If your organization already runs Microsoft 365, giving everyone Copilot is a reasonable first step. Microsoft Copilot and Copilot Chat can be covered by Microsoft's HIPAA BAA when configured correctly. The gaps are elsewhere: no healthcare data enrichment, no memory of your programs and patients, and no patient-facing calls, texts or chat.
Takeaways
Compliance alone isn't the argument
Microsoft says Copilot and Copilot Chat "support HIPAA compliance for properly configured implementations."
Copilot is a general assistant
It isn't built around NPI or CMS reference data, your care programs, or a record of which patients you called last week.
It doesn't talk to patients
Calls, texts and web chat with TCPA handling are a separate system you'd have to build or buy.
Building is a real program
A model API with a BAA is the start, not the product.
Copilot is HIPAA-eligible. Say it plainly.
Older versions of this argument leaned on "Copilot isn't HIPAA compliant." That isn't accurate in 2026, so we won't make it.
Here is what Microsoft says:
- Microsoft Copilot (formerly Microsoft 365 Copilot) and Microsoft Copilot Chat "support HIPAA compliance for properly configured implementations."
- Copilot Chat gets enterprise data protection when a user signs in with a Microsoft Entra work account, with no admin action needed. Microsoft says it "supports the BAA and HIPAA compliance for prompts and responses."
- The BAA is offered by default through Microsoft's Data Protection Addendum. Both Copilot products are on the in-scope list.
- Web search queries are not covered by the BAA. Consumer Copilot, used with a personal Microsoft account, "is for personal use."
So if staff are pasting PHI into personal ChatGPT accounts, moving them to Copilot Chat on work sign-in fixes the BAA problem. That's a real improvement. See shadow AI in healthcare for why it matters.
Where Copilot stops
The question isn't whether Copilot is allowed. It's whether it does the healthcare work. Four gaps show up fast.
No healthcare data enrichment
Copilot reads your files. It doesn't look up a provider's NPI, match a practice to CMS data, or fill in what a payer list left out. You do that by hand, then paste it back.
No outreach memory
It isn't built to track your CCM program rules, your AWV outreach script, or which patients were already called. You keep that record somewhere else.
No patient-facing channels
Copilot works with staff. It doesn't place outbound calls, answer an inbound line, send texts, or run a chat widget on your website.
No TCPA handling
Patient outreach brings consent, calling hours, opt-out and AI disclosure rules. Those need to live in the system that sends the message.
None of this is a knock on Copilot. It's a general-purpose assistant built for documents, email and meetings. Healthcare operations need care gap lists, payer files, provider directories and patient conversations.
What building it yourself actually involves
The usual build path is a model API with a BAA, plus your own engineering. For Microsoft shops that usually means Azure OpenAI inside your own tenant. Outside Azure, OpenAI offers a BAA for its API by request, contingent on Modified Retention settings. Confirm BAA scope for whichever model service you pick. Getting a covered model is the easy part.
Everything else is yours to build and run:
- Data plumbing. Ingest patient lists, payer reports and spreadsheets in whatever shape they arrive. Clean them. Match them to NPI and CMS reference data.
- Memory. Store what the organization knows about programs, patients and past outreach. Let staff see and correct it.
- Access control and logging. HIPAA's Security Rule requires mechanisms that "record and examine activity" in systems containing electronic PHI. You need role-based access and an audit trail.
- Voice and text. Telephony, phone numbers, speech recognition and synthesis, voicemail handling, and warm transfers to staff.
- Compliance logic. Consent records, calling-hour limits by time zone, opt-out across every channel, and AI disclosure at the start of each call. See our TCPA guide and AI disclosure laws.
- Maintenance. Model versions change. Vendor feature scope under BAAs changes. State laws change. Someone owns that forever.
We're not going to put a dollar figure on this. It depends on your team, your stack, and how much you already have. The honest framing: it's an engineering program with permanent staff, not a project with an end date.
See what a healthcare AI workspace does
Free for you and two colleagues, with a HIPAA BAA. No card. No clock.
A fair decision framework
| Feature | Your situation | Best fit |
|---|---|---|
| Office work on Microsoft 365 | Mostly documents, email and meetings, little patient data | Copilot Chat on work sign-in is probably enough |
| Strong in-house engineering | Unusual workflows, engineers who have shipped HIPAA and telephony systems | Building on a BAA-eligible model API can make sense |
| Ops teams in healthcare data | Payer lists, attribution files and spreadsheets daily, no data team | A healthcare AI workspace saves the most time |
| Patient outreach | Calls, texts or web chat with patients, TCPA exposure | Buy a platform with consent and opt-out built in |
Copilot is enough when most work is documents, email and meetings, and patient data is incidental. Turn on work sign-in, write an acceptable use policy, and train staff.
Build when your workflows are unusual, you have engineers who've shipped HIPAA and telephony systems, and you're ready to own maintenance for years.
Buy when your team lives in healthcare data and patient outreach, you don't have a data or engineering team for it, and you need results this quarter.
Many organizations do two of these at once. Copilot for office work and a healthcare platform for operations is a common, sensible pairing.
Where Rivvi fits
Rivvi is a HIPAA-compliant AI workspace built for the gaps above. Staff chat with it, upload patient lists and payer reports, and build work product. Uploads are enriched against CMS and NPI registry data. Memory of your organization can be viewed, edited and corrected by your team.
On the same memory sits an action layer: inbound and outbound AI calls, texts, and a website chat widget, on the Team plan. TCPA opt-out is honored on every outreach path. When the schedule lives in your EHR, Rivvi warm-transfers the patient to the right person or creates a follow-up task for staff.
It also works alongside Microsoft. Connectors cover SharePoint, OneDrive, Excel, Outlook and Power BI, and a Teams app lets staff tag @Rivvi in a channel.
For proof at scale: at Southeast Medical Group (August 2026), Rivvi reached 104,000+ patients with a 0.45% opt-out rate.
Side-by-side details are in Rivvi vs Copilot and Rivvi vs ChatGPT.
Try the healthcare layer Copilot doesn't have
You and two colleagues, with a HIPAA BAA. No card. No clock.