An Azure offering that provides a suite of purpose-built technologies for protected health information in the cloud.
- Azure OpenAI Service: Yes. The provided context states that Microsoft offers a HIPAA Business Associate Agreement through the Product Terms and the Data Protection Addendum (DPA) for in-scope Microsoft services, and a Microsoft Q&A answer in the context states that Azure OpenAI Service is covered under the DPA and that Azure OpenAI is covered under Microsoft’s BAA for eligible customers.
- Azure AI Foundry: No explicit confirmation is provided in the context. The provided context does not contain official documentation stating that Azure AI Foundry, as a named service, is currently a HIPAA in-scope covered service under the Product Terms and the DPA’s Business Associate provisions. A Microsoft Q&A answer in the context states that HIPAA BAA coverage is determined at the Azure service level rather than at the individual model level, and that there is no official documentation explicitly confirming HIPAA BAA coverage at the individual partner or community model level in Azure AI Foundry.
Supported facts from the context:
- Microsoft’s HIPAA BAA is available by default through the Microsoft Product Terms and the Microsoft Products and Services Data Protection Addendum (DPA) for customers who are covered entities or business associates under HIPAA.
- Having a BAA with Microsoft does not by itself make a workload HIPAA compliant; the organization remains responsible for its own compliance program, internal processes, and service configuration.
- Microsoft cannot use a customer’s own BAA; Microsoft uses its standardized HIPAA BAA.
References:
- HIPAA (US)
- Health Insurance Portability and Accountability Act (HIPAA) & Health Information Technology for Economic and Clinical Health (HITECH) Act
- Does Azure OpenAI fall under the DPA? - Microsoft Q&A
- Is Qwen3-VL-235B deployed as serverless API in Foundry covered under our HIPAA BAA for image inputs? - Microsoft Q&A