Justin McKelvey
Fractional CTO · 15 years, 50+ products shipped
Is Microsoft Copilot HIPAA Compliant in 2026? Yes — Except the Part That Searches the Web
Quick Answer
Mostly yes — and the contract is the easy part. Microsoft lists Microsoft 365 Copilot and Copilot Chat as HIPAA in-scope services, and its BAA is delivered by default through the Data Protection Addendum you already accepted — no signature, no sales call, no extra fee. Two things sit outside it: web search queries (Microsoft's own footnote) and your SharePoint permissions, which Copilot inherits on purpose. Consumer Copilot and GitHub Copilot are not on the list.
Verified September 2026 against Microsoft's own HIPAA/HITECH compliance offering and Copilot enterprise-data-protection documentation · Author: Justin McKelvey, fractional CTO & AI consultant, 15 years in software, 50+ products shipped
I wrote about whether Claude is HIPAA compliant earlier today, and the answer there was uncomfortable: the plans a small practice actually buys — Claude Team, self-serve ChatGPT Business — are the ones excluded from a BAA. Pay more, get nothing.
Microsoft is the opposite story, and almost nobody believes me the first time I say it.
Microsoft already signed. That's the part nobody believes.
Anthropic and OpenAI both put a BAA behind a sales conversation. Microsoft doesn't. From Microsoft's own HIPAA compliance documentation:
The Microsoft HIPAA Business Associate Agreement is available through the Microsoft Online Services Data Protection Addendum by default to all customers who are covered entities or business associates under HIPAA.
By default. No request form. No signature ceremony. No line item. If you bought a commercial Microsoft 365 subscription, you accepted the Data Protection Addendum at purchase, and the BAA came with it.
I've now watched three practices sign expensive enterprise AI agreements with other vendors while sitting on an unused, already-executed Microsoft BAA covering a tool their staff was using anyway. That is a genuinely expensive misunderstanding, and it happens because everyone reasons from the Anthropic/OpenAI model — compliance is the premium tier — and Microsoft simply doesn't work that way.
What's actually in scope, and the two names that matter
Microsoft publishes an explicit list of HIPAA in-scope services. For Office 365 Commercial, the list names, among others:
- Microsoft 365 Copilot
- Microsoft 365 Copilot Chat
- Exchange Online, SharePoint Online, OneDrive for Business, Microsoft Teams, Power Automate, Power Apps, Power BI
Both Copilot entries appear again in Microsoft's GCC table. Microsoft Copilot for Security is listed separately on the platform-level list.
One naming note before you go looking, because it will confuse you otherwise: Microsoft renamed these in 2026. Microsoft 365 Copilot is now just Microsoft Copilot, and Microsoft 365 Copilot Chat is now Microsoft Copilot Chat. Microsoft's own documentation says licences and interfaces may still show the old names during the transition, and that nothing about security, compliance or privacy changed in the rename. So if your admin centre says one thing and the compliance page says another, they are the same product.
Microsoft 365 Copilot runs $30/user/month on top of a qualifying Microsoft 365 subscription. That's the price of the licence, not the price of compliance — the BAA costs nothing extra, which is the whole point of this page.
The exclusion Microsoft prints in a footnote
Here is the sentence worth the entire article, and Microsoft puts it in footnote two of a page most people never open:
Microsoft Copilot and Microsoft Copilot Chat support HIPAA compliance for properly configured implementations. HIPAA compliance doesn't apply to web search queries as they aren't covered by the DPA and Business Associate Agreement (BAA).
Copilot doesn't only answer from your tenant. To ground answers in current information it can generate a short search query from your prompt and send it to the Bing search service. And Microsoft is unusually clear about what happens at that boundary: the Bing search service "operates separately from Microsoft 365," is governed by the Microsoft Services Agreement between each user and Microsoft, and in that context Microsoft "acts as an independent data controller" — not as a processor following your instructions.
To be fair about what Microsoft does commit to here: it says those queries are sent over a secure connection with user and tenant identifiers removed, aren't shared with advertisers, and aren't used to train its foundation models. Those are real protections. They are also not a BAA.
So the practical risk isn't abstract. It's a front-desk staffer typing "what does this denial code mean for Maria Delgado's claim" into Copilot and Copilot deciding the answer needs a web lookup. The identifiers Microsoft strips are the tenant and user ones. The prompt text is what the query is generated from.
The fix is a setting, and it takes an admin about ten minutes. Microsoft lets you control Copilot's access to public web content at the tenant or group level. For any group that touches PHI, turn it off. You lose current-events grounding, which almost no clinical-adjacent workflow needs, and you close the one gap Microsoft explicitly tells you is outside your BAA.
Copilot inherits your permissions, which is where the real breach lives
The second exposure isn't in the contract either, and it's the one I'd actually lose sleep over.
Microsoft's design commitment is that "Copilot respects your identity model and permissions, inherits your sensitivity labels, applies your retention policies." Read as a security promise, that's excellent: Copilot cannot show a user anything that user couldn't already open.
Read as a risk statement, it's a warning. Copilot doesn't create new exposure — it makes existing exposure findable. The overshared SharePoint site from a 2021 migration. The "Everyone except external users" permission somebody applied to a folder to unblock a deadline. The Teams recording of a case discussion sitting in a channel half the practice can read.
None of that was a HIPAA incident while it was buried under four clicks and nobody knew the path. Copilot is a search engine over exactly that material, run in natural language by staff who have no idea what they're allowed to find. A BAA does not touch this. It is entirely, permanently yours.
The micro-action, and you can do it this afternoon: pick the three SharePoint sites or Teams channels most likely to contain PHI, open the permissions on each, and answer one question — can anyone see this who has no clinical reason to? That's a fifteen-minute check that tells you whether Copilot is a compliance tool or a discovery engine pointed at your own back office.
The Copilots that are not this Copilot
"Copilot" is now the brand name on several unrelated Microsoft products, and people assume the compliance answer travels with the word. It does not.
- GitHub Copilot — a different product under different terms, not named on Microsoft's HIPAA in-scope list. Treat that absence as a no. Realistically this matters less than it sounds, since PHI shouldn't be in your source code either way — but I've seen it in test fixtures more than once. (If you're comparing coding assistants rather than office ones, that's GitHub Copilot vs Claude Code.)
- Consumer Copilot — the free web version, and Copilot on Microsoft 365 Personal or Family. Microsoft's BAA runs to commercial customers through the DPA. A consumer subscription isn't one. This is the solo-practitioner trap: same interface, same logo, no contract underneath.
- Copilot Studio agents — Microsoft's guidance is to check each agent's own privacy statement and terms, because an agent may route your data somewhere the base product doesn't. Don't assume an agent inherits Copilot's coverage.
Microsoft won't sign your BAA, and won't call it compliance either
Two more things Microsoft states plainly, both of which get misread in opposite directions.
First: Microsoft will not accept your BAA template. Its own words — "Microsoft can't use a customer's Business Associate Agreement" — because it runs one standardised hyperscale service for everyone. If your compliance counsel's process is "send our BAA to the vendor," that process terminates here. You take Microsoft's, which was drafted with a consortium of academic medical centres, or you take nothing.
Second, and this is where the easy-BAA story stops being good news: "By offering a Business Associate Agreement, Microsoft helps support your HIPAA compliance. However, using Microsoft services doesn't on its own achieve HIPAA compliance."
Everything on your side of the line survives the contract intact — access control, minimum necessary, staff training, breach detection and notification, and a written policy naming which tools are approved for what. And with Copilot, the access-control half carries far more weight than it does with a standalone chatbot, precisely because Copilot is wired into everything you already store.
What I tell owners
The Microsoft answer is the good one, and that's exactly what makes it dangerous.
With Claude or ChatGPT, the contract question is a wall. You hit it, you can't get past it, and the wall makes you think. With Microsoft you walk straight through — the BAA is already there, Copilot is on the list, nothing blocks you — and so the thinking never happens. I have never once seen a practice that discovered its Microsoft BAA also go and audit its SharePoint permissions in the same week.
So the order I'd actually work in, and it is not the order the question implies:
- Confirm you're on commercial Microsoft 365, not consumer. Thirty seconds. Decides whether any of the rest applies.
- Turn off Copilot's public web access for any group touching PHI. Ten minutes. Closes the one gap Microsoft names in writing.
- Audit permissions on the three sites most likely to hold PHI. An afternoon. This is the real one.
- Write down which tools are approved for what — including the ones on people's phones, which is where the actual breach comes from.
- Then ask whether you need a different AI vendor at all. Usually you don't, and that's the cheapest finding in the list.
If you'd rather not sequence that yourself, the AI Readiness Assessment ($2,500 flat — two weeks, a written roadmap, fee credited against a build within 90 days) is this exercise done properly: which processes, in what order, on which tools, with the governance written down instead of assumed. The do-it-yourself version is the CFSB Playbook ($397). If you want to talk through one practice, that's what strategy calls are for. And if you're weighing Copilot against Claude for general business work rather than compliance, that comparison is here.
Said plainly rather than hedged: this is a technology explainer written by a fractional CTO who implements these systems, not legal advice. Use it to ask your compliance counsel a sharper question than "is Copilot okay?" — try "our Microsoft BAA covers Copilot, so who turned off public web access for the clinical group, and when did we last audit SharePoint permissions?" That one has an answer, and if nobody has it, you've found your actual problem.
Next step Get the free repo audit →
What your AI stack actually costs
Prices changed 3x this year. The always-current cost sheet: sticker price vs what heavy use actually costs for Cursor, Claude, Replit, Lovable, Bolt & more.
Frequently Asked Questions
- Is Microsoft Copilot HIPAA compliant?
- Microsoft 365 Copilot can be, and the contract side is easier than with any other major AI vendor. Microsoft names both Microsoft 365 Copilot and Microsoft 365 Copilot Chat on its published list of HIPAA in-scope services, and its HIPAA Business Associate Agreement is offered through the Microsoft Online Services Data Protection Addendum by default to every commercial customer who is a covered entity or business associate. There is no request form, no sales call and no extra fee. But 'compliant' still isn't a property Copilot has — Microsoft's own wording is that Copilot supports HIPAA compliance for properly configured implementations, and two specific things fall outside that: web search queries, and whatever your SharePoint permissions are already exposing.
- Do I need to sign a separate BAA with Microsoft?
- No, and this is the single most common thing practices get wrong in the helpful direction. Microsoft's HIPAA BAA is delivered through the Data Protection Addendum that every commercial customer already accepted at purchase. You do not sign anything additional, you do not contact sales, and you do not pay more. That is the opposite of Anthropic and OpenAI, both of which gate a BAA behind a sales-assisted enterprise plan. The practical consequence: a lot of practices are paying for an enterprise AI contract they didn't need because they assumed Microsoft worked the same way as everyone else.
- Does Copilot's web search break HIPAA?
- It sits outside the BAA, which is not the same as breaking HIPAA but is the thing to actually manage. Microsoft states in a footnote that HIPAA compliance doesn't apply to web search queries because they aren't covered by the DPA and BAA. When Copilot grounds an answer in the web, it generates a short query and sends it to the Bing search service — which Microsoft says operates separately from Microsoft 365, under the Microsoft Services Agreement, with Microsoft acting as an independent data controller rather than as your processor. Microsoft does say user and tenant identifiers are stripped. The query text itself is still derived from the prompt. If the prompt contained a patient's name, that's the leg to worry about, and it's the one an admin can switch off.
- Is GitHub Copilot HIPAA compliant?
- GitHub Copilot is a different product from Microsoft 365 Copilot, sold under different terms, and it is not named on Microsoft's published HIPAA in-scope services list. Treat that absence as a no until someone shows you otherwise in writing. It matters more than it sounds, because 'Copilot' is now the brand name on at least four unrelated Microsoft products, and people reason about them as if the compliance answer travels with the word. It doesn't.
- Can I use Copilot on Microsoft 365 Personal or Family with patient data?
- No. Microsoft's HIPAA BAA is offered to commercial customers through the Data Protection Addendum, and a consumer Microsoft 365 subscription is not a commercial agreement — there is no BAA in it to rely on. This catches solo practitioners more than anyone, because a one-person practice often runs on a personal Microsoft account that has quietly acquired a Copilot subscription. The tool looks identical. The contract underneath it is not.
- If Microsoft signed a BAA, is my practice compliant?
- No, and Microsoft says so itself: offering a BAA helps support your compliance, but using Microsoft services doesn't on its own achieve it. Microsoft also won't sign your BAA — it only offers its own, because it runs one standardised multi-tenant service for everyone. Everything on your side of the line is still yours: who can open which SharePoint site, whether the prompt needed the patient's name, staff training, breach detection, and a written policy naming which tools are approved for what. With Copilot the access-control half is unusually load-bearing, because Copilot deliberately inherits your existing permissions.
More on AI for Business
Is Claude HIPAA Compliant in 2026? Not on the Plan You're Probably Using
No AI model is HIPAA compliant. A signed Business Associate Agreement is — and Anthropic won't sign one for Claude Pro, Max, Team, or self-serve Enterprise. Here's exactly which tiers of Claude and ChatGPT are covered, which ones aren't, and why the business plan you bought is probably the wrong one.
Claude Usage Limits in 2026: There Is No Number, and That's the Answer
Anthropic doesn't publish a message count for any Claude plan — not Free, not Pro, not Max. What it publishes are multipliers and two meters. Here's how the 5-hour window and the weekly cap actually work, what each tier is reported to get, and what to do the third time you hit the wall.
Is n8n Free? Yes — If You're Willing to Be the Sysadmin (2026)
Yes, genuinely — n8n's self-hosted Community Edition is free with unlimited executions, which almost nothing else in automation offers. The bill just moves somewhere else. Here's what free costs in practice, what n8n Cloud runs, and how to tell which one you actually want.
Is DeepSeek Free? Yes — And That's the Part to Think About (2026)
Yes. DeepSeek's chat app is free with no paid tier at all — no Plus, no Pro, nothing to upgrade to. That's rarer than it sounds, and it's why the interesting question isn't the price. Here's what free actually costs a business, and the one version of DeepSeek that's free AND private.
Written by
Justin McKelvey
Fractional CTO & AI consultant in Austin, TX. 15 years building software, 50+ products shipped, $53M+ in client revenue generated. I help $1M–$50M founders ship production software and automate operations with AI — without hiring a full-time executive team.
Work with me