HIPAA & PRIVACY

Is Dropbox HIPAA Compliant?

Yes, on a team plan with a signed BAA. Dropbox Standard, Advanced, and Enterprise all qualify, and a US admin can sign the BAA from the admin console in a few minutes. Basic, Plus, Family, and Professional never qualify. The part most practices get wrong is what comes after the signature: sharing defaults, device controls, and the features Dropbox itself excludes from the agreement.

Cyanotype of a desk with a closed laptop, an external drive and a coiled cableFIG · 01
A desk with a closed laptop, an external drive and a coiled cable.

Yes — On Any Dropbox Team Plan With a BAA

Dropbox will sign a Business Associate Agreement for Standard, Advanced, and Enterprise teams. The BAA is a legal contract, not a security setting. After signing, you still have to lock down sharing, devices, and deletion, and keep PHI out of the features Dropbox excludes.

Standard / Advanced / Enterprise + BAA

HIPAA-eligible for PHI

Basic / Plus / Family / Professional

No BAA. Never compliant.

BAA signed in Admin console → Settings → Team profile — US customers only · Dropbox Dash is excluded

Which Dropbox Plans Get a BAA

HIPAA does not certify software. A cloud vendor that stores PHI for you is a business associate, and 45 CFR §164.502(e) says you may only hand ePHI to a business associate under a written contract. Dropbox offers that contract, the Business Associate Agreement, only to team accounts. Every consumer and solo plan is out, no matter how much you pay for storage.

PlanWho it's forBAADeleted-file recoveryPrice (annual)
Basic (free)IndividualNo30 days$0
PlusIndividualNo30 days$9.99/mo
FamilyUp to 6 peopleNo30 days$16.99/mo
Professional / EssentialsSolo professionalNo180 daysfrom $16.58/mo
Standard (a.k.a. Business)Teams, 3+ usersYes180 days$15/user/mo
Advanced (a.k.a. Business Plus)Teams, 3+ usersYes365 days$24/user/mo
EnterpriseLarge orgsYes365 daysCustom quote

Prices as of Aug 2026, billed annually; monthly billing runs about 20% higher ($18 Standard, $30 Advanced). Dropbox uses “Standard/Advanced” in the US and “Business/Business Plus” in some markets for the same tiers.

“A Professional plan with 3 TB and a password on every link is still a consumer account in Dropbox's eyes. No team, no admin console, no BAA.”

Pick Standard when

You have 3–15 staff, one office, and mostly need secure storage plus password-protected links to send records to patients or other providers.

Pick Advanced when

You need file-event audit logs, device approvals, tiered admin roles, or a full year of recovery. Auditors ask for the activity log first; Standard can't produce it at file level.

Solo clinician? A one-person practice can still buy Standard: Dropbox bills a 3-seat minimum (about $45/mo annual). That is cheaper than a breach. See who HIPAA applies to if you are unsure you are a covered entity.

How to Sign the Dropbox BAA

Dropbox is one of the few storage vendors with a fully self-service BAA. No sales call, no minimum seat count beyond the plan's own 3-user floor, no surcharge. The whole thing takes about five minutes. Do it before the first patient file is uploaded, not after: a BAA is not retroactive, and PHI stored without one is a reportable disclosure.

1

Confirm you hold a team admin role

Only certain admin types can execute the BAA. On Advanced and Enterprise, that means a Team admin (not a User-management or Support admin). On Standard there is a single admin role.

2

Open Admin console → Settings

Sign in at dropbox.com with the admin account, click Admin console in the left sidebar, then Settings.

3

Go to Team profile under Account

In the Account group, click Team profile. Scroll to the Advanced block at the bottom of that page.

4

Click Set up BAA, review, and sign

Dropbox presents its standard BAA. Read the subcontractor and breach-notice clauses; you cannot redline this document, so decide whether its terms work for you before signing.

5

File the executed copy

A signed copy downloads to the admin's Dropbox automatically. You can re-download it later from the same Team profile → Advanced → Download BAA. Store it with your other vendor contracts; OCR asks for BAAs during investigations.

US customers only

The electronic BAA appears only for teams with a US billing address. Others must go through Dropbox sales.

Blocks reseller support

A team with a signed BAA cannot enable reseller support. If an MSP resells your seats, ask them how they handle this.

Keep it 6 years

§164.316(b)(2) requires retaining policies and contracts for six years from when they were last in effect.

The BAA covers Dropbox. It does not cover the people you share with.

Sending a shared folder to a billing company or transcription service creates a second business associate relationship. You need your own agreement with them; use the BAA template generator to draft it.

Dropbox HIPAA Settings: The 10-Item Admin Checklist

The signed BAA makes Dropbox eligible. These settings make your deployment defensible. Work through them in the admin console, tick each one off, and record the completed list as evidence in your risk assessment. Dropbox moves menu items occasionally; the paths below are current as of Aug 2026.

0 of 10 configured

Dropbox encrypts files with AES-256 at rest and TLS in transit on every plan, which satisfies the addressable encryption standard in 45 CFR §164.312. Dropbox holds the keys, though. If you want zero-knowledge storage, see the Sync.com row in our file-sharing comparison.

What the Dropbox BAA Does and Doesn't Cover

Dropbox's HIPAA page draws a hard line around its own products. Two exclusions trip practices up in 2026: the AI layer, and every app that plugs into Dropbox from the outside.

Inside the BAA

  • Dropbox file storage and sync (team folders, member folders)
  • Shared links and shared folders
  • Dropbox Paper docs inside the team account
  • Admin console, activity logs, and reports
  • Dropbox Sign — only on an annual Standard or Premium Sign plan with its own BAA

Outside the BAA

  • Dropbox Dash, including Dash inside Dropbox (AI search and summaries)
  • Any third-party app or integration connected to Dropbox
  • Basic, Plus, Family, Professional, and Essentials accounts
  • A staff member's personal Dropbox linked on a work computer
  • Files a team member moves out of the team account
  • Dropbox Sign on monthly billing or without a signed Sign BAA

Dropbox Dash is the new exposure point

Dropbox states plainly that Dash “doesn't support compliance with HIPAA, including Dash in Dropbox.” Dash indexes connected content to answer questions and build summaries, and that processing sits outside the BAA. If your team has Dash, keep it disconnected from any folder holding PHI and tell staff not to ask it about patients. Treat it the same way you treat consumer ChatGPT: a tool that never sees a name, date of birth, or diagnosis.

Dropbox Sign for consent forms

Sign is a separate product with its own BAA, available only on annual Standard or Premium Sign plans above a minimum contract value, through your account manager. When HIPAA mode is on, Dropbox disables CC recipients and emailed PDF copies of signed documents. For lower volumes, compare it with DocuSign's HIPAA terms before committing.

6 Dropbox Sharing Mistakes That Turn Into Breaches

Dropbox has not been the weak link in the breaches we see reported. The practices using it have. These six patterns show up again and again in common HIPAA violations, and every one of them is preventable with an admin setting plus a one-sentence rule for staff.

Emailing an open share link to a patient

A link with no password and no expiration is a permanent, unauthenticated door to that file. Forwarded email, a shared family inbox, or a compromised account exposes the record indefinitely.

Fix: Require password + expiration at the team level so staff can't skip it. Deliver the password by phone or portal, and set links to expire in 7 days or less.

Syncing the PHI folder to a personal laptop

Dropbox's desktop client mirrors everything a member can see. A home computer with no disk encryption, shared with family, now holds your patient records outside every control you configured.

Fix: Turn on device approvals (Advanced) and limit each member to approved, encrypted devices. Use selective sync so PHI folders never download to laptops that leave the building.

Keeping a departed employee as a member for 'a few weeks'

Former staff keep full access, and their linked devices keep syncing. Delayed offboarding is a recurring finding in OCR settlements.

Fix: Same-day removal. Remote-wipe their devices, transfer their folders to a manager, and log the date. Put Dropbox on the offboarding checklist next to EHR access.

Letting members connect any app to Dropbox

A PDF editor, a Zapier automation, or an AI note tool linked by one member can read every folder that member can. None of those vendors are covered by the Dropbox BAA.

Fix: Block member-installed apps in the admin console. Maintain a short approved list; each approved vendor needs its own BAA on file.

Naming files with patient identifiers

Names and dates of birth in filenames appear in notifications, desktop previews, activity logs, and the recipient's browser tab. That is a disclosure even if the file itself is protected.

Fix: Use internal IDs or dates only: 'intake-2026-0417.pdf', not 'Maria_Lopez_intake.pdf'. Follow the minimum necessary rule for folder names too.

Trusting the 30-day trash as your backup

Permanent deletion by a member, or an expired recovery window, means a record is gone. Medical record retention laws run 6 to 10 years in most states.

Fix: Restrict permanent deletion to admins, and either buy the Data Governance add-on for retention policies or keep an independent, BAA-covered backup.

Staff behaviour is a training problem. Add a five-minute Dropbox module to your annual session and check understanding with the HIPAA training quiz. When something does go wrong, the incident report form captures what you need for the four-factor risk assessment.

Dropbox vs. Google Drive, OneDrive, and Box for PHI

Dropbox's strength is the sync client everyone already knows and a BAA you can sign in minutes. Its weakness is that it is storage only: no native DLP, no email or video under the same agreement, and the useful audit log lives on the pricier tier.

CapabilityDropboxGoogle DriveOneDriveBox
Cheapest BAA tierStandard, $15/userBusiness Starter, $7/userBusiness Basic, $7/userEnterprise, ~$35/user
How you get the BAASelf-sign in admin console (US)Accept in Admin ConsoleIncluded in Microsoft DPARequest; legal returns it
Link passwordsYes, all team plansNo (sign-in required instead)YesYes
Native DLP / PHI detectionNoEnterprise editionsBusiness Premium+Yes (Box Shield)
File-level audit logAdvanced+All paid editionsAll commercial plansAll BAA tiers
AI feature under the BAANo (Dash excluded)Gemini: verify current scopeCopilot: verify current scopeBox AI: verify current scope
Bundled with email/videoNoGmail, MeetOutlook, TeamsNo

Prices per user per month, annual billing, as of Aug 2026.

Stay on Dropbox if

Your team already lives in the desktop client, you send records to outside parties often (password links are simpler than Drive's sign-in model), and you run email and telehealth through vendors with their own BAAs.

Move to Google Drive or OneDrive if

You want one BAA to cover storage, email, calendar, and video. See our Google Drive and Microsoft Teams guides for the suite-level setup.

Look at Box if

You are a multi-site group or hospital department that needs built-in PHI classification, watermarking, and enterprise audit tooling, and can absorb the Enterprise-tier price.

Quick Reference: Dropbox HIPAA Compliance

Team plans = Yes

Standard ($15), Advanced ($24), and Enterprise are BAA-eligible. 3-seat minimum, annual pricing as of Aug 2026.

Consumer and solo plans = No

Basic, Plus, Family, Professional, and Essentials cannot get a BAA. Never store PHI in them.

Sign the BAA yourself

Admin console → Settings → Team profile → Advanced → Set up BAA. US customers only. Copy auto-downloads.

10 settings after signing

Required 2FA, team-only sharing, link passwords + expiry, no-download links, device approvals, remote wipe, admin-only deletion, retention, app lockdown, activity review.

Excluded from the BAA

Dropbox Dash (AI), every third-party integration, and Dropbox Sign unless on an annual Sign plan with its own BAA.

Related Tools & Guides