25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Is Microsoft OneNote HIPAA Compliant?

Microsoft OneNote is HIPAA compliant and can be used to create, store, and share Protected Health Information (PHI) when an organization subscribes to a Microsoft 365 plan that supports HIPAA compliance and the OneNote app if configured to comply with the Security Rule. If these conditions are not met, organizations can still use OneNote, but not to create, store, or share PHI.

Microsoft OneNote is a digital note taking application that can be used on smartphones, tablets, and desktop computers. The application can be used to create, store, and share to do lists, screen grabs, and audio files. Healthcare professionals will no doubt see the appeal of OneNote, but care must be taken when using the application to avoid violations of HIPAA Rules.

Before any software or cloud platform can be used in connection with any electronic PHI (ePHI), it is first necessary to enter into a business associate agreement with the software/platform provider. If ePHI is to be used, adding it to the application or sharing data through it means the software/platform provider will be classed as a business associate. As such, they must ensure that appropriate security measures are incorporated into the platform to keep ePHI secure and prevent unauthorized access. Not all companies are willing to sign a BAA, although Microsoft does offer a BAA for many of its products.

Microsoft’s BAA covers many services in Microsoft 365 business plans – including OneNote and OneDrive for storing OneNote content. Data stored on OneDrive are protected by encryption, and Microsoft 365 business plans include access controls and meets HIPAA auditing requirements. Access logs can be obtained from Microsoft on request.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Microsoft 365 users are often targeted by cybercriminals seeking access to login credentials and the ePHI stored in Microsoft 365 accounts, so 2-factor authentication should be set up to prevent accounts from being accessed if credentials are compromised. Naturally, care should be taken sharing any data through either OneNote or OneDrive. ePHI should only be shared with individuals authorized to view the information.

Is Microsoft OneNote HIPAA Compliant?

So, is Microsoft OneNote HIPAA compliant? Provided a BAA has been obtained from Microsoft, OneNote can be HIPAA compliant. However, obtaining a BAA from Microsoft is just one element of HIPAA compliance. It is up to each organization to subscribe to a Microsoft 365 plan that supports HIPAA compliance  and to ensure that OneNote and associated products are configured correctly and are used in a HIPAA compliant manner.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist