Healthcare IT for New Jersey medical practices732-362-4949
Practice-side self-assessment

Microsoft 365 security checklist for medical practices

One staff account can reach email, files, teams, apps, and devices. Review the six access doors, the evidence behind each one, and the person responsible for the next decision.

Open the six-door checklist

Educational guidance only. This checklist is not a complete security assessment, risk analysis, legal opinion, or compliance certification. Do not place tenant details or PHI into public tools.

01Sign-in and adminsMFA, roles, emergency access
02Mailbox and forwardingRules, delegates, phishing response
03Teams and groupsMembers, owners, shared work
04SharePoint and OneDriveSites, links, guests, permissions
05Apps and vendorsConsent, partners, service access
06Devices and evidenceIntune, sessions, logs, recovery
The same identity can open several routes. Review the route, record, and owner together.
Quick answer

Microsoft 365 security is not one switch. A useful review connects identity, mail, collaboration, apps, devices, logs, recovery, and ownership. If an answer is unknown, record the gap and route it to the right owner instead of marking the tenant secure.

Six doors, one account

Start with the controls a staff identity can actually reach.

Use the checklist as a discussion guide. Do not enter usernames, tenant IDs, admin links, message contents, screenshots, configuration exports, passwords, or PHI into this page.

VerifyAsk a question that can be answered from approved tenant records or an authorized review.
RetainKeep only the evidence and decision record the practice has approved and can protect.
AssignName the practice, IT, Microsoft, vendor, or specialist owner for the next action.
01

Sign-in and administrator access

Confirm how users authenticate, which accounts hold privileged roles, how departures close access, and how authorized administrators regain access during an identity emergency.

Verify

Which users and admins are covered by the selected MFA method? Are daily accounts separate from admin accounts? Are inactive users and privileged roles reviewed after staff changes?

Evidence to retain

Approved role list, authentication approach, emergency-access owner, offboarding record, exceptions, and last review date. Do not export secrets into an unsecured file.

Unknown means

Route tenant cleanup and controlled changes to Microsoft 365 management. Route formal access-control conclusions to the practice's compliance or legal owner.

  • Every person uses a named account
  • Privileged roles have an approved business reason
  • Emergency access is protected and tested appropriately
  • Role changes and departures trigger access review
02

Mailbox rules and phishing paths

Review forwarding, delegates, shared mailboxes, suspicious inbox rules, impersonation protections, and the path staff use to report a questionable message or account change.

Verify

Who can forward mail externally? Which users have delegate access? Who owns shared mailboxes? Can the practice investigate unexpected rules or trusted-sender phishing?

Evidence to retain

Approved forwarding and delegation list, shared-mailbox owner, mail-protection scope, report-and-escalate path, exceptions, and response owner.

Unknown means

Use Microsoft 365 management for configuration ownership and healthcare cybersecurity for a wider preventive email-control review. Active compromise belongs to the practice's current provider, insurer, or approved incident-response path.

  • External forwarding has an approved purpose
  • Shared mailboxes have named owners
  • Unexpected rules have an investigation path
  • Staff know how to report suspicious messages
03

Teams, groups, and shared work

Teams and Microsoft 365 groups can connect conversations, calendars, files, and membership. Review owners and access as one working system rather than as isolated apps.

Verify

Which teams and groups still support current work? Does each space have a responsible owner? Are guest members, private channels, and staff-role changes reflected in access?

Evidence to retain

Current workspace owner, intended members, guest purpose, sensitive-workflow boundary, approved exception, and date of the last owner review.

Unknown means

Assign practice leadership to confirm the workflow and intended members. Assign the tenant administrator to make approved membership or ownership changes.

  • Every active workspace has a current owner
  • Membership follows the intended staff role
  • Guest access has a business purpose and owner
  • Unused spaces have a review or closure decision
04

SharePoint and OneDrive sharing

A site-level setting, organization-level setting, link type, guest identity, or inherited permission can change who reaches a file. Review the actual sharing path and the content owner together.

Verify

Which sites allow external sharing? Are anonymous links allowed where they should not be? Who can invite guests? Can owners remove access and explain inherited permissions?

Evidence to retain

Approved site purpose, owner, external-sharing level, guest list or review record, sensitive-content boundary, exception, and access-removal path.

Unknown means

Use tenant management for approved sharing changes. Use compliance or legal specialists to decide retention, ePHI handling, contracts, and policy interpretation.

  • Site and organization sharing settings are understood
  • Sensitive work has a named storage location
  • Guests and links can be reviewed and removed
  • Content owners know who should retain access
05

Applications, guests, and vendor access

Third-party apps, vendor administrators, service principals, integrations, and delegated permissions can reach Microsoft 365 without looking like a normal staff account.

Verify

Which applications and vendors have tenant access? Who approved them? What permissions were granted? Does access still match the contract, workflow, and current support need?

Evidence to retain

Application or vendor name, business purpose, approval owner, permission scope, contractual route, review date, support contact, and removal decision.

Unknown means

Pause new access until the correct practice and technical owners are identified. Vendor contract, BAA, legal, and formal risk questions stay with their qualified owners.

  • Every connected app has an identifiable owner
  • Permissions match the approved business purpose
  • Vendor admin access has an escalation path
  • Unused access has a removal decision
06

Devices, sessions, logs, and recovery

Account security depends on the devices and sessions that use it, the audit evidence available after a change, and the separate recovery decisions for retained content and backup.

Verify

Which devices are enrolled or approved? What does an Intune status actually test? Who reviews audit events and alerts? What is retained, backed up, and recoverable under the chosen license and scope?

Evidence to retain

Device category, enrollment and policy scope, exceptions, alert owner, audit availability, retention decision, backup responsibility, restore evidence, and escalation path.

Unknown means

Use Microsoft 365 management for tenant and device administration. Use disaster recovery for backup and restore proof. Use compliance for formal evidence requirements.

  • Approved device categories and exceptions are known
  • Intune status is not treated as HIPAA certification
  • Audit availability and response ownership are recorded
  • Retention and backup are treated as separate decisions
No pass or fail score

An unknown answer is a routing signal.

A short checklist cannot prove a tenant secure. Its value is showing where configuration, evidence, approval, or ownership is missing before someone makes a broad change.

KnownThe approved setting, evidence, owner, and review event can be explained.
Needs an ownerThe business decision or record is unclear, even if a setting is visible.
Needs specialist reviewThe answer depends on licensing, security, legal, compliance, vendor, or recovery expertise.
Platform and licensing boundaries

The same checklist can produce different answers in different tenants.

Microsoft 365 plans, add-ons, configuration history, identity design, device platforms, and business workflows affect which controls exist and how they should be introduced.

Review current licensing and platform documentation before changing production. A feature name alone does not establish coverage, correct rollout, or compliance.

A Microsoft BAA, Security Defaults, Conditional Access, Defender, Intune, encryption, or an audit log can support safeguards. None of them alone makes a medical practice HIPAA compliant.
Security Defaults and Conditional Access

Microsoft describes Security Defaults as a baseline without customization. Conditional Access offers more control and requires eligible Microsoft Entra licensing. Review the current Security Defaults guidance and Conditional Access overview.

Intune device compliance

Intune evaluates managed devices against configured organizational rules. Its compliant status is a tenant policy result, not a HIPAA conclusion. See Microsoft Intune device compliance.

External sharing

SharePoint and OneDrive sharing depends on organization, site, guest, link, and identity settings. More restrictive settings can limit broader ones. See Microsoft external sharing guidance.

Audit evidence

Searchability and retention vary by audit product and licensing. Confirm what evidence is available before relying on a retention window. See Microsoft Purview Audit guidance.

Healthcare responsibility

HHS cybersecurity goals identify high-impact practices such as email security, MFA, training, encryption, and access management. They do not make this article a risk analysis. See the HHS Healthcare Cybersecurity Performance Goals.

Route the discovered gap

Use the page that owns the next decision.

This article owns education and self-assessment. Implementation, formal evidence, migration, and routine support have separate planned-service owners.

Existing tenant setting or owner is unknownIdentity, administrators, mailboxes, Teams, SharePoint, OneDrive, Intune, approved changes, and recurring records.Microsoft 365 management
Controls extend beyond Microsoft 365Email, identity, endpoints, vendors, remote access, network safeguards, logging, and escalation across the environment.Healthcare cybersecurity
Formal safeguard or evidence questionRisk analysis, policy, BAA, responsibility mapping, legal interpretation, and compliance-readiness records.Compliance support
Users, mail, files, or devices are movingPilot, cutover, validation, rollback, vendor coordination, and post-migration stabilization.Cloud migration
One current user issueOutlook, password, sync, workstation, mailbox, or access troubleshooting for a routine problem.IT support
Backup or restore proof is missingProtected scope, backup evidence, restore testing, recovery priorities, and continuity ownership.Disaster recovery
Checklist questions

Clarify what this guide can and cannot answer.

Does a Microsoft BAA make the tenant HIPAA compliant?

No. Contract terms and eligible services are only part of the picture. The practice remains responsible for its use, configuration, safeguards, policies, workforce, vendors, evidence, and risk analysis.

Is MFA enough to secure Microsoft 365?

No. MFA is important, but the practice should also review privileged roles, sign-in paths, mail rules, sharing, apps, guests, devices, logs, response, and ownership.

Is an Intune compliant status a compliance decision?

No. It means a managed device met the rules configured for that tenant and policy evaluation. It is not a legal conclusion, certification, or substitute for risk analysis.

Should every practice use the same settings?

No. Licensing, workflows, device types, locations, vendors, data handling, and risk decisions differ. Broad changes should be tested and approved against the actual environment.

What should we send in a first request?

Share the broad concern, approximate users and locations, affected Microsoft 365 areas, tenant history, current owner, timing, and the decision still open. Do not send sensitive tenant data.

What if several checklist answers are unknown?

That usually means the tenant needs a bounded review before broad changes. The first useful output is a known-state record, open questions, owners, safe priorities, and service routing.

Primary sources used for this review

Source and freshness boundary

Microsoft product behavior, licensing, and documentation change. This page was reviewed against the linked primary sources on August 29, 2026. Confirm current Microsoft terms and tenant facts before implementation.

These sources do not endorse HealthDesk IT, prove a tenant secure, establish compliance, replace a formal risk analysis, or authorize changes to systems or data.

Microsoft 365 tenant review

Turn unknown checklist answers into owned work.

If several answers are unclear, HealthDesk IT can map the existing tenant, separate configuration from practice decisions, and identify which changes need approval, testing, another specialist, or ongoing ownership.

  • Call: 732-362-4949
  • Useful context: approximate users and locations, tenant history, broad area of concern, current owner or vendor, and timing
  • Do not send: PHI, usernames, passwords, tenant IDs, admin links, email contents, screenshots, exports, or access keys

Email or phone is required. Submission does not create a client relationship, guarantee availability or outcomes, establish compliance, or authorize access to systems or data.