The Microsoft BAA covers Microsoft’s obligations. Your subscriptions, identities, and data are yours to safeguard.
What you get
- Evidence from Defender for Cloud, Entra ID, Key Vault, and Monitor
- Conditional access and MFA coverage reporting
- Storage and database encryption verification
- Subscription-level scope mapping for ePHI workloads
The shared responsibility line
This is where most teams get it wrong. Your provider secures the infrastructure. You secure your configuration, your identities, your data classification, your logging retention, and your workforce. Every enforcement action we have read involved the second half of that sentence, not the first.
How it fits together
| Layer | Who owns it | How SuperHIPAA helps |
|---|---|---|
| Infrastructure | Provider (under BAA) | We verify your BAA is current and covers the services you use |
| Configuration | You | Continuous checks mapped to §164.312 |
| Data classification | You | ePHI inventory and flow mapping |
| Workforce | You | Training, acknowledgement, access reviews |
| Documentation | You | Policies, risk analysis, evidence, all versioned |
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.