Can You Turn On Copilot Without Breaking HIPAA?
Somebody at your practice is already using AI. Maybe it's the front desk pasting an insurance denial letter into ChatGPT to draft an appeal. Maybe it's a manager summarizing patient complaints. Your staff will use these tools one way or another. The part you control is whether the tool they use sits inside your compliance boundary or outside it.
Microsoft is now putting Copilot in front of every Microsoft 365 user, so this decision is landing on medical practices whether they planned for it or not.
The line that matters
There are two different products wearing the Copilot name, and the difference is the whole ballgame for HIPAA.
The free Copilot, the one anyone can open in a browser or that comes bundled with Windows, is a consumer product. There's no business associate agreement behind it. If a staff member pastes anything containing patient information into it, that data has left your HIPAA boundary. Same story as free ChatGPT. Once it's pasted, you can't get it back, you can't audit it, and no agreement obligates anyone to protect it.
Microsoft 365 Copilot, the paid version that lives inside Outlook, Word, and Teams on your business tenant, is a different product. It runs inside your Microsoft 365 environment, your data stays in your tenant, and Microsoft's business associate agreement covers it the same way it covers your email and files. For a practice under 300 users it's an add-on license at $21 per user per month on top of your existing Microsoft 365 subscription. One catch worth knowing: when Copilot reaches out to the web to answer a question, that web search query falls outside the agreement, so part of setting it up correctly is deciding whether web search stays on.
So the answer to the headline question is yes, you can. But BAA coverage is only the first requirement, and it's the easy one.
The permission problem Copilot will find for you
Here's what actually goes wrong when a practice turns Copilot on: it starts answering questions using every file the asking user can technically reach.
Copilot doesn't have its own key to your data. It uses the permissions each user already has. That sounds safe until you ask when anyone last checked what those permissions actually are. In a lot of small practices the honest answer is never. Files get shared to "everyone in the company" because that was the fastest way to make an error go away three years ago. A billing spreadsheet sits in a Teams channel the whole staff was added to for a holiday party. Nobody notices, because nobody goes looking.
Copilot goes looking. That's its job. Ask it a question and it will cheerfully pull the answer from a folder the user forgot they could open. The permission problem was always there. Copilot just turns it from a filing cabinet nobody opens into a search engine everyone uses.
What turning it on properly looks like
Before Copilot goes live at a practice, the work is on the data side, not the AI side:
- Find out what's shared too broadly, and fix it. Microsoft's own tools will show you files shared with the whole organization.
- Decide where patient information is allowed to live, and label it. Microsoft 365 supports sensitivity labels that can keep marked content out of places it shouldn't go.
- Block the consumer versions. If the paid Copilot is your sanctioned tool, the free one in the browser should be off the menu on work devices.
- Write it down. Your HIPAA risk analysis is supposed to reflect how you actually handle patient data, and "we turned on an AI assistant" belongs in it.
None of this is exotic. It's the same permissions and data hygiene work a practice should have anyway. Copilot just removes the option of skipping it.
The question to ask this week
You don't need us for the first step. Ask your staff, without making it a gotcha: is anyone using ChatGPT or Copilot for work, and for what? You want honest answers, because the version of this that hurts you is the one nobody admits to.
If the answers worry you, resist the urge to ban AI outright. Bans push the same behavior onto personal phones where you can't see it. Give people a sanctioned tool inside the boundary, and clean up what that tool can reach.
What would Copilot find if it went looking through your shared files today? That's worth knowing before Microsoft answers it for you.
Tech 360 Solutions provides managed IT and cybersecurity for small businesses in the Kansas City metro. Built for HIPAA, FTC Safeguards, and other regulated environments.
See Where Your IT Actually Stands
Free compliance and IT assessment, a $500 value. Actionable findings on where your systems stand and what, if anything, needs attention.
- Response within 1 business day
- Written report you can keep
- Follow-up only if you ask