Is Microsoft OneNote HIPAA Compliant for Shared Tumor Board Notebooks with Images?

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Is Microsoft OneNote HIPAA Compliant for Shared Tumor Board Notebooks with Images?

Kevin Henry

HIPAA

August 26, 2026

8 minutes read
Share this article
Is Microsoft OneNote HIPAA Compliant for Shared Tumor Board Notebooks with Images?

Yes—Microsoft OneNote can be used in a HIPAA-compliant manner for shared tumor board notebooks with images when it is deployed within eligible Microsoft 365 services, covered by a Business Associate Agreement, and configured with the right technical and administrative safeguards. Compliance depends on how you implement controls, not on a product “certification.”

This guide explains what you must put in place across plans, agreements, configuration, storage, access control, auditing, and governance to meet the HIPAA Security Rule for Protected Health Information (PHI). It is informational and not legal advice.

Microsoft 365 Plan Requirements

To keep PHI in OneNote, you need Microsoft 365 plans that include enterprise-grade OneDrive for Business and SharePoint Online, where OneNote notebooks are stored and protected. Consumer services (personal OneDrive, personal Microsoft accounts, or standalone free OneNote) are not appropriate for PHI.

  • Choose Business, Enterprise, or Government plans that are eligible for a Business Associate Agreement and include enterprise security features.
  • Ensure availability of Microsoft Entra ID for identity and access, Microsoft Purview for data protection, and, ideally, device and app management (for example, Intune) to govern endpoints that sync notebook content.
  • Host every tumor board notebook in a SharePoint site or a OneDrive for Business library provisioned for the care team; do not store on local drives or personal cloud locations.

Selecting a plan is the foundation for Data Storage Compliance; the plan you choose must support Encryption Standards, Access Control Mechanisms, and Audit Logging Requirements you intend to enforce.

Business Associate Agreement Necessities

A Business Associate Agreement (BAA) with Microsoft is mandatory if you will handle PHI in Microsoft 365. The BAA sets permitted uses and disclosures, breach reporting obligations, and baseline safeguards for covered services.

  • Verify that the BAA is executed for your tenant before placing PHI in OneNote, and confirm that the services underlying OneNote (SharePoint Online and OneDrive for Business) are in scope.
  • Understand shared responsibility: Microsoft secures the cloud infrastructure and service-level encryption, while you configure identity, access, endpoint protection, retention, and incident response.
  • Inventory add-ins, connectors, or third-party integrations touching notebooks; either bring them under a separate BAA or disable them for PHI workloads.
  • Document your HIPAA Security Rule risk analysis and risk management plan covering OneNote usage, images, and collaboration workflows.

OneNote Configuration Guidelines

Create a dedicated, secured container

  • Provision a dedicated SharePoint site (or Team-backed site) per tumor board or service line; store a single authoritative notebook there to prevent shadow copies.
  • Disable external sharing on the site by default; limit access to internal users assigned to the board.
  • Enable versioning and recycle bin protections to support recovery and oversight.

Apply data protection at the container

  • Apply a sensitivity label at the site or team level that enforces internal-only access, encryption, and restrictive sharing boundaries for all content, including the OneNote notebook.
  • Use Microsoft Purview DLP policies to prevent external sharing of notebook pages, block copy/print where feasible, and warn on attempted PHI exfiltration.

Harden collaboration and export paths

  • Restrict export and print routes (PDF exports, email sharing, “Copy link” scope) through policy and DLP; prefer viewing within the client over file downloads.
  • Require opening notebooks with authenticated clients; avoid anonymous links entirely.

Control endpoints and caches

  • Because OneNote maintains local caches, require device encryption (e.g., BitLocker/FileVault), strong sign-in, and automatic screen lock on all endpoints used for tumor board access.
  • Use Intune app protection and Conditional Access to allow sync only on compliant or managed devices; block “Save As” to unmanaged locations with endpoint DLP.
  • Enable remote wipe or selective wipe for lost or deprovisioned devices.

Handle images deliberately

  • Prefer de-identified images when feasible; if PHI must remain, capture only the minimum necessary and avoid storing raw DICOM sets in OneNote.
  • Strip image metadata before insertion when possible, and keep clinical source-of-truth images in your PACS/VNA, linking out if needed rather than duplicating large studies.

Secure Data Storage Practices

Meeting Data Storage Compliance hinges on encryption, key management, data residency, and lifecycle controls for notebook content and embedded images.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

  • Encryption Standards: ensure encryption in transit and at rest is enabled across the tenant; use industry-standard protocols (for example, TLS 1.2+ in transit and strong AES-based encryption at rest).
  • Key management: default service-managed keys are acceptable for many programs; if policy requires customer-managed keys, evaluate Customer Key or double key approaches recognizing potential feature trade-offs.
  • Retention and records: apply retention labels to tumor board notebooks to meet clinical and legal timelines; configure disposition reviews and immutable storage where required.
  • Geography: confirm data residency aligns with organizational and regulatory commitments; avoid cross-tenant or cross-geo sprawl for PHI content.
  • Backups and restore: test restore paths (version history, site restores) and document who can initiate recoveries to maintain chain of custody for PHI.

Access Control Implementation

Access Control Mechanisms are central to the HIPAA Security Rule. Your goal is least privilege, strong authentication, and tight session controls that reflect clinical operations.

  • Identity: require unique user IDs, multifactor authentication, and passwordless or phishing-resistant methods where supported.
  • Conditional Access: allow notebook access only from compliant, risk-free sessions; block download on unmanaged devices and enforce web-only sessions if necessary.
  • Group-based access: control notebook permissions via a dedicated security group mapped to the tumor board roster; automate join/leave for rotating clinicians.
  • Just-in-time access: use access reviews and time-bound assignments for temporary participants; remove access immediately when rotations end.
  • External collaboration: if inter-facility boards are required, use B2B collaboration with strict policy, verify BAAs between entities, and keep guests in separate groups with the narrowest scope.
  • Emergency access: maintain break-glass accounts with monitored, auditable use and strong compensating controls.

Audit Logging and Monitoring

To satisfy Audit Logging Requirements, you must be able to trace who accessed, edited, exported, or shared notebook content and when, alongside sign-in and administrative activity.

  • Enable the unified audit log for your tenant and retain logs per policy; include site, file, and sharing events associated with the notebook’s SharePoint library.
  • Alerting: create alerts for mass exports, external sharing attempts, unusual access patterns, or high-risk sign-ins related to tumor board resources.
  • Defend against exfiltration: monitor endpoints for clipboard, USB, and print events where PHI is involved; triage and document response actions.
  • Operationalize oversight: conduct periodic audit reviews, reconcile attendance against access logs for each board meeting, and record approvals for any permissions changes.
  • Incident readiness: script playbooks for suspected PHI leakage from OneNote, including containment, forensics, notification, and lessons learned.

Compliance Best Practices for Tumor Boards

Tumor boards blend multidisciplinary collaboration with sensitive imaging and narratives. Align your OneNote workflow with governance that protects PHI while supporting care decisions.

  • Standardize: use a board-approved notebook template with defined sections (case overview, imaging summary, pathology, plan) and label guidance for PHI fields.
  • Minimum necessary: capture only what you need for decision-making; avoid free-texting identifiers when a case ID suffices.
  • Image discipline: insert de-identified snapshots or annotated views, not entire studies; record the authoritative PACS link and accession number rather than duplicating data.
  • Roster hygiene: verify membership ahead of each meeting; use lobby or waiting-room patterns in meetings and restrict notebook access to confirmed participants.
  • Lifecycle: close cases, apply retention labels, and archive sections on a schedule; review access quarterly and after roster changes.
  • Training: brief all participants on PHI handling, DLP prompts, and incident reporting pathways; reinforce sanctions policy for noncompliance.

Conclusion

OneNote can support HIPAA-compliant tumor board collaboration with images when you pair eligible Microsoft 365 services under a Business Associate Agreement with rigorous configuration, encryption, access controls, and monitoring. If you cannot enforce these safeguards across cloud, users, and endpoints, do not place PHI in the notebook.

FAQs

What Microsoft 365 plans support HIPAA compliance?

Business, Enterprise, and Government Microsoft 365 plans that are eligible for a Business Associate Agreement and include OneDrive for Business and SharePoint Online can support HIPAA-aligned deployments. Consumer offerings (personal OneDrive or free OneNote) are not appropriate for PHI.

How does a Business Associate Agreement affect OneNote usage?

The BAA contractually covers Microsoft’s handling of PHI in eligible services. It does not make you automatically compliant; you must still implement the HIPAA Security Rule through access controls, encryption, auditing, risk management, and workforce training before storing PHI in OneNote.

What are the best practices for securing PHI in OneNote?

Store the notebook in a SharePoint or OneDrive for Business site with a sensitivity label, restrict external sharing, enforce MFA and Conditional Access, protect endpoints and OneNote caches, apply DLP and retention policies, and monitor the unified audit log for anomalous behavior.

Can images in tumor board notebooks be stored compliantly?

Yes, if you use eligible Microsoft 365 services under a BAA and enforce safeguards. Prefer de-identified images, strip metadata when possible, limit content to the minimum necessary, and keep authoritative imaging in your PACS with links in OneNote to avoid duplicating large PHI datasets.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles