Compliance Answer

Is Microsoft Copilot HIPAA Compliant?

Two products, one name, opposite answers. Microsoft settled which is which in January 2025, and most of your staff never got the memo.

The Verdict

No, if you mean the product Microsoft actually calls Microsoft Copilot. That is the personal-account assistant at copilot.microsoft.com, it carries no BAA, and its conversations are used to train Microsoft's AI models unless the user opts out. Yes, with conditions, for Microsoft 365 Copilot, the work product you sign into with a Microsoft Entra account. Microsoft names that one in its HIPAA in-scope services list, covered by the BAA through the Data Protection Addendum. Web search queries are carved out of both. Verified 2026-08-05.

The sign-in decides the answer.

Microsoft Renamed the Answer in January 2025

Microsoft states it plainly in its Copilot administration documentation: "Since January 2025, the Copilot experience for work and education no longer shares the same name as the Copilot experience for personal use."

That single sentence is the reason this question is so badly answered everywhere else. Two products, one brand syllable apart, and the compliance answer flips between them.

Microsoft's own naming, verified against Microsoft Learn 2026-08-05
Microsoft CopilotMicrosoft 365 Copilot and Microsoft 365 Copilot Chat
Who it is forPersonal useWork and education
Sign-inPersonal Microsoft account (MSA)Microsoft Entra work or school account
Where you find itThe Microsoft Copilot app on web, desktop and mobile; copilot.microsoft.com; copilot.com; copilot.ai; bing.com/chat; bing.com/copilotsearchThe Microsoft 365 Copilot app; copilot.cloud.microsoft; Copilot Chat in Edge, Outlook and Teams; the Copilot pane in Word, Excel and PowerPoint
Named in Microsoft's HIPAA in-scope services listNoYes, both, in the Office 365 Commercial and GCC tables
BAANoneAvailable by default through the Online Services Data Protection Addendum
Enterprise data protectionNoYes, under the DPA and Product Terms, with Microsoft acting as data processor
Trains on your conversationsYes by default, opt-out availableNo. Microsoft states prompts, responses and Graph data are not used to train foundation LLMs
Verdict for PHINeverPermitted under the BAA, with the web search carve-out and your tenant work done

This is not legal advice, and your counsel makes the call for your organization.

Read the last two rows together. The same person, the same question, the same red-blue-green-yellow icon, and the difference between a covered disclosure and a reportable one is which account they were signed into at the time.

Microsoft went further than renaming. The legacy Copilot in Windows experience was replaced, and Microsoft states that the consumer Microsoft Copilot app "doesn't support Microsoft Entra authentication." A staff member who opens it with a work account gets bounced to the browser. A staff member who opens it with the personal account they use at home gets a fully working assistant with none of the paperwork.

If you want the eight-product version of this question, including Security Copilot, Copilot Studio and GitHub Copilot, that is the full product matrix, eight products deep.

If You Meant Microsoft 365 Copilot: The Coverage and Its Carve-Out

There's no BAA to request. Microsoft's HIPAA Business Associate Agreement is made available through the Microsoft Online Services Data Protection Addendum by default to every customer that is a covered entity or a business associate under HIPAA, and everything then turns on which services that BAA reaches. Microsoft 365 Copilot and Microsoft 365 Copilot Chat both appear in the in-scope list, under the Office 365 Commercial and GCC applicability tables. Microsoft Copilot on a personal account is not named anywhere in it. The procurement mechanics, including what to keep on file for an audit, are worked through on the full product matrix, eight products deep.

Commercial and GCC are the published rows. GCC High and DoD do not appear in that applicability table. If you operate in either, verify separately rather than reading the Commercial row across. Absence from a table is not a denial, but it is not coverage either.

The carve-out inside the coverage. Microsoft states it in a footnote most deployments never read: "Microsoft 365 Copilot and Microsoft 365 Copilot Chat support HIPAA compliance for properly configured implementations. HIPAA compliance doesn't apply to web search queries as they aren't covered by the DPA and Business Associate Agreement (BAA)."

Operationally: when Copilot decides a prompt would answer better with current web context, it does not send the prompt. It generates a short query of a few words and sends that to the Bing search service, with user and tenant identifiers removed. Microsoft commits in the Product Terms that those queries are not used to train foundation models, not used to improve Bing, not shared with advertisers and treated as customer confidential information. All of that is real, and none of it is the DPA or the BAA. Bing is operating as an independent data controller at that point, not as your business associate.

What to do with that:

  1. Decide, do not default. The Allow web search in Copilot policy in Cloud Policy service for Microsoft 365 turns web search on or off tenant-wide, or on for Copilot Chat while off in Copilot work mode, and it stays on until somebody configures it.
  2. Log it either way. The generated web queries are searchable and auditable through Purview eDiscovery and DSPM for AI, alongside the prompt and the response. That log is your evidence, and it is the same log that will show you a query no one should have typed.
  3. Write it into the policy in plain language. "Do not put patient information in a prompt you expect Copilot to look up on the web" is a sentence a scheduler can follow. "Web-grounded queries fall outside the DPA" is not.

Training and Data Handling, by Sign-In

Microsoft's stated position and the document it appears in, verified 2026-08-05
Microsoft's stated positionWhere Microsoft states it
Microsoft 365 Copilot (Entra account)"Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft 365 Copilot."Data, Privacy, and Security for Microsoft 365 Copilot, Microsoft Learn, updated 2026-07-09
Microsoft 365 Copilot Chat (Entra account)Same commitment. Prompts and responses stay inside the Microsoft 365 service boundary and are logged in Exchange for audit and eDiscovery.Enterprise data protection in Microsoft 365 Copilot and Copilot Chat, updated 2026-05-29
Web search queries from eitherNot used to train foundation models, identifiers stripped. Outside the DPA and the BAA.Data, privacy, and security for web search in Microsoft 365 Copilot and Copilot Chat, updated 2026-07-15
Microsoft Copilot (personal Microsoft account)Conversation activity is used to train Microsoft's generative AI models. Opting out excludes future conversations. The opt-out does not exclude use for general product or system improvement, advertising, digital safety, security or compliance.Microsoft Copilot privacy controls, Microsoft Support

The subprocessor question your CISO will ask sits underneath all of this. Microsoft 365 Copilot no longer runs only on Microsoft-hosted models, and which outside models your tenant allows is an admin setting. Who those subprocessors are, which arrangement sits outside the DPA, and where the toggle lives are on the full product matrix, eight products deep. Check 4 in the list below is what to do about it.

Microsoft Holds a Shelf of Certifications. None of Them Is a BAA

Microsoft 365 Copilot is documented as carrying GDPR support, ISO 27001, HIPAA and ISO/IEC 42001 for AI management systems. Procurement reads that list and closes the ticket. Microsoft's own compliance page closes it differently: there is no certification standard that HHS approves to demonstrate HIPAA compliance, by anyone.

  • A certification is an auditor's report. Someone examined a control set at a point in time and described what they found. ISO 42001 says Microsoft runs a governed AI management system. It says nothing about who may receive PHI.
  • A BAA is a contract. It binds the vendor to the Security Rule, defines permitted uses and disclosures, allocates liability and flows obligations down to subcontractors. 45 CFR 164.502(e) requires it before PHI is disclosed. An audit report does not substitute.

The practical version: Microsoft 365 Copilot is permitted for PHI because it is named in the in-scope services list, not because Microsoft holds ISO 42001. Microsoft Copilot on a personal account is not permitted, and no certificate Microsoft holds changes that, because the consumer product is not in the list and no BAA reaches it.

Two Icons, One Name, Two Legal Regimes

Five things that go wrong when a policy says "Copilot" and means only one of them

1

The policy names a brand, so it governs nothing.

"Staff may use Copilot for approved work" permits the consumer app by its own words. Name the product, the sign-in and the surface: Microsoft 365 Copilot and Microsoft 365 Copilot Chat, signed in with your organization account, in the Microsoft 365 Copilot app, Teams, Outlook and the Office apps. Everything else is out of scope by omission, which is how a policy that names products by their real names does its job.

2

The Copilot key does not care which one you meant.

The key on the keyboard, and Win+C, open whatever the machine is configured to open. On a managed commercial device that is the Microsoft 365 Copilot app. On a personal laptop it is the consumer one. Same key, same reflex, different regime.

3

The phone is the leak.

Copilot Chat with enterprise data protection is available at no extra cost to Entra users on most Microsoft 365 and Office 365 plans, so the governed option is usually sitting there already, paid for and unopened. The consumer app is a free download that signs in with the account already on the phone. The path of least resistance is the ungoverned one, and it's free.

4

Bing is a Copilot entry point.

Microsoft lists bing.com/chat and bing.com/copilotsearch among the personal-use Copilot surfaces. A staff member who types a question into Bing and gets a Copilot answer has used the consumer product without ever opening an app called Copilot.

5

The BAA ends at Microsoft's edge.

Even on the covered product, your permission model, your sensitivity labels, your retention, your web search decision and your subprocessor settings sit on your side of that edge. OCR audits the side Microsoft doesn't sign for.

The Copilot Nobody Licensed

A charge nurse dictates a shift handoff into the Copilot on her phone on the drive home, because writing it out takes twenty minutes she doesn't have. She signed in with the account she has had since 2011. That product trains on conversation activity by default. It is not in Microsoft's in-scope services list, no BAA reaches it, and nothing about the interface tells her any of that.

She has not broken your policy. Your policy said "Copilot."

That is shadow AI, and the naming collision makes Microsoft's version of it worse than most. With ChatGPT the consumer and enterprise products at least look different and get bought differently. With Copilot the two products share a name, an icon, a keyboard key and a search engine. The sign-in is the only thing that separates them, and the interface never shows it.

Bans don't fix this, because the underlying need is real and the free version is already on the phone. The fix is precision about which product is permitted, a governed route that is genuinely easier than the ungoverned one, and an audit trail that will hold up when someone asks. The rest of that argument is HIPAA and AI compliance.

What to Verify Before You Assert Coverage

Six checks, in the order a compliance officer can actually run them.

  1. Pull the current in-scope services list from Microsoft's HIPAA and HITECH compliance page and save a dated copy showing Microsoft 365 Copilot and Microsoft 365 Copilot Chat. It changes. Your evidence should be a snapshot, not a link.
  2. Pull the BAA itself from the Service Trust Portal and file it with the snapshot.
  3. Decide the web search policy and record the decision, whichever way it goes. Left unconfigured, web search is on.
  4. Check the subprocessor and preview-model settings in the Microsoft 365 admin center. Preview models with data retention sit outside the DPA and are default-off. Confirm they still are.
  5. Confirm tenant auditing is on and that Purview retention for Copilot interactions matches your policy, before you tell anyone the interactions are logged.
  6. Settle what counts as PHI in a prompt. This is where most policies are vaguest and most incidents start, and it is the one item on this list that is not a Microsoft setting. What counts as PHI in a prompt.

Microsoft Copilot and HIPAA: Common Questions

Is Microsoft Copilot HIPAA compliant?

No, not the product Microsoft calls Microsoft Copilot. That is the personal-account assistant at copilot.microsoft.com and in the Microsoft Copilot app, it has no BAA, and it trains on conversation activity by default. Microsoft 365 Copilot, the work product signed into with an Entra account, is a different product with a different answer.

Is Microsoft 365 Copilot HIPAA compliant?

Yes, with conditions. Microsoft names Microsoft 365 Copilot in its HIPAA in-scope services list, and the BAA reaches it by default through the Online Services Data Protection Addendum. The conditions are real: web search queries are outside that coverage, and your tenant permissions, labeling and auditing are your side of the agreement.

Do we have to request the Microsoft BAA?

No. Microsoft states the HIPAA Business Associate Agreement is available through the Online Services Data Protection Addendum by default to all customers that are covered entities or business associates. Microsoft also states it cannot use a customer's own BAA template. Retrieve the document from the Service Trust Portal and keep it on file.

Is Copilot Chat covered, or only the paid Copilot?

Yes, both. Microsoft names Microsoft 365 Copilot and Microsoft 365 Copilot Chat in the same in-scope table. Copilot Chat comes at no extra cost to Entra users on most Microsoft 365 and Office 365 plans, so the covered option is usually already licensed.

Does Microsoft Copilot train on our data?

Yes, on a personal Microsoft account, by default, with an opt-out that covers future conversations only. No, on the commercial products: Microsoft states prompts, responses and data accessed through Microsoft Graph are not used to train foundation LLMs.

What happened to Copilot in Windows?

It was replaced. The legacy Copilot in Windows experience was superseded for commercial users by the Microsoft 365 Copilot app, and Microsoft states the consumer Copilot app does not support Microsoft Entra authentication. A work account that tries to sign into it gets redirected to Copilot Chat in the browser.

Is SOC 2 or ISO 42001 enough for PHI?

No. A certification describes controls an auditor observed. A BAA is the contract 45 CFR 164.502(e) requires before PHI may be disclosed. Microsoft's own compliance page states there is no HHS-approved certification standard for HIPAA compliance.

We already have the Microsoft BAA. Are we done?

No. The BAA reaches Microsoft 365 Copilot, which is named in the in-scope services list. It does not reach the Microsoft Copilot your staff opened on a personal account, and it never covered your permission model, your labeling or your audit configuration.

Is this legal advice?

No. This is not legal advice, and your counsel makes the call for your organization.

Your Policy Probably Says "Copilot." That Is the Problem.

A policy that names a brand permits every product wearing it. Generate a healthcare-ready draft that names the product, the sign-in and the surface, so the permission you grant is the one you meant.