Cybersecurity

Is OneDrive HIPAA Compliant?

Is OneDrive HIPAA compliant? Not by default. Here is what the BAA covers, the eight tenant settings that actually matter, and how OneDrive fails in practice.

Douglyn 10 min read
A clinician's laptop showing a cloud storage folder with a padlock overlay, patient charts visible as secured tiles in a medical office

Short answer: no, and yes. OneDrive is not HIPAA compliant out of the box, and no product is. It can be made compliant, and in a properly configured Microsoft 365 tenant it is a defensible place to keep patient records.

That distinction is not pedantry. It is the difference between a practice that passes an audit and one that discovers, after an incident, that the platform it trusted was doing exactly what it was configured to do.

Key takeaways

  • OneDrive is HIPAA-capable, not HIPAA-compliant. Microsoft sells you a capability; compliance is what you do with it.
  • You need a signed BAA, and it is available only on business and enterprise plans. Personal and consumer OneDrive accounts are never covered.
  • A BAA on its own protects nothing. Most failures we find are in tenants with a perfectly valid agreement in place.
  • Anonymous sharing links are the single most common breach cause. Disable them at tenant level rather than training against them.
  • SharePoint and Teams share the same settings. A locked-down OneDrive beside an open Teams channel is not locked down.

The three conditions

Every honest answer to “is OneDrive HIPAA compliant” reduces to three things being true at once.

1. Contract — a signed BAA with Microsoft

Any vendor storing, processing, or transmitting PHI on your behalf is a business associate and requires a signed Business Associate Agreement. Microsoft offers one under Microsoft 365 business and enterprise plans.

What it does not cover is as important. A personal OneDrive account, a free Microsoft account, or a consumer subscription sits entirely outside the framework regardless of how careful the user is. This matters because the failure mode is so ordinary: a staff member working from home signs into their own account, syncs a folder for convenience, and moves PHI outside the BAA without ever intending to.

2. Configuration — the tenant defaults are wrong for you

Microsoft tunes default settings for collaboration, because most customers are not handling protected health information. Anonymous link sharing is available by default. External sharing is permissive by default. Audit log retention varies by licence tier and is frequently shorter than the time it takes to notice a breach.

None of this is Microsoft behaving badly. It is a general-purpose product shipped with general-purpose defaults, and closing the gap is your obligation, not theirs.

3. Behaviour — how your workforce actually uses it

A correctly licensed, correctly configured tenant still fails the moment someone creates an anonymous share of a folder containing patient records. This is why the technical control beats the training: if the option does not exist, the mistake cannot be made.

Making OneDrive HIPAA compliant: the eight settings

In a Microsoft 365 business or enterprise tenant with a signed BAA:

  1. Disable anonymous sharing links at the organisation level in the SharePoint admin centre. This is the setting that causes the most breaches and the one most often left at its permissive default.
  2. Set default link type to “specific people” rather than “anyone”, so the safe choice is the automatic one.
  3. Enforce link expiration on any external sharing you do allow. An indefinitely valid link is a standing exposure that nobody is tracking.
  4. Require MFA on every account that can reach PHI, without exceptions for executives — privileged accounts are precisely the ones targeted.
  5. Enable audit logging and check the retention period on your licence tier.
  6. Restrict external sharing by domain so sharing works with your billing company and referring practices, and nowhere else.
  7. Turn on DLP policies for health information so PHI leaving the tenant is flagged or blocked.
  8. Disable sync to unmanaged devices, otherwise PHI lands on personal laptops outside your control.

Do all eight and OneDrive is a defensible place for PHI. Skip step one and the rest barely matters.

OneDrive for Business vs personal OneDrive

These are different products that share a name, and conflating them is a compliance failure waiting to happen.

OneDrive for BusinessPersonal OneDrive
BAA availableYes, on business and enterprise plansNever
Admin-controlled sharing policyYesNo
Audit loggingYesNo
DLP policiesYesNo
Suitable for PHIYes, once configuredNo, under any circumstances

The practical risk is not that someone deliberately chooses the wrong one. It is that both are installed on the same laptop, both show a cloud folder in File Explorer, and the visual difference is a colour.

SharePoint and Teams are the same decision

OneDrive, SharePoint and Teams sit on the same Microsoft 365 BAA and share the same external-sharing infrastructure. They have to be configured together.

This is the gap we find most often after a OneDrive lockdown: the practice restricted OneDrive sharing, left Teams external access permissive, and PHI simply moved channels. Files shared in a Teams chat are stored in OneDrive — so a Teams sharing decision is a OneDrive sharing decision, whether or not anyone framed it that way.

Configure the tenant, not the product.

What OneDrive gives you, and what it does not

What you get from Microsoft: encryption at rest and in transit by default, the technical capability for granular access control, audit logging, DLP tooling, and a BAA that allocates responsibility for the platform layer.

What remains entirely yours: deciding who should have access to what, reviewing that periodically, ensuring unique user identification so actions are attributable to individuals, keeping logs long enough to be useful, and making sure the configuration you chose at rollout is still the configuration in force two years later.

That last one deserves emphasis. Settings drift. Someone needs an exception for a project, it gets granted, and nobody revisits it. A tenant that was compliant at rollout and has never been reviewed since is not a compliant tenant — it is an unknown one.

How to verify rather than assume

If you want an actual answer about your own environment rather than a general one:

  • Check whether anonymous links exist right now. Not whether they are allowed — whether any are live. This is usually the moment the conversation changes.
  • Pull the external sharing report and look at which domains hold access.
  • Confirm audit log retention against your licence tier, and compare it to how long a breach typically goes undetected.
  • List accounts without MFA. There are almost always a few, and they are usually senior.
  • Check for personal account sync on managed devices.

Each of these is a question with a factual answer, which is what an auditor will want and what a general assurance cannot provide.

Where this fits

OneDrive is one platform in a broader question. The BAA-plus-configuration-plus- behaviour pattern applies identically to Google Drive, Dropbox, Box and ShareFile, and the encryption and retention obligations sit above all of them. If you are deciding how your practice should handle records generally rather than auditing one product, start with HIPAA-compliant file sharing and document storage, which covers the requirements across platforms, secure transmission, and the two separate retention clocks people routinely confuse.

If OneDrive is already in place and you want to know where you actually stand, a tenant review answers it in a few hours rather than in a breach notification. Talk to us about a HIPAA configuration review — or read how we approach healthcare IT and compliance.

Frequently Asked Questions

Is Microsoft OneDrive HIPAA compliant?

OneDrive can be used in a HIPAA-compliant way, but it is not compliant out of the box and no product ever is. Three things have to be true. First, you need a signed Business Associate Agreement with Microsoft, available under Microsoft 365 business and enterprise plans and never under a personal or consumer account. Second, the tenant has to be configured correctly: external sharing restricted, link expiration enforced, anonymous links disabled, audit logging enabled with adequate retention, and MFA on every account. Third, your workforce has to actually use it that way. A correctly licensed, correctly configured tenant still fails the moment someone creates an anonymous 'anyone with the link' share of a folder containing patient records. Compliance is the combination of contract, configuration, and behaviour.

Is OneDrive for Business HIPAA compliant?

The 'for Business' tier is what makes a BAA available, which is the difference that matters, but the BAA alone does not configure the tenant. OneDrive for Business can be made compliant and is the only version worth considering for PHI. Personal OneDrive accounts are never covered by a BAA regardless of how carefully the user behaves, so a staff member syncing patient files to a personal account puts you outside the framework entirely even if every business setting is correct.

How do I make OneDrive HIPAA compliant?

Eight settings, in a Microsoft 365 business or enterprise tenant with a signed BAA. Disable anonymous sharing links at the organisation level in the SharePoint admin centre. Set the default link type to specific people rather than anyone. Enforce expiration on external links. Require MFA on every account that can touch PHI. Enable audit logging and verify the retention period on your licence tier. Restrict external sharing to known partner domains. Turn on DLP policies for health information. Disable sync to unmanaged devices so PHI does not land on personal laptops. The first of those does most of the work, because an anonymous link is an unauthenticated public door into your records and it will not appear in a permissions review.

Does a Microsoft BAA make OneDrive compliant on its own?

No, and this is the most expensive misunderstanding in the whole topic. A BAA is a contract allocating responsibility between you and Microsoft. It obliges Microsoft to handle PHI appropriately within their platform and it does nothing about how your tenant is configured or how your staff use it. Most of the failures we find in practice are in tenants with a perfectly valid BAA. The agreement is necessary and nowhere near sufficient.

Are SharePoint and Teams covered by the same settings as OneDrive?

They sit on the same Microsoft 365 BAA and share the same external-sharing infrastructure, so they need to be configured together. This is a common and serious gap: a practice locks down OneDrive, leaves Teams external access permissive, and PHI moves through Teams channels and chat attachments instead. OneDrive actually stores the files shared in Teams chats, so a Teams sharing decision is a OneDrive sharing decision. Configure the tenant, not the product.

Can we store patient records in OneDrive at all?

Yes, in a properly licensed and configured tenant with a signed BAA, and many practices do exactly that defensibly. OneDrive is not inherently unsuitable for PHI. The question is never whether the platform is capable but whether your specific tenant has been configured to use that capability, and whether anyone has verified it recently rather than assuming the settings chosen at rollout are still in place.

What is the most common OneDrive HIPAA failure?

Anonymous sharing links, by a wide margin. Someone shares a folder using a link that requires no authentication, usually to solve an urgent problem with an outside party, and the link then exists indefinitely: forwardable by anyone who receives it, and invisible in most access reviews because it is not a permission granted to a person. The second most common is a personal account, where a staff member syncs work files to consumer OneDrive for convenience and takes the data outside the BAA entirely.
Tags: is onedrive hipaa compliant onedrive hipaa compliance is microsoft onedrive hipaa compliant onedrive for business hipaa sharepoint hipaa compliance microsoft 365 baa

Let's Build Your Technology Strategy

Ready to transform your IT from a cost center into a competitive advantage? Talk to our team.

Prefer to talk? We answer during business hours and return calls the same day.