Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors

Is Dropbox HIPAA compliant?

Is Dropbox HIPAA compliant? Yes — on a Business plan (Standard, Advanced, or Enterprise) with a signed Business Associate Agreement, then MFA, tight permissions, and audit. Personal, Plus, and “I encrypted the zip myself” are no. This is the Dropbox question, not a how-to for moving PHI in general.

If you meant how to transfer PHI (SFTP / email / a BAA for any vendor) → HIPAA-compliant data transfer. If you meant storage productsmedical data storage solutions. If you meant anonymize firstwhat is data anonymization.

This page already owns /blog/is-dropbox-hipaa/. Dropbox is fine for admin files with a BAA; diagnostic DICOM needs a viewer / PACS, not a second Dropbox page. PYCAD is not a Dropbox reseller and does not sign BAAs for anyone else’s storage.

At a glance

Requirement Compliant Not
Account Dropbox Business: Standard, Advanced, or Enterprise Free, personal, or Plus, for any PHI
BAA Signed with Dropbox, on that Business tenant Assuming the logo is enough, or a reseller’s BAA that is not Dropbox’s
Configuration MFA required, folder permissions, public links off, logs reviewed Default sharing, everyone is an editor
Training Staff know what may live here and what may not “They’ll figure it out”

Dropbox has offered BAAs on business tiers since November 2015. The BAA is the legal floor, not the finish. Dropbox holds the vault; you set the combination.

Configure it

  • MFA — required for every user, not optional. A stolen password is otherwise the whole tenant.
  • Permissions — minimum necessary. Viewer vs editor per folder. Few admins. No master-key groups “for convenience.”
  • Public links — off for any folder that might hold PHI. A public link is a breach the moment it is created.
  • Audit logs — who opened, downloaded, changed permissions, logged in from where. Read them. HIPAA’s accounting story dies if you cannot show this.

Third-party apps connected to the tenant are outside the Dropbox BAA. Each one needs its own, or it does not touch PHI. That is the usual silent hole.

Not for diagnostic DICOM

Dropbox will store a .dcm the way it stores a PDF. That is not a clinical system. There is no diagnostic viewer (window/level, measurements, multi-frame), studies are huge and slow as a folder of files, and the activity log is not a radiology audit. Put the CT in PACS or a web viewer built for it. Keep Dropbox for handbooks, policy drafts, de-identified research once it is actually de-identified, and marketing files.

FAQ

Can I encrypt the files myself and use a personal Dropbox?

No. Encryption is one control. The BAA is the legal control, and Dropbox only offers it on Business. A personal account with a password-protected zip is still willful use of a non-BA vendor.

What if someone shares a PHI folder with a public link?

That is a breach. Investigate scope, notify the individuals, report to HHS. This is why public links are disabled in the Admin Console, not left as a training topic.

Does the Dropbox BAA cover apps I connect?

No. The BAA covers data inside Dropbox. A connected editor, CRM, or e-sign tool is a new business associate. No BAA there, no PHI there.

Can we use Dropbox for diagnostic images?

Do not. Wrong tool: no viewer, no clinical audit, bad fit for study size. Admin files with a BAA, yes. Diagnostic DICOM, no.

PYCAD builds custom web DICOM viewers and imaging pipelines — not a Dropbox competitor and not a HIPAA-as-a-service. Case studies.

We build custom medical imaging platforms — advanced DICOM viewers, AI segmentation, and the clinical systems around them.

Get in Touch

Copyright © 2026 PYCAD. All Rights Reserved.