Healthcare · Compliance

HIPAA and Power Platform: What Hospitals Need to Know

Yes, Power Platform is covered under Microsoft's HIPAA BAA. That's the easy part. Here's where it actually gets complicated.

Uzarion Technology Group · Updated August 2026

The short answer: yes, it's covered

Microsoft includes a HIPAA Business Associate Agreement at no extra cost, folded into the Online Services Data Protection Addendum. Once your organization identifies as a HIPAA covered entity or business associate under Microsoft's terms, it's automatically in effect. Power BI, Power Apps, Power Automate, Dataverse, and Copilot Studio are all on the current in-scope list, right alongside Exchange, SharePoint, Teams, and Microsoft 365 Copilot.

Quick disclaimer: this is general information, not legal or compliance advice. Microsoft's list of in-scope services changes over time — check it directly against Microsoft's current HIPAA/HITECH documentation before making any real decision, and loop in your compliance officer.

A signed BAA is the floor, not the finish line

Microsoft is upfront about this: HIPAA compliance runs on a shared responsibility model. They secure the cloud infrastructure underneath everything. Everything built on top of it — access controls, sharing settings, encryption checks, audit logs, your own documented risk analysis — that's on you. A BAA gets you into the building. It doesn't configure the locks.

Where hospitals actually trip up

Third-party connectors in Power Automate

This is the one that catches people off guard most. Microsoft's BAA covers Microsoft's own in-scope services — full stop. It does not automatically extend to a third-party connector sitting inside a Power Automate flow. Build a flow that touches PHI and routes it to some outside email service, SMS gateway, or third-party CRM, and that vendor is now its own separate business associate. They need their own BAA with your organization. Microsoft's agreement doesn't cover them just because the flow itself lives inside a covered tool.

The fix is a Data Loss Prevention policy in the Power Platform admin center, restricting which connectors are even allowed in an environment that touches PHI. Make connector approval a governance decision up front, not something left to whoever happens to be building the flow that week.

Copilot and AI features

Copilot Studio is covered, but Microsoft is explicit that it "isn't intended for use as a medical device." Anything that calls out to Azure OpenAI Service for prompts or grounding data deserves a real look before you point it at PHI. Microsoft says that data isn't cached for model training — and that's probably true — but "the vendor said so" and "we documented our own assessment against our PHI policies" are two different things. Do the second one.

Audit log retention set too short

Unified audit logging is easy to turn on and easy to forget to configure properly. The default retention window is often shorter than what a hospital actually needs. Microsoft's own guidance points to at least a year, and commonly seven for higher-risk environments — worth checking against your specific obligations rather than trusting the out-of-box setting.

Dataverse roles and Power BI sharing that got a little too generous

Security roles in Dataverse are powerful, and it's tempting to over-grant access early in a build just to speed up testing — and then never go back and tighten it. Power BI has the same problem in a different shape: a well-secured dataset can still leak PHI through a dashboard that's shared too broadly, or an export-to-Excel button nobody thought to restrict.

Where to start

None of this is a case against using Power Platform in healthcare. It's a genuinely capable, well-covered set of tools. The risk isn't the platform — it's treating "Microsoft signed a BAA" as the end of the conversation instead of where it actually starts.

This reflects our understanding of Microsoft's HIPAA BAA coverage and Power Platform capabilities as of August 2026, for general informational purposes only. It isn't legal or compliance advice. Microsoft's in-scope services list and product terms change — confirm current requirements directly with Microsoft's documentation and your own compliance counsel before making decisions.

Not sure where your organization stands?

Request a free, no-obligation Microsoft 365 / Power Platform audit and we'll tell you plainly.

Request a Quote