An Azure offering that provides a suite of purpose-built technologies for protected health information in the cloud.
Welcome to Microsoft Q&A
Hello @Yamara Pinon I hope you are doing well,
Azure OpenAI Service is listed as a HIPAA‑eligible service in the Microsoft Trust Center. That means when your tenant has a signed Business Associate Agreement (BAA) with Microsoft, workloads using Azure OpenAI — including GPT‑4o — are covered under HIPAA. Eligibility is defined at the service level, not per model. If GPT‑4o is available in Azure OpenAI, it inherits the service’s HIPAA compliance status.
Regional Deployment East US and East US 2 are HIPAA‑eligible regions for Azure OpenAI workloads. Deploying GPT‑4o in those regions for text‑based PHI processing is supported, provided your organization’s BAA is active. You can confirm GPT‑4o availability in those regions via the Azure OpenAI model availability documentation.
Documentation Confirmation There is no separate HIPAA eligibility matrix per model. Instead, HIPAA eligibility is tied to the Azure OpenAI Service itself. GPT‑4o is listed in the model availability tables, and the service is HIPAA‑eligible under the BAA. This is the official confirmation you can cite in your architecture documentation.
Short answer: There is no separate Microsoft document that names GPT‑4o explicitly as “HIPAA‑eligible”; instead Microsoft treats HIPAA eligibility at the service level — Azure OpenAI Service
Architectural Recommendation
Ensure your tenant has a signed BAA with Microsoft.
Deploy GPT‑4o in East US or East US 2 where HIPAA support is documented.
- Validate with your compliance officer and Microsoft account team before production rollout.
😊 If my answer helped you resolve your compliance planning, please consider marking it as the correct answer. This helps others in the community find solutions more easily. Thanks!