Is Dropbox HIPAA compliant? Yes — on a Business plan (Standard, Advanced, or Enterprise) with a signed Business Associate Agreement, then MFA, tight permissions, and audit. Personal, Plus, and “I encrypted the zip myself” are no. This is the Dropbox question, not a how-to for moving PHI in general.
If you meant how to transfer PHI (SFTP / email / a BAA for any vendor) → HIPAA-compliant data transfer. If you meant storage products → medical data storage solutions. If you meant anonymize first → what is data anonymization.
This page already owns /blog/is-dropbox-hipaa/. Dropbox is fine for admin files with a BAA; diagnostic DICOM needs a viewer / PACS, not a second Dropbox page. PYCAD is not a Dropbox reseller and does not sign BAAs for anyone else’s storage.
At a glance
| Requirement | Compliant | Not |
|---|---|---|
| Account | Dropbox Business: Standard, Advanced, or Enterprise | Free, personal, or Plus, for any PHI |
| BAA | Signed with Dropbox, on that Business tenant | Assuming the logo is enough, or a reseller’s BAA that is not Dropbox’s |
| Configuration | MFA required, folder permissions, public links off, logs reviewed | Default sharing, everyone is an editor |
| Training | Staff know what may live here and what may not | “They’ll figure it out” |
Dropbox has offered BAAs on business tiers since November 2015. The BAA is the legal floor, not the finish. Dropbox holds the vault; you set the combination.
Configure it
- MFA — required for every user, not optional. A stolen password is otherwise the whole tenant.
- Permissions — minimum necessary. Viewer vs editor per folder. Few admins. No master-key groups “for convenience.”
- Public links — off for any folder that might hold PHI. A public link is a breach the moment it is created.
- Audit logs — who opened, downloaded, changed permissions, logged in from where. Read them. HIPAA’s accounting story dies if you cannot show this.
Third-party apps connected to the tenant are outside the Dropbox BAA. Each one needs its own, or it does not touch PHI. That is the usual silent hole.
Not for diagnostic DICOM
Dropbox will store a .dcm the way it stores a PDF. That is not a clinical system. There is no diagnostic viewer (window/level, measurements, multi-frame), studies are huge and slow as a folder of files, and the activity log is not a radiology audit. Put the CT in PACS or a web viewer built for it. Keep Dropbox for handbooks, policy drafts, de-identified research once it is actually de-identified, and marketing files.
FAQ
Can I encrypt the files myself and use a personal Dropbox?
No. Encryption is one control. The BAA is the legal control, and Dropbox only offers it on Business. A personal account with a password-protected zip is still willful use of a non-BA vendor.
What if someone shares a PHI folder with a public link?
That is a breach. Investigate scope, notify the individuals, report to HHS. This is why public links are disabled in the Admin Console, not left as a training topic.
Does the Dropbox BAA cover apps I connect?
No. The BAA covers data inside Dropbox. A connected editor, CRM, or e-sign tool is a new business associate. No BAA there, no PHI there.
Can we use Dropbox for diagnostic images?
Do not. Wrong tool: no viewer, no clinical audit, bad fit for study size. Admin files with a BAA, yes. Diagnostic DICOM, no.
PYCAD builds custom web DICOM viewers and imaging pipelines — not a Dropbox competitor and not a HIPAA-as-a-service. Case studies.