Healthcare organizations want the productivity benefits of Microsoft 365 Copilot, but those benefits must be balanced with privacy, security, and compliance requirements.
I recently worked with a healthcare customer whose compliance team was concerned about persistent meeting artifacts. They wanted users to benefit from Copilot during Microsoft Teams meetings, but they did not want every conversation recorded or a transcript available afterward—especially for meetings involving sensitive operational, workforce, legal, compliance, or patient-related discussions.
Microsoft Teams provides an option that can help with this scenario: allowing Copilot only during the meeting while disabling recording and transcription.
Important: This article describes a technical configuration and customer scenario. It is not legal or compliance advice. Your privacy, security, compliance, records-management, and legal teams should determine whether this configuration is appropriate for your organization and specific meeting types.
Why This Matters in Healthcare
Healthcare organizations conduct many meetings where the discussion may include sensitive information:
- Patient care coordination
- Quality and safety reviews
- Compliance investigations
- Workforce and employee matters
- Security incidents
- Legal or risk-management discussions
- Research and clinical program planning
A recording or transcript can become an additional persistent information asset that must be appropriately protected, retained, governed, and eventually disposed of.
The HIPAA Security Rule requires covered entities and business associates to implement reasonable and appropriate administrative, physical, and technical safeguards for electronic protected health information. This includes evaluating risk, controlling access, implementing audit controls, and periodically reviewing security measures. The U.S. Department of Health and Human Services provides an overview of these requirements here.
HIPAA’s minimum necessary standard also generally calls for organizations to limit unnecessary access to protected health information, although important exceptions apply—including certain disclosures for treatment. HHS provides additional guidance on the minimum necessary requirement.
Turning off recording and transcription does not automatically make a meeting compliant. However, reducing the creation of unnecessary meeting artifacts can be one useful part of a broader, risk-based healthcare data-governance strategy.
Copilot Without a Persistent Transcript
When a Teams meeting is configured for Only during the meeting, Copilot can use temporary speech-to-text data to understand the active conversation. A traditional meeting transcript does not need to be started.
Users can ask Copilot to:
- Summarize what has been discussed
- Identify decisions
- List open questions
- Capture action items
- Explain areas of disagreement
- Help someone catch up after joining late
Microsoft explains that Copilot must be manually started by a participant in this configuration. Copilot can then provide insights based on the conversation taking place while it is active. See Microsoft’s guidance for using Copilot without recording or transcribing a Teams meeting.
There are two important limitations users must understand.
First, Copilot does not automatically start when the meeting begins. If someone activates it five minutes into the meeting, it will not have the same context it would have had if it had been started at the beginning.
Second, users should capture anything they need before leaving the meeting. Without transcription, they will not have the same post-meeting Copilot conversation history or transcript-based recap. Microsoft recommends copying any Copilot content users want to keep before the meeting ends.
Watch the Complete Walkthrough
In the following video, I demonstrate the user experience, the corresponding Teams administrative policies, the Facilitator consideration, and several lessons I learned while implementing this for a healthcare customer.
How to Use Copilot in Teams Without Recording or Transcription: Admin Setup & Gotchas
The Administrative Configuration
For this scenario, the goal was to create a scoped Teams meeting policy that:
- Prevented users from recording meetings
- Prevented users from starting transcription
- Allowed Copilot to operate during the meeting
- Avoided enabling a transcript-dependent post-meeting Copilot experience
The settings are managed through Teams meeting policies in the Teams admin center. In the video, I walk through the relevant recording, transcription, and Copilot controls and show the resulting experience from a user’s perspective.
For a healthcare organization, I would normally begin with a limited population instead of immediately applying a new policy globally. A pilot group gives the organization an opportunity to test the technical behavior and evaluate it with stakeholders from:
- Privacy and compliance
- Information security
- Legal and risk management
- Records management
- Clinical or operational leadership
- Microsoft 365 administration
- End-user training and adoption
The appropriate configuration may differ between clinical, administrative, research, legal, HR, and general collaboration scenarios. A single organization-wide meeting policy may not be the right answer for every healthcare meeting.
“No Transcript” Does Not Mean “No Compliance Data”
This distinction is critical.
Although participants may not receive a traditional meeting recording or transcript, Copilot prompts and responses can still be subject to Microsoft Purview retention policies. Depending on the organization’s configuration, those interactions may also be discoverable through Microsoft Purview eDiscovery.
Microsoft explicitly notes that Copilot prompts and responses may be retained for compliance purposes even when recording and transcription are disabled. Microsoft’s Purview training covers auditing, retention, eDiscovery, and compliance controls for Copilot interactions.
Healthcare organizations should therefore evaluate more than the visible Teams recap. The governance review should include:
- Copilot interaction retention
- Microsoft Purview Audit
- eDiscovery requirements
- Data Loss Prevention policies
- Sensitivity labels
- Records-management obligations
- Access to saved notes or exported Copilot responses
- Organizational policies governing the entry of PHI into AI-assisted experiences
The user experience may feel temporary, but the organization’s compliance controls can still operate behind the scenes.
The Lesson We Almost Missed: Facilitator Still Creates Loop Artifacts
This was one of the most important lessons from my recent engagement.
While working to Copilot to operate only during the meeting. Recording was disabled, transcription was disabled, and users did not receive the traditional transcript-based recap we were trying to avoid.
But Loop files were still appearing.
That initially seemed inconsistent with the policy design. After investigating, we discovered that the files were not being created by the personal Copilot experience—they were being generated because Microsoft Facilitator was enabled.
This distinction is easy to miss:
- Copilot only during the meeting gives an individual user private, real-time assistance without requiring a persistent transcript.
- Facilitator is a shared meeting agent that can generate collaborative notes and other meeting artifacts.
Microsoft documents that Facilitator’s meeting data is stored as a .loop file in the Meetings folder of the OneDrive account belonging to the user who initiated Facilitator. The data is treated as meeting transcript data for governance purposes. Facilitator notes may also be available to meeting participants through Notes and the meeting recap. Microsoft documents Facilitator’s behavior, storage, and administrative controls here.
For a healthcare organization, that Loop file is not simply a convenient set of notes. Depending on what was discussed, it could contain sensitive operational information, workforce information, security details, or protected health information. It becomes another persistent artifact that must be considered in the organization’s access, sharing, retention, eDiscovery, lifecycle-management, and data-protection strategy.
Copilot and Facilitator Require Separate Governance Decisions
Disabling recording and transcription while allowing Copilot during the meeting does not automatically prevent Facilitator from producing shared meeting content.
Healthcare organizations should make separate decisions about:
- Whether users should have access to Copilot during meetings.
- Whether users should be allowed to initiate Facilitator.
- Which meeting types are appropriate for shared AI-generated notes.
- Which users or groups should be allowed to use Facilitator.
- How the resulting Loop files should be stored, accessed, retained, labeled, and disposed of.
Facilitator can be extremely useful for approved operational meetings where collaborative notes, decisions, and follow-up actions are valuable. However, it may not be appropriate for every sensitive clinical, compliance, legal, HR, or incident-response meeting.
Microsoft allows administrators to control whether Facilitator is available across the organization or only to selected groups of users through Teams app policies and app-centric management. One important administrative nuance is that access to Facilitator can be scoped, while Microsoft’s control for turning off AI-generated meeting notes is currently tenant-wide rather than user-specific.
That makes intentional scoping particularly important. Instead of assuming every Copilot-licensed user should also be able to initiate Facilitator, organizations can identify the populations and meeting scenarios where persistent collaborative notes have a defined business purpose and an approved governance model.
The practical lesson is simple:
If your goal is to use Copilot without creating persistent meeting artifacts, do not stop after validating the recording, transcription, and Copilot policies. Verify whether Facilitator is enabled and inspect the resulting Loop behavior as part of your testing.
The Meeting Option That Can Cause Confusion and Broke Things For Us
One of the most important lessons from this implementation involved the meeting organizer’s Copilot setting.
If an organizer changes the meeting from Only during the meeting to During and after the meeting, Copilot expects transcription to be available. If the organization’s policy prevents transcription, the user may receive an error indicating that Copilot cannot access the meeting.
From the user’s perspective, that can look like a licensing problem or a broken Copilot deployment. In reality, it may simply be a mismatch between:
- The organization’s transcription policy
- The Copilot meeting option selected by the organizer
- The type of Copilot experience the user is attempting to start
Microsoft’s meeting guidance confirms that During and after the meeting requires transcription, while Only during the meeting can operate without it. Review the current Copilot behavior in Microsoft Teams meetings.
This is why user education is just as important as the policy itself.
A Healthcare Deployment Checklist
Before introducing this configuration more broadly, consider the following:
- Classify the meeting scenarios. Determine where in-meeting Copilot is appropriate and where AI assistance should be restricted entirely.
- Engage compliance early. Validate the design with privacy, security, legal, records-management, and compliance stakeholders.
- Use scoped policies. Pilot with specific users or groups before considering a broader rollout.
- Review more than recordings and transcripts. Evaluate Purview retention, auditing, eDiscovery, DLP, sensitivity labels, and exported Copilot content.
- Evaluate and scope Facilitator separately. Determine which users should be able to initiate Facilitator and which meeting scenarios justify shared AI-generated notes. Test where the resulting Loop files are stored, who can access them, and how retention, sensitivity labels, eDiscovery, sharing, and lifecycle controls apply.
- Test for unexpected artifacts. After a pilot meeting, inspect the organizer’s and initiator’s OneDrive, the meeting chat, Notes, Recap, Loop, and relevant Purview experiences. Confirm that the meeting produces only the artifacts your governance team expects.
- Train meeting organizers. Explain the difference between Only during the meeting and During and after the meeting.
- Prepare users for the temporary experience. Users should capture approved action items or summaries before the meeting ends.
- Test the complete workflow. Validate the experience using representative accounts, policies, licenses, meeting types, and organizational controls.
- Review the configuration periodically. Microsoft Teams and Copilot capabilities continue to evolve, and healthcare organizations should reassess their controls as features change.
Finding the Right Balance
Healthcare organizations do not necessarily have to choose between disabling Copilot completely and generating a recording and transcript for every meeting.
The Only during the meeting option provides another path: users can receive real-time assistance while the organization limits the creation of traditional post-meeting artifacts.
It is not a substitute for a complete healthcare compliance strategy. It is a technical control that can support a broader strategy built around risk assessment, appropriate access, retention, auditing, training, and clearly defined meeting scenarios.
The Facilitator lesson also demonstrates why organizations must test the entire meeting experience—not just the most visible policy settings. Copilot may be operating as expected while another enabled capability is still creating shared, persistent content.
For the healthcare customer that inspired this video, the technical settings were only part of the solution. The real success came from understanding the user experience, finding the unexpected Loop artifacts, separating Copilot governance from Facilitator governance, and teaching organizers how the different options behave.
That is the lesson I hope this walkthrough helps other healthcare organizations apply.