For many clinics and care facilities, Microsoft 365 is the center of daily work: email, calendars, Teams chat, SharePoint files and OneDrive storage. Because it holds so much sensitive information, it is also a top target. Attackers who steal an email password can read messages, send convincing fraud emails from a trusted account and download shared files.
Microsoft 365 includes many security features, but not all are switched on by default, and available features depend on your license. Here is a baseline worth reviewing.
This is the single most important step. Require MFA for all users, with extra care for administrators. Where your license allows, use conditional access policies, which can require MFA based on location, device or risk. If you use the basic security defaults option, confirm that it is enabled.
Avoid leaving exceptions for individuals or shared mailboxes with passwords that can sign in directly.
Older email protocols do not support MFA, and attackers use them to bypass it. Disable legacy authentication unless you have an unavoidable and documented need for it.
Limit the number of global administrators to a small number of people
Use separate administrator accounts, not the same account used for daily email
Require strong MFA, ideally phishing-resistant methods
Keep an emergency access account, secured and monitored, in case of lockout
Configure anti-phishing, anti-spam and anti-malware policies. Where licensed, use features that scan links and attachments at the time of click. Add a banner to messages from outside the organization, so staff can quickly see when an email did not originate internally. Combine this with SPF, DKIM and DMARC for your domain.
A common attacker trick is to create a hidden inbox rule that forwards mail to an outside address. Block or alert on external auto-forwarding, and review mailbox rules during investigations.
Make sure that unified audit logging is turned on and that logs are retained for a period that meets your needs. Set alerts for:
Suspicious sign-ins, such as impossible travel or sign-ins from unexpected countries
Creation of forwarding rules
Changes to administrator roles
Mass downloads or deletions
The alerts only help if someone watches them, so decide who is responsible.
SharePoint, OneDrive and Teams make it easy to share. Review settings so that:
External sharing is limited to what you need
Anonymous links expire
Sensitive folders are restricted to specific groups
Guest accounts are reviewed regularly and removed when no longer needed
Depending on license, consider sensitivity labels, data loss prevention policies and message encryption. Even a simple policy that warns users when they are about to send Social Security numbers or medical record numbers outside the organization can prevent mistakes.
Require devices accessing company data to meet basic standards, such as a passcode, encryption and current updates. Intune or similar management tools can enforce these, and allow removal of company data from lost devices.
Microsoft keeps the service running, but you are responsible for your data. Retention and recycle bin features help with accidental deletion, though they are not a complete backup. Consider a third-party backup for mailboxes, SharePoint and OneDrive, especially if records retention matters.
Microsoft offers a HIPAA business associate agreement through its standard licensing terms for covered services. Review the terms with your compliance officer, and remember that using the service does not by itself make you compliant. Your configuration and policies matter.
Microsoft provides a Secure Score dashboard that lists recommended actions for your tenant and shows progress. It is a good starting point for prioritizing, though not every recommendation fits every organization.
Check who has admin rights, which accounts are inactive, what sharing exists and what alerts fired. Compare settings against your documented policy.
UnityCare IT manages Microsoft 365 for healthcare organizations and can review your tenant against these baseline settings, then help turn on the missing controls without disrupting staff.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172