Microsoft 365 security checklist for medical practices
One staff account can reach email, files, teams, apps, and devices. Review the six access doors, the evidence behind each one, and the person responsible for the next decision.
Educational guidance only. This checklist is not a complete security assessment, risk analysis, legal opinion, or compliance certification. Do not place tenant details or PHI into public tools.
Microsoft 365 security is not one switch. A useful review connects identity, mail, collaboration, apps, devices, logs, recovery, and ownership. If an answer is unknown, record the gap and route it to the right owner instead of marking the tenant secure.
Start with the controls a staff identity can actually reach.
Use the checklist as a discussion guide. Do not enter usernames, tenant IDs, admin links, message contents, screenshots, configuration exports, passwords, or PHI into this page.
Sign-in and administrator access
Confirm how users authenticate, which accounts hold privileged roles, how departures close access, and how authorized administrators regain access during an identity emergency.
Which users and admins are covered by the selected MFA method? Are daily accounts separate from admin accounts? Are inactive users and privileged roles reviewed after staff changes?
Approved role list, authentication approach, emergency-access owner, offboarding record, exceptions, and last review date. Do not export secrets into an unsecured file.
Route tenant cleanup and controlled changes to Microsoft 365 management. Route formal access-control conclusions to the practice's compliance or legal owner.
- Every person uses a named account
- Privileged roles have an approved business reason
- Emergency access is protected and tested appropriately
- Role changes and departures trigger access review
Mailbox rules and phishing paths
Review forwarding, delegates, shared mailboxes, suspicious inbox rules, impersonation protections, and the path staff use to report a questionable message or account change.
Who can forward mail externally? Which users have delegate access? Who owns shared mailboxes? Can the practice investigate unexpected rules or trusted-sender phishing?
Approved forwarding and delegation list, shared-mailbox owner, mail-protection scope, report-and-escalate path, exceptions, and response owner.
Use Microsoft 365 management for configuration ownership and healthcare cybersecurity for a wider preventive email-control review. Active compromise belongs to the practice's current provider, insurer, or approved incident-response path.
- External forwarding has an approved purpose
- Shared mailboxes have named owners
- Unexpected rules have an investigation path
- Staff know how to report suspicious messages
Teams, groups, and shared work
Teams and Microsoft 365 groups can connect conversations, calendars, files, and membership. Review owners and access as one working system rather than as isolated apps.
Which teams and groups still support current work? Does each space have a responsible owner? Are guest members, private channels, and staff-role changes reflected in access?
Current workspace owner, intended members, guest purpose, sensitive-workflow boundary, approved exception, and date of the last owner review.
Assign practice leadership to confirm the workflow and intended members. Assign the tenant administrator to make approved membership or ownership changes.
- Every active workspace has a current owner
- Membership follows the intended staff role
- Guest access has a business purpose and owner
- Unused spaces have a review or closure decision
SharePoint and OneDrive sharing
A site-level setting, organization-level setting, link type, guest identity, or inherited permission can change who reaches a file. Review the actual sharing path and the content owner together.
Which sites allow external sharing? Are anonymous links allowed where they should not be? Who can invite guests? Can owners remove access and explain inherited permissions?
Approved site purpose, owner, external-sharing level, guest list or review record, sensitive-content boundary, exception, and access-removal path.
Use tenant management for approved sharing changes. Use compliance or legal specialists to decide retention, ePHI handling, contracts, and policy interpretation.
- Site and organization sharing settings are understood
- Sensitive work has a named storage location
- Guests and links can be reviewed and removed
- Content owners know who should retain access
Applications, guests, and vendor access
Third-party apps, vendor administrators, service principals, integrations, and delegated permissions can reach Microsoft 365 without looking like a normal staff account.
Which applications and vendors have tenant access? Who approved them? What permissions were granted? Does access still match the contract, workflow, and current support need?
Application or vendor name, business purpose, approval owner, permission scope, contractual route, review date, support contact, and removal decision.
Pause new access until the correct practice and technical owners are identified. Vendor contract, BAA, legal, and formal risk questions stay with their qualified owners.
- Every connected app has an identifiable owner
- Permissions match the approved business purpose
- Vendor admin access has an escalation path
- Unused access has a removal decision
Devices, sessions, logs, and recovery
Account security depends on the devices and sessions that use it, the audit evidence available after a change, and the separate recovery decisions for retained content and backup.
Which devices are enrolled or approved? What does an Intune status actually test? Who reviews audit events and alerts? What is retained, backed up, and recoverable under the chosen license and scope?
Device category, enrollment and policy scope, exceptions, alert owner, audit availability, retention decision, backup responsibility, restore evidence, and escalation path.
Use Microsoft 365 management for tenant and device administration. Use disaster recovery for backup and restore proof. Use compliance for formal evidence requirements.
- Approved device categories and exceptions are known
- Intune status is not treated as HIPAA certification
- Audit availability and response ownership are recorded
- Retention and backup are treated as separate decisions
An unknown answer is a routing signal.
A short checklist cannot prove a tenant secure. Its value is showing where configuration, evidence, approval, or ownership is missing before someone makes a broad change.
The same checklist can produce different answers in different tenants.
Microsoft 365 plans, add-ons, configuration history, identity design, device platforms, and business workflows affect which controls exist and how they should be introduced.
Review current licensing and platform documentation before changing production. A feature name alone does not establish coverage, correct rollout, or compliance.
Microsoft describes Security Defaults as a baseline without customization. Conditional Access offers more control and requires eligible Microsoft Entra licensing. Review the current Security Defaults guidance and Conditional Access overview.
Intune evaluates managed devices against configured organizational rules. Its compliant status is a tenant policy result, not a HIPAA conclusion. See Microsoft Intune device compliance.
SharePoint and OneDrive sharing depends on organization, site, guest, link, and identity settings. More restrictive settings can limit broader ones. See Microsoft external sharing guidance.
Searchability and retention vary by audit product and licensing. Confirm what evidence is available before relying on a retention window. See Microsoft Purview Audit guidance.
HHS cybersecurity goals identify high-impact practices such as email security, MFA, training, encryption, and access management. They do not make this article a risk analysis. See the HHS Healthcare Cybersecurity Performance Goals.
Use the page that owns the next decision.
This article owns education and self-assessment. Implementation, formal evidence, migration, and routine support have separate planned-service owners.
Clarify what this guide can and cannot answer.
Does a Microsoft BAA make the tenant HIPAA compliant?
No. Contract terms and eligible services are only part of the picture. The practice remains responsible for its use, configuration, safeguards, policies, workforce, vendors, evidence, and risk analysis.
Is MFA enough to secure Microsoft 365?
No. MFA is important, but the practice should also review privileged roles, sign-in paths, mail rules, sharing, apps, guests, devices, logs, response, and ownership.
Is an Intune compliant status a compliance decision?
No. It means a managed device met the rules configured for that tenant and policy evaluation. It is not a legal conclusion, certification, or substitute for risk analysis.
Should every practice use the same settings?
No. Licensing, workflows, device types, locations, vendors, data handling, and risk decisions differ. Broad changes should be tested and approved against the actual environment.
What should we send in a first request?
Share the broad concern, approximate users and locations, affected Microsoft 365 areas, tenant history, current owner, timing, and the decision still open. Do not send sensitive tenant data.
What if several checklist answers are unknown?
That usually means the tenant needs a bounded review before broad changes. The first useful output is a known-state record, open questions, owners, safe priorities, and service routing.
Primary sources used for this review
Source and freshness boundary
Microsoft product behavior, licensing, and documentation change. This page was reviewed against the linked primary sources on August 29, 2026. Confirm current Microsoft terms and tenant facts before implementation.
These sources do not endorse HealthDesk IT, prove a tenant secure, establish compliance, replace a formal risk analysis, or authorize changes to systems or data.
Turn unknown checklist answers into owned work.
If several answers are unclear, HealthDesk IT can map the existing tenant, separate configuration from practice decisions, and identify which changes need approval, testing, another specialist, or ongoing ownership.
- Call: 732-362-4949
- Useful context: approximate users and locations, tenant history, broad area of concern, current owner or vendor, and timing
- Do not send: PHI, usernames, passwords, tenant IDs, admin links, email contents, screenshots, exports, or access keys
