Skip to content
← Insights

August 12, 2026

Putting AI to work in a Microsoft 365 organization

Download the full white paper (PDF)

The complete edition – app-by-app detail, setup steps, a governance checklist, and full vendor sources.

All three leading AI assistants – Microsoft 365 Copilot, ChatGPT and Claude – can now work with Microsoft 365 content. But they get there by materially different routes, and those routes decide what setup you need and what your agreements actually cover when client information is involved.

This guide is written for an organization centered on Microsoft 365 – Outlook, Word, Excel, PowerPoint, Teams, SharePoint – that handles client information some of the time. Two questions run through every section: what can it do here, and what does it take to set up?

One rule frames all of it: capability is not coverage

Every assistant described here will work on whatever you give it. Whether your agreements cover that work when it touches protected health information depends on the product tier, the specific feature and its data path, and the configuration – never on the tool’s enthusiasm. A feature existing does not mean your Business Associate Agreement covers it.

And a further step: coverage is not compliance. A BAA is one prerequisite. Risk analysis, minimum-necessary access, policy, training, monitoring and incident response complete the picture.

The three paths into Microsoft 365

Every integration follows one of three architectures. Understanding them once saves re-learning them app by app:

  • Built in (Copilot) – the assistant is part of Microsoft 365 itself. Core grounding runs through Microsoft Graph under the signed-in user’s existing identity and permissions, and interactions can be audited and retained through Microsoft Purview when the necessary licensing and controls are configured.
  • Add-in beside the file (ChatGPT and Claude add-ins) – a sidebar works directly on the open workbook, deck or document. The file stays in Office, while selected content and prompts are processed by the configured AI service.
  • External app plus connector (ChatGPT apps, Claude’s connector) – the assistant’s own interface reaches into tenant content. Each connected path is a separate grant, governed partly on the vendor’s side.

The rule of thumb: moving away from native Microsoft integration adds another identity, data-processing and governance layer to review – and the plan tier increasingly decides whether client information is covered.

What each assistant does, app by app

  • Word – Copilot drafts, rewrites and summarizes inside the document. Claude for Word edits the open file as tracked changes with clickable citations. ChatGPT has no documented Word add-in; documents are reached indirectly through its SharePoint app.
  • Excel – Copilot generates formulas, charts and PivotTables linked to source data. ChatGPT’s sidebar builds, cleans and debugs whole workbooks. Claude answers with cell-level citations you can click and keeps formula relationships intact.
  • PowerPoint – Copilot builds a deck from a prompt or a Word file. ChatGPT drafts and revises slides while preserving editable structure. Claude builds on the deck’s own template and converts bullets into native, editable charts.
  • Outlook – Copilot drafts replies, summarizes threads and preps you for meetings. ChatGPT reaches the mailbox from its own interface rather than a pane inside Outlook. Claude for Outlook (beta) triages mail and leaves drafts unsent in the compose pane.
  • Teams – Copilot is the standout meeting assistant, though post-meeting recap requires saved transcription. ChatGPT searches chats and channels and creates Planner tasks. Claude has no Teams surface; its connector reads Teams content read-only.
  • SharePoint and OneDrive – Copilot grounds natively across the files, mail and chats each user may already access. ChatGPT retrieves per user, or syncs an indexed copy into OpenAI’s environment. Claude’s connector retrieves on demand under delegated permissions.

What the agreements cover today

  • Microsoft 365 Copilot – Microsoft lists Copilot as an in-scope service under its HIPAA BAA, assuming the Copilot add-on on an eligible Microsoft 365 plan. Generated web search, agents, connectors and opt-in preview retention models still need separate review before PHI use.
  • ChatGPT – covered in the regulated tiers only: ChatGPT for Healthcare, or Enterprise with a Regulated Workspace. The Excel and PowerPoint add-ins are expressly named there. ChatGPT Business has no BAA path.
  • Claude – Anthropic’s BAA covers HIPAA-ready Enterprise first-party features. Its Microsoft 365 connector and Office add-ins sit outside that BAA today, whatever plan you hold – which removes most of the connected Microsoft work described above.

Consumer ChatGPT and Claude subscriptions sit outside those vendors’ published organizational BAA-eligible offerings. If staff are using personal AI accounts for work, that use falls outside your approved contractual path – and a covered alternative, deliberately rolled out, is the practical fix. Blocking alone tends to drive use underground.

Where each platform fits

For a Microsoft 365-centered healthcare organization expecting AI workflows that may involve PHI, Microsoft 365 Copilot is often the most practical platform to evaluate first – because the identity, permissions, applications and governance environment are already Microsoft. Regulated ChatGPT is a credible separate-platform alternative with broad BAA-eligible functionality and a heavier contracting path. Claude Enterprise can support covered first-party workflows, with the Microsoft-integration track treated separately.

That is a platform-fit conclusion, not a compliance guarantee. And you do not have to pick a single vendor – what matters is that every tool in use has a defined lane, and that staff know which lane they are in.

The governance checklist

Beyond tool choice, these are the items that decide whether adoption is actually governed:

  • A feature-level approval register – approve by exact feature and path, not by vendor brand.
  • Minimum necessary – don’t give an AI more data than the workflow requires.
  • Offboarding – disable accounts, revoke OAuth and delegated connections and connector tokens, remove workspace access, review retained conversations.
  • A retention map – vendor backend retention, local browser storage, synced indexes and your own legal retention duties are four different clocks.
  • A meeting transcription policy – which meetings may be transcribed, whether transcripts are saved, and who can access them.
  • Human review – formulas, bulk edits, payer analysis and outbound email get reviewed before reliance.
  • Incident response – a defined step for “PHI went into an unapproved tool or excluded feature.”

One caution that applies to all three vendors: files and emails from outside your organization can contain hidden text designed to manipulate an AI assistant. Treat inbound email and external files as untrusted input, and require human review before accepting consequential changes.

A practical first pilot

For a smaller ABA or behavioral-health organization, a sensible first phase is small and quick: three to five users, one or two workflows, non-PHI or properly de-identified content, and a short fixed scope. Measure specific things – time saved, rework required, output quality, and any permission issues the pilot uncovers. Then decide the covered path before any PHI use.

Review who can access what first. No assistant fixes inappropriate existing access – and Copilot in particular makes existing oversharing easier to find. That review is the work that makes everything after it safe to say yes to.

Common questions

Is any of these tools “HIPAA compliant”?+

No tool is HIPAA compliant or non-compliant on its own. Compliance is a property of your organization’s configuration, agreements and use. Each vendor offers paths that can support regulated work, and each also has surfaces its agreements exclude.

Can we use PHI as soon as a BAA is signed?+

No. Confirm the exact service and feature are within the covered path, then complete risk analysis, access review, minimum-necessary rules, policy, training, retention and incident-response planning.

Our staff already use personal ChatGPT or Claude accounts for work. Does choosing a covered platform fix that?+

It is the necessary first half. Consumer subscriptions sit outside those vendors’ published organizational BAA paths, so personal-account use with client information creates uncontrolled disclosure risk. The fix is a covered alternative good enough that staff prefer it, plus clear policy and training – blocking alone tends to drive use underground.

Can Copilot see everything in Microsoft 365?+

No. For core grounding, Copilot can surface content the signed-in user already has permission to access. That is exactly why permission cleanup matters – over-shared content becomes easier to find.

What should our first pilot look like?+

For a smaller ABA or behavioral-health organization: three to five users, one or two workflows, non-PHI or properly de-identified content, a short fixed scope, and specific measures – time saved, rework required, output quality, and permission issues discovered.

Do we have to pick one vendor?+

No. A workable pattern is Copilot as the primary BAA-in-scope organizational platform – subject to feature, model-path and configuration review – with a covered enterprise chat tool, or a strictly non-PHI tool with clear policy, for specific teams. What matters is that every tool in use has a defined lane, and staff know which is which.

Not sure where to start?

In a short, no-commitment conversation we’ll help you find the safest first step for your practice.

Putting AI to work in a Microsoft 365 organization | Anchor Networks