Vendor compliance profile

Is Microsoft Forms HIPAA compliant?

Microsoft Forms appears in Microsoft's current Office 365 HIPAA/HITECH in-scope services list, but a Forms workflow is not automatically HIPAA compliant. Verify the qualifying Microsoft agreement and tenant, response storage, sharing, email notifications, file uploads, Power Automate flows, exports, support, and every connected service before collecting PHI.

Reviewed by Evidence: Public first-party sourcesConfidence: High
Visit vendor site

Direct compliance answer

Microsoft Forms HIPAA, BAA, PHI, and SOC 2 snapshot

Last checked: 2026-08-28 | Confidence: High

Direct answerMicrosoft Forms appears in Microsoft's current Office 365 HIPAA/HITECH in-scope services list, but a Forms workflow is not automatically HIPAA compliant. Verify the qualifying Microsoft agreement and tenant, response storage, sharing, email notifications, file uploads, Power Automate flows, exports, support, and every connected service before collecting PHI.
BAA availabilityMicrosoft says its HIPAA BAA is available through the Online Services Data Protection Addendum for eligible covered entities and business associates. Verify the tenant, subscription, current terms, and exact service scope.
Can it handle PHI?Answers, free text, file uploads, respondent identity, sharing links, notification emails, Excel exports, Power Automate flows, and connected apps can expose PHI.
SOC 2 caveatMicrosoft makes independently audited compliance reports available through its Service Trust Portal. Review the latest report scope for the tenant and services used; audit evidence does not replace Forms workflow review.
What to verifyWhether the Microsoft HIPAA BAA and current service list cover Forms in the exact tenant and subscription. Where responses and uploads are stored and which owners, collaborators, guests, support staff, and administrators can access them.

HIPAA status signal

Conditional

BAA public signal

Microsoft BAA in-scope service

SOC 2 evidence signal

Microsoft audit evidence

PHI warning: Answers, free text, file uploads, respondent identity, sharing links, notification emails, Excel exports, Power Automate flows, and connected apps can expose PHI.

Search query answers

Is Microsoft Forms HIPAA compliant?

Microsoft lists Forms among the Office 365 services in scope for its HIPAA BAA in applicable environments. That supports a conditional path, not automatic compliance: the customer must verify licensing, agreement scope, tenant settings, response storage, sharing, notifications, exports, and integrations.

Does Microsoft offer a BAA for Forms?

Microsoft says its HIPAA BAA is available through the Microsoft Online Services Data Protection Addendum for covered entities and business associates, and its in-scope services table includes Forms. Confirm the current agreement and qualifying subscription for the exact tenant.

Can Microsoft Forms collect PHI?

Potentially, but only after the Microsoft BAA, in-scope service status, tenant, storage, access, notification, export, and integration controls are approved. File uploads, Excel exports, email alerts, Power Automate flows, and shared links need separate review.

Is a personal Microsoft Forms account covered for PHI?

Do not assume a personal or consumer Microsoft account is covered. Verify the organization-controlled Microsoft 365 environment, qualifying license and agreement, admin controls, data location, support scope, and the exact Forms workflow.

HIPAA, BAA, and SOC 2 summary

HIPAAMicrosoft's HIPAA/HITECH offering lists Forms in the Office 365 Commercial and GCC in-scope service tables. Microsoft also states that using an in-scope service does not by itself make the customer's workflow compliant.
BAAMicrosoft says its HIPAA BAA is available through the Online Services Data Protection Addendum for eligible covered entities and business associates. Verify the tenant, subscription, current terms, and exact service scope.
SOC 2Microsoft makes independently audited compliance reports available through its Service Trust Portal. Review the latest report scope for the tenant and services used; audit evidence does not replace Forms workflow review.
PHI riskAnswers, free text, file uploads, respondent identity, sharing links, notification emails, Excel exports, Power Automate flows, and connected apps can expose PHI.
CategoryHIPAA-Compliant Forms and Intake Software
Last checked2026-08-28
ConfidenceHigh

Public evidence and open questions

What public sources say

  • Microsoft lists Forms among Office 365 services in scope for the HIPAA BAA in Commercial and GCC environments.
  • Microsoft says the HIPAA BAA is available through its Online Services Data Protection Addendum for eligible customers.
  • Microsoft states that customers remain responsible for their own compliance and use of Microsoft services.

What remains unconfirmed

  • Whether the buyer's exact Microsoft 365 license, tenant, region, support path, and agreement include the planned Forms workflow.
  • Whether file uploads, email alerts, Excel workbooks, SharePoint or OneDrive storage, Power Automate flows, exports, and third-party connectors remain in approved scope.

What it may be used for

  • Organization-managed Microsoft 365 form workflows after BAA scope, tenant eligibility, storage, permissions, notifications, and integrations are verified.
  • Low-PHI requests that use neutral questions and keep ordinary email, public links, and unsupported connectors away from sensitive responses.
  • Vendor comparison for teams already governing Microsoft 365 identity, SharePoint, OneDrive, and Power Platform services.

What not to use it for

  • Collecting PHI through a personal Microsoft account or an unverified tenant and subscription.
  • Sending response content through ordinary email notifications, public sharing links, ungoverned exports, or uncovered Power Automate connectors.
  • Assuming Microsoft 365 security or BAA availability covers every form, user, add-on, integration, and downstream system.

What to verify with the vendor

  • Whether the Microsoft HIPAA BAA and current service list cover Forms in the exact tenant and subscription.
  • Where responses and uploads are stored and which owners, collaborators, guests, support staff, and administrators can access them.
  • Whether email receipts, notifications, Excel exports, SharePoint or OneDrive files, Power Automate flows, APIs, and third-party apps can contain PHI.
  • Whether sharing, retention, deletion, audit, DLP, conditional access, MFA, and incident response controls are configured and documented.

Safer alternatives and related profiles

Safer alternatives to consider

  • Jotform HIPAA-enabled forms after its eligible plan, BAA activation, notifications, uploads, and integration scope are verified.
  • Google Forms only inside an eligible managed Google Workspace environment after BAA acceptance and downstream handling are reviewed.
  • A healthcare-specific intake platform when identity, consent, document exchange, routing, and EHR integration need a purpose-built covered workflow.

FAQ

Is Microsoft Forms HIPAA compliant?

Microsoft lists Forms among the Office 365 services in scope for its HIPAA BAA in applicable environments. That supports a conditional path, not automatic compliance: the customer must verify licensing, agreement scope, tenant settings, response storage, sharing, notifications, exports, and integrations.

Does Microsoft offer a BAA for Forms?

Microsoft says its HIPAA BAA is available through the Microsoft Online Services Data Protection Addendum for covered entities and business associates, and its in-scope services table includes Forms. Confirm the current agreement and qualifying subscription for the exact tenant.

Can Microsoft Forms collect PHI?

Potentially, but only after the Microsoft BAA, in-scope service status, tenant, storage, access, notification, export, and integration controls are approved. File uploads, Excel exports, email alerts, Power Automate flows, and shared links need separate review.

Is a personal Microsoft Forms account covered for PHI?

Do not assume a personal or consumer Microsoft account is covered. Verify the organization-controlled Microsoft 365 environment, qualifying license and agreement, admin controls, data location, support scope, and the exact Forms workflow.

Will Microsoft Forms sign a BAA?

Microsoft says its HIPAA BAA is available through the Online Services Data Protection Addendum for eligible covered entities and business associates. Verify the tenant, subscription, current terms, and exact service scope.

Can Microsoft Forms be used with PHI?

Do not use this vendor with PHI until your organization verifies BAA scope, covered services, configuration, access controls, data retention, and connected integrations.

Does SOC 2 mean Microsoft Forms is HIPAA compliant?

No. SOC 2 evidence can support security diligence, but it does not prove HIPAA compliance, confirm BAA coverage, or approve PHI use. Review HIPAA terms, BAA scope, covered services, configuration, and intended workflow separately.

What should buyers verify before using Microsoft Forms with PHI?

Whether the Microsoft HIPAA BAA and current service list cover Forms in the exact tenant and subscription. Where responses and uploads are stored and which owners, collaborators, guests, support staff, and administrators can access them. Whether email receipts, notifications, Excel exports, SharePoint or OneDrive files, Power Automate flows, APIs, and third-party apps can contain PHI. Whether sharing, retention, deletion, audit, DLP, conditional access, MFA, and incident response controls are configured and documented.

Last checked and source notes

Last checked
2026-08-28
Confidence
High
Dataset rows
274 vendors