Let’s be real, Microsoft 365 is amazing for collaboration. Teams, SharePoint, OneDrive… it’s all there, ready to make your medical practice run smoother than a freshly waxed floor. But here’s the thing: out of the box, M365 is configured for maximum collaboration, not maximum security.
And when you’re dealing with patient records in Mesa? That’s a HIPAA violation waiting to happen.
I’ve seen it dozens of times. A well-meaning office manager sets up Microsoft 365, everyone gets their logins, and suddenly the whole team is sharing files like it’s 2005. Except now, when something goes sideways, it’s not just embarrassing, it’s a $50,000 fine from the Office for Civil Rights.
So let’s talk about the seven settings that nearly every medical practice gets wrong, and how to fix them before they become expensive problems.
1. External Sharing is Wide Open (Yes, Really)
By default, SharePoint and OneDrive let users share files with anyone, even people outside your organization. That means Dr. Smith can accidentally email a patient chart to the wrong Gmail address, and boom, that file is accessible to a complete stranger.
The Fix: Lock down external sharing to “Only people in your organization” for any sites containing protected health information (PHI). Go to the SharePoint admin center, click on Policies > Sharing, and dial it down. If you absolutely need to share with outside vendors (labs, specialists, etc.), use specific sharing links that expire and require authentication.
HIPAA Reality: Unrestricted external sharing = automatic violation if PHI gets exposed. The OCR doesn’t care if it was an accident.

2. Multi-Factor Authentication Isn’t Required
I’ll make this one simple: if you’re not requiring MFA for every user accessing M365, you’re gambling with your practice. Passwords get phished, stolen, or reused from breached websites. MFA stops 99.9% of automated attacks cold.
Yet somehow, practices still resist it. “It’s too complicated for our front desk staff.” You know what’s more complicated? Explaining to your patients why their data was stolen because Brenda clicked a fake Microsoft login page.
The Fix: Go to the Azure AD/Entra admin center and turn on Security Defaults (if you’re a smaller practice) or set up Conditional Access policies that require MFA for all users. Yes, all users. Doctors, nurses, billing: everyone.
HIPAA Reality: The Security Rule requires “procedures for verifying that a person or entity seeking access to electronic protected health information is the one claimed.” MFA is basically the only way to do this in 2026.
3. Audit Logs Aren’t Turned On
Here’s a fun question: if someone accessed a patient file they shouldn’t have, could you prove it? Could you even find out?
Most practices can’t, because they never turned on audit logging. By default, Microsoft 365 keeps some basic logs, but the detailed audit data: the stuff that shows who viewed what and when: isn’t retained unless you configure it.
The Fix: Turn on unified audit log search in the Microsoft Purview compliance portal. Then set up retention policies to keep those logs for at least six years (that’s the HIPAA requirement). Want to get fancy? Set up alerts for suspicious activity, like someone downloading 500 patient files at 2 AM.
HIPAA Reality: The Security Rule explicitly requires audit controls. If you can’t produce logs during an investigation, you’re basically admitting you weren’t compliant.

4. Default Sharing Links Are Set to “Anyone”
When someone clicks “Share” on a file in OneDrive or SharePoint, what kind of link does M365 create by default? If you’ve never changed this setting, it’s probably “Anyone with the link”: meaning the file is accessible without even logging in.
That’s fantastic for sharing cat videos. It’s catastrophic for patient records.
The Fix: In the SharePoint admin center, change the default sharing link type to “Specific people” instead of “Anyone.” This forces users to explicitly choose who can access each file, rather than creating open links that can be forwarded to anyone.
HIPAA Reality: PHI should never be accessible via an anonymous link. Period. Even if it’s password-protected (which, let’s be honest, is usually “password123”).
5. Guest Access in Teams is Enabled (And Nobody Knows Who the Guests Are)
Microsoft Teams is incredible for collaboration. It’s also incredible for accidentally giving your lab vendor permanent access to your entire clinical operations channel: including all those patient discussions you probably shouldn’t be having in Teams anyway.
Guest access lets external users join your Teams, view files, and participate in conversations. The problem? Most practices enable it, add a few guests, and then completely forget about it. Those guest accounts stay active forever, long after the vendor relationship ends.
The Fix: Go to the Teams admin center and decide whether you actually need guest access. If you do, set up a process to review guest users quarterly and remove anyone who shouldn’t have access anymore. Better yet, use expiring guest access that automatically disables accounts after 90 days.
HIPAA Reality: Business Associate Agreements (BAAs) need to cover anyone with access to PHI. If you can’t identify all your guests, you can’t verify you have proper agreements in place.
6. Data Loss Prevention Policies Don’t Exist
DLP policies are like having a bouncer at the door of your data. They can automatically detect when someone tries to share sensitive information (like Social Security numbers or patient IDs) and block it before it leaves your organization.
Most practices? They don’t have any DLP policies set up. Zero. Zilch. Which means there’s nothing stopping someone from emailing an entire patient database to their personal Gmail account.
The Fix: Set up DLP policies in the Microsoft Purview compliance portal. Start simple: create policies that detect and block sharing of common PHI identifiers. Then expand from there. You can set policies to block, warn users, or just alert admins depending on the sensitivity.
HIPAA Reality: While not explicitly required, DLP is one of the best ways to satisfy the Security Rule’s requirement for “technical policies and procedures” that restrict access to authorized users.

7. Retention Policies Aren’t Configured (Or They’re Set to Delete Everything)
HIPAA requires you to keep patient records for at least six years (longer in some states). But what about all those Teams chats, emails, and SharePoint documents that contain PHI? Are they being retained properly?
I’ve seen practices with two opposite problems: either they never configured retention (so data gets deleted after default timeframes), or they set everything to “never delete” and now they’re paying Microsoft a fortune in storage costs while creating a litigation nightmare.
The Fix: Create retention policies that align with HIPAA requirements. Keep PHI-related content for at least six years, but don’t keep everything forever. Use retention labels in SharePoint to mark specific content that needs longer retention. And for the love of all that is holy, document your retention policy and stick to it.
HIPAA Reality: The Privacy Rule requires covered entities to retain records for six years from creation or last effective date. If you can’t prove you retained records properly, you’re in violation.
The Mesa Reality Check
Here’s the thing about running a medical practice in Mesa: you’re competing with massive healthcare systems that have entire IT departments. Your patients expect the same level of security and convenience, but you’re working with a fraction of the resources.
That’s where getting your M365 configuration right makes all the difference. These seven settings aren’t complicated to fix, but they require someone who knows what they’re doing and understands how HIPAA actually works in the real world.
Most “IT guys” can set up email and install software. But configuring M365 for HIPAA compliance? That’s a different beast. It requires understanding both the technology and the regulatory framework: and frankly, that’s pretty rare.
If you’re reading this and thinking “I have no idea if we have these settings configured correctly,” you’re not alone. And you’re smart to worry about it. Because the OCR doesn’t care about good intentions when they’re writing six-figure fines.
Want someone to audit your current M365 setup and fix the problems before they become expensive? That’s literally what we do. No high-pressure sales pitch, no jargon-filled reports you won’t understand: just a straightforward assessment and a plan to get you compliant without breaking the bank.
Check us out at ustech.ninja and let’s make sure your collaboration tools are actually working for you, not creating liability.
Because in 2026, “we didn’t know” isn’t a defense. But “we have an expert making sure we’re covered” absolutely is.





