HIPAA BAA Coverage for Azure OpenAI and Azure AI Foundry

Temitope Ayodeji Osuntoyinbo 0 Reputation points Microsoft External Staff
2026-08-27T22:01:12.39+00:00

Clarification Needed: HIPAA BAA Coverage for Azure OpenAI Service and Azure AI Foundry.

Hello everyone, a customer is requesting clarification regarding the HIPAA BAA coverage for Azure OpenAI and Azure AI Foundry.

  1. Please confirm in writing, in this case record, whether Azure OpenAI Service is currently a HIPAA in-scope covered service under the Product Terms and the DPA's Business Associate provisions. Yes or no.
  2. The same confirmation for Azure AI Foundry.

We are a healthcare software company handling protected health information, and an auditor will not accept "generally included" or "review the documentation" as evidence.

Azure Health Data Services
Azure Health Data Services

An Azure offering that provides a suite of purpose-built technologies for protected health information in the cloud.

0 comments No comments

2 answers

Sort by: Most helpful
  1. Marcin Policht 107.2K Reputation points MVP Volunteer Moderator
    2026-08-27T22:29:52.54+00:00

    Refer to https://learn.microsoft.com/en-us/answers/questions/5709673/is-our-azure-openai-covered-with-a-baa-or-can-it-b

    These are the steps you could follow to answer your questions in details:

    1. Contract/BAA proof Your BAA for Azure OpenAI comes via Microsoft’s DPA, not a per‑service contract; download and file it with your EA/MCA/CSP. Docs: DPA (Microsoft BAA terms) here: https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA; HIPAA offering/roles: https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-hipaa-us. Confirm with your account team that Azure OpenAI is consumed under that agreement.
    2. Scope discipline (text only for PHI) Until Microsoft explicitly lists modality coverage, treat PHI as text‑only in Azure OpenAI; don’t send PHI via images or realtime audio. Image scope caution (community moderator) → https://learn.microsoft.com/en-us/answers/questions/2106637/azure-openai-hipaa-compliance-status. Realtime audio uncertainty (eligibility not confirmed) → https://learn.microsoft.com/en-us/answers/questions/5616040/clarification-request-hipaa-eligibility-of-azure-o.
    3. Private network boundary Place Azure OpenAI behind a VNET + Private Endpoints (no public ingress), and front with your private API gateway if needed. Azure OpenAI FAQ confirms VNET/Private Endpoints support here: https://learn.microsoft.com/en-us/azure/ai-foundry/openai/faq?view=foundry-classic. Keep architecture diagrams and endpoint screenshots as audit evidence.
    4. Identity, access, and encryption Enforce MFA/Conditional Access and least‑privilege RBAC via Microsoft Entra ID; require TLS 1.2+ and encrypt any stored data. This maps to HIPAA’s administrative/technical safeguards under shared responsibility: https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-hipaa-us. Document policies, control owners, and monitoring in your evidence pack.
    5. Data‑handling posture (no model training on your data) Azure OpenAI (Azure Direct Models) does not train foundation models on your prompts/outputs without your instruction/permission. Microsoft’s data/privacy statement for Azure Direct Models: https://learn.microsoft.com/en-us/azure/ai-foundry/responsible-ai/openai/data-privacy?view=foundry-classic. Keep this page in your auditor binder and reference it in your DPIA/Risk Analysis.
    6. Abuse‑monitoring retention decides and verify Decide whether to allow Microsoft’s abuse‑monitoring storage; if you require stricter control, verify it’s off and retain proof. How to verify storage for abuse monitoring is off: https://learn.microsoft.com/en-us/azure/ai-foundry/responsible-ai/openai/data-privacy?view=foundry-classic#how-can-a-customer-verify-if-data-storage-for-abuse-monitoring-is-off. Store screenshots/change tickets alongside your logging/redaction policy.
      1. If using OpenAI (direct) instead of Azure For OpenAI API (non‑Azure), obtain a separate BAA from OpenAI; ChatGPT consumer tiers are not HIPAA‑eligible. OpenAI BAA request instructions: https://help.openai.com/en/articles/8660679-how-can-i-get-a-business-associate-agreement-baa-with-openai-for-the-api-services. Regardless of path, maintain an evidence bundle: signed master agreement, current DPA, configs (VNET/PE), and data‑handling records.

    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-08-27T22:01:28.32+00:00
    1. Azure OpenAI Service: Yes. The provided context states that Microsoft offers a HIPAA Business Associate Agreement through the Product Terms and the Data Protection Addendum (DPA) for in-scope Microsoft services, and a Microsoft Q&A answer in the context states that Azure OpenAI Service is covered under the DPA and that Azure OpenAI is covered under Microsoft’s BAA for eligible customers.
    2. Azure AI Foundry: No explicit confirmation is provided in the context. The provided context does not contain official documentation stating that Azure AI Foundry, as a named service, is currently a HIPAA in-scope covered service under the Product Terms and the DPA’s Business Associate provisions. A Microsoft Q&A answer in the context states that HIPAA BAA coverage is determined at the Azure service level rather than at the individual model level, and that there is no official documentation explicitly confirming HIPAA BAA coverage at the individual partner or community model level in Azure AI Foundry.

    Supported facts from the context:

    • Microsoft’s HIPAA BAA is available by default through the Microsoft Product Terms and the Microsoft Products and Services Data Protection Addendum (DPA) for customers who are covered entities or business associates under HIPAA.
    • Having a BAA with Microsoft does not by itself make a workload HIPAA compliant; the organization remains responsible for its own compliance program, internal processes, and service configuration.
    • Microsoft cannot use a customer’s own BAA; Microsoft uses its standardized HIPAA BAA.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.