HIPAA Compliant Cloud Storage: Comparing Dropbox, Google Drive, OneDrive, and Box

“Is Dropbox HIPAA compliant?” is one of the most common questions healthcare organizations ask — and the honest answer is that no cloud storage product is compliant or non-compliant on its own. HIPAA compliance comes from the combination of a signed Business Associate Agreement, the right service tier, and how you configure sharing and access. The same brand can be perfectly acceptable on one plan and a violation waiting to happen on another.

The BAA is the dividing line

When you store protected health information (PHI) in a cloud platform, that vendor becomes your business associate, and HIPAA requires a Business Associate Agreement (BAA) before any PHI is uploaded. This is where the consumer-versus-business distinction matters. Free and personal tiers generally will not sign a BAA; the vendor’s HIPAA obligations only attach to specific paid plans.

Signing the BAA is necessary but not sufficient. Most real-world cloud-storage breaches are not the vendor’s fault — they come from configuration: a folder shared with a public “anyone with the link” URL, an over-broad share to an entire domain, a former employee whose access was never revoked, or PHI synced to an unencrypted personal laptop. A compliant platform configured carelessly still exposes patients.

Configuration is where compliance lives

Whichever platform you choose, the controls that matter are similar: enforce multi-factor authentication, restrict external sharing and disable public links for folders containing PHI, apply role-based access so staff see only what they need, enable encryption at rest and in transit (all four platforms support this on business tiers), turn on audit logging, and review access regularly. Treat your cloud storage as another system that belongs in your formal risk analysis rather than an afterthought.

Put cloud storage in your Security Risk Analysis

The HIPAA Security Rule requires a Security Risk Analysis (SRA) — “an accurate and thorough assessment of the potential risks and vulnerabilities” to electronic PHI, at 45 CFR § 164.308(a)(1)(ii)(A). Cloud storage belongs squarely in that assessment: document which platform holds PHI, confirm the BAA is in place, record how sharing and encryption are configured, and identify the risk of misconfigured links or stale access. The SRA is what turns “we think Drive is fine” into documented, defensible evidence.

The proposed 2026 Security Rule update

In December 2024, the Office for Civil Rights published a Notice of Proposed Rulemaking (NPRM) that would strengthen the Security Rule by making controls such as multi-factor authentication, encryption of ePHI, and a maintained technology asset inventory effectively mandatory rather than “addressable.” The rule is not final, and if adopted as proposed, organizations would have roughly a 240-day compliance window after publication. For cloud storage, the practical takeaway is that MFA and encryption — already best practice — would move from recommended to required, so configure them now.

How Medcurity helps

Medcurity helps you document which cloud platforms hold PHI, confirm your BAAs are in place, and capture how each is configured — all inside a guided Security Risk Analysis and policy framework built for audits. Pricing starts at $499/year (about $42/month) for a single organization; larger or multi-entity groups can request a quote. From here, see our Business Associate Agreement guide and our guidance on managing HIPAA compliance with IT vendors.

Frequently asked questions

Is Dropbox HIPAA compliant?

Dropbox can be used in a HIPAA-compliant way on Dropbox Business plans that include a signed BAA, with sharing and access properly configured. Free and personal Dropbox accounts do not come with a BAA and should not store PHI.

Does Google Drive require anything special for PHI?

Yes. You need a Google Workspace plan, you must accept Google’s BAA in the Admin console, and you must restrict PHI to the BAA-covered core services and lock down external sharing. Consumer Gmail/Drive accounts are not covered.

Is encryption alone enough to be compliant?

No. Encryption is important, but compliance also requires a signed BAA, access controls, audit logging, and a documented risk analysis. A platform can be encrypted and still cause a breach through a misconfigured public share link.

Which cloud storage is best for a small practice?

Any of the major business tiers — Dropbox Business, Google Workspace, OneDrive for Business, or Box — can work if you sign the BAA and configure them correctly. The “best” choice usually comes down to what your practice already uses and can administer securely, not the brand itself.