Rules and compliance
Is Microsoft Copilot HIPAA compliant?
Short answerMicrosoft 365 Copilot and Copilot Chat, used with a work account signed in through Microsoft Entra ID, are in scope for Microsoft's HIPAA business associate agreement, which comes with its Data Protection Addendum. The consumer Copilot app has no BAA, and GitHub's terms bar protected health information without GitHub's written consent. Web search queries fall outside the BAA even in covered Copilot, as of October 8, 2026.
HIPAA does not certify software. A practice can send PHI to an AI vendor when the vendor has a BAA with the practice, the product is in scope, and the feature is covered. Microsoft says its BAA supports a customer's compliance and that using its services does not achieve compliance on its own. The same test applies to ChatGPT and Claude.
Which Copilot products are covered by Microsoft's BAA?
Five products carry the Copilot name, and the account staff sign in with decides which terms apply. Microsoft has renamed Microsoft 365 Copilot to Microsoft Copilot, and Microsoft 365 Copilot Chat to Microsoft Copilot Chat, while its consumer app is also called Copilot. A work or school account through Entra ID gets enterprise data protection under the DPA. A personal Microsoft account gets the consumer terms.
| Copilot product | How staff sign in | BAA coverage | Before PHI goes in |
|---|---|---|---|
| Microsoft 365 Copilot (now Microsoft Copilot), the paid license | Work or school account, Entra ID | In scope, listed as Microsoft Copilot | Turn off web search, previews and unapproved agents |
| Copilot Chat with enterprise data protection (now Microsoft Copilot Chat) | Work or school account, Entra ID | In scope, listed as Microsoft Copilot Chat | Turn off web search; confirm staff use their work account |
| Consumer Copilot app | Personal Microsoft account, or no sign-in | No BAA | Keep PHI out |
| GitHub Copilot | GitHub account | No BAA; GitHub's DPA bars PHI without GitHub's prior, written, and specific consent | Keep PHI out of prompts, code and repositories |
| Dragon Copilot for clinicians (Dragon Medical One and DAX combined) | Entra ID, deployed by the health system | Under the DPA and Dragon Copilot terms; absent from Microsoft's general in-scope list | Confirm the BAA names it; set access controls and patient consent |
How does a practice get Microsoft's BAA?
Microsoft's Products and Services Data Protection Addendum says that when a customer is a covered entity or business associate and puts PHI in its data, executing the customer's agreement also executes the HIPAA BAA. Nothing extra is signed. The BAA lists the services it applies to, and Microsoft's HIPAA page names Microsoft Copilot and Microsoft Copilot Chat among in-scope services in the commercial cloud and GCC. A customer can opt out of the BAA by written notice, so confirm nobody in the organization has.
Which Copilot features fall outside the BAA?
- Web search. Copilot turns part of a prompt into a short query for Bing. Microsoft says the DPA and HIPAA compliance do not apply to those queries. Admins turn web search off with the Allow web search in Copilot policy in Cloud Policy service.
- Previews. The DPA's HIPAA terms do not apply to previews unless a preview allows personal data processing, and Microsoft tells customers to keep regulated data out of them.
- Agents and connectors. Microsoft tells admins to read each agent's privacy statement and terms of use before allowing it.
- Anthropic models with Data Retention. These run under Anthropic's own terms, outside Microsoft's DPA, and stay off until an admin opts in. Other Anthropic models in Copilot run under Microsoft's DPA and are on by default for most commercial tenants outside the EU, EFTA and UK.
What should a practice verify before entering PHI in Copilot?
- Confirm the organization is a covered entity or business associate under the DPA and that no BAA opt-out was sent.
- Check the BAA's service list for the exact Copilot product staff use, and keep a dated copy.
- Confirm staff sign in with Entra ID work accounts and keep patient work out of the consumer app.
- Turn off web search, previews and unapproved agents, and leave Anthropic models with Data Retention off.
- Fix SharePoint, OneDrive and Teams permissions first. Copilot shows each user the content that user can already open.
- Set Purview retention for Copilot interactions, review audit records on a schedule, and add Copilot to the risk analysis and AI use policy.
Is GitHub Copilot HIPAA compliant?
GitHub's Data Protection Agreement prohibits customers from providing GitHub any personal data that is PHI under HIPAA without GitHub's prior, written, and specific consent. GitHub is absent from Microsoft's HIPAA in-scope list. Keep patient records out of prompts, code, test fixtures, issues and repositories, and build test data from synthetic records.
Is Dragon Copilot HIPAA compliant?
Dragon Copilot is Microsoft's clinical documentation assistant, launched in March 2025 to bring Dragon Medical One dictation and DAX ambient listening into one product. Microsoft's privacy white paper places it under the DPA, the Product Terms and the Dragon Copilot Service Specific Terms, and states Microsoft's commitment to HIPAA. Microsoft's general HIPAA in-scope list does not name it, so confirm in the health system's agreement that the BAA covers it.
Microsoft keeps audio, transcripts and flowsheet values for up to 90 days, anonymizes selected data to the HIPAA de-identification standard, and trains Dragon Copilot models on anonymized data only. Clinicians review and sign every note, the organization limits each patient's data to clinicians with a treatment relationship, and Microsoft tells users to obtain patient consent before recording an encounter.
Can staff use Copilot without a BAA?
Staff can use the consumer app or GitHub Copilot for work with no PHI: policy drafts, template letters and patient education written from a blank page. Text is de-identified under Safe Harbor only when all 18 identifiers are gone for the patient and relatives, employers and household members, and the practice has no actual knowledge the remainder identifies the person. Removing a name alone leaves PHI.
A hosted model for patient work
Patient work goes to a model SUPERWISE® hosts on its own servers, under a BAA with the practice. For the outside tools staff keep using, Sentinel replaces the identifiers it recognizes before a prompt leaves the PC.
Sentinel for outside tools
Sentinel replaces supported identifiers with placeholders on the PC and records each inspected interaction. Sentinel does not make Copilot, any other tool, or a practice HIPAA compliant. Copilot coverage is in development. Sentinel replaces email addresses and phone numbers; Social Security, passport, driver's license, tax and national ID numbers; credit card, IBAN, and bank account numbers; IP and MAC addresses; VINs; API keys and other secrets; and dates of birth and medical record numbers when they are labeled. It does not cover names, street addresses, other dates, or unlabeled record numbers.
Free practical kit
HIPAA and AI: a checklist for using ChatGPT and Claude
Eight pages: both vendor plan tables, all 18 identifiers as a tick-box list, and a seven-part practice checklist.
Frequently asked questions
- Does Microsoft sign a BAA for Copilot?
- Yes. Microsoft's BAA comes with its Data Protection Addendum for covered entities and business associates, and Microsoft lists Microsoft Copilot and Microsoft Copilot Chat as in scope, as of October 8, 2026.
- Is Microsoft 365 Copilot HIPAA compliant?
- It can support HIPAA compliance when staff sign in with Entra ID work accounts and the practice configures it, including turning off web search. Microsoft says web search queries fall outside the DPA and the BAA.
- Is Copilot Chat HIPAA compliant?
- Copilot Chat with enterprise data protection is in scope under Microsoft's BAA when staff sign in with a work account. The consumer Copilot app, used with a personal Microsoft account, has no BAA.
- Is GitHub Copilot HIPAA compliant?
- GitHub offers no BAA for it. GitHub's Data Protection Agreement bars PHI without GitHub's prior, written, and specific consent, so keep patient data out of prompts and repositories.
- Is Dragon Copilot or DAX HIPAA compliant?
- Microsoft governs Dragon Copilot under its DPA and Dragon Copilot terms and states a commitment to HIPAA. Confirm the health system's BAA names it, and obtain patient consent before recording.
- Can a behavioral health practice use Copilot?
- Behavioral health notes are PHI, so the same test applies: a work account, a product in scope of Microsoft's BAA, web search off, and access limited to the clinicians who need the records.
- Is ChatGPT HIPAA compliant?
- Consumer ChatGPT plans carry no BAA, and OpenAI covers only listed products. See Is ChatGPT HIPAA compliant?
Sources
- Microsoft Learn, HIPAA and HITECH Act compliance offering. Read October 8, 2026.
- Microsoft, Products and Services Data Protection Addendum, May 2026 (HIPAA Business Associate and Previews sections). Read October 8, 2026.
- Microsoft Learn, Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat. Read October 8, 2026.
- Microsoft Learn, Data, privacy, and security for Microsoft Copilot. Read October 8, 2026.
- Microsoft Learn, Data, privacy, and security for web search in Microsoft Copilot and Microsoft Copilot Chat. Read October 8, 2026.
- Microsoft Learn, Anthropic models in Microsoft Online Services. Read October 8, 2026.
- Microsoft Support, Privacy FAQ for Microsoft Copilot. Read October 8, 2026.
- GitHub, Data Protection Agreement, October 2025 (section 12). Read October 8, 2026.
- Microsoft Learn, Dragon Copilot privacy white paper. Read October 8, 2026.
- Microsoft Learn, Frequently asked questions about Dragon Copilot. Read October 8, 2026.
- Microsoft Learn, What is Microsoft Dragon Copilot (physicians)? Read October 8, 2026.
- Microsoft Source, Microsoft Dragon Copilot provides the healthcare industry's first unified voice AI assistant, March 3, 2025. Read October 8, 2026.
- HHS, HIPAA de-identification guidance.
- HHS, Guidance on HIPAA and cloud computing.
Reviewed