What Vendor Policies Should a Dental Office Review in Microsoft 365?

What Vendor Policies Should a Dental Office Review in Microsoft 365?

Use this Microsoft 365 vendor policy review checklist for dental offices to tier vendors, collect evidence, and document HIPAA due diligence.

LakeRidge Team
July 19, 2026
9 min read

Share:

Schedule Your Free Compliance Consultation

Feeling overwhelmed by compliance requirements? Not sure where to start? Get expert guidance tailored to your specific needs in just 15 minutes.

Personalized Compliance Roadmap
Expert Answers to Your Questions
No Obligation, 100% Free

CMMC Phase 2 begins November 10, 2026.

A dental office should review each vendor’s access to Microsoft 365, exposure to electronic protected health information (ePHI), security practices, incident response commitments, and contract terms before allowing the vendor to connect or receive data. This Microsoft 365 vendor policy review checklist for dental offices helps an office manager assign a risk tier, request evidence appropriate to that tier, and document a defensible decision under HIPAA’s policies-and-procedures standard at 45 CFR 164.316(a). The goal is not to collect every possible security document; it is to verify that the vendor’s controls match the data, access, and operational risk involved.

How should a dental office assign vendor risk tiers?

Start by classifying the vendor based on what it can see, change, store, or transmit in Microsoft 365. A company that only delivers printed appointment reminder postcards is not evaluated the same way as an IT provider with Global Administrator access, or a scheduling integration that reads patient email attachments from a shared mailbox.

For an office manager, the most useful questions are practical: Does the vendor receive patient information? Can it access email, SharePoint, Teams, OneDrive, or backups? Does it have an administrator account? Can it export data to its own system? Could a failure interrupt scheduling, billing, or patient communications?

Risk tier Typical Microsoft 365 vendor relationship Data or access exposure Approval expectation
Tier 1: Low Office supply provider; public training platform with no patient accounts; marketing vendor using de-identified metrics No ePHI, no Microsoft 365 tenant access, no access to staff mailboxes or files Office manager review and documented business purpose
Tier 2: Moderate Managed print vendor scanning to a designated mailbox; secure e-signature service; website chat provider; backup monitoring vendor May receive limited ePHI or metadata; limited application access; may process email or documents Office manager plus privacy/security decision-maker; BAA when ePHI is involved
Tier 3: High Managed service provider; dental IT consultant; email security provider; appointment integration; claims or document automation platform Persistent access to Microsoft 365, privileged roles, mailbox access, API permissions, or routine ePHI processing Formal security review, BAA, written approval, and recurring reassessment
Tier 4: Critical Microsoft 365 tenant administrator; cloud backup and recovery provider; identity management provider; virtual desktop or hosted communications vendor Global Administrator, Exchange Administrator, data recovery access, identity control, or ability to materially disrupt operations Leadership approval, detailed contract review, tested access controls, and at least annual review

Do not tier a vendor based only on company size or reputation. A small local IT company with delegated administrator privileges may present more risk than a large software company that never receives ePHI. Your Microsoft 365 vendor due-diligence process should follow the access and data path, not the vendor’s marketing claims.

What belongs in a Microsoft 365 vendor policy review checklist for dental offices?

Use the checklist below before enabling a Microsoft Entra ID enterprise application, sharing a SharePoint folder, granting a vendor mailbox delegation, or assigning any Microsoft 365 administrative role. Record the answers in the vendor file, along with the reviewer, date, tier, and final approval decision.

Review item Tier 1 Tier 2 Tier 3 Tier 4
Document service, business owner, and data involved Required Required Required Required
Confirm whether the vendor creates, receives, maintains, or transmits ePHI Required Required Required Required
Review Microsoft Entra ID permissions, OAuth scopes, and consent request If application connected Required Required Required
Verify least-privilege access and named vendor accounts Not usually needed Required when access exists Required Required; use privileged access controls
Require multifactor authentication (MFA) Not applicable Required for portal or tenant access Required Required; phishing-resistant MFA preferred
Review Business Associate Agreement (BAA) Not applicable if no ePHI Required if ePHI involved Required Required
Review security evidence and incident response process Basic questionnaire Security summary or questionnaire SOC 2 or equivalent evidence SOC 2, penetration testing, recovery evidence, and detailed review
Set access expiration and offboarding procedure As needed Required Required Required; quarterly access validation
Obtain leadership approval before production use As defined by policy Recommended Required Required

For Microsoft 365-connected vendors, inspect the actual permissions rather than relying on a salesperson’s statement that access is “secure.” Examples requiring closer review include Mail.Read, Mail.ReadWrite, Files.Read.All, Sites.Read.All, offline_access, and application permissions that allow access without an individual user being signed in. A scheduling vendor that needs access to one shared calendar should not receive broad access to every mailbox or SharePoint site in the tenant.

Which Microsoft 365 settings deserve special attention?

  • Confirm that vendor administrators use separate named accounts rather than a shared “IT Support” account.
  • Review delegated admin relationships and remove unused Microsoft Partner delegated administration access.
  • Use Microsoft Entra ID Conditional Access to require MFA and block legacy authentication for vendor accounts.
  • Limit SharePoint and OneDrive sharing to specific people or approved domains; do not use anonymous “Anyone” links for files containing patient information.
  • Review Enterprise Applications in Microsoft Entra ID and remove inactive integrations, expired pilots, and unapproved user consent.
  • Require the vendor to notify the practice before subcontractors receive access to ePHI or Microsoft 365 systems.

What evidence should the practice obtain from higher-risk vendors?

A vendor’s evidence should be proportionate to its tier. A small vendor may not have a SOC 2 report, but it should still be able to explain its safeguards, encryption, access controls, backup approach, and breach response process. Lack of a SOC 2 report is not automatically disqualifying; unexplained gaps, refusal to sign a BAA, or unrestricted administrator access are more meaningful warning signs.

  • SOC 2 Type II report: Request the most recent report for Tier 3 and Tier 4 vendors. Review the scope, report period, exceptions, complementary customer controls, and whether the service you use is included.
  • Penetration-test summary: For high-risk vendors, request a recent independent test summary showing testing date, scope, severity findings, and remediation status. You do not need exploit details.
  • HIPAA BAA: Obtain a signed BAA before ePHI is disclosed to a business associate. Confirm the legal entity named in the BAA matches the company providing the service.
  • Incident response policy: Verify that the vendor has a defined process for investigating, containing, documenting, and notifying customers about security incidents.
  • Encryption statement: Confirm encryption in transit using current TLS and encryption at rest for stored ePHI, backups, and portable devices.
  • Business continuity and recovery evidence: For critical vendors, request recovery objectives, backup frequency, disaster-recovery testing results, and a contact path for urgent outages.
  • Subprocessor list: Identify cloud hosts, support providers, backup providers, and offshore support organizations that may handle practice data.
  • Insurance certificate: Consider cyber liability and errors-and-omissions coverage for vendors that administer the tenant or handle significant patient data.

Keep only the evidence needed to support your decision. A concise vendor review form, signed BAA, current SOC 2 summary, permission screenshot, and approval record are often more usable during an audit than an unreviewed folder of documents.

How should the office perform an annual vendor reassessment?

HIPAA allows policies and procedures to change when changes are documented and implemented appropriately. Under 45 CFR 164.316(a), your vendor review policy should therefore include a repeatable reassessment process—not a one-time intake form that is never revisited.

  1. Export the active vendor list. Combine accounts payable records, Microsoft Entra ID Enterprise Applications, delegated admin relationships, shared mailbox permissions, and SharePoint external-sharing reports.
  2. Confirm the business owner. Ask each department whether the service is still used, what data it receives, and whether its access remains necessary.
  3. Reconfirm tier and data flow. A vendor may move from Tier 1 to Tier 3 if a new integration begins reading patient emails or storing treatment-plan documents.
  4. Refresh evidence. Request updated SOC 2 reports, penetration-test summaries, insurance certificates, BAA confirmations, and material security-policy changes for Tier 3 and Tier 4 vendors.
  5. Review Microsoft 365 access. Validate roles, MFA enrollment, Conditional Access coverage, OAuth permissions, mailbox delegation, and inactive accounts.
  6. Document exceptions. If a vendor lacks a desired artifact, record the reason, compensating controls, approver, and planned review date.
  7. Offboard what is no longer needed. Remove application consent, revoke accounts and tokens, end file sharing, recover equipment, and retain the termination record.

Reassess earlier than the annual cycle after a vendor breach, acquisition, new subprocessor, major Microsoft 365 integration, change in ePHI use, or request for expanded privileges. This is the operational part of a Microsoft 365 vendor review checklist for a dental practice: the file must reflect the relationship as it exists now.

Which contractual flow-down clauses should be included?

Your contract and BAA should turn review findings into enforceable obligations. The practice should have legal counsel review final language, especially for larger commitments, but the following operational requirements are reasonable starting points for a high-risk vendor relationship.

Vendor shall access Practice Microsoft 365 systems only through named,
authorized accounts approved by Practice. Vendor shall not use shared
administrator credentials and shall require multifactor authentication
for all personnel with access to Practice systems or ePHI.

Vendor shall use ePHI only to perform contracted services and shall not
sell, mine, train artificial intelligence models on, or otherwise use
ePHI for its own purposes without Practice's prior written authorization.

Vendor shall notify Practice without unreasonable delay, and no later
than 24 hours after discovery, of a suspected or confirmed security
incident involving Practice ePHI, Microsoft 365 credentials, or data.

Vendor shall ensure that each subcontractor with access to ePHI agrees
in writing to the same privacy, security, breach-notification, and
return-or-destruction obligations applicable to Vendor.

Upon termination, Vendor shall promptly return or securely destroy
Practice data as directed, revoke all access credentials and tokens,
and provide written confirmation of completion.

Also include rights to request reasonable security evidence, require cooperation during an incident, prohibit assignment without notice, and require advance notice of material changes to hosting locations or subprocessors. For a managed service provider, specify the approved Microsoft 365 roles—such as Exchange Administrator or Helpdesk Administrator—and prohibit Global Administrator unless the practice has approved it in writing for a defined purpose and time.

Start by inventorying every vendor connected to your tenant or patient workflows, then use this review process to close the highest-risk gaps before renewing contracts or granting new access.

 

Quick & Simple

Discover Our Cybersecurity Compliance Solutions:

Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you

 CMMC Level 1 Compliance App

CMMC Level 1 Compliance

Become compliant, provide compliance services, or verify partner compliance with CMMC Level 1 Basic Safeguarding of Covered Contractor Information Systems requirements.
 NIST SP 800-171 & CMMC Level 2 Compliance App

NIST SP 800-171 & CMMC Level 2 Compliance

Become compliant, provide compliance services, or verify partner compliance with NIST SP 800-171 and CMMC Level 2 requirements.
 HIPAA Compliance App

HIPAA Compliance

Become compliant, provide compliance services, or verify partner compliance with HIPAA security rule requirements.
 ISO 27001 Compliance App

ISO 27001 Compliance

Become compliant, provide compliance services, or verify partner compliance with ISO 27001 requirements.
 FAR 52.204-21 Compliance App

FAR 52.204-21 Compliance

Become compliant, provide compliance services, or verify partner compliance with FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems requirements.
 ECC Compliance App

ECC Compliance

Become compliant, provide compliance services, or verify partner compliance with Essential Cybersecurity Controls (ECC – 2 : 2024) requirements.