Is OneDrive HIPAA Compliant?
Is OneDrive HIPAA compliant? Not by default. Here is what the BAA covers, the eight tenant settings that actually matter, and how OneDrive fails in practice.
Short answer: no, and yes. OneDrive is not HIPAA compliant out of the box, and no product is. It can be made compliant, and in a properly configured Microsoft 365 tenant it is a defensible place to keep patient records.
That distinction is not pedantry. It is the difference between a practice that passes an audit and one that discovers, after an incident, that the platform it trusted was doing exactly what it was configured to do.
Key takeaways
- OneDrive is HIPAA-capable, not HIPAA-compliant. Microsoft sells you a capability; compliance is what you do with it.
- You need a signed BAA, and it is available only on business and enterprise plans. Personal and consumer OneDrive accounts are never covered.
- A BAA on its own protects nothing. Most failures we find are in tenants with a perfectly valid agreement in place.
- Anonymous sharing links are the single most common breach cause. Disable them at tenant level rather than training against them.
- SharePoint and Teams share the same settings. A locked-down OneDrive beside an open Teams channel is not locked down.
The three conditions
Every honest answer to “is OneDrive HIPAA compliant” reduces to three things being true at once.
1. Contract — a signed BAA with Microsoft
Any vendor storing, processing, or transmitting PHI on your behalf is a business associate and requires a signed Business Associate Agreement. Microsoft offers one under Microsoft 365 business and enterprise plans.
What it does not cover is as important. A personal OneDrive account, a free Microsoft account, or a consumer subscription sits entirely outside the framework regardless of how careful the user is. This matters because the failure mode is so ordinary: a staff member working from home signs into their own account, syncs a folder for convenience, and moves PHI outside the BAA without ever intending to.
2. Configuration — the tenant defaults are wrong for you
Microsoft tunes default settings for collaboration, because most customers are not handling protected health information. Anonymous link sharing is available by default. External sharing is permissive by default. Audit log retention varies by licence tier and is frequently shorter than the time it takes to notice a breach.
None of this is Microsoft behaving badly. It is a general-purpose product shipped with general-purpose defaults, and closing the gap is your obligation, not theirs.
3. Behaviour — how your workforce actually uses it
A correctly licensed, correctly configured tenant still fails the moment someone creates an anonymous share of a folder containing patient records. This is why the technical control beats the training: if the option does not exist, the mistake cannot be made.
Making OneDrive HIPAA compliant: the eight settings
In a Microsoft 365 business or enterprise tenant with a signed BAA:
- Disable anonymous sharing links at the organisation level in the SharePoint admin centre. This is the setting that causes the most breaches and the one most often left at its permissive default.
- Set default link type to “specific people” rather than “anyone”, so the safe choice is the automatic one.
- Enforce link expiration on any external sharing you do allow. An indefinitely valid link is a standing exposure that nobody is tracking.
- Require MFA on every account that can reach PHI, without exceptions for executives — privileged accounts are precisely the ones targeted.
- Enable audit logging and check the retention period on your licence tier.
- Restrict external sharing by domain so sharing works with your billing company and referring practices, and nowhere else.
- Turn on DLP policies for health information so PHI leaving the tenant is flagged or blocked.
- Disable sync to unmanaged devices, otherwise PHI lands on personal laptops outside your control.
Do all eight and OneDrive is a defensible place for PHI. Skip step one and the rest barely matters.
OneDrive for Business vs personal OneDrive
These are different products that share a name, and conflating them is a compliance failure waiting to happen.
| OneDrive for Business | Personal OneDrive | |
|---|---|---|
| BAA available | Yes, on business and enterprise plans | Never |
| Admin-controlled sharing policy | Yes | No |
| Audit logging | Yes | No |
| DLP policies | Yes | No |
| Suitable for PHI | Yes, once configured | No, under any circumstances |
The practical risk is not that someone deliberately chooses the wrong one. It is that both are installed on the same laptop, both show a cloud folder in File Explorer, and the visual difference is a colour.
SharePoint and Teams are the same decision
OneDrive, SharePoint and Teams sit on the same Microsoft 365 BAA and share the same external-sharing infrastructure. They have to be configured together.
This is the gap we find most often after a OneDrive lockdown: the practice restricted OneDrive sharing, left Teams external access permissive, and PHI simply moved channels. Files shared in a Teams chat are stored in OneDrive — so a Teams sharing decision is a OneDrive sharing decision, whether or not anyone framed it that way.
Configure the tenant, not the product.
What OneDrive gives you, and what it does not
What you get from Microsoft: encryption at rest and in transit by default, the technical capability for granular access control, audit logging, DLP tooling, and a BAA that allocates responsibility for the platform layer.
What remains entirely yours: deciding who should have access to what, reviewing that periodically, ensuring unique user identification so actions are attributable to individuals, keeping logs long enough to be useful, and making sure the configuration you chose at rollout is still the configuration in force two years later.
That last one deserves emphasis. Settings drift. Someone needs an exception for a project, it gets granted, and nobody revisits it. A tenant that was compliant at rollout and has never been reviewed since is not a compliant tenant — it is an unknown one.
How to verify rather than assume
If you want an actual answer about your own environment rather than a general one:
- Check whether anonymous links exist right now. Not whether they are allowed — whether any are live. This is usually the moment the conversation changes.
- Pull the external sharing report and look at which domains hold access.
- Confirm audit log retention against your licence tier, and compare it to how long a breach typically goes undetected.
- List accounts without MFA. There are almost always a few, and they are usually senior.
- Check for personal account sync on managed devices.
Each of these is a question with a factual answer, which is what an auditor will want and what a general assurance cannot provide.
Where this fits
OneDrive is one platform in a broader question. The BAA-plus-configuration-plus- behaviour pattern applies identically to Google Drive, Dropbox, Box and ShareFile, and the encryption and retention obligations sit above all of them. If you are deciding how your practice should handle records generally rather than auditing one product, start with HIPAA-compliant file sharing and document storage, which covers the requirements across platforms, secure transmission, and the two separate retention clocks people routinely confuse.
If OneDrive is already in place and you want to know where you actually stand, a tenant review answers it in a few hours rather than in a breach notification. Talk to us about a HIPAA configuration review — or read how we approach healthcare IT and compliance.


