Massive Bio has made its inaugural strategic investment in Rivvi. Read the announcement

← Blog
TECHNOLOGYRivvi · July 30, 2025 · Updated October 1, 2026 · 7 min read

Why not give everyone Copilot for healthcare

If your organization already runs Microsoft 365, giving everyone Copilot is a reasonable first step. Microsoft Copilot and Copilot Chat can be covered by Microsoft's HIPAA BAA when configured correctly. The gaps are elsewhere: no healthcare data enrichment, no memory of your programs and patients, and no patient-facing calls, texts or chat.

Takeaways

  1. Compliance alone isn't the argument

    Microsoft says Copilot and Copilot Chat "support HIPAA compliance for properly configured implementations."

  2. Copilot is a general assistant

    It isn't built around NPI or CMS reference data, your care programs, or a record of which patients you called last week.

  3. It doesn't talk to patients

    Calls, texts and web chat with TCPA handling are a separate system you'd have to build or buy.

  4. Building is a real program

    A model API with a BAA is the start, not the product.

Copilot is HIPAA-eligible. Say it plainly.

Older versions of this argument leaned on "Copilot isn't HIPAA compliant." That isn't accurate in 2026, so we won't make it.

Here is what Microsoft says:

  • Microsoft Copilot (formerly Microsoft 365 Copilot) and Microsoft Copilot Chat "support HIPAA compliance for properly configured implementations."
  • Copilot Chat gets enterprise data protection when a user signs in with a Microsoft Entra work account, with no admin action needed. Microsoft says it "supports the BAA and HIPAA compliance for prompts and responses."
  • The BAA is offered by default through Microsoft's Data Protection Addendum. Both Copilot products are on the in-scope list.
  • Web search queries are not covered by the BAA. Consumer Copilot, used with a personal Microsoft account, "is for personal use."

So if staff are pasting PHI into personal ChatGPT accounts, moving them to Copilot Chat on work sign-in fixes the BAA problem. That's a real improvement. See shadow AI in healthcare for why it matters.

Where Copilot stops

The question isn't whether Copilot is allowed. It's whether it does the healthcare work. Four gaps show up fast.

No healthcare data enrichment

Copilot reads your files. It doesn't look up a provider's NPI, match a practice to CMS data, or fill in what a payer list left out. You do that by hand, then paste it back.

No outreach memory

It isn't built to track your CCM program rules, your AWV outreach script, or which patients were already called. You keep that record somewhere else.

No patient-facing channels

Copilot works with staff. It doesn't place outbound calls, answer an inbound line, send texts, or run a chat widget on your website.

No TCPA handling

Patient outreach brings consent, calling hours, opt-out and AI disclosure rules. Those need to live in the system that sends the message.

None of this is a knock on Copilot. It's a general-purpose assistant built for documents, email and meetings. Healthcare operations need care gap lists, payer files, provider directories and patient conversations.

What building it yourself actually involves

The usual build path is a model API with a BAA, plus your own engineering. For Microsoft shops that usually means Azure OpenAI inside your own tenant. Outside Azure, OpenAI offers a BAA for its API by request, contingent on Modified Retention settings. Confirm BAA scope for whichever model service you pick. Getting a covered model is the easy part.

Everything else is yours to build and run:

  1. Data plumbing. Ingest patient lists, payer reports and spreadsheets in whatever shape they arrive. Clean them. Match them to NPI and CMS reference data.
  2. Memory. Store what the organization knows about programs, patients and past outreach. Let staff see and correct it.
  3. Access control and logging. HIPAA's Security Rule requires mechanisms that "record and examine activity" in systems containing electronic PHI. You need role-based access and an audit trail.
  4. Voice and text. Telephony, phone numbers, speech recognition and synthesis, voicemail handling, and warm transfers to staff.
  5. Compliance logic. Consent records, calling-hour limits by time zone, opt-out across every channel, and AI disclosure at the start of each call. See our TCPA guide and AI disclosure laws.
  6. Maintenance. Model versions change. Vendor feature scope under BAAs changes. State laws change. Someone owns that forever.

We're not going to put a dollar figure on this. It depends on your team, your stack, and how much you already have. The honest framing: it's an engineering program with permanent staff, not a project with an end date.

See what a healthcare AI workspace does

Free for you and two colleagues, with a HIPAA BAA. No card. No clock.

A fair decision framework

FeatureYour situationBest fit
Office work on Microsoft 365Mostly documents, email and meetings, little patient dataCopilot Chat on work sign-in is probably enough
Strong in-house engineeringUnusual workflows, engineers who have shipped HIPAA and telephony systemsBuilding on a BAA-eligible model API can make sense
Ops teams in healthcare dataPayer lists, attribution files and spreadsheets daily, no data teamA healthcare AI workspace saves the most time
Patient outreachCalls, texts or web chat with patients, TCPA exposureBuy a platform with consent and opt-out built in

Copilot is enough when most work is documents, email and meetings, and patient data is incidental. Turn on work sign-in, write an acceptable use policy, and train staff.

Build when your workflows are unusual, you have engineers who've shipped HIPAA and telephony systems, and you're ready to own maintenance for years.

Buy when your team lives in healthcare data and patient outreach, you don't have a data or engineering team for it, and you need results this quarter.

Many organizations do two of these at once. Copilot for office work and a healthcare platform for operations is a common, sensible pairing.

Where Rivvi fits

Rivvi is a HIPAA-compliant AI workspace built for the gaps above. Staff chat with it, upload patient lists and payer reports, and build work product. Uploads are enriched against CMS and NPI registry data. Memory of your organization can be viewed, edited and corrected by your team.

On the same memory sits an action layer: inbound and outbound AI calls, texts, and a website chat widget, on the Team plan. TCPA opt-out is honored on every outreach path. When the schedule lives in your EHR, Rivvi warm-transfers the patient to the right person or creates a follow-up task for staff.

It also works alongside Microsoft. Connectors cover SharePoint, OneDrive, Excel, Outlook and Power BI, and a Teams app lets staff tag @Rivvi in a channel.

For proof at scale: at Southeast Medical Group (August 2026), Rivvi reached 104,000+ patients with a 0.45% opt-out rate.

Side-by-side details are in Rivvi vs Copilot and Rivvi vs ChatGPT.

Try the healthcare layer Copilot doesn't have

You and two colleagues, with a HIPAA BAA. No card. No clock.

Sources

Try it on your own data today.

Free to start. Most teams are using it the same day.