Hi Lauren, great question. Outlook by itself isn’t automatically HIPAA compliant, but Microsoft 365 can be configured to meet HIPAA requirements. The key is that compliance depends on the plan and settings, not just creating a new email address. You’ll need a Microsoft 365 Business or Enterprise plan that includes security and compliance features, and you must sign a Business Associate Agreement (BAA) with Microsoft. After that, you’ll want to enable encryption, multi-factor authentication, and data loss prevention policies to protect PHI.
Can you confirm if you already have a Microsoft 365 subscription for the new business or if you’re starting from scratch?
Best,
Rez