HIPAA Compliant Cloud Storage: Comparing Dropbox, Google Drive, OneDrive, and Box
“Is Dropbox HIPAA compliant?” is one of the most common questions healthcare organizations ask — and the honest answer is that no cloud storage product is compliant or non-compliant on its own. HIPAA compliance comes from the combination of a signed Business Associate Agreement, the right service tier, and how you configure sharing and access. The same brand can be perfectly acceptable on one plan and a violation waiting to happen on another.
The BAA is the dividing line
When you store protected health information (PHI) in a cloud platform, that vendor becomes your business associate, and HIPAA requires a Business Associate Agreement (BAA) before any PHI is uploaded. This is where the consumer-versus-business distinction matters. Free and personal tiers generally will not sign a BAA; the vendor’s HIPAA obligations only attach to specific paid plans.
- Dropbox offers a BAA on Dropbox Business / Standard and above, not on free or Basic personal accounts.
- Google Drive can be covered under the Google Workspace BAA, but you must accept the BAA in the Admin console and restrict PHI to the covered core services.
- Microsoft OneDrive is covered under the Microsoft 365 / OneDrive for Business BAA, which Microsoft includes for eligible commercial and enterprise plans — not consumer OneDrive.
- Box offers a BAA on its Business and Enterprise tiers and markets directly to regulated industries.
Signing the BAA is necessary but not sufficient. Most real-world cloud-storage breaches are not the vendor’s fault — they come from configuration: a folder shared with a public “anyone with the link” URL, an over-broad share to an entire domain, a former employee whose access was never revoked, or PHI synced to an unencrypted personal laptop. A compliant platform configured carelessly still exposes patients.
Configuration is where compliance lives
Whichever platform you choose, the controls that matter are similar: enforce multi-factor authentication, restrict external sharing and disable public links for folders containing PHI, apply role-based access so staff see only what they need, enable encryption at rest and in transit (all four platforms support this on business tiers), turn on audit logging, and review access regularly. Treat your cloud storage as another system that belongs in your formal risk analysis rather than an afterthought.
Put cloud storage in your Security Risk Analysis
The HIPAA Security Rule requires a Security Risk Analysis (SRA) — “an accurate and thorough assessment of the potential risks and vulnerabilities” to electronic PHI, at 45 CFR § 164.308(a)(1)(ii)(A). Cloud storage belongs squarely in that assessment: document which platform holds PHI, confirm the BAA is in place, record how sharing and encryption are configured, and identify the risk of misconfigured links or stale access. The SRA is what turns “we think Drive is fine” into documented, defensible evidence.
The proposed 2026 Security Rule update
In December 2024, the Office for Civil Rights published a Notice of Proposed Rulemaking (NPRM) that would strengthen the Security Rule by making controls such as multi-factor authentication, encryption of ePHI, and a maintained technology asset inventory effectively mandatory rather than “addressable.” The rule is not final, and if adopted as proposed, organizations would have roughly a 240-day compliance window after publication. For cloud storage, the practical takeaway is that MFA and encryption — already best practice — would move from recommended to required, so configure them now.
How Medcurity helps
Medcurity helps you document which cloud platforms hold PHI, confirm your BAAs are in place, and capture how each is configured — all inside a guided Security Risk Analysis and policy framework built for audits. Pricing starts at $499/year (about $42/month) for a single organization; larger or multi-entity groups can request a quote. From here, see our Business Associate Agreement guide and our guidance on managing HIPAA compliance with IT vendors.
Frequently asked questions
Is Dropbox HIPAA compliant?
Dropbox can be used in a HIPAA-compliant way on Dropbox Business plans that include a signed BAA, with sharing and access properly configured. Free and personal Dropbox accounts do not come with a BAA and should not store PHI.
Does Google Drive require anything special for PHI?
Yes. You need a Google Workspace plan, you must accept Google’s BAA in the Admin console, and you must restrict PHI to the BAA-covered core services and lock down external sharing. Consumer Gmail/Drive accounts are not covered.
Is encryption alone enough to be compliant?
No. Encryption is important, but compliance also requires a signed BAA, access controls, audit logging, and a documented risk analysis. A platform can be encrypted and still cause a breach through a misconfigured public share link.
Which cloud storage is best for a small practice?
Any of the major business tiers — Dropbox Business, Google Workspace, OneDrive for Business, or Box — can work if you sign the BAA and configure them correctly. The “best” choice usually comes down to what your practice already uses and can administer securely, not the brand itself.