Microsoft 365 Security Basics Every Clinic Should Switch On

For many clinics and care facilities, Microsoft 365 is the center of daily work: email, calendars, Teams chat, SharePoint files and OneDrive storage. Because it holds so much sensitive information, it is also a top target. Attackers who steal an email password can read messages, send convincing fraud emails from a trusted account and download shared files.

Microsoft 365 includes many security features, but not all are switched on by default, and available features depend on your license. Here is a baseline worth reviewing.

1. Require multi-factor authentication

This is the single most important step. Require MFA for all users, with extra care for administrators. Where your license allows, use conditional access policies, which can require MFA based on location, device or risk. If you use the basic security defaults option, confirm that it is enabled.

Avoid leaving exceptions for individuals or shared mailboxes with passwords that can sign in directly.

2. Block legacy authentication

Older email protocols do not support MFA, and attackers use them to bypass it. Disable legacy authentication unless you have an unavoidable and documented need for it.

3. Protect administrator accounts

Limit the number of global administrators to a small number of people

Use separate administrator accounts, not the same account used for daily email

Require strong MFA, ideally phishing-resistant methods

Keep an emergency access account, secured and monitored, in case of lockout

4. Turn on email protection

Configure anti-phishing, anti-spam and anti-malware policies. Where licensed, use features that scan links and attachments at the time of click. Add a banner to messages from outside the organization, so staff can quickly see when an email did not originate internally. Combine this with SPF, DKIM and DMARC for your domain.

5. Restrict automatic forwarding

A common attacker trick is to create a hidden inbox rule that forwards mail to an outside address. Block or alert on external auto-forwarding, and review mailbox rules during investigations.

6. Enable auditing and alerts

Make sure that unified audit logging is turned on and that logs are retained for a period that meets your needs. Set alerts for:

Suspicious sign-ins, such as impossible travel or sign-ins from unexpected countries

Creation of forwarding rules

Changes to administrator roles

Mass downloads or deletions

The alerts only help if someone watches them, so decide who is responsible.

7. Manage sharing carefully

SharePoint, OneDrive and Teams make it easy to share. Review settings so that:

External sharing is limited to what you need

Anonymous links expire

Sensitive folders are restricted to specific groups

Guest accounts are reviewed regularly and removed when no longer needed

8. Use data protection features

Depending on license, consider sensitivity labels, data loss prevention policies and message encryption. Even a simple policy that warns users when they are about to send Social Security numbers or medical record numbers outside the organization can prevent mistakes.

9. Secure devices

Require devices accessing company data to meet basic standards, such as a passcode, encryption and current updates. Intune or similar management tools can enforce these, and allow removal of company data from lost devices.

10. Back up your data

Microsoft keeps the service running, but you are responsible for your data. Retention and recycle bin features help with accidental deletion, though they are not a complete backup. Consider a third-party backup for mailboxes, SharePoint and OneDrive, especially if records retention matters.

11. Sign a business associate agreement

Microsoft offers a HIPAA business associate agreement through its standard licensing terms for covered services. Review the terms with your compliance officer, and remember that using the service does not by itself make you compliant. Your configuration and policies matter.

Use the Secure Score

Microsoft provides a Secure Score dashboard that lists recommended actions for your tenant and shows progress. It is a good starting point for prioritizing, though not every recommendation fits every organization.

Review quarterly

Check who has admin rights, which accounts are inactive, what sharing exists and what alerts fired. Compare settings against your documented policy.

UnityCare IT manages Microsoft 365 for healthcare organizations and can review your tenant against these baseline settings, then help turn on the missing controls without disrupting staff.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172