Yes, and? They are not sending your PHI to Microsoft.
Or, if they use Microsoft cloud services like 365 or Azure, where they are sending PHI to Microsoft, Microsoft agrees to follow local healthcare information protection law. In the US, as a business associate, they are a covered entity under HIPAA and must maintain compliance to protect your information.
tl;dr:
Neat! But please don't shine lasers into your eyes even if it's supposed to be invisible.