CompyMax

HIPAA compliant cloud storage

Where documents containing patient information end up. Sharing settings and connected third-party apps are the recurring gap.

Storage is where documents drift. A scanned referral goes into a folder, a link is shared to move it along, and the link keeps working long after the person who needed it has gone. Public or anyone-with-the-link sharing is the failure mode that recurs, because it is a two-click action available to every staff member and it leaves behind nothing that looks like a mistake.

Connected applications are the other half. A storage account is usually the hub every other tool plugs into, and vendors here are consistent in placing those third-party connections outside the agreement, which means coverage effectively ends the moment a file syncs somewhere else. A workable product gives an administrator real control: restrict external sharing, expire links, allowlist connected apps, prevent permanent deletion, and show an audit trail of who opened what.

6 file storage and sharing tools compared

6 of 6 can be used with patient information under a signed agreement. Each row is drawn from that vendor’s published documentation as read on the date shown — open an entry for the full conditions and sources.

VendorVerdictAgreement and planHow to get itNot coveredReviewed
BoxBox (Enterprise, Enterprise Plus, Enterprise Advanced)ConditionalBox Enterprise, Enterprise Plus or Enterprise AdvancedAdmin Console → Account & Billing → HIPAA Compliance → 'Request a HIPAA BAA' → complete the form → Continue.Box Personal, Starter and Business accounts.
DropboxDropbox team accountsConditionalTeam plans: Standard, Advanced, Business, Business Plus, Enterprise, Education and Dropbox Sign.US customers: Admin console → Settings → Account → Team profile → Advanced → 'Set up BAA'. Outside the US: email sales@dropbox.com.Dropbox Dash. Dropbox states Dash does not support compliance with HIPAA, including Dash in Dropbox.
Google DriveGoogle Drive on Google Workspace or Cloud IdentityConditionalGoogle Workspace or Cloud Identity. Google scopes coverage by service through Included Functionality rather than by subscription tier.Nothing to request and no signature to chase — a super administrator accepts it in the Admin console under Account settings → Legal and compliance.Drive on a personal Google account. The amendment is accepted in the Admin console, which a consumer account does not have.
OneDriveOneDrive for BusinessConditionalApplies by default to business and government Online Services customers. Coverage is scoped by service, not subscription tier.Nothing to request. Download the agreement from the Service Trust Portal.Consumer OneDrive on a personal Microsoft account — Microsoft's list names 'OneDrive for Business' specifically.
SpiderOakSpiderOak encrypted backup and storageConditionalNot stated. SpiderOak names no plan, and qualifies its support to 'certain customers'.SpiderOak's HIPAA page points to information on how to request a SpiderOak business associate agreement. Confirm eligibility for your account and product before relying on it.Customers SpiderOak does not accept. Its own wording limits support to certain customers.
TresoritTresorit encrypted cloud storageConditionalNot stated. Tresorit's security page says it signs agreements with customers seeking HIPAA compliance without naming a plan.Not described on the security page beyond the statement that Tresorit signs them. Request it through Tresorit sales or support before uploading patient data.Anything you copy out of Tresorit. The protection is a property of the store, not of the file.

What to check before you adopt one

  • Check whether an administrator can disable public or anyone-with-the-link sharing outright, rather than relying on each staff member to pick the right option every time.
  • Ask how permanent deletion works and whether you can stop staff destroying records you are obliged to keep for years.
  • Get the vendor's position on connected third-party apps in writing, since storage sits at the centre of everything and these connections are routinely outside scope.
  • Confirm the agreement is signed before you migrate, because several vendors state it must be in place before any patient files are transferred in.
  • Verify that the audit log records file access and sharing events, and that it is retained at least as long as your own record-keeping obligations.

The expensive mistake

Migrating years of scanned records into a new account first and sorting the paperwork out afterwards. Several vendors state plainly that the agreement must exist before patient files arrive, and a bulk upload is not something you can undo. The same mistake happens on downgrade: moving to a cheaper plan can end coverage while every file stays exactly where it is.

Tracking which of these your organization uses?

The vendor and BAA register keeps every tool that touches patient information, its agreement status and its renewal date in one place — seeded from this research. See pricing.

Information, not certification and not legal advice. Each entry reflects that vendor’s published documentation as read on the date shown on its page. Vendors change terms without notice — confirm anything you rely on directly with them.