Outlook can enable HIPAA compliance, but currently only if it’s part of one of the paid Enterprise versions of Office 365. Microsoft provides a Business Associate Agreement (BAA) for the Enterprise version of Office 365.
The free email platform offered by Microsoft, Outlook.com, doesn’t appear to have been built to handle ePHI securely or to comply with HIPAA. However, Outlook can be used as a HIPAA-friendly service with a paid Office 365 subscription and additional client-side encryption.
For HIPAA compliance features, users must be on one of the following plans: Office 365 Business Premium, Office 365 Business Essentials, Office 365 ProPlus, Office 365 Enterprise E1, Office 365 Enterprise E2, or Office 365 Enterprise E3.