← All platforms
APP · Operations

Compliance

Microsoft 365 tenant checks for MSPs with healthcare clients: scans against the HIPAA Security Rule, a client questionnaire and a report of what was found.

Compliance connects to a client's Microsoft 365 tenant and runs an automated risk assessment against the HIPAA Security Rule — mailbox and identity configuration, access controls, logging, encryption, and more — then pairs the scan with a short questionnaire covering the administrative and physical safeguards no API can see. The two feed a single scored report, branded with your MSP's name, that you hand straight to the client. Built for MSPs with healthcare clients who need to show they're taking HIPAA risk seriously — practices, clinics, and any covered entity or business associate whose contracts or cyber insurance ask for a documented risk assessment. Run it during onboarding, at renewal, or whenever a client asks "are we okay?" v1 ships the HIPAA Security Rule control pack: automated checks scored against real tenant data, plus the attestation questionnaire for anything outside M365's visibility. A SOC 2 pack is next on the roadmap for MSPs whose clients need that framework instead. Every finding comes with a guided remediation runbook — what's wrong, why it matters, and the exact steps (or a one-click fix, where the tenant API allows it) to close the gap. A change log records what was applied, when, and by whom, so the next assessment shows real progress instead of the same list of findings. Compliance is a risk assessment, not a guarantee: it shows exactly where a tenant stands against the HIPAA Security Rule today and hands you a runbook for closing what it finds — real evidence you can act on and hand to a client, updated every time you reassess.

Explore this offering
  1. 01
    ComplianceReview the offering and its scope.
  2. 02
    See what is includedRead the description and requirements before getting started.
  3. 03
    Apply for the betaUse the link on this page for the next step.
Offering overview. Follow the details on this page.