Is Copilot HIPAA Compliant?
Copilot is a brand, not a product. Eight Microsoft products carry the name and Microsoft's HIPAA paperwork names only some of them.
The Verdict
Yes, with conditions, for three products. Microsoft names Microsoft 365 Copilot, Microsoft 365 Copilot Chat and Microsoft Copilot for Security in its HIPAA in-scope services list, and the BAA reaches them through the Online Services Data Protection Addendum. No for Microsoft Copilot signed in with a personal Microsoft account. Unverified for GitHub Copilot and Microsoft Dragon Copilot, neither of which appears in that list. The answer follows the product, not the brand. Verified against Microsoft documentation 2026-08-05.
| Product | Who signs in | Named in Microsoft's HIPAA BAA scope | Trained on your data | Verdict for PHI |
|---|---|---|---|---|
| Microsoft 365 Copilot (paid add-on, grounded in your tenant) | Microsoft Entra work or school account | Yes. Named in the Office 365 in-scope table, Commercial and GCC rows | No. Microsoft states prompts, responses and Graph data are not used to train foundation LLMs | Permitted under the Microsoft BAA. Your tenant configuration is still yours to defend |
| Microsoft 365 Copilot Chat (included at no extra cost, web-grounded) | Microsoft Entra work or school account | Yes. Named in the same table | No, same commitment | Permitted, except web search queries, which Microsoft carves out of both the DPA and the BAA |
| Microsoft Copilot for Security (Security Copilot) | Entra, through the security stack | Yes. Named in Microsoft's in-scope cloud platforms and services list | No. Microsoft states customer data is not used to train Azure OpenAI foundation models | Permitted under the BAA. Not available in GCC, GCC High or DoD |
| Microsoft Copilot Studio (agent builder) | Entra, Power Platform | Contested. Its own Microsoft Learn page says it is covered by the HIPAA BAA. The master in-scope list does not name it | Governed by Power Platform terms | Get the coverage confirmed in writing before any agent touches PHI |
| Microsoft Copilot (personal use) | Personal Microsoft account | No | Yes by default. Conversations are used to train Microsoft's generative AI models unless the user opts out | Never for PHI. See the naming problem with "Microsoft Copilot" |
| Copilot in Windows / the Copilot key | Personal Microsoft account | No. The legacy Copilot in Windows experience was replaced; the consumer app does not accept Entra sign-in | Consumer terms apply | Never for PHI |
| GitHub Copilot | GitHub account | Not documented. Absent from Microsoft's in-scope list. GitHub's Copilot product terms do not mention HIPAA, a BAA or PHI | See GitHub's own retention terms | Unverified. Treat as no BAA until GitHub confirms one in writing |
| Microsoft Dragon Copilot (ambient clinical documentation) | Healthcare licensing agreement | Not documented. Absent from the in-scope list. Microsoft's Dragon Copilot privacy white paper never uses the phrase "Business Associate Agreement" | AI models trained solely on anonymized data, anonymized within 90 days to the HIPAA de-identification standard | Unverified in public documentation. Confirm coverage in your executed agreement |
This is not legal advice, and your counsel makes the call for your organization.
Four of those eight rows are the same answer written four different ways, which is why "is Copilot HIPAA compliant" is a question no honest one-word answer fits. The last two rows are the ones worth a phone call. Microsoft's own healthcare documentation product does not appear on Microsoft's own HIPAA in-scope list, and its privacy white paper does not use the words that would settle it.
Where the Microsoft BAA Actually Sits
Compliance teams go looking for a document to countersign. There isn't one. That absence misleads in both directions.
The Microsoft Online Services Data Protection Addendum carries Microsoft's HIPAA Business Associate Agreement by default to every customer that is a covered entity or a business associate. There is nothing to request and nothing to negotiate. Microsoft states plainly that it will not accept your organization's BAA template, because one standardized agreement covers every tenant on a multitenant service.
That makes "did we get a BAA" a question with no useful answer. Everything turns on which named services it actually covers, and Microsoft publishes and revises that list. Two things follow.
- Coverage is decided by the list, and the list names products. A product with Copilot in its name is covered only if it appears there. Four Copilot products do. At least two do not.
- Microsoft's Office 365 applicability table publishes a Commercial row and a GCC row. GCC High and DoD are not in that table. If either is your environment, the Commercial row does not answer your question and you need a separate confirmation.
What to keep on file for an audit: the BAA document from the Service Trust Portal, a dated copy of the in-scope services list showing the specific Copilot products you deployed, and your own record of when each was turned on. That file proves what Microsoft is bound to. It proves nothing about your own configuration.
One documented exception sits inside the coverage, and Microsoft states it directly: "HIPAA compliance doesn't apply to web search queries as they aren't covered by the DPA and Business Associate Agreement (BAA)." What Copilot actually sends to the Bing search service, what Microsoft strips out of it first, and the tenant policy that turns it off are worked through on the naming problem with "Microsoft Copilot".
| Product | Microsoft's stated position on training | Where Microsoft states it |
|---|---|---|
| Microsoft 365 Copilot | "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft 365 Copilot." | Data, Privacy, and Security for Microsoft 365 Copilot (Microsoft Learn, updated 2026-07-09) |
| Microsoft 365 Copilot Chat | Same commitment, extended to Copilot Chat under enterprise data protection | Enterprise data protection in Microsoft 365 Copilot and Copilot Chat (updated 2026-05-29) |
| Web search queries from either | Not used to train generative AI foundation models, not used to improve Bing, not shared with advertisers. Outside the DPA and the BAA. | Data, privacy, and security for web search in Microsoft 365 Copilot and Copilot Chat (updated 2026-07-15) |
| Microsoft Copilot for Security | "No, Customer Data isn't used to train Azure OpenAI Service foundation models, and this commitment is documented in our Product Terms." | Security Copilot Data and Compliance FAQ (updated 2026-05-28) |
| Microsoft Copilot (personal account) | Conversation activity is used to train Microsoft's generative AI models. Opting out excludes future conversations. The opt-out does not exclude use for general product improvement, advertising, digital safety, security or compliance. | Microsoft Copilot privacy controls (Microsoft Support) |
| Microsoft Dragon Copilot | "Dragon Copilot's AI/ML models are trained solely on anonymized data." Select customer data goes to a research environment and is anonymized within 90 days | Dragon Copilot privacy white paper (Microsoft Learn, updated 2026-06-30) |
The subprocessor line nobody reads. More than one company's models now serve Microsoft 365 Copilot. Microsoft names both Anthropic and OpenAI as subprocessors inside those experiences, with Anthropic models on by default for most commercial customers outside the EU, EFTA and the UK. The Product Terms, the DPA and enterprise data protection extend to them under the standard arrangement, so coverage holds. Two exceptions do not.
- Anthropic models are currently excluded from the EU Data Boundary and, where applicable, in-country processing commitments.
- Preview models with data retention are a different instrument entirely. Microsoft states that data for those is "stored by Anthropic and not subject to your Microsoft Customer Agreement including commitments in the Product Terms and DPA." They are default-off and require an explicit admin opt-in.
If your organization has ever enabled a preview model, someone made a BAA decision through a feature toggle. Check it before you assert coverage. The control sits in the Microsoft 365 admin center under Copilot, Settings, AI providers operating as Microsoft subprocessors.
The Certification Lists on the Two Unverified Rows
This matters most on the two rows above where the answer is unverified. GitHub publishes security assurances. Dragon Copilot lists SOC 1 Type II, SOC 2 Type II, C5 Type II and NEN 7510. Microsoft itself publishes SOC 2, ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO/IEC 42001, HITRUST CSF, FedRAMP authorizations and more. Every one of those is real, and not one of them is the instrument HIPAA asks for.
Why an attestation cannot do a contract's job, including what 45 CFR 164.502(e) requires and when: that argument lives on the naming problem with "Microsoft Copilot".
- SOC 2 is not a BAA, argued at length.
- HITRUST and ISO certifications are not a BAA either.
The Real Risk Is Not the Model
Five tenant realities that decide whether your Copilot deployment survives an audit
Copilot inherits your permission sprawl
It answers from everything the user can technically access: the HR spreadsheet shared to "everyone" in 2021, the patient complaint log in an open SharePoint site. Copilot did not create the exposure. It industrialized the discovery of it.
"Can access" and "should access" are different audits
Most tenants have never reconciled the two. Copilot makes the gap searchable in natural language.
PHI moves between M365 surfaces
A summary generated in a Teams chat from a clinical document is a new copy of PHI in a new location, with its own retention and sharing questions.
The audit answer lives in Purview
Microsoft logs Copilot interactions under Audit (Standard) once tenant auditing is enabled, and the log now includes the generated web search queries alongside the prompt and response, searchable through Purview eDiscovery and DSPM for AI. Verify auditing is on and retention matches your policy before you assert coverage to an investigator.
A BAA does not fix any of this
Microsoft's paper covers Microsoft's conduct. Your permission model, labeling, and monitoring are your side of the deal, and OCR audits your side.
The Copilot Your Staff Actually Opened
Somewhere in your organization this week, a scheduler pasted a patient list into the Copilot on her home laptop to reformat it into a table, because the one at work is slower and she's got forty minutes of work left at nine at night. The account she used is the personal one she keeps for Xbox, and on that account the product trains on her conversations by default. It sits outside every agreement described on this page. The icon is the same.
A product matrix doesn't reach this. A per-product verdict settles what your organization is permitted to deploy, and that is half the question. The other half is what your workforce already opened, and that half is shadow AI.
Governance lives in that gap: a policy that names products the way Microsoft names them, row by row, and a log that answers the question an investigator will actually ask. HIPAA and AI compliance is where that case gets made in full.
Before You Turn It On
The organizations that deploy Copilot safely do the unglamorous work first: a permissions review of the sites and shares Copilot will read, sensitivity labels on PHI-bearing locations, Purview audit configuration, a decision on web search, a check on which model subprocessors are enabled, and a policy that names which roles get Copilot and for what. The ones that don't are running a natural-language search engine over every mistake in their tenant.
Before any of it, decide what counts as PHI in a prompt. What counts as PHI is the definition most policies leave loose, and loose is where incidents begin.
Copilot and HIPAA: Common Questions
Does Microsoft sign a BAA that covers Copilot?
Yes, for the Copilot products named in its in-scope services list. Microsoft's HIPAA Business Associate Agreement is available through the Online Services Data Protection Addendum by default to customers that are covered entities or business associates, with no separate request. Microsoft 365 Copilot, Microsoft 365 Copilot Chat and Microsoft Copilot for Security are named. One documented carve-out: HIPAA compliance does not apply to generated web search queries, which fall outside both the DPA and the BAA.
Is the free Copilot HIPAA compliant?
No. Microsoft Copilot on a personal Microsoft account has no BAA path, no tenant controls, and trains on conversation activity by default. Treat it the way you treat consumer ChatGPT with patient information, which is to say never.
Does Copilot train on our data?
No, not for the commercial products. Microsoft states that prompts, responses and data accessed through Microsoft Graph are not used to train foundation LLMs. With the enterprise Copilot the exposure question is access, not training. With the consumer one it is both.
Is Microsoft Copilot Studio covered by the BAA?
Unverified, and Microsoft's own documentation disagrees with itself. The Copilot Studio compliance page states the product is covered under the HIPAA BAA. Microsoft's master in-scope cloud services list does not name it. Get the coverage confirmed in writing for your specific agreement before an agent handles PHI.
Is GitHub Copilot HIPAA compliant?
No documented BAA exists. GitHub Copilot does not appear in Microsoft's HIPAA in-scope services list, and GitHub's own Copilot product terms do not mention HIPAA, a Business Associate Agreement or protected health information. Treat it as a developer tool that must never see production PHI, including PHI pasted into a prompt while debugging.
Is Microsoft Security Copilot covered?
Yes. Microsoft states that Security Copilot "is now listed and covered by Business Associate Agreement," and it appears in the in-scope cloud platforms and services list. It is not available in GCC, GCC High or DoD environments.
Can clinicians use Copilot for clinical notes?
No. Microsoft 365 Copilot is a productivity assistant, not a clinical documentation tool. Microsoft's purpose-built product is Dragon Copilot, and its BAA coverage is not stated in the public documentation we could verify. Keep the two use cases in separate policy lanes and settle Dragon Copilot's paper in your own contract.
We already have the Microsoft BAA. Are we done?
No. The BAA settles Microsoft's obligations and nothing else. An investigator opens with your side: the permission model, the sensitivity labels, the audit configuration, the web search decision, the subprocessor settings and the workforce policy.
Is this legal advice?
No. This is not legal advice, and your counsel makes the call for your organization.
The Policy Question Comes Before the License Question
Whether it is Copilot, ChatGPT, or both, the first control is a policy your staff can follow. Generate a healthcare-ready draft in minutes, then decide which tools earn a place in it.