Healthcare organizations use Microsoft 365 for email, files, collaboration, identity, and administration. That concentration makes the tenant operationally valuable—and a frequent target for phishing, password theft, consent abuse, inbox-rule manipulation, and data exfiltration.
HHS explains that using a cloud service for ePHI can be permissible when the relationship and environment meet applicable HIPAA requirements, including an appropriate Business Associate Agreement where required. Microsoft also publishes HIPAA-oriented access-control guidance. Neither source says that buying the service makes an organization compliant by itself.
1. Protect every identity
- Require MFA for all users, including administrators and contractors.
- Use phishing-resistant authentication for privileged and high-risk roles where supported.
- Block legacy authentication and other paths that bypass modern controls.
- Maintain separate administrative accounts for privileged work.
- Protect emergency access accounts with documented monitoring and testing.
- Review risky sign-ins, disabled users, stale accounts, and authentication-method changes.
2. Apply Conditional Access deliberately
Conditional Access can evaluate user, device, application, location, and sign-in risk before allowing access. Start in report-only mode, exclude carefully controlled emergency accounts, test critical workflows, and document why each policy exists.
Common policies require MFA, block legacy authentication, restrict administrator access, require compliant devices for sensitive apps, and challenge or block risky sign-ins. Licensing and clinical workflow requirements vary, so design policies against the actual tenant rather than copying a generic template.
3. Reduce standing privilege
- Assign the least-permissive built-in role that supports each task.
- Limit Global Administrator assignments and review them regularly.
- Use time-bound or approval-based privilege where licensing supports it.
- Separate tenant administration from routine email and web use.
- Review application registrations, service principals, delegated permissions, and third-party consent.
4. Harden email and collaboration
- Configure SPF, DKIM, and DMARC for every sending domain.
- Use anti-phishing, impersonation, attachment, and link protections appropriate to risk.
- Limit automatic external forwarding and alert on suspicious forwarding rules.
- Train staff to report suspicious messages through a defined workflow.
- Review external sharing defaults for SharePoint, OneDrive, and Teams.
- Use sensitivity, retention, and data-loss controls where they match documented requirements.
5. Connect device trust to access
A valid password and MFA prompt do not prove that a device is healthy. Maintain an inventory, encrypt supported devices, apply security updates, deploy endpoint protection, remove local administrator rights where practical, and define what qualifies as a compliant device.
For personally owned devices, document whether access is allowed, which applications may store organizational data, how data is separated, and what happens when a device is lost or a user leaves.
6. Turn on useful logging and alert ownership
Confirm that audit, sign-in, mailbox, administrative, and security events needed for your risk and response process are available and retained long enough. Licensing affects features and retention, so document what the organization can investigate.
Assign an owner and escalation path for high-risk sign-ins, new administrative roles, suspicious inbox rules, unusual forwarding, mass downloads, application consent, disabled security controls, and emergency-account use. Alerts without a response owner become background noise.
7. Control onboarding and offboarding
- Use unique accounts tied to an approved role and manager.
- Apply group-based access instead of one-off permissions where practical.
- Review access when roles or locations change.
- Immediately block sign-in, revoke sessions, remove tokens, and recover devices at termination.
- Preserve or transfer business records according to approved retention and legal requirements.
8. Test a cloud account-compromise playbook
- Confirm the alert through a trusted channel.
- Disable or restrict the account and revoke active sessions and tokens.
- Reset credentials and review authentication methods.
- Inspect sign-ins, inbox rules, forwarding, delegated access, consent grants, downloads, and administrative changes.
- Determine whether ePHI or other sensitive information was accessed or disclosed.
- Coordinate security, privacy, legal, insurance, and notification decisions.
- Document the timeline, evidence, decisions, recovery, and lessons learned.
Authoritative resources
- Microsoft: Configure Entra HIPAA Access Control Safeguards
- Microsoft: Zero Trust Identity Deployment Guidance
- HHS: Guidance on HIPAA and Cloud Computing
- CISA: Require Multifactor Authentication
This article is educational and does not constitute legal advice, Microsoft licensing advice, or a guarantee of security or compliance. Validate controls against current licensing and organizational requirements.


