For practices handling patient information
You are responsible for protecting patient data in Microsoft 365. Nobody configured it for that.
Billing companies, medical management firms, therapy and behavioral health practices, home health agencies, and DME suppliers — organizations of five to twenty-five people where the administrator wears six hats and one of them, without anyone deciding it, became IT.
Your tenant was set up to get email working. It was almost certainly never configured against the obligations you carry. That gap does not announce itself — it surfaces during a client security review, an insurance renewal, or an incident.
What I find in practice tenants
These are not hypotheticals. They are the findings that come up again and again in small practices running Microsoft 365 without a dedicated administrator.
The owner’s account has no MFA on it
Staff accounts often get multi-factor authentication first, and the practice owner — who has the most access and the most valuable mailbox — gets an exemption because the prompts are inconvenient. That is the single account an attacker most wants.
Former employees can still sign in
A billing coordinator left eight months ago. Their account was never disabled, their licence is still being paid for, and their password has not changed since the day they were hired. Offboarding is the step that gets skipped when nobody owns it.
Nothing is backing up Microsoft 365
Retention is not backup. Microsoft keeps your data available and protects it against their own outages — that is a different job from restoring a mailbox a departing employee emptied, or files that ransomware encrypted and then synced. If nobody has set up a backup, there is not one.
Auto-forwarding rules nobody audits
A mailbox rule quietly copying inbound mail to an outside address is one of the most common findings in a compromised tenant, and one of the easiest to miss. Nobody notices because nothing appears broken.
Shared mailboxes that can be signed into directly
A shared mailbox like billing@ or intake@ is supposed to be accessed through delegation, not signed into. When sign-in is left enabled on the underlying account, you have an unlicensed, unmonitored door into patient correspondence.
The Microsoft 365 Security & Licensing Consultation
A guided working session. I look through your tenant with you and then write up what I found.
What it covers
- Identity and access — MFA coverage, admin accounts, conditional access, legacy authentication.
- Account lifecycle — active accounts with no current owner, stale sign-ins, offboarding gaps.
- Mail flow — auto-forwarding and transport rules, external sharing, shared mailbox sign-in.
- Data protection — what is retained, what is actually recoverable, and the difference.
- Audit and logging — whether the record you would need after an incident is being kept.
- Licensing — what you are paying for, what is assigned, and what is going unused.
What you receive
A written findings report
Each finding written in plain language, with what it is, why it matters to a practice like yours, and what fixing it involves. Yours to keep and to hand to anyone you like.
A scored security posture
Where your tenant stands today across the areas above, so you have a baseline rather than a vague sense of unease.
A licensing waste analysis
Unassigned licences, duplicate paid features, and subscriptions bought for staff who left. This line alone often covers the cost of the remediation work.
The terms, plainly
- No obligation. The report is yours whether or not we work together.
- No sales pitch. If you would rather read the findings and go quiet, that is a normal outcome.
- No changes to your tenant. The consultation looks; it does not touch. Nothing is altered without your explicit go-ahead.
What a client says
Jeff is not only highly skilled, trusted, and responsive, but he watches out for his clients with diligence and care. He was instrumental in helping to upgrade our Privacy and Security to 100% compliance and his support was incredibly helpful! I highly recommend him for any IT needs!
The work happens after your day ends
A practice cannot lose a clinical day to an IT project. When scheduling drives revenue and patients are already booked, a migration that runs from nine to five is not an inconvenience — it is a day of cancelled appointments and a waiting room of people who now have to be called.
So tenant changes, migrations, and cutovers are scheduled outside your working hours by default. You are not paying an after-hours premium for it; it is simply how this practice is built to operate.
All of it is administrative work inside Microsoft 365, delivered remotely. There is no truck roll to wait on and nobody walking through your office past patient information.
Why it matters here specifically
Small practices rarely have a slow week to spend. The alternative to after-hours work is usually no work at all — the project gets deferred another quarter, and the gap stays open.
Questions practices ask
Does Microsoft 365 back up my email?
Not in the way most people mean. Microsoft 365 has retention policies, a recycle bin, and version history, and Microsoft protects the service against its own failures. None of that is a backup you control. It will not reliably bring back a mailbox that was deliberately emptied months ago, files that were encrypted and then synced to the cloud, or a site someone deleted past its retention window. If nobody has deliberately set up a backup for your tenant, you do not have one.
Does using Microsoft 365 make my practice HIPAA compliant?
No. Microsoft will sign a Business Associate Agreement covering its own services, but that only addresses Microsoft’s side of the arrangement. How your tenant is configured, who has access, what is logged, and what you can produce as evidence remain yours. Microsoft 365 can be configured to support your HIPAA Security Rule obligations — it does not satisfy them on its own, and no product can make an organization "HIPAA certified" because no such certification exists.
Should we turn on Microsoft 365 Copilot?
Eventually, probably — but not first. Copilot answers using whatever the person asking already has access to. In a practice where the files sit in one shared location that everyone can open, that means Copilot can summarise patient information for a staff member who was never meant to see it, and do it instantly and helpfully. Nothing is being breached; the permissions were always that way, Copilot just makes them consequential. Sort out who can reach what, then turn it on.
Do I have to move off my current IT provider to do this?
No. The consultation is a read-only look at your tenant and a written report. Plenty of practices run it alongside an existing provider — sometimes to get a second opinion, sometimes to hand the findings to that provider to act on.
Find out where your tenant actually stands
A written report you keep, and nothing in your tenant changes.
- No obligation — the report is yours either way.
- No sales pitch — the findings stand on their own.
- No changes are made to your tenant.