Is Dropbox HIPAA Compliant?
Yes, on a team plan with a signed BAA. Dropbox Standard, Advanced, and Enterprise all qualify, and a US admin can sign the BAA from the admin console in a few minutes. Basic, Plus, Family, and Professional never qualify. The part most practices get wrong is what comes after the signature: sharing defaults, device controls, and the features Dropbox itself excludes from the agreement.
FIG · 01Yes — On Any Dropbox Team Plan With a BAA
Dropbox will sign a Business Associate Agreement for Standard, Advanced, and Enterprise teams. The BAA is a legal contract, not a security setting. After signing, you still have to lock down sharing, devices, and deletion, and keep PHI out of the features Dropbox excludes.
Standard / Advanced / Enterprise + BAA
HIPAA-eligible for PHI
Basic / Plus / Family / Professional
No BAA. Never compliant.
BAA signed in Admin console → Settings → Team profile — US customers only · Dropbox Dash is excluded
Which Dropbox Plans Get a BAA
HIPAA does not certify software. A cloud vendor that stores PHI for you is a business associate, and 45 CFR §164.502(e) says you may only hand ePHI to a business associate under a written contract. Dropbox offers that contract, the Business Associate Agreement, only to team accounts. Every consumer and solo plan is out, no matter how much you pay for storage.
| Plan | Who it's for | BAA | Deleted-file recovery | Price (annual) |
|---|---|---|---|---|
| Basic (free) | Individual | No | 30 days | $0 |
| Plus | Individual | No | 30 days | $9.99/mo |
| Family | Up to 6 people | No | 30 days | $16.99/mo |
| Professional / Essentials | Solo professional | No | 180 days | from $16.58/mo |
| Standard (a.k.a. Business) | Teams, 3+ users | Yes | 180 days | $15/user/mo |
| Advanced (a.k.a. Business Plus) | Teams, 3+ users | Yes | 365 days | $24/user/mo |
| Enterprise | Large orgs | Yes | 365 days | Custom quote |
Prices as of Aug 2026, billed annually; monthly billing runs about 20% higher ($18 Standard, $30 Advanced). Dropbox uses “Standard/Advanced” in the US and “Business/Business Plus” in some markets for the same tiers.
“A Professional plan with 3 TB and a password on every link is still a consumer account in Dropbox's eyes. No team, no admin console, no BAA.”
Pick Standard when
You have 3–15 staff, one office, and mostly need secure storage plus password-protected links to send records to patients or other providers.
Pick Advanced when
You need file-event audit logs, device approvals, tiered admin roles, or a full year of recovery. Auditors ask for the activity log first; Standard can't produce it at file level.
Solo clinician? A one-person practice can still buy Standard: Dropbox bills a 3-seat minimum (about $45/mo annual). That is cheaper than a breach. See who HIPAA applies to if you are unsure you are a covered entity.
How to Sign the Dropbox BAA
Dropbox is one of the few storage vendors with a fully self-service BAA. No sales call, no minimum seat count beyond the plan's own 3-user floor, no surcharge. The whole thing takes about five minutes. Do it before the first patient file is uploaded, not after: a BAA is not retroactive, and PHI stored without one is a reportable disclosure.
Confirm you hold a team admin role
Only certain admin types can execute the BAA. On Advanced and Enterprise, that means a Team admin (not a User-management or Support admin). On Standard there is a single admin role.
Open Admin console → Settings
Sign in at dropbox.com with the admin account, click Admin console in the left sidebar, then Settings.
Go to Team profile under Account
In the Account group, click Team profile. Scroll to the Advanced block at the bottom of that page.
Click Set up BAA, review, and sign
Dropbox presents its standard BAA. Read the subcontractor and breach-notice clauses; you cannot redline this document, so decide whether its terms work for you before signing.
File the executed copy
A signed copy downloads to the admin's Dropbox automatically. You can re-download it later from the same Team profile → Advanced → Download BAA. Store it with your other vendor contracts; OCR asks for BAAs during investigations.
US customers only
The electronic BAA appears only for teams with a US billing address. Others must go through Dropbox sales.
Blocks reseller support
A team with a signed BAA cannot enable reseller support. If an MSP resells your seats, ask them how they handle this.
Keep it 6 years
§164.316(b)(2) requires retaining policies and contracts for six years from when they were last in effect.
The BAA covers Dropbox. It does not cover the people you share with.
Sending a shared folder to a billing company or transcription service creates a second business associate relationship. You need your own agreement with them; use the BAA template generator to draft it.
Dropbox HIPAA Settings: The 10-Item Admin Checklist
The signed BAA makes Dropbox eligible. These settings make your deployment defensible. Work through them in the admin console, tick each one off, and record the completed list as evidence in your risk assessment. Dropbox moves menu items occasionally; the paths below are current as of Aug 2026.
0 of 10 configured
Dropbox encrypts files with AES-256 at rest and TLS in transit on every plan, which satisfies the addressable encryption standard in 45 CFR §164.312. Dropbox holds the keys, though. If you want zero-knowledge storage, see the Sync.com row in our file-sharing comparison.
What the Dropbox BAA Does and Doesn't Cover
Dropbox's HIPAA page draws a hard line around its own products. Two exclusions trip practices up in 2026: the AI layer, and every app that plugs into Dropbox from the outside.
Inside the BAA
- Dropbox file storage and sync (team folders, member folders)
- Shared links and shared folders
- Dropbox Paper docs inside the team account
- Admin console, activity logs, and reports
- Dropbox Sign — only on an annual Standard or Premium Sign plan with its own BAA
Outside the BAA
- Dropbox Dash, including Dash inside Dropbox (AI search and summaries)
- Any third-party app or integration connected to Dropbox
- Basic, Plus, Family, Professional, and Essentials accounts
- A staff member's personal Dropbox linked on a work computer
- Files a team member moves out of the team account
- Dropbox Sign on monthly billing or without a signed Sign BAA
Dropbox Dash is the new exposure point
Dropbox states plainly that Dash “doesn't support compliance with HIPAA, including Dash in Dropbox.” Dash indexes connected content to answer questions and build summaries, and that processing sits outside the BAA. If your team has Dash, keep it disconnected from any folder holding PHI and tell staff not to ask it about patients. Treat it the same way you treat consumer ChatGPT: a tool that never sees a name, date of birth, or diagnosis.
Dropbox Sign for consent forms
Sign is a separate product with its own BAA, available only on annual Standard or Premium Sign plans above a minimum contract value, through your account manager. When HIPAA mode is on, Dropbox disables CC recipients and emailed PDF copies of signed documents. For lower volumes, compare it with DocuSign's HIPAA terms before committing.
6 Dropbox Sharing Mistakes That Turn Into Breaches
Dropbox has not been the weak link in the breaches we see reported. The practices using it have. These six patterns show up again and again in common HIPAA violations, and every one of them is preventable with an admin setting plus a one-sentence rule for staff.
Emailing an open share link to a patient
A link with no password and no expiration is a permanent, unauthenticated door to that file. Forwarded email, a shared family inbox, or a compromised account exposes the record indefinitely.
Fix: Require password + expiration at the team level so staff can't skip it. Deliver the password by phone or portal, and set links to expire in 7 days or less.
Syncing the PHI folder to a personal laptop
Dropbox's desktop client mirrors everything a member can see. A home computer with no disk encryption, shared with family, now holds your patient records outside every control you configured.
Fix: Turn on device approvals (Advanced) and limit each member to approved, encrypted devices. Use selective sync so PHI folders never download to laptops that leave the building.
Keeping a departed employee as a member for 'a few weeks'
Former staff keep full access, and their linked devices keep syncing. Delayed offboarding is a recurring finding in OCR settlements.
Fix: Same-day removal. Remote-wipe their devices, transfer their folders to a manager, and log the date. Put Dropbox on the offboarding checklist next to EHR access.
Letting members connect any app to Dropbox
A PDF editor, a Zapier automation, or an AI note tool linked by one member can read every folder that member can. None of those vendors are covered by the Dropbox BAA.
Fix: Block member-installed apps in the admin console. Maintain a short approved list; each approved vendor needs its own BAA on file.
Naming files with patient identifiers
Names and dates of birth in filenames appear in notifications, desktop previews, activity logs, and the recipient's browser tab. That is a disclosure even if the file itself is protected.
Fix: Use internal IDs or dates only: 'intake-2026-0417.pdf', not 'Maria_Lopez_intake.pdf'. Follow the minimum necessary rule for folder names too.
Trusting the 30-day trash as your backup
Permanent deletion by a member, or an expired recovery window, means a record is gone. Medical record retention laws run 6 to 10 years in most states.
Fix: Restrict permanent deletion to admins, and either buy the Data Governance add-on for retention policies or keep an independent, BAA-covered backup.
Staff behaviour is a training problem. Add a five-minute Dropbox module to your annual session and check understanding with the HIPAA training quiz. When something does go wrong, the incident report form captures what you need for the four-factor risk assessment.
Dropbox vs. Google Drive, OneDrive, and Box for PHI
Dropbox's strength is the sync client everyone already knows and a BAA you can sign in minutes. Its weakness is that it is storage only: no native DLP, no email or video under the same agreement, and the useful audit log lives on the pricier tier.
| Capability | Dropbox | Google Drive | OneDrive | Box |
|---|---|---|---|---|
| Cheapest BAA tier | Standard, $15/user | Business Starter, $7/user | Business Basic, $7/user | Enterprise, ~$35/user |
| How you get the BAA | Self-sign in admin console (US) | Accept in Admin Console | Included in Microsoft DPA | Request; legal returns it |
| Link passwords | Yes, all team plans | No (sign-in required instead) | Yes | Yes |
| Native DLP / PHI detection | No | Enterprise editions | Business Premium+ | Yes (Box Shield) |
| File-level audit log | Advanced+ | All paid editions | All commercial plans | All BAA tiers |
| AI feature under the BAA | No (Dash excluded) | Gemini: verify current scope | Copilot: verify current scope | Box AI: verify current scope |
| Bundled with email/video | No | Gmail, Meet | Outlook, Teams | No |
Prices per user per month, annual billing, as of Aug 2026.
Stay on Dropbox if
Your team already lives in the desktop client, you send records to outside parties often (password links are simpler than Drive's sign-in model), and you run email and telehealth through vendors with their own BAAs.
Move to Google Drive or OneDrive if
You want one BAA to cover storage, email, calendar, and video. See our Google Drive and Microsoft Teams guides for the suite-level setup.
Look at Box if
You are a multi-site group or hospital department that needs built-in PHI classification, watermarking, and enterprise audit tooling, and can absorb the Enterprise-tier price.
Quick Reference: Dropbox HIPAA Compliance
Team plans = Yes
Standard ($15), Advanced ($24), and Enterprise are BAA-eligible. 3-seat minimum, annual pricing as of Aug 2026.
Consumer and solo plans = No
Basic, Plus, Family, Professional, and Essentials cannot get a BAA. Never store PHI in them.
Sign the BAA yourself
Admin console → Settings → Team profile → Advanced → Set up BAA. US customers only. Copy auto-downloads.
10 settings after signing
Required 2FA, team-only sharing, link passwords + expiry, no-download links, device approvals, remote wipe, admin-only deletion, retention, app lockdown, activity review.
Excluded from the BAA
Dropbox Dash (AI), every third-party integration, and Dropbox Sign unless on an annual Sign plan with its own BAA.
Related Tools & Guides
Best HIPAA-Compliant File Sharing
Dropbox, Google Drive, OneDrive, Box, Egnyte, Sync, and ShareFile compared on BAA tier and controls.
Is Google Drive HIPAA Compliant?
Workspace BAA, sharing defaults, DLP rules, and the settings that matter.
HIPAA Encryption Requirements
What the Security Rule expects for ePHI at rest and in transit.
BAA Template Generator
Build the agreements you need with your own downstream vendors.
HIPAA Risk Assessment Tool
Document cloud storage as an asset and score its risks.