovering deleted mailboxes, files and Teams data
    Reducing email-based fraud and impersonation
    Protecting HR and payroll information
    Reviewing EHR and practice-management integrations
    Preparing for ransomware and account compromise

    Microsoft Copilot and AI governance

    Copilot and other AI tools can expose overshared or poorly governed information and introduce new PHI-handling risks. Mycelium 365 helps healthcare organisations prepare responsibly by:

    SharePoint and OneDrive permission reviews
    Data classification and sensitivity labelling
    AI acceptable-use policies
    Approved application controls and pilot groups
    Licence governance and configuration
    Data loss prevention for AI interactions
    Staff awareness, monitoring and adoption reporting
    Restrictions on PHI in unapproved AI tools

    General-purpose Microsoft 365 Copilot should not be used to diagnose patients, determine treatment or replace clinical judgment.

    Why Mycelium 365

    Mycelium 365 helps United States healthcare organisations translate security, privacy and operational requirements into practical Microsoft 365 controls. We manage and monitor the technology and provide supporting evidence, while each healthcare organisation retains responsibility for its HIPAA compliance program, policies, workforce, legal decisions and patient obligations.

    • On-the-ground resources across the United States
    • Security by design
    • Managed services rather than reactive support
    • Microsoft 365 expertise
    • HIPAA-supporting safeguards
    • Managed cybersecurity and SOC
    • Evidence and reporting
    • Multi-location delivery
    • Centralised governance
    • Continuous improvement

    Our service approach

    A repeatable five-step model that scales from a single practice to a multi-state healthcare group.

    1

    Discover

    • Microsoft 365 environment, users, devices and administrators
    • Licences, sharing, security controls and backups
    • EHR and practice-management integrations
    • Regulatory, contractual and policy context
    2

    Assess

    • Risk findings and control-gap analysis
    • Priority remediation plan
    • Responsibility matrix
    • HIPAA safeguard mapping and roadmap
    3

    Secure

    • Identity, device, email and information controls
    • Backup, logging and monitoring
    • Administrative governance
    • Documented configurations and evidence
    4

    Manage

    • Administration, support, onboarding and termination
    • Monitoring, incident response and backup oversight
    • Reporting and control reviews
    • Multi-location coordination
    5

    Improve

    • Security and HIPAA-support reviews
    • Trend analysis and remediation tracking
    • Licence optimisation and user feedback
    • Technology roadmap and continuous improvement

    Does Your Microsoft 365 Environment Support Your HIPAA Obligations?

    Microsoft 365 can provide strong security and compliance capabilities, but those capabilities must be appropriately licensed, configured, governed, monitored and used.

    Mycelium 365 can assess your environment, identify priority risks and establish a practical roadmap for HIPAA-supporting Microsoft 365 safeguards.

    Frequently asked questions

    Is Microsoft 365 HIPAA compliant?+

    Microsoft 365 includes services and security capabilities that can be used within a HIPAA compliance program when the appropriate services, licensing, contractual arrangements and safeguards are in place. Compliance depends on how the healthcare organisation configures and uses the platform, manages its workforce, handles PHI and fulfils its broader legal obligations.

    Does Microsoft sign a Business Associate Agreement?+

    Microsoft offers a HIPAA Business Associate Agreement (BAA) for eligible services and customers. Coverage depends on the specific Microsoft services in use, licensing and how the environment is configured. Each customer should verify the current BAA scope, terms and eligible services directly with Microsoft.

    Does a BAA make Microsoft 365 compliant?+

    No. A BAA is a contractual and legal component of a compliance program, not a substitute for security controls. Even with a BAA in place, the covered entity or business associate must still configure, govern, monitor and use Microsoft 365 in line with HIPAA and its own policies.

    What are HIPAA administrative safeguards?+

    Administrative safeguards are policies and procedures that manage the selection, development, implementation and maintenance of security measures to protect ePHI — including risk analysis, risk management, assigned security responsibility, workforce security, security awareness and training, incident procedures, contingency planning, evaluation, business-associate arrangements and documentation.

    What are HIPAA physical safeguards?+

    Physical safeguards address the physical protection of information systems and related buildings and equipment — including facility access controls, workstation use and security, and device and media controls covering disposal, reuse, accountability and backup.

    What are HIPAA technical safeguards?+

    Technical safeguards address the technology and related policies used to protect ePHI and control access — including access control, audit controls, integrity, person or entity authentication and transmission security. Required and addressable implementation specifications must be evaluated in the context of the entity's risks and circumstances.

    How does Microsoft 365 support access control?+

    Microsoft Entra ID provides unique user identification, authentication and authorisation. Conditional Access, MFA, Privileged Identity Management, role-based groups, access reviews and session controls help enforce least privilege and support HIPAA access-control requirements.

    How can Microsoft Intune protect healthcare devices?+

    Microsoft Intune can enforce encryption, screen-lock, compliance and update policies on Windows, macOS, iOS and Android devices, deploy applications, protect ePHI in mobile apps for both corporate and personal devices, and support remote wipe of lost or stolen devices.

    Does HIPAA require multi-factor authentication?+

    HIPAA does not name specific technologies, but authentication and access-control safeguards are required. MFA is a widely accepted control to help address these requirements and is consistent with current guidance and healthcare cybersecurity practices.

    Does HIPAA require encryption?+

    Encryption is an addressable implementation specification under the Security Rule, meaning covered entities and business associates must assess it in the context of their risks and either implement it, adopt an equivalent alternative or document why it is not reasonable and appropriate. In practice, encryption of ePHI at rest and in transit is a common expectation.

    Do healthcare providers need Microsoft 365 backups?+

    Microsoft provides service availability and short-term retention, but this is not a substitute for independent backup. A dedicated Microsoft 365 backup service protects Exchange Online, SharePoint, OneDrive and Teams-related data against accidental deletion, ransomware, malicious activity and long-term recovery needs.

    How should terminated workforce access be removed?+

    Access should be disabled promptly on termination, active sessions revoked, MFA and app passwords reset, mailboxes and files retained per policy, and devices recovered or remotely wiped. Standardised, ticketed offboarding produces evidence that supports HIPAA workforce security requirements.

    Can Mycelium 365 guarantee HIPAA compliance?+

    No technology provider can independently guarantee a healthcare organisation's HIPAA compliance. Mycelium 365 helps implement, manage and document Microsoft 365 safeguards that support HIPAA requirements. The healthcare organisation remains responsible for its compliance program, risk analysis, policies, workforce practices, patient rights and legal decisions.

    Can you support multi-state healthcare groups?+

    Yes. Mycelium 365 standardises Microsoft 365 administration, identity, device management, security and support across multiple facilities and states, with consistent policies, common reporting and coordinated response, while recognising legitimate differences between locations.

    Can you help prepare for a HIPAA breach investigation?+

    Mycelium 365 supports detection, alert investigation, account containment, session revocation, device isolation, log preservation, technical scoping, timeline development, identification of affected systems, incident documentation, recovery and remediation, and coordinates with your legal, compliance and executive teams. Legal breach determinations rest with the covered entity and its advisers.

    Does 42 CFR Part 2 apply to our organisation?+

    42 CFR Part 2 imposes additional confidentiality requirements on providers that hold substance-use-disorder records from federally assisted programs. Standard HIPAA controls alone do not automatically satisfy Part 2. Providers should seek specific legal and compliance review.

    Do state privacy laws apply in addition to HIPAA?+

    Yes, potentially. State privacy, medical-record, consumer-health-data and breach-notification laws may apply in addition to HIPAA and can vary by state, provider type, information type, contract, licensing body and program. A single national Microsoft 365 configuration cannot be presented as satisfying every state law.

    Can Microsoft Copilot be used with PHI?+

    Microsoft 365 Copilot operates against content the user can already access, so poorly governed SharePoint or OneDrive permissions can expose PHI through Copilot responses. Copilot use with PHI requires appropriate licensing, contractual coverage, permission remediation, data classification, DLP, acceptable-use policies, human oversight and monitoring. General-purpose Copilot should not be used to diagnose patients or determine treatment.

    What evidence can you provide for a security review?+

    Depending on the services engaged, Mycelium 365 can provide access-review reports, sign-in and audit logs, Conditional Access configuration, device compliance and patch status, DLP and sharing reports, backup and recovery-test records, incident timelines, remediation records and monthly service reporting.

    Can you work with our EHR provider?+

    Microsoft 365 can be managed alongside EHR and practice-management systems. Mycelium 365 reviews integrations for identity, security, access and data-protection risks so those systems remain safely connected, while the EHR vendor remains responsible for its own software and configuration.

    Authoritative sources

    • US Department of Health and Human Services (HHS)
    • HHS Office for Civil Rights (OCR) — HIPAA Privacy, Security and Breach Notification Rule guidance
    • Substance Abuse and Mental Health Services Administration (SAMHSA) — 42 CFR Part 2 guidance
    • State attorneys general and state health departments for applicable state privacy and breach laws

    Verify the current legal status and effective dates of any recently proposed or final HIPAA rule changes using official HHS sources before making compliance decisions.

    Related services

    This page covers the US healthcare vertical. For our United States presence generally — including Cori Avery, who is based in Florida and supports US clients in their local timezone — see Microsoft 365 support in Florida.