Azure HIPAA

Kevin Meyer 0 Reputation points
2026-08-04T17:40:15.6433333+00:00

I would like to use Azure for HIPAA services. How can I get a BAA to cover the services specifically the OpenAI models listed in Azure.

Azure OpenAI in Foundry Models
0 comments No comments

2 answers

Sort by: Most helpful
  1. SRILAKSHMI C 19,730 Reputation points Microsoft External Staff Moderator
    2026-09-02T17:07:04.7666667+00:00

    Hello @Kevin Meyer

    Thank you for reaching out to Microsoft Q&A.

    Microsoft provides a HIPAA Business Associate Agreement (BAA) for eligible customers using Microsoft services that are within the HIPAA compliance scope. There is generally no separate BAA that needs to be signed specifically for Azure. Microsoft states that the HIPAA BAA is made available through the Microsoft Product Terms and the Microsoft Products and Services Data Protection Addendum (DPA).

    For Azure OpenAI, HIPAA coverage should be evaluated based on the applicable Azure service and compliance scope, rather than treating each OpenAI model as a separate BAA. The currently available Microsoft documentation does not provide a model-by-model HIPAA BAA coverage matrix for individual GPT models.

    If you are accessing an Azure OpenAI deployment through Microsoft Foundry, Foundry provides the interface for accessing the underlying Azure OpenAI deployment; the relevant service and deployment configuration should therefore be reviewed when determining whether your workload is within the applicable compliance boundary.

    What you should do

    Confirm that your Azure agreement/subscription is covered by Microsoft's HIPAA BAA through the applicable Product Terms and DPA.

    Confirm that the Azure OpenAI Service and the specific deployment configuration you intend to use are within the applicable HIPAA compliance scope.

    Review the model and deployment availability for your required region and workload.

    Configure the surrounding Azure environment with the appropriate security controls, including access control, encryption, networking, and auditing.

    It is also important to note that having a Microsoft BAA does not by itself make an application HIPAA compliant. Your organization remains responsible for configuring and operating the solution in accordance with its HIPAA obligations.

    For the contractual and compliance details, please refer to Microsoft's HIPAA – Azure Compliance documentation and the Microsoft Service Trust Portal.

    HIPAA – Azure Compliance

    Microsoft Service Trust Portal

    I Hope this helps. Do let me know if you have any further queries.


    If this answers your query, please do click Accept Answer and Yes for was this answer helpful.

    Thank you!

    Was this answer helpful?


  2. Marcin Policht 105.8K Reputation points MVP Volunteer Moderator
    2026-08-04T18:33:07.63+00:00

    Microsoft's BAA is made available by default through the acceptance of the Microsoft Product Terms and Data Protection Addendum (DPA) included with your Azure enterprise or pay-as-you-go agreement.

    More at https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-hipaa-us

    and https://www.accountablehq.com/post/azure-baa-how-to-sign-microsoft-s-business-associate-agreement-and-meet-hipaa-requirements

    Azure and HIPAA

    There is currently no certification program approved by the US Department of Health and Human Services (HHS) through which a CSP acting as a business associate could demonstrate compliance with HIPAA and the HITECH Act. However, HIPAA and HITECH Act requirements have been mapped to other established security frameworks and standards that CSPs typically attest to:

    • The National Institute of Standards and Technology (NIST) SP 800-66 An Introductory Resource Guide for Implementing the HIPAA Security Rule, which addresses security concepts in the HIPAA Security Rule and explains how they relate to other NIST publications on information security. Specifically, Appendix D – Security Rule Standards and Implementation Specifications Crosswalk provides a catalog of the HIPAA Security Rule standards and implementation specifications, and maps each to relevant security controls detailed in NIST SP 800-53 Security and Privacy Controls for Information Systems and Organizations. NIST SP 800-53 serves as the baseline control set for the US Federal Risk and Authorization Management Program (FedRAMP). Therefore, a FedRAMP assessment and authorization provides strong assurances that HIPAA Security Rule safeguard standards and specifications are addressed adequately. Both Azure and Azure Government maintain a FedRAMP High Provisional Authorization to Operate (P-ATO) issued by the FedRAMP Joint Authorization Board (JAB).
    • The Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM), which maps HIPAA and HITECH Act requirements to CCM control objectives covering fundamental security principles across CCM domains. Both Azure and Azure Government maintain the CSA STAR Certification and CSA STAR Attestation that are based on the CCM.
    • The HHS HIPAA Security Rule Crosswalk to NIST Cyber Security Framework, which maps each administrative, physical and technical safeguard standard and implementation specification in the HIPAA Security Rule to a relevant NIST Cybersecurity Framework (CSF) subcategory, and provides relevant control mapping to other standards including ISO/IEC 27001 and NIST SP 800-53. Both Azure and Azure Government align with the NIST CSF and are certified under ISO/IEC 27001.

    To support our customers who are subject to HIPAA compliance, Microsoft will enter into BAAs with its covered entity and business associate customers. Azure has enabled the physical, technical, and administrative safeguards required by HIPAA and the HITECH Act inside the in-scope Azure services, and offers a HIPAA BAA as part of the Microsoft Product Terms (formerly Online Services Terms) to all customers who are covered entities or business associates under HIPAA for use of such in-scope Azure services. In the BAA, Microsoft makes contractual assurances about data safeguarding, reporting (including breach notifications), data access in accordance with HIPAA and the HITECH Act, and many other important provisions. Microsoft enables you in your compliance with HIPAA and the HITECH Act, and adheres to the HIPAA Security Rule requirements in its capacity as a business associate.


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.