Is Microsoft Copilot HIPAA Compliant?
Closer to yes than most AI tools, and that is exactly why it needs a harder look. The compliance question is not the model. It is your tenant.
The Verdict
Microsoft 365 Copilot can operate under HIPAA. It is named in Microsoft's HIPAA in-scope services list, and the BAA is available by default through the Online Services Data Protection Addendum. The free consumer Copilot cannot. Between those two sentences sits the risk most organizations miss.
Copilot surfaces whatever the signed-in user can already access, so every permission mistake in your tenant becomes an AI-powered disclosure engine.
| Version | BAA coverage | Trains on your data | Verdict for PHI |
|---|---|---|---|
| Copilot (free, consumer, personal accounts) | No | Consumer terms apply | Never |
| Microsoft 365 Copilot Chat with enterprise data protection (Entra ID sign-in) | In Microsoft's HIPAA in-scope list; web search queries excluded | No | Conditional; keep web-grounded queries away from PHI |
| Microsoft 365 Copilot (paid, tenant-integrated) | Yes: named in the HIPAA in-scope services list under the DPA/BAA | No | Possible, with tenant controls in place |
| Microsoft Dragon Copilot (formerly DAX Copilot, ambient clinical documentation) | Vendor states "built to support HIPAA-compliant standards"; confirm coverage in your agreement | De-identified data used for model improvement | Purpose-built for clinical use; verify in contract |
The Consumer Trap
Staff with a personal Microsoft account get a Copilot that looks identical to the enterprise one and carries none of its protections. Your policy has to name the difference, because the icon will not.
The Real Risk Is Not the Model
Five tenant realities that decide whether your Copilot deployment survives an audit
Copilot inherits your permission sprawl
It answers from everything the user can technically access: the HR spreadsheet shared to "everyone" in 2021, the patient complaint log in an open SharePoint site. Copilot did not create the exposure. It industrialized the discovery of it.
"Can access" and "should access" are different audits
Most tenants have never reconciled the two. Copilot makes the gap searchable in natural language.
PHI moves between M365 surfaces
A summary generated in a Teams chat from a clinical document is a new copy of PHI in a new location, with its own retention and sharing questions.
The audit answer lives in Purview
Microsoft logs Copilot interactions automatically under Audit (Standard) once tenant auditing is enabled. Verify your tenant's auditing is on and retention matches your policy before you assert coverage to an auditor.
A BAA does not fix any of this
Microsoft's paper covers Microsoft's conduct. Your permission model, labeling, and monitoring are your side of the deal, and OCR audits your side.
Before You Turn It On
The organizations that deploy Copilot safely do the unglamorous work first: a permissions review of the sites and shares Copilot will read, sensitivity labels on PHI-bearing locations, Purview audit configuration, and a policy that names which roles get Copilot and for what. The ones that skip it are running a natural-language search engine over every mistake in their tenant.
Where Copilot fits against the other enterprise AI options, including multi-model alternatives: the independent platform comparison.
Copilot and HIPAA: Common Questions
Does Microsoft sign a BAA that covers Copilot?
Yes. Microsoft's HIPAA in-scope services list names Microsoft 365 Copilot and Copilot Chat explicitly, and the BAA is available by default through the Online Services Data Protection Addendum. One documented carve-out: HIPAA compliance does not apply to web search queries, which fall outside the DPA and BAA.
Is the free Copilot HIPAA compliant?
No. Consumer Copilot has no BAA path and no tenant controls. Treat it exactly like consumer ChatGPT with patient information, which is to say never.
Does Copilot train on our data?
Microsoft states that Microsoft 365 Copilot does not use your tenant data to train foundation models. With Copilot, the exposure question is access, not training.
Can clinicians use Copilot for clinical notes?
M365 Copilot is a productivity assistant, not a clinical documentation tool. For ambient clinical documentation, Microsoft's purpose-built product is Dragon Copilot (formerly DAX Copilot). Keep the two use cases in separate policy lanes.
We already have the Microsoft BAA. Are we done?
No. The BAA covers Microsoft. Your permission model, your labels, your audit configuration, and your workforce policy are what an investigator will ask about first.
The Policy Question Comes Before the License Question
Whether it is Copilot, ChatGPT, or both, the first control is a policy your staff can follow. Generate a healthcare-ready draft in minutes, then decide which tools earn a place in it.