palmiq Speak to an expert

Copilot Readiness for Healthcare: Fix the Tenant First

6 min read Microsoft

Microsoft 365 Copilot readiness for healthcare: what to fix in your tenant — permissions, policy, licensing — before you buy Copilot seats.

A sleek modern workspace featuring an iMac displaying a desert road and a stylish desk lamp.

The first question we usually get about Microsoft 365 Copilot is what it costs per user.

It’s the wrong first question. Not because price doesn’t matter, but because the seat price is the smallest and most predictable part of the decision. What determines whether Copilot is useful or embarrassing is the state of your Microsoft 365 tenant — who has access to what, how many old SharePoint sites nobody owns anymore, and whether patient or employee data is sitting somewhere it shouldn’t be.

Copilot answers questions using the content a given user already has permission to see. If your permissions are loose, Copilot will be efficient at surfacing things you didn’t intend to surface. That’s the whole project in one sentence.

Here’s how to think through it before you sign anything.

The seat price is not the project cost

Copilot is an add-on, not a standalone product. Microsoft’s nonprofit offers page states that a separate license for a qualifying Microsoft 365 plan is required to purchase Microsoft 365 Copilot. That “base license plus Copilot seat” structure is the single most common source of budget surprise for smaller organizations, so confirm which of your existing plans qualify before you build a number for your practice administrator or your board.

Pricing note: the figures below are as published in the cited sources on their publication dates — November and December 2025 for the third-party coverage; Microsoft’s nonprofit pages carry no publication date. Copilot pricing has changed repeatedly. Re-verify current pricing on Microsoft’s official Microsoft 365 Copilot pricing pages before you commit to a budget.

Microsoft introduced a purpose-built SKU for smaller organizations, Microsoft 365 Copilot Business. Third-party partner and distributor coverage describes it as aimed at organizations under 300 seats and priced from roughly $21 per user per month, versus $30 per user per month for the standard Microsoft 365 Copilot add-on (TrustedTech Team, November 19, 2025; TD SYNNEX, December 1, 2025). The same third-party coverage indicates Copilot Business attaches to Microsoft 365 Business Standard and Business Premium.

Treat those numbers as leads, not gospel. Promotional rates below the standard price have been reported more than once, and third-party sources disagree on when those promotions end. If a vendor — including us — quotes you a price from a blog post, ask them to confirm it against Microsoft’s own pricing page on the day you’re budgeting.

If you’re a nonprofit health entity, there’s a separate track worth checking. Microsoft’s nonprofit pages list Microsoft 365 Copilot as an add-on at a discounted price of $25.50 (USD) per user per month, paid yearly, for eligible nonprofits, and Microsoft states that nonprofit discounts are permitted for nonprofit staff and volunteers — not for program participants, members, or donors. For the newer Copilot Business SKU, a discussion post in Microsoft’s nonprofit partner community forum on November 21, 2025 (a forum thread, not official documentation) described only a limited-time introductory offer and noted that nonprofit pricing was not available for that product at that point, so don’t assume ongoing nonprofit pricing exists without written confirmation from Microsoft. Nonprofit grant and discount terms have shifted before; if that’s your situation, ask us and we’ll walk the current structure with you.

Copilot sees what your permissions already allow

This is Microsoft product behavior, not a scare tactic: Copilot’s answers are bounded by each user’s existing permissions. It doesn’t grant new access. It makes existing access dramatically easier to use.

In a healthcare setting, that has teeth. Consider what tends to accumulate in a clinic or small health system tenant after a few years:

  • SharePoint sites shared with “everyone except external users” because it was faster than building a group
  • Shared mailboxes for referrals, billing, or intake that half the staff can open
  • Departmental Teams created for a project in 2021 with no owner and no retention policy
  • Report exports and patient lists pulled from the EHR for a one-time audit and never deleted
  • Credentialing files, incident reports, or HR investigation notes parked in a personal OneDrive that was later shared broadly
  • Release-of-information and prior-authorization attachments sitting in mailbox folders
  • Old biller, vendor, and contractor guest accounts nobody removed after the engagement ended

None of that is unusual. All of it becomes more visible the moment a staff member can ask a natural-language question across the tenant. The risk isn’t that Copilot breaks a rule — it’s that a front-desk coordinator asks a reasonable question and gets an answer assembled from a folder they were never supposed to have.

The pre-rollout work is unglamorous and specific: review SharePoint and Teams permissions, retire broad sharing links, identify and label sensitive data, assign owners to orphaned sites, and clean up shared mailboxes and stale guest access. Do that first and Copilot becomes useful. Skip it and you’ve bought a faster way to find your worst-organized data.

Who should get the first seats

A blanket rollout is rarely the right move. Start where the work is document-heavy, the output is internal, and the review path is obvious.

Reasonable first cohorts in a clinic or small health system: practice administration, revenue cycle and billing, HR, credentialing, and marketing or patient communications. Meeting recaps, policy drafts, spreadsheet summaries, and internal reporting are low-risk places to learn what the tool is actually good at.

Clinical documentation workflows deserve a separate, slower conversation with your compliance lead and your EHR roadmap in the room. Don’t fold them into a general productivity pilot.

Write the policy before the first prompt

Copilot’s outputs are probabilistic. They require human review, every time. That needs to be written down before seats go live, not after someone pastes an AI-drafted summary into a patient-facing message.

A short, adoptable acceptable-use policy should cover:

  • What categories of data may and may not be entered into an AI assistant, with PHI called out explicitly
  • Mandatory human review of anything patient-facing or payer-facing
  • Retention and records expectations for AI-generated content
  • Who to contact when output looks wrong, and how it gets reported

On regulatory questions, get real advice rather than marketing assurances. Organizations handling protected health information may face HIPAA obligations, state privacy law, and grant or contractual restrictions that bear on AI processing. Have legal and compliance review your intended use cases before the pilot, not after.

Any claims about data residency, tenant data boundaries, or whether your data is used to train models should be read directly from Microsoft’s current documentation and quoted precisely. Those are the first claims a compliance officer will challenge, and they deserve a primary source.

One scoping note: Copilot feature availability and licensing differ in government and regulated cloud environments. If you operate in GCC or GCC High, verify separately. Nothing here covers those tenants.

Security posture comes first

Enabling generative AI across organizational data raises the cost of a security gap. Identity, endpoint, email, network, and backup posture are prerequisites, not follow-up items.

palmiq builds that foundation with the vendors we partner with: Microsoft, Fortinet, Sophos, CrowdStrike, SentinelOne, Veeam, and Acronis, where we hold Platinum partner status in the top 1% globally. Our MDR and EDR services run through a 24/7 SOC with a 15-minute response SLA on critical issues, and within that scope we sustain a 99.9% threat neutralization rate across 1,200+ threats neutralized monthly.

That’s the platform we want under a tenant before AI reads across it. None of it is an endorsement of any particular AI capability, and none of it substitutes for your own compliance review.

A reasonable first 90 days

  1. Readiness assessment. Inventory licensing, permissions, sharing links, orphaned sites, guest accounts, and where PHI and other sensitive data actually live.
  2. Remediation. Fix sharing defaults and labeling before any seat is assigned.
  3. Policy. Adopt the acceptable-use and human-review rules, with compliance sign-off.
  4. Small pilot. A focused cohort, a defined use-case list, and named reviewers.
  5. Measure, then decide. Expand based on what the pilot showed, not on a promo deadline.

Licensing is the easy part. Data readiness is the project.

If you want a straight assessment of where your Microsoft 365 tenant stands before you commit to Copilot seats, book a discovery call. We’ll tell you what needs fixing first.

Want this handled for you?

We run managed IT, security and backup for organisations that would rather not read another article about it.

Speak to an expert

or call 703-336-9700