An Azure offering that provides a suite of purpose-built technologies for protected health information in the cloud.
- HIPAA eligibility for Azure OpenAI (including GPT‑4o) is determined at the service/feature and region level, not per individual model name in isolation. A workload is HIPAA-eligible only when:
- It runs in an Azure region where the required Azure AI/OpenAI features are listed as supported for HIPAA-covered workloads, and
- It is covered under a signed Microsoft Business Associate Agreement (BAA) for the tenant.
- The context does not state that GPT‑4o in Azure OpenAI Service, in East US or East US 2, is approved for processing PHI in production. It only shows that various AI/ML features (for example, Model Serving, AI Gateway, AI Guardrail, Vector Search, etc.) have HIPAA regional support across many regions, including East US and East US 2, but it does not map those entries specifically to Azure OpenAI GPT‑4o usage. As a result, based on the context alone, there is no definitive confirmation that GPT‑4o in East US/East US 2 can be used today for PHI processing in production.
- The context does not contain any official documentation statement that explicitly names GPT‑4o as HIPAA-eligible. It only provides:
- A model availability table for Azure OpenAI models (including GPT‑4o) by region.
- Separate HIPAA “Regional support for features” tables for Azure Databricks capabilities.
For authoritative confirmation on:
- Whether Azure OpenAI (and specifically GPT‑4o) is in-scope for HIPAA under the Microsoft BAA, and
- Whether East US / East US 2 deployments of GPT‑4o are approved for PHI,
the correct path is to:
- Review the official Azure OpenAI and HIPAA/BAA documentation in the Microsoft Trust Center and Azure compliance documentation, and
- If still unclear, open a formal Microsoft support request or work with the organization’s Microsoft account team to obtain written confirmation for compliance and production use with PHI.
References: