COMPLIANCE OPERATIONS

Best HIPAA Compliant File Sharing & Cloud Storage

For most small practices the best HIPAA compliant file sharing option is the suite you already pay for: Google Workspace and Microsoft 365 both cover Drive, OneDrive, and SharePoint under a BAA on every business plan from $7/user/month. If you want files the vendor itself cannot read, Sync.com offers zero-knowledge encryption with a no-cost BAA from $6/user/month. For a dedicated governance platform, Egnyte is the strongest mid-market pick; Box and ShareFile only carry a BAA on their pricier tiers.

All seven platforms encrypt files at rest and in transit under 45 CFR §164.312. The decisions that matter are which plan the BAA attaches to, whether you can password-protect and expire outbound links, and what audit trail you get without an upgrade. If you also send PHI by email, pair this with our HIPAA email comparison. Last verified 2026-08-24.

Best If You Already Pay for a Suite

Google Workspace / Microsoft 365

Both include a BAA on every business plan — from $7/user/mo, no new vendor needed

Best Zero-Knowledge on a Budget

Sync.com

End-to-end encrypted by default, BAA at no extra cost, from $6/user/mo

Best Dedicated Compliance Platform

Egnyte

Sensitive-data classification, audit reporting, and governance built for regulated files

Cyanotype of a storage rack with a coiled patch cable and a closed laptop on the shelfFIG · 01
A storage rack with a coiled patch cable and a closed laptop on the shelf.

Do you need new file sharing software at all?

Most practices already pay for HIPAA-eligible cloud storage without realizing it. Google Workspace and Microsoft 365 both cover Drive, OneDrive, and SharePoint under a BAA on every business plan — the compliance gap is usually an unsigned BAA and permissive sharing defaults, not the software itself. Before buying anything, check whether your current suite is already covered (our guides on Google Drive and Dropbox walk through the exact settings).

Stay on your suite

  • You already pay for Workspace or Microsoft 365
  • PHI is shared mostly inside your own team
  • You can lock down sharing defaults yourself

Buy a dedicated platform

  • You exchange records with patients, attorneys, or payers weekly
  • You need zero-knowledge encryption or granular audit reports
  • Your suite tier locks DLP or audit logs behind an upgrade

Which HIPAA compliant file sharing platforms are worth comparing?

Every platform below will sign a Business Associate Agreement on at least one plan and encrypts files in transit and at rest. The differences that matter are which plan unlocks the BAA, whether the vendor can read your files, and what audit trail you get without an upgrade. Prices are per user per month on annual billing, verified August 2026.

Google Drive (Workspace)

BAA on every paid Workspace edition, accepted in the Admin Console

Strengths

  • BAA covers Drive on all paid editions, from $7/user/mo (annual)
  • Accept the BAA yourself: Admin Console → Account → Legal and compliance
  • Drive audit log and sharing restrictions on every paid edition
  • Shared drives keep PHI owned by the practice, not a departing employee

Limitations

  • No password-protected links (expiry dates only)
  • DLP rules require an Enterprise edition; Vault starts at Business Plus
  • Free and consumer Drive accounts are never BAA-eligible
Best for: Practices already running Gmail and Workspace
Full Google Drive HIPAA setup guide

OneDrive / SharePoint (Microsoft 365)

BAA built into Microsoft's Data Protection Addendum — no signature step

Strengths

  • BAA applies to all commercial plans via the Microsoft DPA
  • 1 TB per user on Business Basic at $7/user/mo (annual, since July 2026)
  • Password-protected and expiring links included on every plan
  • Purview audit log records file access, sharing, and downloads

Limitations

  • Purview DLP policies need Business Premium ($22/user/mo)
  • SharePoint sharing defaults are permissive until an admin tightens them
  • Consumer OneDrive (Microsoft 365 Personal/Family) is not covered
Best for: Practices on Outlook, Teams, and the Microsoft stack
How the same BAA covers Microsoft Teams

Box

Enterprise content platform with native DLP and governance

Strengths

  • Native data-loss protection and threat detection on Enterprise
  • Granular link controls: passwords, expiry, download limits, watermarks
  • Box Sign e-signature and Box Governance retention add-ons
  • Mature HIPAA program used by hospitals and research groups

Limitations

  • BAA only on Enterprise, Enterprise Plus, and Enterprise Advanced
  • Business and Business Plus plans are explicitly not BAA-eligible
  • Enterprise lists around $35/user/mo (annual) with a 3-user minimum
Best for: Multi-site groups and research organizations with IT staff

Dropbox

Familiar sync client with a self-service electronic BAA

Strengths

  • BAA available on every team plan (Standard, Advanced, Enterprise)
  • US admins sign the BAA electronically from the admin console
  • Standard starts at $15/user/mo with 3 TB pooled team storage
  • Dropbox Sign is covered by the same BAA

Limitations

  • File-event audit logs require Advanced ($24/user/mo, 3-user minimum)
  • No native DLP — relies on third-party integrations
  • Dropbox Dash (AI search) is excluded from HIPAA support
Best for: Small teams that already live in the Dropbox desktop client
Is Dropbox HIPAA compliant? Settings that matter

Egnyte

Compliance-first file platform with classification and audit reporting

Strengths

  • HIPAA-compliant storage listed on every plan; signs a BAA
  • Sensitive-data discovery flags PHI sitting in the wrong folder
  • Detailed audit reports on file access, sharing, and permission changes
  • Hybrid option syncs an on-premises server with the cloud

Limitations

  • Business plan is $22/user/mo (annual only)
  • Ransomware detection and lifecycle rules start at Enterprise Lite ($39)
  • More administration than a solo practice wants to own
Best for: Practices that want governance without a full enterprise contract

Sync.com

Zero-knowledge encrypted storage with a no-cost BAA

Strengths

  • Zero-knowledge, end-to-end encryption — Sync cannot read your files
  • BAA at no additional charge on Teams plans
  • Teams 1 TB at $6/user/mo (annual) is the cheapest BAA-eligible tier here
  • Link passwords, expiry dates, and download limits included

Limitations

  • No native DLP or content scanning (zero-knowledge prevents it)
  • Thinner admin audit trail than Box, Egnyte, or Microsoft
  • Weaker real-time co-editing and fewer integrations
Best for: Solo and small practices that want maximum encryption for the least money

ShareFile (Progress)

Secure client document exchange with e-signature built in

Strengths

  • HIPAA support and BAA on the Premium plan
  • Branded client portal for records requests and intake packets
  • E-signature and encrypted-email plugin included on Premium
  • Detailed activity reporting on every download and upload

Limitations

  • Premium is $26/user/mo (annual) with a 3-user minimum — about $78/mo floor
  • Advanced tier ($16.50) is not positioned for HIPAA
  • 3 TB account storage cap at both tiers
Best for: Practices exchanging documents with patients, attorneys, and payers

How do the file sharing security features compare?

Encryption at rest is table stakes — every vendor here has it. The rows below are where they actually diverge: who holds the keys, how tightly you can control an outbound link, and whether you get a usable audit trail on the plan that carries your BAA.

FeatureDriveOneDriveBoxDropboxEgnyteSyncShareFile
BAA on entry-level business plan
Yes
Yes
No
Yes
Yes
Yes
No
Zero-knowledge encryption
No
No
No
No
No
Yes
No
Password-protected links
No
Yes
Yes
Yes
Yes
Yes
Yes
Link expiration dates
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Native DLP / PHI detection
Partial
Partial
Yes
No
Partial
No
No
File-event audit logs at BAA tier
Yes
Yes
Yes
Partial
Yes
Partial
Yes
Built-in e-signature
No
No
Yes
Yes
Partial
No
Yes
Self-service BAA (no sales call)
Yes
Yes
Partial
Yes
Partial
Partial
Partial

Legend: = Yes · = Higher tier, add-on, or limited · = No. DLP: Google needs an Enterprise edition, Microsoft needs Business Premium, Egnyte's classification deepens on upper tiers. Dropbox file-event logs need Advanced. Verified August 2026.

Which plan actually carries the BAA, and what does it cost?

This is the table vendors bury. A platform being “HIPAA compliant” means nothing if your plan is not the one the BAA attaches to. Two of the seven — Box and ShareFile — do not offer a BAA on their cheaper business tiers. Prices are per user per month on annual billing as of August 2026; monthly billing typically adds 15–25%.

PlatformBAA-eligible planFrom / user / moStorage & notesHow you get the BAA
Google Workspace (Drive)Any paid edition (Business Starter+)$730 GB pooled/user (Starter); 2 TB (Standard, $14)Accept in Admin Console → Legal and compliance
Microsoft 365 (OneDrive/SharePoint)Any commercial plan (Business Basic+)$71 TB/user; DLP needs Premium ($22)Included in Microsoft DPA — nothing to sign
BoxEnterprise, Enterprise Plus, Enterprise Advanced~$35Unlimited; 3-user minimumRequest in Admin Console; legal team returns it in 3–5 business days
DropboxStandard, Advanced, Enterprise (all team plans)$153 TB team (Standard); audit logs need Advanced ($24)Sign electronically from the admin console (US customers)
EgnyteBusiness and above$22100 GB/user; annual billing onlyRequest from Egnyte during onboarding
Sync.comTeams 1 TB, 2 TB, 10 TB, Enterprise$61 TB/user (Teams 1 TB); 10 TB at $15Request from support; no additional charge
ShareFile (Progress)Premium$263 TB account; 3-user minimumEnabled with Premium; BAA via Progress

Cost for a 5-person practice (annual billing)

$30/mo

Sync.com Teams 1 TB — zero-knowledge, BAA included

$35/mo

Google Workspace Starter or Microsoft 365 Basic — suite plus BAA

~$175/mo

Box Enterprise at list — the only BAA-eligible Box tier

Whatever you pick, keep the executed BAA on file with your other vendor agreements — our BAA template covers the clauses OCR expects to see if it ever asks.

Which HIPAA compliant cloud storage is best for your practice?

Match the platform to how PHI actually moves in your office. A practice that mostly stores scanned records internally has different needs from one that sends intake packets to 40 new patients a week. If you are unsure which category you fall in, the risk assessment tool will surface where files leave your control.

Solo or 2–5 provider practice

Sync.com Teams, or the suite you already pay for

At $6–7/user you get a BAA-covered drive either way. Choose Sync.com if you want files unreadable by the vendor; choose Workspace or Microsoft 365 if you want files inside Gmail or Outlook.

Practice on Google Workspace or Microsoft 365

Stay put — sign the BAA and lock down sharing

Google needs the BAA accepted in the Admin Console; Microsoft's is already in the DPA. Then disable 'anyone with the link', turn on link expiry, and review the Drive or Purview audit log monthly.

Heavy document exchange with patients and third parties

ShareFile Premium

A branded portal, e-signature, and per-download activity reports make records requests, intake packets, and attorney exchanges auditable without email attachments.

Behavioral health or any practice with psychotherapy notes

Sync.com or Egnyte

Zero-knowledge encryption (Sync.com) or folder-level classification and access reports (Egnyte) give the extra separation psychotherapy notes require under 45 CFR §164.508(a)(2).

Multi-site group, FQHC, or research organization

Box Enterprise or Egnyte Enterprise Lite

Native DLP, retention policies, legal holds, and admin reporting justify the price once you have an IT or compliance lead to run them.

What makes file sharing HIPAA compliant?

No storage product is compliant on its own. HIPAA regulates your practice, and the platform is one control inside your program. The four requirements below map directly to the Security Rule; the detailed encryption requirements guide covers the technical specifics.

Executed BAA before the first PHI upload

45 CFR §164.308(b)(1)

Critical

The vendor is a business associate the moment it stores PHI for you. Sign or accept the BAA first, then migrate files — not the other way around.

Encryption at rest and in transit

45 CFR §164.312(a)(2)(iv) & (e)(2)(ii)

Critical

Addressable, not optional in practice: OCR treats unencrypted lost files as a breach. Every vendor here meets this; zero-knowledge (Sync.com) goes further by withholding the key from the vendor.

Unique logins, MFA, and role-based folder access

45 CFR §164.312(a)(1) & (d)

Required

No shared 'frontdesk' account. Enforce MFA for every user with PHI access and scope folders to job roles so a billing clerk cannot open psychotherapy notes.

Audit logs you actually review

45 CFR §164.312(b)

Required

Turn on file-event logging, export or retain it for six years, and put a monthly review on someone's calendar. An unread log will not help you in an investigation.

The two file sharing mistakes that become breaches

'Anyone with the link' sharing

A public link to a folder of scanned records is an impermissible disclosure the day it is created — and a reportable breach once discovered.

Sync clients on personal devices

Desktop sync copies PHI to laptops and phones your BAA does not cover. Restrict sync to managed devices or disable it for PHI folders.

Either mistake triggers the breach notification clock, and civil penalties in 2026 run up to $2,190,294 per violation category per year. Misconfigured sharing is one of the most common HIPAA violations OCR sees from small practices — and one of the easiest to prevent with a single admin setting.

What changed for HIPAA file sharing in 2026?

Two pricing moves reshaped the cheap end of this market. Microsoft raised Business Basic to $7 and Business Standard to $14 on July 1, 2026, and Google's Business Starter now also sits at $7 on annual billing. That puts the two suites at price parity for a BAA-covered drive — the choice between them is now purely about whether your practice lives in Gmail or Outlook, not cost. Both still lock DLP behind an upgrade (Enterprise editions at Google, Business Premium at Microsoft), which is where a dedicated tool like Egnyte earns its fee for practices that need PHI detection rather than just storage.

The bigger shift is on the enforcement side. OCR's Risk Analysis Enforcement Initiative keeps producing settlements where the missing document is not a BAA but a risk analysis that names where PHI is stored. Our read: list every cloud folder that holds PHI, the plan tier it sits on, and the date the BAA was executed. That single table is what an investigator asks for first, and it is the reason we favor platforms with a self-service BAA — Google, Microsoft, Dropbox — over ones that route the request through a sales or legal queue. The MFA mandate in HHS's proposed Security Rule update (final action now expected in 2027) points the same way: pick the platform where you can enforce MFA today without a plan change.

Quick Reference Card

If You NeedOur PickFrom (annual)
Already on Google WorkspaceDrive + accept BAA$7/user
Already on Microsoft 365OneDrive/SharePoint$7/user
Cheapest zero-knowledgeSync.com Teams 1 TB$6/user
Dedicated governanceEgnyte Business$22/user
Patient/attorney document portalShareFile Premium$26/user
Familiar sync clientDropbox Standard$15/user
Enterprise DLP + retentionBox Enterprise~$35/user

Three things to do the same day you pick a platform: execute the BAA, disable public link sharing, and add the platform to your HIPAA compliance checklist as a business associate with an annual review date.

Related Tools & Guides