Share via

Need to sign HIPAA BAA with personal Azure account

Facundo Lopez 0 Reputation points
2026-05-05T12:57:43.9066667+00:00

"I have an Azure Pay-as-you-go subscription and need to sign a HIPAA Business Associate Agreement to cover my Azure OpenAI Service usage. I cannot access the self-service BAA portal (aka.ms/BAA or servicetrust.microsoft.com) because those portals require a work/school account. Please advise on how to sign the BAA as an individual Azure customer."

Azure Policy
Azure Policy

An Azure service that is used to implement corporate governance and standards at scale for Azure resources.


1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-05-05T12:58:01.3166667+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    A HIPAA Business Associate Agreement (BAA) with Microsoft is available to individual Azure customers, but it is not signed through a separate, custom contract or a customer-specific BAA form.

    Key points for this scenario:

    1. No separate BAA to sign
      • There is no separate contract to sign for a HIPAA BAA with Microsoft Azure. The HIPAA BAA is incorporated by default into the Microsoft Product Terms and the Microsoft Products and Services Data Protection Addendum (DPA) for all customers who are covered entities or business associates under HIPAA.
      • The Product Terms reference the DPA, which states that execution of the customer’s volume licensing agreement includes execution of the HIPAA BAA.
    2. Applicability to Azure Pay‑As‑You‑Go
      • For Azure, the licensing agreements under which Azure is purchased incorporate the Microsoft Product Terms and the DPA. When that agreement is accepted for the subscription (including Pay‑As‑You‑Go), the HIPAA BAA terms are in effect for in‑scope services for any customer that is a covered entity or business associate under HIPAA.
      • This applies even if the subscription is associated with an individual account, as long as the customer is acting as a covered entity or business associate.
    3. No use of customer‑authored BAAs
      • Microsoft cannot use a customer’s own BAA template. The Microsoft HIPAA BAA is standardized to match how Microsoft operates its hyperscale, multitenant cloud services.
    4. Accessing the BAA text and related documentation
      • The HIPAA BAA is available via the Microsoft Product Terms and the Microsoft Products and Services DPA. The BAA itself is also exposed via the Microsoft HIPAA BAA link.
      • If access to portals such as the Service Trust Portal or specific URLs requires a work/school account, the underlying legal effect of the BAA does not depend on portal access; it is attached to the licensing agreement that governs the Azure subscription.
    5. Compliance responsibility
      • Having the BAA in place supports HIPAA compliance but does not, by itself, make an Azure OpenAI–based solution HIPAA compliant. The customer remains responsible for configuring and operating the solution so that it aligns with HIPAA and HITECH requirements.

    In practice, for an individual Pay‑As‑You‑Go Azure customer using Azure OpenAI for HIPAA‑regulated workloads, the BAA is considered executed through acceptance of the applicable Azure agreement that incorporates the Microsoft Product Terms and DPA; no additional signing step or portal action is required, even if the self‑service BAA portal cannot be accessed with a personal account.


    References:

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.